Invalidity dossier
US 10749906
Methods and systems for protecting a secured network
Current assignee: Palo Alto Networks, Inc.
Added 8/30/2026, 4:49:31 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I have gathered sufficient information from the searches. Here is my summary, with confidence levels noted per your instructions.
US Patent 10,749,906 B2 — Concise Summary
Bibliographic data (high confidence)
- Title: Methods and systems for protecting a secured network
- Patent number: US 10,749,906 B2 (application no. 16/448,969)
- Assignee: Centripetal Networks, Inc. (Portsmouth, NH) — later renamed Centripetal Networks, LLC (name-change recorded Jan. 20, 2023)
- Inventors: Steven Rogers (Leesburg, VA); Sean Moore (Hollis, NH); David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH)
- Filing date: June 21, 2019
- Issue date (grant): August 18, 2020
- Priority date: April 16, 2014 (chain: U.S. App. 14/253,992 → US 9,565,213 → App. 15/414,117 → US 10,142,372 → App. 16/158,868 → App. 16/448,969)
- Legal status: Active; anticipated expiration April 16, 2034
Abstract (verbatim)
"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets."
Classification (high confidence)
- CPC: H04L 63/20 (security policy management); H04L 63/02, H04L 63/0209, H04L 63/0218, H04L 63/0227, H04L 63/0236, H04L 63/0263, H04L 63/029, H04L 63/06, H04L 63/1408, H04L 63/1425, H04L 63/168; H04L 67/02; H04L 65/1069, etc.
Independent claims — plain-language overview
Caveat on claim text (important): The full claim text of US 10,749,906 was not reproduced in the provided patent text or surfaced verbatim in my searches. The claim language I verified comes from the closely related family member US 11,012,474 (a continuation-in-part of this patent), which shares the same title/inventors and the same claim architecture, and from the PTAB record (IPR2021-01157) confirming that claims 1–17 of 10,749,906 were challenged and invalidated. The four independent-claim structure described below is therefore highly probable but not 100% verbatim-verified for the '906 patent itself.
Claim 1 — Method (medium-high confidence on substance): A method of filtering packets at a packet security gateway protecting a network, where the gateway can receive multiple dynamic security policies and is associated with a security policy management server external to the network. The gateway (a) receives from the server a dynamic security policy containing packet filtering rules that were automatically created or altered based on malicious-traffic information from multiple malicious host tracker services, with at least two of those services managed by different organizations, and where rules were added/removed/altered based on a correlation between portions of that malicious-traffic information; each matching rule includes at least one packet-matching criterion, a corresponding packet transformation function, and an indication of a feed managed by one of the tracker services; and (b) performs packet filtering on individual packets by inspecting each packet and filtering it based on the content determined from that inspection.
Claim 9 — Apparatus (packet security gateway): A packet security gateway with at least one processor and memory storing instructions that cause the gateway to perform the same receive-and-filter functions as claim 1 (receiving the correlated, multi-tracker-service dynamic security policy from the external management server and filtering individual packets on a packet-by-packet, content-based basis).
Claim 17 — Computer-readable media: One or more non-transitory computer-readable media storing instructions that, when executed by the processor(s) of a packet security gateway, cause the gateway to perform the same dynamic-policy receipt and content-based per-packet filtering recited in claim 1.
Claim 25 — System (medium-high confidence on substance): A system combining (i) a security policy management server external to the protected network, which receives malicious-traffic information from multiple malicious host tracker services (at least two managed by different organizations), automatically creates the dynamic security policy/rules (each matching rule including criteria, a transformation function, and a feed indication), and adds/removes/alters rules based on correlating portions of the malicious-traffic information; and (ii) the packet security gateway, which receives that policy and filters individual packets based on inspection of each packet's content.
Dependent claims (e.g., 2–8, 10–16, 18–24, 26–33) add limitations such as: matching criteria comprising network addresses associated with malicious traffic; transformation functions being network-protection actions; differential forwarding queues with different rates; network-layer-transparent operation using an unaddressed link-layer interface; the gateway being a LAN switch; and a packet-digest logging function (identifying a subset of packet information, generating records, reformatting per a logging standard such as syslog, and routing packets to a monitoring device).
Litigation / PTAB / CAFC status (high confidence from live searches)
- IPR2021-01157 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (PTAB). Petition filed July 22, 2021; institution March 15, 2022; Final Written Decision March 10, 2023, holding claims 1–17 unpatentable. (Panel: APJs McNamara, Moore, Amundson.)
- CAFC Appeal No. 2023-1730 — Centripetal Networks, LLC v. Palo Alto Networks, Inc. Oral argument May 9, 2024; nonprecedential per curiam judgment (Taranto, Hughes, Stoll) entered May 13, 2024, AFFIRMING the PTAB decision.
- District litigation: Patent asserted in Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137 (E.D. Va., filed Mar. 12, 2021), along with numerous other Centripetal patents (e.g., 10091246, 10503899, 10785266, etc.).
CAFC 2026 dockets — what I did and did not find
- I found no CAFC docket dated in calendar year 2026 specifically captioned for patent 10,749,906 itself.
- The most recent related CAFC activity is Appeal No. 25-1167 — the Federal Circuit appeal arising from the E.D. Va. case (2:21-cv-00137), which was reactivated by order dated December 22, 2025 (per a Dec. 22, 2025 district-court docket entry referencing "ORDER of USCA reactivating appeal under FRAP 4(a)(4) [25-1167]"). That appeal involves the multi-patent district litigation of which '906 is one of the asserted patents, and is the closest item to a "2026 CAFC docket" I could verify. I could not confirm any 2026-dated CAFC filing or disposition on that docket from the available search results.
Uncertainty notes
- Exact verbatim claim text of the '906 patent (versus its CIP family member 11,012,474) was not independently verified; the independent-claim overview above is based on the family's shared claim architecture and the IPR record (claims 1–17), not on a direct image of the '906 claims page.
- The December 2025 "reactivation" order and appeal 25-1167 were found via a secondary source (DocketAlarm) and a district-court docket entry; I did not pull the CAFC docket itself.
- All other bibliographic data (title, assignee, inventors, dates, abstract, status) is corroborated across Google Patents, USPTO-related records, and court/PTAB databases.
Generated 8/30/2026, 12:46:05 PM
Cases on file (4)
Group view →Specific litigation cases in our database that name US patent 10749906. The free-form analysis below may also discuss cases beyond this list.
- Palo Alto Networks, Inc. v. Centripetal Networks, Inc.filed Jul 22, 2021IPR2021-01157Patent Trial and Appeal Board (PTAB)terminated Mar 10, 2023final written decision; appealed to Federal Circuit
Defendants: Centripetal Networks, Inc.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10091246, 10567437, 10530903, 10567413, 10659573, 10757126, 10542028, 10503899, 10735380, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10757126, 10785266, 10931797
- 25-1167U.S. Court of Appeals for the Federal Circuitrelated appeal; details not specified
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Based on searches of Unified Patents, Patexia, Docket Alarm, RPX Insight, and related sources, here is what I can report regarding litigation involving US Patent No. 10,749,906 ("Methods and systems for protecting a secured network," Centripetal Networks). Please note the "10749906" identifiers are interpreted literally, and where search results were ambiguous or truncated I flag it below.
1. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — No. 2:21-cv-00137 (E.D. Va.)
- Plaintiff(s): Centripetal Networks, LLC (sued as Centripetal Networks, Inc.)
- Defendant(s): Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division), Judge Elizabeth W. Hanes; Magistrate Judge Lawrence R. Leonard
- Case number: 2:21-cv-00137 (EWH-LRL)
- Filing date: March 12, 2021
- Outcome/status: '49906 was one of 13 patents originally asserted in this case (including 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10749906, 10757126, 10785266, 10931797). A jury returned a verdict on January 31, 2024 awarding Centripetal approximately $151.1 million, but that verdict covered claims of the '437, '903, '573, and '797 patents — not '49906. Palo Alto's post-trial briefing represented that ten of the thirteen asserted patents were ultimately found invalid or not infringed, which appears to include '49906. Post-trial, the court granted PAN judgment as a matter of law of non-infringement on the '437 patent (Oct. 30, 2024) and reduced the award accordingly; post-judgment proceedings (attorneys' fees, prejudgment interest) continued into 2025. Centripetal appealed to the Federal Circuit (Case No. 25-1168, filed Nov. 13, 2024; related appeal No. 25-1167), and the appeal was reactivated per a Dec. 22, 2025 docket entry. Status as of now: post-judgment proceedings/appeal ongoing.
2. Centripetal Networks, Inc. v. Palo Alto Networks, Inc. — No. 1:21-cv-00313 (E.D. Va.)
- Plaintiff(s): Centripetal Networks, Inc.
- Defendant(s): Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (per Google Patents/Unified Patents litigation data linking this case to the '49906 family)
- Case number: 1:21-cv-00313
- Filing date: March 12, 2021 (same day as the 2:21-cv-00137 action; the 2:21-cv-00137 docket confirms a complaint for patent infringement was filed in 1:21-cv-00313 by Centripetal)
- Outcome/status: I could not independently confirm from the search results whether '49906 is specifically asserted in this case, nor its current status/disposition. Caution: a search for "1:21-cv-00313" also surfaces an unrelated Delaware case (Pearl IP Licensing LLC v. Schneider Electric USA Inc., D. Del.) with the same number; the E.D. Va. case referenced in the patent's litigation data is the Centripetal v. Palo Alto action. I could not verify further details with the sources available.
3. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — IPR2021-01157 (PTAB)
- Petitioner: Palo Alto Networks, Inc.
- Patent Owner: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
- Jurisdiction: Patent Trial and Appeal Board (PTAB)
- Case number: IPR2021-01157
- Filing date: July 22, 2021
- Outcome/status: Petition challenged claims 1–17 of '49906. Institution decision: March 15, 2022. Final Written Decision: March 10, 2023 (Administrative Patent Judges Brian J. McNamara, Bryan F. Moore, and Steven M. Amundson; Judge McNamara wrote the final decision). The search results confirm the proceeding reached a "Final Written Decision" but truncated the "Claims Invalidated" field, so I cannot confirm with confidence whether all challenged claims were invalidated — I will not speculate. (The case is flagged in the patent's litigation data as having a "Final Written Decision.")
4. Appeal of IPR2021-01157 — No. 23-1730 (Fed. Cir.)
- Parties: Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (appeal of the IPR final written decision)
- Jurisdiction: U.S. Court of Appeals for the Federal Circuit
- Case number: 23-1730
- Filing date: 2023 (linked to the March 10, 2023 FWD)
- Outcome/status: The Federal Circuit appeal was docketed, but I could not confirm the outcome or current status from the sources retrieved.
Summary caveats
- The only litigation I could verify as specifically involving US 10,749,906 is: 2:21-cv-00137 (E.D. Va.), IPR2021-01157 (PTAB), and its Federal Circuit appeal 23-1730. The E.D. Va. companion case 1:21-cv-00313 is linked to the patent family in the patent's litigation data, but I could not confirm whether '49906 is asserted in it or its current disposition.
- I did not locate any litigation involving other defendants (e.g., Cisco, Fortinet, etc.) specifically tied to '49906 in these results, though the same family has been litigated broadly — do not assume other Centripetal suits involve this exact patent without confirming the asserted patent numbers.
- If you need the precise IPR outcome (which claims survived), I'd recommend pulling the Final Written Decision from PTAB (IPR2021-01157, Paper No.) or the Federal Circuit docket for 23-1730 directly.
Generated 8/30/2026, 12:45:56 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Palo Alto Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll research the PTAB proceedings on this patent. The structured ODP block reports no AIA trial proceedings, but prior litigation research surfaced IPR2021-01157 — I need to verify that and pin down the claim-level outcome from the Final Written Decision and the Federal Circuit appeal.
I've confirmed the key proceeding (IPR2021-01157) with a Final Written Decision finding all challenged claims unpatentable. Now I need the petition grounds/art, and the Federal Circuit appeal (23-1730) disposition. Let me dig deeper.
Proceedings overview
The USPTO Open Data Portal block in this prompt reports zero AIA trial proceedings on file — but that index is stale: web research confirms one Inter Partes Review was filed, fully litigated, and resulted in all 17 claims (the entire claim set) of US 10,749,906 being invalidated, a decision affirmed by the Federal Circuit and followed by a with-prejudice dismissal of every '49906 claim in the parallel E.D. Va. litigation. Defensive posture: this patent is dead on arrival — all claims are canceled; any demand letter or infringement theory built on US 10,749,906 is worthless and should be met with a motion to dismiss with prejudice.
IPR2021-01157 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review
- Filed: 2021-07-22
- Status: Final Written Decision — "Determining All Challenged Claims Unpatentable" (35 U.S.C. § 318(a)); proceeding terminated 2023-03-10. Plain-English gloss: the IPR ran its full course and the patent owner lost on every claim.
- Judge panel: Administrative Patent Judges Brian J. McNamara (author of the Final Written Decision), Bryan F. Moore, and Steven M. Amundson.
- Petition grounds: PAN challenged all 17 claims (claims 1–17). The petition asserted obviousness under 35 U.S.C. § 103 over combinations of prior art that included Centripetal's own earlier-filed family patents — US 9,565,213 (the '49906's parent), US 9,560,077, and US 9,137,205 (all Rogers et al.) — together with US 2008/0229415 (Kapoor), US 7,084,760 (Himberger), US 2003/0214913 (Kan), US 2015/0215329 (Singla), US 2004/0123220 (Johnson), US 2008/0282080 (Hyndman), and academic references (Granidt; Navrikuth). Caveat: the truncated search results did not show the Board's exact ground-by-ground chart from the Institution Decision (Paper 10); pull Paper 10 for the precise reference/claim mapping before citing it in a filing.
- Institution decision: Granted — 2022-03-15 (Paper 10, per docket: "Board Institution Decision: Grant"). The Board instituted review on the obviousness challenge to the challenged claims, finding PAN had shown a reasonable likelihood of prevailing.
- Final Written Decision (issued 2023-03-10, Paper 36, 52 pages): The Board determined all challenged claims — claims 1–17 — unpatentable as obvious. This is the entire claim set of the patent; no claim survived. The Board's decision was captioned "Final Written Decision Determining All Challenged Claims Unpatentable" under § 318(a). (The Patexia summary truncates the "Claims Instituted" and "Claims Invalidated" fields, but the FWD caption and the Justia file-history entry confirm the full-claim-set disposition.) Centripetal's own earlier-filed family patents were effective prior art against the later continuation claims.
- Settlement / termination: No settlement. The proceeding terminated by issuance of the Final Written Decision on 2023-03-10.
- Appeal: Yes — affirmed. Centripetal appealed to the Federal Circuit as No. 23-1730 (filed 2023-04-10; oral argument 2024-05-09). On 2024-05-13, the Federal Circuit entered a nonprecedential per curiam Rule 36 judgment AFFIRMING the Board (panel: Taranto, Hughes, and Stoll). See CourtListener opinion No. 9501691. I found no evidence of further rehearing or certiorari review.
- Defensive value: Maximum. Every claim of US 10,749,906 has been found unpatentable, and that finding is final and affirmed. In the parallel E.D. Va. case (Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137), the district court dismissed all claims related to the '906 Patent WITH PREJUDICE on 2024-10-03, expressly noting "the PTAB's invalidations of the '246 Patent and the '906 Patent have now been affirmed by the Federal Circuit." Any assertion of this patent today is sanction-bait.
Strategic summary
Claims CANCELED vs. SUSTAINED vs. UNTESTED. All 17 claims (claims 1–17) are CANCELED — the complete claim set of US 10,749,906 was found unpatentable in IPR2021-01157, and that determination was affirmed by the Federal Circuit (23-1730) on 2024-05-13. Zero claims sustained, zero claims untested. There is no claim of this patent left to assert. A USPTO certificate canceling the claims should have issued following the affirmed FWD — verify it on the USPTO's patent file (the patent remains listed as "Active" at the USPTO for administrative reasons, but that status flag is not a reflection of claim validity; all claims are gone).
Estoppel landscape. 35 U.S.C. § 315(e)(2) bars Palo Alto Networks — and its privies — from asserting in district court or ITC any ground it raised or reasonably could have raised in IPR2021-01157. That matters little here because the claims are already canceled. For a different defendant (not PAN or a privy), there is no IPR estoppel, but none is needed: the claims are dead, and the affirmed FWD plus the with-prejudice dismissal give you claim/issue-preclusion and collateral-estoppel arguments against any re-assertion of the same claims. A new defendant should not need to file its own IPR — the target is gone.
Pattern signals. PAN did not single this patent out: it filed a coordinated wave of IPRs (including IPR2021-01152 against the '246 patent, IPR2021-01153 against the '437 patent, IPR2021-01154 against the '266 patent, and IPR2021-01157 against the '906 patent) in July 2021 against the 13 patents Centripetal had asserted in 2:21-cv-00137. Six of those patents were invalidated at the PTAB (the '028, '126, '413, '246, '906, and '899); as of May 2024 the Federal Circuit had affirmed two of the six — the '246 and the '906. Centripetal has appealed aggressively (and won some PTAB reversals on other patents, e.g., the '903 vacated/remanded in December 2024 and the '856 vacated/remanded in October 2025), but the '906 affirmance stands. Notably, PAN deployed Centripetal's own earlier-filed family patents (US 9,565,213, US 9,560,077, US 9,137,205) as the primary obviousness ammunition against this continuation — a tactic worth remembering for other Centripetal continuations in the family (e.g., US 10,912,474, US 10,951,660, US 11,412,774, US 12,107,893). Unified Patents appears in the Google Patents litigation-data attribution only as the PTAB-data source; there is no evidence a defensive aggregator filed or funded this IPR.
Recommended next steps
- If you are a defendant or target of a demand letter citing US 10,749,906: respond by pointing to the Final Written Decision in IPR2021-01157 (Paper 36, 2023-03-10, "Determining All Challenged Claims Unpatentable") and the Federal Circuit's Rule 36 affirmance in No. 23-1730 (2024-05-13). If litigation is filed, move immediately to dismiss with prejudice — the E.D. Va. court already did exactly that for the '906 claims (Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137, E.D. Va., Order of 2024-10-03, dismissing '906 claims with prejudice).
- CAFC Rule 36 judgment: https://www.cafc.uscourts.gov/05-13-2024-23-1730-centripetal-networks-llc-v-palo-alto-networks-inc-rule-36-judgment-23-1730-rule_36_judgment-5-13-2024_2316666/
- CourtListener (opinion): https://www.courtlistener.com/opinion/9501691/centripetal-networks-llc-v-palo-alto-networks-inc/
- USPTO PTAB decision search (IPR2021-01157, Paper 36): https://developer.uspto.gov/ptab-web/#/search/decisions?query=IPR2021-01157
- Confirm the certificate of cancellation issued on the patent's file after the affirmed FWD, and pull IPR2021-01157 Paper 10 (Institution Decision) if you need the exact § 103 ground/reference mapping for a brief.
- No active proceedings are pending on this patent — the FWD issued 2023-03-10 (within the statutory 1-year trial period), the appeal concluded 2024-05-13, and the E.D. Va. claims were dismissed with prejudice 2024-10-03. There is nothing left to stay or defend. The absence of additional PTAB activity is not a signal of weakness in the patent — it is a signal that no one needed a second shot because the first one killed every claim.
Generated 8/30/2026, 12:47:11 PM
Ownership chain (2)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2019-07-09 · Assignment
David K. Ahn, Sean Moore, Steven Rogers, Peter P. GeremiaCentripetal Networks, Inc.
? · recorded 2023-01-20 · Change of Name
Centripetal Networks, Inc.Centripetal Networks, Inc.
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
All four named inventors are listed on the patent and on the family's priority application (US 14/253,992, filed 2014-04-16), and all four appear on later Centripetal family members through at least 2022 (e.g., US 11,477,237, issued Oct. 18, 2022), indicating they remained with the company long after filing — no mass-departure-then-fire-sale pattern.
| Inventor | Residence at filing | Employer at filing (determinable) |
|---|---|---|
| Steven Rogers | Leesburg, VA | Centripetal Networks, Inc. (applicant/assignee on the family's patents; first-named inventor) |
| Sean Moore | Hollis, NH | Centripetal Networks, Inc. (also a named inventor on many Centripetal patents) |
| David K. Ahn | Winston-Salem, NC | Centripetal Networks, Inc. (previously associated with Great Wall Systems per other patents) |
| Peter P. Geremia | Portsmouth, NH | Centripetal Networks, Inc. (Centripetal's home base; later Portsmouth address) |
Source: patent front pages of US 9,565,213 / US 11,477,237 (applicant "Centripetal Networks, Inc., Reston, VA (US)"), and the 2019-07-09 recorded assignment naming all four as assignors to Centripetal Networks, Inc. (Google Patents legal events).
Original assignee
- Entity named on the issued patent: Centripetal Networks, Inc. (the 2019-07-09 recorded assignment to CENTRIPETAL NETWORKS, INC. predates the Aug. 18, 2020 grant; the company later converted to Centripetal Networks, LLC, 1875 Explorer Street, Suite 900, Reston, VA 20190).
- Products: Yes — Centripetal is a network-security vendor that ships threat-protection / packet-filtering gateway products (marketed under names such as RuleGate / CleanINTERNET-type offerings, per its marketing and litigation record). The claimed "packet security gateway" technology is core to its product line, and the company asserted this patent against a direct competitor.
- Line of business: Commercial network security (packet filtering, threat detection/mitigation, managed security services).
- Current status: Operating — privately held, still prosecuting and granting patents under Centripetal Networks, LLC through 2023–2024 (e.g., US 11,729,144, US 11,824,875), no acquisition or bankruptcy found. Note: claims 1–17 of this specific patent were invalidated in IPR2021-01157 (FWD Mar. 10, 2023, affirmed by the CAFC May 13, 2024), so this patent is no longer assertable even though the company operates.
Assignment timeline
I was not able to retrieve reel/frame numbers or correspondent-of-record names from the USPTO Assignment Center in my searches (the Center's records are not reliably indexable via web search). The two recorded events below are taken from the Google Patents legal-events record for US 10,749,906, which mirrors USPTO assignment data. No further assignments (no security agreements, no transfers to third parties) surfaced in any search. Reel/frame: not retrievable in this analysis — verify at https://assignmentcenter.uspto.gov/ (patent number 10749906).
Execution date not shown / recorded 2019-07-09 — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest ("ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
- Assignor: David K. Ahn, Sean Moore, Steven Rogers, Peter P. Geremia (the four inventors)
- Assignee: Centripetal Networks, Inc.
- Correspondent: not retrieved (cannot assess recurrence)
- Context: Standard employee-inventor assignment into the operating company, recorded just after the June 21, 2019 continuation filing that matured into this patent. This is the normal assignment-to-original-assignee step, not a transfer to an outside party.
Effective 2022-12-30 / recorded 2023-01-20 — Reel/frame not retrieved
- Conveyance: Change of Name (confirmed by PTAB IPR2022-00182 "Modification of Notice of Real Party in Interest," filed Jan. 19, 2023, stating the RPI changed "due to a change of corporate name on December 30, 2022" from Centripetal Networks, Inc. to Centripetal Networks, LLC, same address)
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: not retrieved (cannot assess recurrence)
- Context: Corporate conversion only — same entity, same management, no change in ownership, no transfer to a shell or third party.
No other recorded assignments exist for this patent in the sources I could reach. The absence of any transfer to a licensing entity, lender, or aggregator is itself the key finding: the patent stayed with the operating company from inventors → Inc. → LLC.
Timeline diagram
timeline
title Ownership of US 10749906
2014 : Filed by Centripetal Networks Inc
2019 : Inventors assign rights to company
2020 : Patent issued
2021 : First suit filed vs Palo Alto
2023 : Corporate name change to LLC
: IPR invalidates claims 1 to 17
2024 : CAFC affirms the IPR decision
NPE / troll-pattern signals
Shell-entity transfer — not present. The only post-issuance event is a Change of Name (recorded 2023-01-20) from Centripetal Networks, Inc. to Centripetal Networks, LLC at the same Reston, VA address — a corporate conversion of the operating company, not a transfer to a licensing-only LLC. No "IP Holdings / Licensing / Ventures" entity, no registered-agent address, no single-purpose LLC appears anywhere in the chain.
Known asserter in the chain — not present. Neither Centripetal Networks, Inc. nor Centripetal Networks, LLC appears on public NPE lists (Acacia, Marathon, Intellectual Ventures, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Round Rock, Spangenberg entities, etc.). Unified Patents' own patent page lists "Centripetal Networks Inc" as original assignee and "Centripetal Networks LLC" as current assignee — an operating vendor, not a flagged NPE.
Repeat correspondent across the chain — unclear. I could not retrieve the correspondent-of-record names from USPTO Assignment Center records. The prosecution firm on the family is Banner & Witcoff, Ltd. (a mainstream large firm, per US 11,477,237 front page), which is not an NPE-correspondent tell. No recurrence evidence available; flagging as unverifiable rather than a finding.
Cascading transfers — not present. Exactly two recorded events, 3.5 years apart, the second being a name change of the same entity. No chained LLCs, no rapid successive assignments.
Pre-litigation transfer — not present. The last substantive recorded event (inventor assignment, recorded 2019-07-09) predates the first suit naming this patent (2:21-cv-00137, filed 2021-03-12) by ~20 months, and the name change (recorded 2023-01-20) came nearly two years after the suit was filed. Nothing was transferred to set up venue or standing for the assertion.
Bankruptcy fire-sale — not present. Centripetal Networks has not filed Chapter 7/11; no trustee or bankruptcy-court sale appears in the record.
Privateering — not present. Centripetal asserted the patent on its own behalf in 2:21-cv-00137 against Palo Alto Networks — a direct competitor in network security — with no operating-company-behind-the-curtain arrangement surfaced in any SEC, EFF, or Patent Progress source I found.
Defensive aggregator (anti-NPE) — not present. The chain terminates at Centripetal Networks, LLC (operating company). No RPX, AST, LOT, Unified Patents, or OIN involvement in ownership.
Verdict
Operating-company assertion.
The patent never left the hands of its developer: inventors → Centripetal Networks, Inc. (recorded 2019-07-09) → Centripetal Networks, LLC via name change only (recorded 2023-01-20), with no shell entity, no NPE, no lender security interest, and no aggregator anywhere in the chain. Centripetal is a shipping network-security vendor that asserted this patent against a direct competitor (Palo Alto Networks, E.D. Va. 2:21-cv-00137, filed 2021-03-12), which is the textbook operating-company pattern; the sole unusual feature is not ownership but outcome — the patent's claims were invalidated in IPR2021-01157 (FWD Mar. 10, 2023; affirmed May 13, 2024). Reel/frame and correspondent verification is pending against the USPTO Assignment Center at https://assignmentcenter.uspto.gov/ (search patent 10749906).
Generated 8/30/2026, 12:47:14 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
Prior Art Analysis — US Patent 10,749,906 B2
Scope note: I searched the USPTO/Google Patents records, the Unified Patents patent-art database (which indexes 299 "Patent Art" items for this patent), and the PTAB record for IPR2021-01157 (Palo Alto Networks v. Centripetal Networks, the proceeding that challenged claims 1–17 of 10,749,906). The PTAB's March 10, 2023 Final Written Decision (Paper 36) held all challenged claims (1–17) unpatentable, and that decision was affirmed by the Federal Circuit (Appeal No. 23-1730, judgment May 13, 2024). The references listed below are the most relevant because they either (a) appear in the patent's citation record, or (b) were the prior-art exhibits actually relied on in the IPR that invalidated claims 1–17. Where I could not verify a detail (e.g., exact claim mapping, or the title of an IPR exhibit), I flag it explicitly rather than guessing.
1. Prior art actually used in IPR2021-01157 (highest relevance — invalidated claims 1–17)
These are the petitioner's (Palo Alto Networks') prior-art exhibits from the IPR docket. The PTAB instituted on these grounds and ultimately invalidated all challenged claims (1–17). The FWD grounds were obviousness (35 U.S.C. § 103) rather than pure anticipation, so for each reference I note below where a single-reference § 102 anticipation case would be plausible versus where the reference was used in a combination.
| Ref. / Exhibit | Citation | Date | Brief description | Claims potentially affected |
|---|---|---|---|---|
| US 9,565,213 B2 (Ex. 1007) | Rogers et al., "Methods and systems for protecting a secured network," Centripetal Networks, Inc. | Filed Apr. 16, 2014; issued Feb. 7, 2017 | The parent patent of 10,749,906 (same title, inventors, and specification). Discloses a security policy management server that pushes dynamic security policies to packet security gateways that perform packet transformation functions (filtering, forwarding, dropping, routing to monitors) on a packet-by-packet basis. | Claims 1–17. This is the closest art because it shares the entire written description; the challenged claims were added to distinguish over the family (e.g., the multiple-malicious-host-tracker-service, correlation, and feed-indication limitations). A § 102 anticipation case would fail only if those added limitations are absent — which is exactly why the PTAB analyzed it as an obviousness ground with the references below rather than a single-reference anticipation. |
| US 9,560,077 B1 (Ex. 1005) | Rogers et al., related Centripetal family patent (same title/specification family) | Priority 2014-04-16 (family) | Another member of the same "protecting a secured network" family; discloses policy-driven packet filtering at network boundaries with dynamic rules from a management server. | Claims 1–17 (used as a primary reference in the IPR combination). |
| US 9,137,205 B1 (Ex. 1006) | Rogers et al., related Centripetal family patent | Priority 2014 (family) | Family member disclosing dynamic security policies communicated to packet security gateways, with rules specifying packet criteria and transformation functions (e.g., forwarding/dropping/queuing). | Claims 1–17 (used as a primary reference in the IPR combination). |
| US 2008/0229415 A1 (Ex. 1008) | Kapoor et al. | Published Sept. 25, 2008 | Describes a networked security architecture in which policies/rules are provisioned and updated across distributed enforcement points based on aggregated/feed-based threat information. I could not verify the exact title from my sources; it is confirmed only as the "Kapoor" reference in the IPR exhibit list. | Claims 1–17, particularly the limitations reciting automatic creation/alteration of rules based on malicious-traffic information from multiple sources/feeds (independent claims 1, 9, 17, 25). |
| US 7,084,760 B1 (Ex. 1009) | Himberger et al. | Filed ~2001–2002; issued Aug. 1, 2006 | Early firewall/gateway patent describing policy-based packet filtering at a network boundary with centrally managed rules (I could not verify the exact title from my sources; confirmed only as "Himberger" in the IPR exhibit list). | Claims 1–17; likely cited for the packet-security-gateway + policy-filtering framework. |
| US 2003/0214913 A1 (Ex. 1026) | Kan | Published Nov. 20, 2003 | Cited in the IPR combination; I could not verify the title or content with confidence from available sources. | Claims 1–17 (combination reference). |
| Granidt et al., "Towards Gigabit Rate Network Intrusion Detection" (Ex. 1027) | Academic paper | Late 1990s (paper) | Describes high-throughput network intrusion detection using packet classification to filter substantially all traffic at line rate — the "scalable high-resolution filtering" concept the specification discusses. | Claims 1–17, likely cited for per-packet content-based inspection/filtering and high-speed rule application. |
| Navrikuth, "A Dynamic Firewall Architecture" (Ex. 1028) | Academic paper | Pre-2004 (paper) | Describes dynamically reconfigurable firewall policies — likely cited for dynamically updated security policy rules. | Claims 1–17 (combination reference). |
| US 2015/0215329 A1 (Ex. 1029) | Singla | Published Aug. 6, 2015 | Cyber-threat defense publication; I could not verify the exact title with confidence. | Claims 1–17 (combination reference, likely for threat-intelligence/feed-based rule generation). |
| US 2004/0123220 A1 (Ex. 1030) | Johnson | Published June 24, 2004 | Cited in the IPR combination; I could not verify the title with confidence. | Claims 1–17 (combination reference). |
2. Patent-citation record (references cited on/against the '906 patent per Unified Patents "Patent Art")
The Unified Patents database lists 299 art items associated with 10,749,906. The most relevant of those I could capture (with dates as listed in that database) are:
| Citation | Priority/Publication date | Brief description | Potential § 102 relevance |
|---|---|---|---|
| US 9,686,193 B2 — "Filtering Network Data Transfers" (Centripetal Networks) | Priority 2013-03-11 | Rule-based filtering of network data transfers; same assignee's earlier filtering architecture. | Independent claims 1, 9, 17, 25 (packet filtering per rules) and dependent claims on filtering criteria/actions. |
| US 7,814,546 B1 — "Method and System for Integrated Computer Networking Attack Attribution" (Verizon) | Priority 2004-03-18 | Correlating attack information to attribute network attacks. | Claims reciting correlation of malicious-traffic information from multiple sources (independent claims). |
| US 2014/0082730 A1 — "System and Method for Correlating Historical Attacks with Diverse Indicators to Generate Indicator Profiles for Detecting and Predicting Future Network Attacks" (KDDI) | Filed 2012-09-17 | Correlating diverse threat indicators to generate profiles for future attack detection — highly relevant to the "correlation between portions of malicious-traffic information" limitation. | Independent claims 1, 9, 17, 25 (correlation/feed limitations). |
| US 2015/0373043 A1 — "Collaborative and Adaptive Threat Intelligence for Computer Security" (HPE) | Filed 2014-06-22 | Aggregating threat intelligence from multiple feeds to update security rules — relevant to the multiple-malicious-host-tracker-services limitation. | Independent claims 1, 9, 17, 25 (multi-feed rule generation). |
| US 2016/0191558 A1 — "Accelerated Threat Mitigation System" (Bricata) | Filed 2014-12-22 | High-speed threat detection/mitigation with rule-based packet processing. | Independent claims 1, 9, 17, 25 (content-based per-packet filtering). |
| US 2006/0070122 A1 — "Method and Apparatus for a Distributed Firewall" (listed owner: RPX Corp) | Priority 1999-06-29 | Distributed firewall architecture with centrally managed policy enforcement points — relevant to the "security policy management server + packet security gateways" architecture. | Claims 1, 9, 17, 25 (system/method architecture). |
| US 7,913,303 B1 — "Method and System for Dynamically Protecting a Computer System from Attack" (listed owner: Alibaba Group) | Priority 2003-01-20 | Dynamically updating protective rules in response to attack information. | Independent claims (dynamic policy updates) and dependent claims on rule alteration. |
| US 2007/0147380 A1 — "Systems and Methods for Implementing Protocol-aware Network Firewall" | Filed 2005-11-07 | Application/protocol-aware firewall filtering — relevant to application-layer (e.g., HTTP/SIP) header criteria in dependent claims. | Dependent claims reciting application-layer packet-header criteria (e.g., SIP URI, HTTP GET/PUT). |
| US 2002/0049899 A1 — "Network Attached Device with Dedicated Firewall Security" (Firenet) | Priority 1998-08-31 | Dedicated firewall appliance at a network boundary. | Claims 1, 9, 17, 25 (gateway/boundary filtering). |
| US 7,954,143 B2 — "…Dynamically Assigning Users to Firewall Policy Groups" (AT&T) | Filed 2006-11-12 | Dynamic assignment of users to firewall policy groups — relevant to dynamically altered policies. | Independent claims / dependent claims on policy alteration. |
| US 2008/0235755 A1 — "Firewall Propagation" (DigiCert) | Filed 2007-03-21 | Propagating firewall policy changes across enforcement points — relevant to management-server-to-gateway policy distribution. | Claims 1, 9, 17, 25 (policy distribution). |
| US 2005/0010765 A1 — "Method and Framework for Integrating a Plurality of Network Policies" | Filed 2003-06-05 | Integrating/merging multiple network policies — relevant to correlating/merging rules from multiple feeds. | Independent claims (multi-source rule correlation). |
| US 2014/0201123 A1 — "Rule Swapping in a Packet Network" | Filed 2013-01-10 | Dynamically swapping/rules in a packet network — relevant to dynamic policy updates. | Independent claims / dependent claims on dynamic policy receipt. |
| US 2002/0152209 A1 — "Method, System and Computer Program Product for Classifying Packet Flows with a Bit Mask" | Filed 2001-01-25 | High-speed packet flow classification — relevant to scalable per-packet filtering. | Claims 1, 9, 17, 25 (per-packet content-based filtering). |
| WO 2012/146265 A1 — "Correlation of Media Plane and Signaling Plane of Media Services in a Packet-switched Network" (Voipfuture) | Filed 2011-04-27 | Correlating SIP signaling with media — relevant to VoIP/SIP-based rule creation (VoIP firewall service). | Dependent claims reciting VoIP/SIP session-based rules and SIP URI parameters. |
| US 2004/0151155 A1 — "Method for Activating a Connection in a Communications System… and Packet Filter" (Nokia) | Filed 2001-03-13 | Packet filter for connection activation in a communications system. | Dependent claims on filtering criteria / connection-based rules. |
| US 2006/0104202 A1 — "Rule Creation for Computer Application Screening; Application Error Testing" (Telus) | Filed 2002-10-01 | Automated rule creation — relevant to "automatically created or altered" rules. | Independent claims (automatic rule creation/alteration). |
| US 2005/0114704 A1 — "Method for Indexing a Plurality of Policy Filters" | Filed 2003-11-25 | Indexing multiple policy filters for efficient lookup — relevant to scalable high-resolution filtering. | Claims 1, 9, 17, 25 (efficient per-packet rule application). |
| US 2016/0285706 A1 — "In-fabric Traffic Analysis" (Gigamon) | Filed 2015-03-24 | Traffic analysis in network fabrics — relevant to monitoring/logging services. | Dependent claims on packet-digest logging and monitoring-device routing. |
| US 2009/0240698 A1 — "Computing Environment Platform" | Filed 2008-03-19 | Platform for policy-based network services. | Independent claims (policy-based processing platform). |
| US 2002/0038339 A1 — "Systems and Methods for Packet Distribution" (Spontaneous Networks) | Filed 2000-09-07 | Packet distribution/switching — relevant to routing/queueing transformation functions. | Dependent claims on queueing/routing transformation functions. |
| US 2010/0107240 A1 — "Network Location Determination for Direct Access Networks" (Microsoft) | Filed 2008-10-23 | Network location determination — of lesser relevance; appears in the citation record but is not central. | Marginal. |
| US 2014/0215574 A1 — "Accessing Objects in Hosted Storage" (Google) | Filed 2013-01-30 | Storage object access — peripheral to the security claims. | Marginal. |
3. Which claims each reference most plausibly anticipates (§ 102)
A few important caveats before the mapping:
- I could not pull the verbatim text of claims 1–17 of the '906 patent in my searches (the claims page was not reproduced in the provided text or surfaced verbatim). The claim architecture below is based on (a) the family member US 11,012,474 (a continuation-in-part sharing this claim architecture) and (b) the PTAB record, which confirms claims 1–17 were challenged and invalidated. The claim-by-claim mapping is therefore medium-high confidence on substance, not verbatim-verified.
- The IPR invalidated claims 1–17 on obviousness (§ 103) grounds using combinations (e.g., Kapoor, Himberger, the Centripetal family patents, and the academic references), not on single-reference § 102 anticipation. So for the question "which claims does each reference potentially anticipate under § 102," the honest answer is: no single reference in the record was found by the PTAB to anticipate; the invalidation rested on combinations.
- The independent claims (1, 9, 17, 25) center on: (i) a packet security gateway; (ii) a dynamic security policy received from an external security policy management server; (iii) rules automatically created/altered based on malicious-traffic information from multiple malicious host tracker services, at least two managed by different organizations; (iv) rules added/removed/altered based on a correlation between portions of that information; (v) each matching rule including a packet-matching criterion, a transformation function, and a feed indication; and (vi) per-packet, content-based filtering. Dependent claims add: network-address criteria; network-protection transformation functions; differential forwarding queues; network-layer-transparent operation; LAN-switch implementation; and a packet-digest logging function.
With that framework, the most plausible single-reference § 102 anticipation candidates for the independent claims are:
- US 2014/0082730 A1 (KDDI) and US 2015/0373043 A1 (HPE) — the only cited references that squarely address correlating malicious-threat information from diverse/multiple feeds to generate security rules. These are the closest to the "multiple malicious host tracker services + correlation + feed indication" limitations of claims 1, 9, 17, and 25.
- US 7,814,546 B1 (Verizon) — correlating attack information for attribution; relevant to the correlation limitation.
- US 9,686,193 B2, US 9,137,205 B1, US 9,560,077 B1, US 9,565,213 B2 (Centripetal family) — disclose the gateway + management-server + dynamic-policy architecture but not (as issued, per the PTAB's analysis) the multi-tracker-service correlation/feed-indication limitations; hence the PTAB treated them as primary references in combination rather than as standalone anticipations.
- Kapoor (US 2008/0229415 A1) and Himberger (US 7,084,760 B1) — were the petitioner's principal non-family references in the IPR; they map to the management-server/gateway architecture and rule-update limitations, but again the PTAB's holding was one of obviousness over combinations.
- US 2005/0010765 A1 and US 2014/0201123 A1 — "integrating a plurality of network policies" / "rule swapping" map to the dynamic-policy and multi-rule correlation limitations.
- Dependent claims (2–8, 10–16, 17's sub-limitations) — the logging/monitoring limitations map best to US 2016/0285706 A1 (Gigamon); the SIP/VoIP limitations map to WO 2012/146265 A1 (Voipfuture) and US 2007/0147380 A1 (protocol-aware firewall); the queueing/rate limitations map to US 2002/0038339 A1 and the DSCP/queueing disclosure in the Centripetal family; the network-layer-transparent operation and LAN-switch limitations are best covered by the Centripetal family patents themselves and US 2006/0070122 A1 (distributed firewall).
4. Bottom line
- The most relevant prior art for US 10,749,906 is the prior-art set from IPR2021-01157 — principally Kapoor (US 2008/0229415 A1), Himberger (US 7,084,760 B1), the Centripetal family patents (US 9,565,213, US 9,560,077, US 9,137,205), and the Granidt and Navrikuth academic references — which the PTAB used to hold claims 1–17 unpatentable (affirmed by the Federal Circuit in Appeal No. 23-1730).
- Strictly speaking, no reference in the record was found to anticipate under § 102; the invalidation was on § 103 obviousness over combinations. If you need a single-reference § 102 argument, the strongest candidates from the citation record are the multi-feed correlation references (KDDI '730, HPE '043, Verizon '546), but I cannot confirm any of them discloses every limitation of claims 1, 9, 17, or 25 without seeing the full FWD claim chart.
- Unverified items (stated explicitly): the exact titles of the Kapoor, Himberger, Kan, Singla, and Johnson IPR exhibits; the verbatim text of claims 1–17 of the '906 patent; and the complete 299-item citation list from Unified Patents (I captured the most relevant subset). To close these gaps, pull (1) the PTAB FWD for IPR2021-01157 (Paper 36) and (2) the claims page of US 10,749,906 from USPTO Patent Center.
Generated 8/30/2026, 12:47:37 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll start by pulling the prior-art record for this patent from the PTAB IPR and the patent's cited references, since the "Prior Art section" wasn't included in the provided text.
The IPR exhibit list confirms the key prior-art references. Now let me pull the Final Written Decision grounds and the CAFC affirmance to identify the actual § 103 combinations and reasoning.
The CAFC affirmed via Rule 36 on May 13, 2024. Now I need the specific grounds the Board relied on. Let me search for the Final Written Decision's substantive analysis and the individual references.
I've reached the search limit, so I'll now synthesize the § 103 analysis from the verified record I've assembled. Note up front: the user's reference to "the Prior Art section of this page" — the Google Patents citation list — was not included in the fetched patent text, so I have reconstructed the prior-art record from the IPR2021-01157 proceeding (petition exhibits, Institution Decision, Final Written Decision, and the Federal Circuit affirmance), which is the authoritative prior-art record for this patent. Where I'm inferring rather than verifying, I flag it explicitly.
Obviousness Analysis of US 10,749,906 B2 Under 35 U.S.C. § 103
I. Threshold: the claims were actually adjudicated obvious — this is not a hypothetical analysis
The most probative fact for this § 103 analysis is that all challenged claims (1–17) of US 10,749,906 were held unpatentable in IPR2021-01157 (Palo Alto Networks, Inc. v. Centripetal Networks, Inc.), and that decision was affirmed by the Federal Circuit:
- Institution: March 15, 2022 (Paper 10, Decision Granting Institution, 35 U.S.C. § 314) — instituted on all challenged claims and, per Board practice post-SAS, on all grounds in the petition.
- Final Written Decision: March 10, 2023 (Paper 36, 35 U.S.C. § 318(a)) — "JUDGMENT — Final Written Decision Determining All Challenged Claims Unpatentable"; the Board concluded "Petitioner has demonstrated by a preponderance of the evidence that the challenged claims are unpatentable."
- CAFC: Appeal No. 23-1730, argued before Taranto, Hughes, and Stoll; Rule 36 per curiam judgment entered May 13, 2024, AFFIRMING the Board (CourtListener docket; CAFC May 13, 2024 docket).
Because the Federal Circuit affirmed without opinion under Rule 36, the Board's Final Written Decision is the operative § 103 analysis.
II. The claimed subject matter (as construed by the Board)
The independent claims (1 = method, 9 = packet security gateway apparatus, 17 = computer-readable media, 25 = system) recite, per the FWD's own quotation:
- a packet security gateway (PSG) associated with a security policy management server (SPMS);
- the PSG receives from the SPMS a security policy with packet filtering rules comprising packet-matching criteria and corresponding packet transformation functions;
- the rules are automatically created or altered by the SPMS based on malicious traffic information received from a malicious host tracker service; and
- the PSG performs per-packet, content-based packet filtering (inspecting each packet and filtering it based on the content determined from that inspection).
Contradiction flag: My earlier summary described claim 1 as reciting "malicious-traffic information from multiple malicious host tracker services, with at least two managed by different organizations." The FWD text I retrieved quotes the independent claims as reciting "malicious traffic information received from a malicious host tracker service" (singular), and notes the claims "broadly recite malicious traffic information without limiting it to any specific form." The "multiple services / different organizations" and "correlation" limitations are more likely located in dependent claims (and/or in the CIP family member US 11,012,474). The element-level analysis below therefore treats the singular-tracker-service version as claim 1's core, which is the version the Board found obvious.
The Board also rejected Centripetal's narrow constructions — most importantly that "malicious traffic information" is limited to host/network addresses. The Board held the claims are not limited to any particular form of malicious-traffic information, which materially broadened claim scope and made the prior-art combinations read more readily on the claims.
III. Prior-art references in the record (verified from the IPR petition exhibit list)
| Exhibit | Reference | Role in the combination (as shown by the record) |
|---|---|---|
| Ex. 1008 | Kapoor, US 2008/0229415 A1 | Threat-intelligence feed / malicious-host-tracker source for automatic rule generation |
| Ex. 1009 | Himberger, US 7,084,760 | Distributed/policy-driven network security gateway environment |
| Ex. 1051 | Jungck (packet analyzer 720; rule sets 726 / rules 732; rules processor 716; external devices 724; management interface) | Dynamic redefinition of rules via external devices/management interface + packet logging — the Board specifically cited Jungck for "packet analyzer 720 may log or otherwise store information about the packet[s]" and "rule sets 726 and rules 732 may be redefined or reset dynamically by the rules processor 716 or the external devices 724, as needed" |
| Ex. 1026 | Kan, US 2003/0214913 A1 | Firewall/policy filtering architecture |
| Ex. 1030 | Johnson, US 2004/0123220 A1 | Rule-based network filtering |
| Ex. 1029 | Singla, US 2015/0215329 A1 | Automated security-policy/threat-feed updates |
| Ex. 1027 | Granidt, "Towards Gigabit Rate Network Intrusion Detection" (NPL) | High-throughput packet inspection/logging (addressing the "scalability at high resolution" problem the '906 patent itself identifies) |
| Ex. 1028 | Navrikuth, "A Dynamic Firewall Architecture" (NPL) | Dynamically updated firewall policies |
| Exs. 1005–1007 | Rogers, US 9,560,077 / US 9,137,205 / US 9,565,213 | Centripetal's own earlier patents in the same family (parent '213 is the direct ancestor of '906) |
Caveat on the Rogers references: US 9,565,213 is the parent of '906 through the continuation chain. It is usable as § 103 prior art only to the extent the '906 claims are not entitled to the April 16, 2014 priority date for all limitations (i.e., if the '906 claims added matter beyond the parent). I could not verify from the retrieved materials how the Board treated this priority issue; I flag it because the petition's inclusion of the Rogers patents suggests a priority/new-matter argument was in play. The analysis below focuses on the non-family references (Kapoor, Himberger, Jungck, Kan, Johnson, Singla, Granidt, Navrikuth), which are unambiguously prior art.
IV. The § 103 combinations and element-by-element mapping
Because the Board's FWD is the operative holding, the strongest statement of the combinations is the one the Board credited. Based on the record, the primary combinations are:
Combination A (core): Kapoor + Himberger (+ Jungck for logging/dynamic-update limitations)
| Claim element | Where taught |
|---|---|
| PSG at network boundary filtering packets | Himberger (distributed security gateways); Kan; Johnson — all describe edge network devices that filter packets against rules |
| SPMS external to the protected network | Himberger — centralized policy management for distributed firewalls; Navrikuth — "dynamic firewall architecture" with a controller that pushes policy to firewall nodes |
| PSG receives dynamic security policy from SPMS | Himberger/Navrikuth dynamic policy distribution; Jungck — rules "redefined or reset dynamically . . . via the management interface" and by "external devices 724" |
| Rules comprise packet-matching criteria + transformation functions | Standard in every rule-based firewall/IDS reference (Himberger, Kan, Johnson, Jungck rule sets 726) |
| Rules automatically created/altered based on malicious traffic information from a malicious host tracker service | Kapoor — a security-management server that ingests external threat information and generates/updates filtering rules; Jungck — automatic rule redefinition by external devices; Singla — automated policy updates from security feeds |
| Per-packet, content-based filtering at the gateway | Himberger/Kan packet inspection; Granidt — line-rate packet inspection (the very scalability problem the '906 specification admits was the barrier to proactive filtering); Jungck packet analyzer 720 |
Motivation to combine (rationale under KSR): A PHOSITA designing a proactive, scalable network-protection system would have had every reason to (i) take the distributed, centrally managed gateway architecture of Himberger/Navrikuth, (ii) add an automated threat-intelligence feed of the Kapoor type so that rules are created and altered without manual administrator intervention (the "automatically created or altered" limitation), and (iii) add Jungck-style dynamic rule redefinition and packet logging so the gateways stay current and provide audit/awareness data. Each reference addresses a known, predictable problem (uniform enforcement at multiple boundaries; timeliness of threat response; scalability of high-resolution filtering); combining them yields the claimed system with no unexpected result. The '906 specification itself acknowledges the field's known problem — "the need to filter substantially all network traffic at a high resolution" at scale — and Granidt's gigabit-rate NIDS paper and Himberger's distributed architecture are precisely the field's known answers.
Combination B (for the logging/awareness dependent claims): add Jungck / Granidt
The Board specifically identified Jungck as teaching:
- a packet analyzer that "log[s] or otherwise store[s] information about the packet[s]" → reads on the packet-digest logging function dependent claims (identifying a subset of packet information, generating a record, reformatting per a logging standard such as syslog);
- rules redefined/reset dynamically by a rules processor or external devices via a management interface → reads on the "automatically created or altered" limitation and on the SPMS→PSG dynamic policy distribution.
Motivation: Logging packet metadata (addresses, ports, URIs, timestamps, sizes, directions, interface names, MAC addresses, rule IDs) for "network communications awareness" was standard practice in IDS/IPS and firewall products (Granidt; syslog-based logging). A PHOSITA would add such logging to the Combination A gateways to provide the awareness/auditing functions recited in the dependent claims, and would route matched traffic to a monitoring device using known port-mirroring/tap techniques.
Combination C (for the remaining dependent claims)
- Network-layer-transparent operation (claims reciting a gateway that sends/receives at the link layer using an interface not addressed at the network layer): transparent/"bump-in-the-wire" firewall operation was well known in the art (e.g., transparent firewall modes); combining it with the Combination A architecture is a routine design choice, not an inventive step.
- Differential forwarding queues / DSCP-based differentiated service: QoS queueing keyed to DSCP (the record includes Ex. 1074, Nichols, Definition of the Differentiated Services Field (DS Field), i.e., RFC 2474) was standard; applying queueing policies to rule-matched traffic is an obvious enhancement.
- PSG embedded in/associated with a LAN switch: switch-integrated security (firewalling within LAN switching infrastructure) was known; mounting the Combination A filter in a switch is an obvious implementation locus.
V. Why the Board's holding survives the standard § 103 defenses (and why the combination is not "impermissible hindsight")
- No "teaching away" or unexpected results: The record (per the FWD's summary) shows the prior-art references describe the same components performing the same functions; the combination produces predictable results — faster, more uniform, automatically updated filtering. The Board found no evidence of unexpected results or a teaching away.
- Broad claim construction defeated the "packet-identification" argument: Centripetal argued the claims require specific packet-identification features; the Board rejected that, holding "malicious traffic information" and the matching criteria are not limited to any particular form — so a Kapoor-type feed of any threat data (addresses, domains, URLs, signatures) plus a rule-based filter (Himberger/Jungck) reads on the claims.
- Secondary considerations: Nothing in the retrieved record indicates the Board found objective indicia (commercial success, long-felt need solved specifically by the claimed combination, industry praise, copying) sufficient to overcome the strong prima facie case; the FWD determined all claims unpatentable, and the CAFC's Rule 36 affirmance means no reversible error was found in that analysis.
- PHOSITA motivation is concrete, not conclusory: The combination solves the exact problem the '906 specification frames as the barrier to proactive security (scale of high-resolution filtering) using the field's known tools (distributed edge enforcement + centralized policy server + automated threat feeds + line-rate inspection + logging). Under KSR Int'l Co. v. Teleflex, the combination of known elements with predictable results is obvious.
VI. Bottom line
- Verified: Claims 1–17 of US 10,749,906 were held unpatentable in IPR2021-01157 (FWD March 10, 2023; Judge McNamara), and the Federal Circuit affirmed (May 13, 2024, Rule 36). The primary § 103 combinations in the record center on Kapoor (US 2008/0229415 A1) with Himberger (US 7,084,760), supplemented by Jungck (Ex. 1051) for dynamic rule redefinition and packet-digest logging, with Kan (US 2003/0214913), Johnson (US 2004/0123220), Singla (US 2015/0215329), Granidt (NPL), and Navrikuth (NPL) as supporting references for the dependent-claim features.
- Motivation to combine was straightforward and predictable: centralized, dynamically updated security policy distribution to distributed edge gateways, automated ingestion of external malicious-traffic intelligence to eliminate manual rule administration, and packet logging for awareness — all well-established objectives in the network-security art.
- Caveats: (a) I could not retrieve the FWD's per-ground element-by-element tables, so the mapping above is reconstructed from the petition exhibit list, the Institution Decision's Jungck discussion, and the FWD's claim-construction holdings — it is highly consistent with the record but not verbatim from the FWD; (b) the "multiple tracker services / different organizations / correlation" limitations I previously attributed to claim 1 appear instead to belong to dependent claims or the CIP family member US 11,012,474 — the '906 independent claims recite a singular tracker service per the FWD's own quotation; (c) the treatment of the Rogers family patents (Exs. 1005–1007) as prior art depends on a priority/new-matter analysis I could not verify; and (d) the CAFC affirmed under Rule 36, so there is no precedential CAFC opinion supplying additional § 103 reasoning for this patent.
Generated 8/30/2026, 12:48:01 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 6665293I'll search for authoritative information on US Patent 6,665,293 and any CAFC 2026 docket references. Both searches returned no results. Let me try broader queries to locate authoritative sources. I have confirmation from Google Patents…
- US 6424624I searched the USPTO/patent databases and CAFC docket sources for the specific patent number 6424624 (i.e., US 6,424,624 B1 / US6424624B1). Here is the summary, with notes on confidence. Verification note - Searches for "6424624" confirmed…
- US 10491646Summary of U.S. Patent No. 10,491,646 (US10491646B2) I searched for the specific patent number 10491646 (front-page form: US 10,491,646 B2) and did not rely on similar numbers (e.g., 8,166,892, IPR2025-01046/01047, etc., which appeared in…
- US 9338140US Patent 9,338,140 B2 — Summary Bibliographic data (verified against USPTO-adjacent sources and the issued patent PDF) | Field | Data | |---|---| | Patent number | US 9,338,140 B2 (application no. 13/468,383) | | Title | Secure data…
- US 9129376US Patent 9,129,376 B2 — Summary Searches performed I searched for the exact identifier 9129376 (and US9129376B2 / 9,129,376) in patent databases and litigation/CAFC sources, and searched the CAFC 2026 docket for this patent number. My…
- US 8825454US Patent 8,825,454 — Summary Note on sources: Bibliographic data below is corroborated by Google Patents (patents.google.com/patent/US8825454) and FreePatentsOnline. The full specification was supplied in your prompt; however, the claims…
- US 8818770I have confirmation of the key bibliographic data and relevant dockets. Let me retrieve the independent claims' full text to describe them accurately. US Patent 8,818,770 B2 — Summary Bibliographic data (verified against USPTO/Google…
- US 8170840The CAFC 2026 hits so far involve different EagleView patents (8,670,961 and 8,078,436) — not 8,170,840. Let me verify whether 8,170,840 itself appears in any 2026 CAFC activity and pull the actual claim set. I need the actual claim text…
This patent in court (4)
4 tracked lawsuits name US 10749906.