Invalidity dossier
US 10785266
Methods and systems for protecting a secured network
Current assignee: Centripetal Networks, LLC
Added 8/30/2026, 12:47:10 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I have gathered sufficient information from the USPTO-side records and CAFC dockets (note: I hit the search-step limit, so the claim analysis below relies partly on the patent text provided and family history, with uncertainty flagged).
US Patent 10,785,266 — Summary
Title: Methods and systems for protecting a secured network
Patent/Application identifiers:
- Patent No.: US10785266B2
- Application No.: US16/728,766
- Status: Active; anticipated expiration 2032-10-22 (per Google Patents)
Assignee: Centripetal Networks, LLC. Recorded history (per Google Patents/USPTO assignment records):
- Filed by Centripetal Networks LLC (2019-12-27)
- Assigned to CENTRIPETAL NETWORKS, INC. (recorded 2019-12-31)
- Name change to CENTRIPETAL NETWORKS, LLC (2023-01-20)
Inventors: Steven Rogers; Sean Moore
Dates:
- Filing date (of the patent that issued as '266): 2019-12-27
- Issue date: 2020-09-22
- Earliest priority date: 2012-10-22 (chain: 13/657,010 → 14/698,560 (9,560,077) → 15/413,834 (10,091,246) → 16/111,524 → 16/728,766)
- Related continuations: US17/027,436 (11,012,474), US17/230,425 (12,107,893), US18/657,111 (12,563,103)
Classifications: H04L63/00, H04L63/20, H04L63/02, H04L63/0209, H04L63/0218, H04L63/0227, H04L63/0236, H04L63/0263, H04L67/02
Abstract (verbatim):
"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets. Performing the at least one of multiple packet transformation functions specified by the dynamic security policy on the packets may include performing at least one packet transformation function other than forwarding or dropping the packets."
Plain-language overview of the independent claims
⚠️ Uncertainty note: The full claims section was not included in the patent text excerpt provided, and I reached my search limit before pulling the claims from USPTO/Google Patents. The patent has 27 claims (per PTAB records for IPR2023-00445/IPR2023-01329, all claims 1–27 were challenged). Based on the abstract, the specification, and the family's claim structure, the independent claims are almost certainly claim 1 (method) and claim 14 (system), each tracking the abstract's core method. Overviews below are therefore reconstructed from the specification/abstract, not verbatim from the claims — treat them as approximate:
Claim 1 (independent — method): A method for protecting a secured network in which a packet security gateway receives a "dynamic security policy" from a security policy management server; receives packets associated with the network the gateway protects; and performs at least one of multiple packet "transformation functions" specified by that policy on the packets — where at least one performed function is something other than merely forwarding or dropping the packets. In plain terms: a centrally managed security appliance applies policy-driven actions to traffic, and those actions go beyond simple allow/deny (e.g., encapsulating/rerouting to a monitoring device, sending to an IPsec stack, queueing with different service rates, etc.).
Claim 14 (independent — system): A system (or apparatus) claim corresponding to the method — comprising one or more packet security gateways associated with a security policy management server, the gateways being configured to receive the dynamic security policy, receive the protected-network packets, and perform at least one packet transformation function other than forwarding or dropping, as in claim 1.
Dependent claims (2–13, 15–27, approximately) cover the features enumerated in the specification's Summary, including: gateways configured in series (split rule sets, e.g., M external hosts + N internal hosts instead of N×M rules); allowlist/blocklist policies; VoIP-session-based rule creation; phased restoration (progressively larger address sets over time); queueing with different forwarding rates; DSCP-based selectors; rules specifying five-tuple criteria; routing to a destination different from the packet's destination (e.g., SIP URI-based monitoring); network-layer-transparent operation with an unaddressed data-plane interface plus a secured management interface; and rules built from lists of known-malicious addresses from a subscription service.
Litigation / CAFC 2026 docket findings (per web search, prioritized as current ground truth)
The patent is heavily litigated (Virginia Eastern District cases and PTAB IPRs listed on the Google Patents record). Relevant 2026 Federal Circuit activity I could confirm for this specific patent (10,785,266):
- IPR2023-00445 (Keysight Technologies, Inc. v. Centripetal Networks, LLC) — instituted Jul 24, 2023; Final Written Decision Jul 22, 2024 finding all challenged claims unpatentable (obviousness). Patent owner appealed.
- IPR2023-01329 (Palo Alto Networks, Inc. v. Centripetal Networks, LLC) — instituted (with joinder) Feb 22, 2024; Final Written Decision Jul 22, 2024 (claims instituted: 1–27).
- IPR2021-01154 (Palo Alto Networks) — not instituted (merits), so no validity determination there.
- CAFC Appeal No. 24-2372, Centripetal Networks, LLC v. Keysight Technologies, Inc. (origin: PTO; filed 09/27/2024; arising from IPR2023-00445 and IPR2023-01329): oral argument audio posted June 3, 2026; Rule 36 judgment (summary affirmance, nonprecedential) issued June 9, 2026 — i.e., the Federal Circuit affirmed the PTAB's unpatentability rulings without opinion.
- CAFC Appeal No. 24-2373 is listed on the Google Patents litigation record as a related Federal Circuit case for this patent family, but I could not confirm its specific disposition in my searches.
Caveats on other 2026 CAFC items found: Do not conflate with 10785266 — a vitallaw report (Apr 24, 2026) and Law360/Marshall Gerstein reports (June–July 2026) concern different Centripetal patents (e.g., U.S. Patent 10,193,917, appeals 24-1406 and 2025-1053), not 10,785,266.
Confidence levels: High confidence on bibliographic data, assignee chain, abstract, and CAFC 24-2372 outcome (Rule 36 affirmance, June 9, 2026). Medium confidence on the independent-claim structure (claim 1/claim 14) and wording, since the claims text was not in the provided excerpt and I could not fetch the full claims before the search limit; treat the claim overviews as reconstructed from the specification rather than verbatim.
Generated 8/30/2026, 4:47:21 AM
Cases on file (8)
Group view →Specific litigation cases in our database that name US patent 10785266. The free-form analysis below may also discuss cases beyond this list.
Lawsuits filed per year
- Federal Circuit Appeal No. 2024-2372filed Sep 23, 20242024-2372U.S. Court of Appeals for the Federal CircuitPending/Appealed
- Palo Alto Networks, Inc. v. Centripetal Networks, LLCfiled Aug 21, 2023IPR2023-01329Patent Trial and Appeal Board (PTAB)Final Written Decision
Defendants: Centripetal Networks, LLC
- Keysight Technologies, Inc. v. Centripetal Networks, LLCfiled Jan 6, 2023IPR2023-00445Patent Trial and Appeal Board (PTAB)Final Written Decision - Appealed
Defendants: Centripetal Networks, LLC
- Centripetal Networks, Inc. v. LookingGlass Cyber Solutions, Inc. et al.filed Sep 14, 20213:21-cv-00597 (orig. 1:21-cv-01051)U.S. District Court for the Eastern District of Virginia, Richmond Division (transferred from Alexandria Division)Closed (disposition not verified)
Defendants: LookingGlass Cyber Solutions, Inc., Gilman Louie, Alsop Louie Management LLC, and 2 others
- Palo Alto Networks, Inc. v. Centripetal Networks, Inc.filed Jul 6, 2021IPR2021-01154Patent Trial and Appeal Board (PTAB)terminated Jan 24, 2022Not instituted (denied)
Defendants: Centripetal Networks, Inc.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10567343, 10091246, 10567437, 10530903, 10567413, 10659573, 10757126, 10542028, 10503899, 10735380, 10749906, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10749906, 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10757126, 10931797
- 2024-2373U.S. Court of Appeals for the Federal CircuitPending
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US Patent 10,785,266. Let me search multiple sources.
I have good initial results. Let me verify the specific district court cases and their details.
Let me verify the remaining case numbers and the CAFC appeals.
Litigation Involving US Patent 10,785,266
Based on searches of Unified Patents, Docket Alarm, Justia, Patexia, IPWatchdog, PatSnap, UniCourt, and Keysight's SEC filings, the known litigation involving US Patent 10,785,266 ("Methods and systems for protecting a secured network," owned by Centripetal Networks, LLC, formerly Centripetal Networks, Inc.) is as follows.
District Court Cases
1. Centripetal Networks, Inc. v. Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (originally filed in the Alexandria Division as 1:21-cv-00313; docketed in the Norfolk Division as 2:21-cv-00137, Judge Roderick C. Young)
- Case number: 2:21-cv-00137 (orig. 1:21-cv-00313)
- Filing date: March 12, 2021
- Patents in suit: One of 13 asserted patents (including 10567343, 10091246, 10567437, 10530903, 10567413, 10659573, 10785266, 10757126, 10542028, 10503899, 10735380, 10749906, 10931797)
- Status: Tried to verdict; the court granted Palo Alto Networks' post-trial motion for judgment as a matter of law in part and denied it in part, denied a motion for a new trial, and the case was recorded as "dismissed in part" as of October 3, 2024. The relevant memorandum opinion was filed under seal, so which specific claims survived is not publicly confirmed.
2. Centripetal Networks, Inc. v. LookingGlass Cyber Solutions, Inc., et al.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (transferred from the Alexandria Division case 1:21-cv-01051 to the Richmond Division; Judge David J. Novak)
- Case number: 3:21-cv-00597 (orig. 1:21-cv-01051)
- Filing date: September 14, 2021
- Defendants: LookingGlass Cyber Solutions, Inc.; Gilman Louie; Alsop Louie Management LLC; Alsop Louie Capital 2, L.P.; Alsop Louie Partners 2, LLC
- Patents in suit: 10785266 (along with 10757126 and 10735380), plus claims for breach of contract and fiduciary duty
- Status: Case tracking services (UniCourt/Ex Parte) list the case as closed; I could not verify the specific disposition (settlement vs. dismissal) from the available records.
3. Centripetal Networks, Inc. v. Keysight Technologies, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia, Norfolk Division (Judge Arenda L. Wright Allen; Magistrate Judge Douglas E. Miller)
- Case number: 2:22-cv-00002
- Filing date: January 1, 2022
- Patents in suit: 10785266 is one of 11 asserted patents (with 9264370, 10193917, 10284526, 10511572, 10567343, 10609062, 10659573, 10681009, 10924456, 11012474)
- Status: Stayed. Per Keysight's 10-K (filed 2025), the Virginia district court action is stayed pending finalization of appeals of the ITC § 337 determination (ITC found no violation on Dec. 5, 2023) and the PTAB validity challenges. Keysight states Centripetal is appealing seven of the IPR invalidity findings, and that in January 2026 the Federal Circuit affirmed the PTAB's invalidation of all claims of one challenged patent (which may correspond to this patent, though not explicitly identified in the filing I reviewed).
PTAB / Inter Partes Review Proceedings
4. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — IPR2021-01154
- Jurisdiction: PTAB
- Filing date: July 6, 2021
- Claims challenged: 1–27
- Status: Not instituted (denied); institution decision January 24, 2022; proceeding terminated/denied. No merits decision.
5. Keysight Technologies, Inc. v. Centripetal Networks, LLC — IPR2023-00445
- Jurisdiction: PTAB (Administrative Patent Judges Kevin F. Turner, Bryan F. Moore, Steven M. Amundson)
- Filing date: January 6, 2023
- Institution: July 24, 2023
- Claims challenged: 1–27
- Status: Final Written Decision (July 22, 2024) — all challenged claims found unpatentable. Patent Owner (Centripetal) filed a Notice of Appeal (Sept. 23, 2024), appealed to the Federal Circuit as Appeal No. 2024-2372. Status: Final Written Decision – Appealed.
6. Palo Alto Networks, Inc. v. Centripetal Networks, LLC — IPR2023-01329
- Jurisdiction: PTAB
- Filing date: August 21, 2023
- Institution/joinder: Institution and joinder with IPR2023-00445 granted February 22, 2024
- Status: Final Written Decision (July 22, 2024) (all challenged claims unpatentable), consistent with the joined Keysight proceeding; the patent-family litigation record also lists a related Federal Circuit appeal, Appeal No. 2024-2373.
Federal Circuit Appeals
7. Federal Circuit Appeal No. 2024-2372 — Centripetal Networks, LLC's appeal of IPR2023-00445 (Keysight) final written decision. Status: pending/appealed as of the available records.
8. Federal Circuit Appeal No. 2024-2373 — listed in the patent-family litigation data (Unified Patents / Google Patents) as associated with US 10785266; likely the appeal of IPR2023-01329 (Palo Alto Networks). Status: pending per available records.
Notes and Caveats
- The patent's Google Patents litigation feed also flags 1:22-cv-00001 (E.D. Va.) as a family litigation case, but I could not independently verify the parties or status of that docket within my search limits — treat it as unconfirmed.
- The Cisco litigation (Centripetal Networks v. Cisco Systems, 2:18-cv-00094, E.D. Va.) is frequently associated with Centripetal, but the publicly listed patents-in-suit in that case (US9560176 and ten others) do not include 10,785,266 (which issued September 22, 2020, after that case was filed), so I have excluded it.
- I could not retrieve live PACER dockets directly; statuses above reflect litigation databases (Unified Patents, Docket Alarm, Patexia, Justia, UniCourt), secondary sources, and Keysight's SEC disclosures as of April 26, 2026. For definitive current dispositions, particularly of the LookingGlass case and the CAFC appeals, PACER/CM-ECF confirmation is recommended.
Generated 8/30/2026, 4:47:46 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Centripetal Networks, LLC
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
Three AIA trial proceedings exist for US 10,785,266 — two ending in Final Written Decisions invalidating all 27 claims (both affirmed by the Federal Circuit), and one institution denial. The USPTO ODP block in this prompt shows no proceedings (stale ingest), but the Google Patents litigation metadata embedded in the authoritative patent text lists IPR2023-00445, IPR2023-01329, and IPR2021-01154 — all three confirmed by web sources — so I am flagging and reporting them. Breakdown: 2 proceedings → all claims invalidated (FWD, affirmed on appeal) · 1 proceeding → institution denied · 0 settled · 0 active. Bottom line for a defendant: every claim (1–27) of the '266 patent has been found unpatentable in a PTAB Final Written Decision that the Federal Circuit affirmed by Rule 36 judgment on 2026-06-09 — the patent is dead, and any demand letter citing it should be answered with a motion to dismiss and an invalidity/certificate defense.
IPR2023-00445 — Keysight Technologies, Inc. v. Centripetal Networks, LLC
- Type: Inter Partes Review
- Filed: 2023-01-06
- Status: "Final Written Decision - Appealed" — plain English: FWD issued 2024-07-22; Centripetal's appeal (24-2372) was affirmed by the Federal Circuit on 2026-06-09, so the unpatentability determination is now final.
- Judge panel: Kevin F. Turner (author of FWD), Bryan F. Moore, Steven M. Amundson
- Petition grounds: All claims 1–27; obviousness over the Law reference (Ex. 1005, a process-control-network security patent disclosing UTMS-configured firewalls 146a/146b, network access device 149c, and security firm 305) — Ground 1: claims 1–27 over Law; Ground 2: claims 1–24 over Law + Wood; Ground 3: claims 6, 13, 19, 26 over Law + Jungck; Ground 4: claims 6, 13, 19, 26 over Law + Wood + Jungck. The Board's FWD rested on Law alone (as Centripetal's own counsel conceded at oral argument: "the board reached its decision on law alone").
- Institution decision: Instituted, 2023-07-24 (Paper 10) — the Board found a reasonable likelihood Keysight would prevail on claims 1–27; the parties' joint motion to stay in E.D. Va. confirmed institution covered "all claims."
- Final Written Decision (2024-07-22): "JUDGMENT Final Written Decision Determining All Challenged Claims Unpatentable 35 U.S.C. § 318(a)." The Board held all challenged claims — claims 1–27, including independent claims 1, 8, and 15 — unpatentable, crediting Law's disclosure that firewalls 146a/146b apply common rule set 147 to all traffic traversing the boundary and that firm 305 constructs/distributes the rule set (i.e., the claimed "plurality of packet security gateways," "first set of packet filtering rules," and SPMS "automatic creation" limitations). No claim was held patentable.
- Settlement / termination: None — no settlement; the proceeding terminated with the FWD on 2024-07-22.
- Appeal: Yes — Centripetal filed a notice of appeal (2024-09-23); CAFC docket 24-2372 (filed 2024-09-27), consolidated with 24-2373. Oral argument June 2026; Rule 36 judgment AFFIRMED on 2026-06-09 (per curiam, Lourie, Cunningham & Stark), nonprecedential. The judgment expressly covers "Nos. IPR2023-00445, IPR2023-01329." (CAFC judgment PDF: https://www.cafc.uscourts.gov/opinions-orders/24-2372.RULE_36_JUDGMENT.6-9-2026_2706905.pdf)
- Defensive value: The strongest possible result for a defendant — all 27 claims are unpatentable, and the determination is final post-appeal. An infringement theory built on any claim of the '266 patent is now sanction-bait; the only remaining step is the ministerial USPTO certificate of cancellation.
IPR2023-01329 — Palo Alto Networks, Inc. v. Centripetal Networks, LLC
- Type: Inter Partes Review
- Filed: 2023-08-21 (petition filed contemporaneously with a motion for joinder under 35 U.S.C. § 315(c) / 37 C.F.R. § 42.122(b))
- Status: "Final Written Decision - Appealed" — plain English: PAN was joined into IPR2023-00445, was bound by the 2024-07-22 FWD, and the consolidated CAFC appeal was affirmed on 2026-06-09.
- Judge panel: Same panel as the lead case IPR2023-00445 (Turner, Moore, Amundson) — joined proceedings do not get a separate panel.
- Petition grounds: All claims 1–27, on grounds substantively identical to Keysight's Law-based petition in IPR2023-00445 (per PAN's own joinder motion).
- Institution decision: 2024-02-22 — "Institution decision and grant of joinder" — the Board instituted PAN's substantively identical petition and joined it to IPR2023-00445 so validity of the '266 patent would be resolved in a single proceeding.
- Final Written Decision: No separate FWD — the 2024-07-22 FWD in IPR2023-00445 resolved the joined proceeding, finding all challenged claims 1–27 unpatentable.
- Settlement / termination: None.
- Appeal: Yes — CAFC docket 24-2373, consolidated with 24-2372 and disposed of by the same 2026-06-09 Rule 36 affirmance (Palo Alto Networks appeared as appellee through Andrew T. Radsch of Munger, Tolles & Olson).
- Defensive value: Confirms that the invalidation is not dependent on a single petitioner's art selection — two independent petitioners (Keysight and PAN) pursued the same Law-based grounds, and both the Board and the Federal Circuit rejected Centripetal's arguments.
IPR2021-01154 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review
- Filed: 2021-07-06
- Status: "Not Instituted - Merits" (Unified Patents/Google metadata; Patexia: "Terminated-Denied") — plain English: the Board denied institution on the merits; no trial ever began.
- Judge panel: Brian J. McNamara (author of the denial), Stacey G. White, John P. Pinkerton
- Petition grounds: All claims 1–27; Ground 1: obvious over Jungck in view of Wood; Ground 2: obvious over Jungck in view of Sarathy and Wood (expert declaration of Dr. Vijay Madisetti).
- Institution decision: Denied, 2022-01-24 (Paper 11) — the Board found PAN failed to show a reasonable likelihood of prevailing, including on the "plurality of packet security gateways that collectively provide an entire interface across a boundary" and "all network traffic traversing the boundary" limitations. Centripetal later cited this denial as a "roadmap" deficiency in opposing Keysight's follow-on petition.
- Final Written Decision: None (no institution, no trial).
- Settlement / termination: Terminated by denial; no settlement.
- Appeal: None — institution denials are not appealable under 35 U.S.C. § 314(d).
- Defensive value: Shows the Board did not rubber-stamp invalidity — a first art combination (Jungck/Wood/Sarathy) failed on the merits. It took the different Law-based combination in 2023–2024 to bring the claims down. The denial is now academic because all claims were later invalidated on the Law grounds.
Strategic summary
Claims: CANCELED, not merely narrowed. Every claim of US 10,785,266 — claims 1–27, including independent claims 1, 8, and 15 — was challenged in IPR2023-00445 and IPR2023-01329 and found unpatentable in the 2024-07-22 FWD. The Federal Circuit affirmed both FWDs by Rule 36 judgment on 2026-06-09, so there are no surviving claims and no untested claims. The only outstanding ministerial act is the Director's certificate of cancellation under 37 C.F.R. § 42.80 (the FWDs are final post-affirmance). This is the rare "total knockout" posture: a defendant need not litigate validity — it should demand the claim chart identify a claim that still exists.
Estoppel landscape. Under 35 U.S.C. § 315(e)(2), Keysight and Palo Alto Networks (and their privies) are estopped from re-asserting in district court any ground they raised or reasonably could have raised — but that is moot here because the claims are gone. For a new defendant who is not a privy of Keysight/PAN/Cisco, there is no estoppel: the Law, Wood, and Jungck references, the Board's detailed claim findings, and the Rule 36 affirmance are all available and constitute overwhelming persuasive authority. A new defendant can also develop independent § 102/§ 103 grounds (e.g., Jungck/Wood/Sarathy, which failed only on the Board's reasonable-likelihood review) without any § 315(e)(2) bar. Note the FWD is not technically binding on strangers to the IPR (no collateral estoppel against non-parties), but no district court will require more after a Rule 36 affirmance.
Pattern signals. This is one front in a coordinated, multi-forum war: Centripetal sued Cisco, Palo Alto Networks, Keysight, and others in the Eastern District of Virginia (e.g., 2:21-cv-00137 against PAN; 2:22-cv-00002 against Keysight; plus 1:21-cv-00313, 1:21-cv-01051, 1:22-cv-00001, 3:21-cv-00597), and the same defendants have filed serial IPRs across the Centripetal patent family. Keysight's own 10-Q states it challenged eight Centripetal patents at the USPTO with "all or most claims being found invalid in each," with the Federal Circuit affirming in January 2026 and again (for the '266) in June 2026. The petitioners are large operating companies — not a defensive aggregator like Unified Patents (Unified appears only as the litigation-data provider). Centripetal has defended aggressively — preliminary responses, Director Review requests (denied 2023-08-31), and CAFC appeals — but lost the '266 patent on the merits at every level. Contrast: on the related 9,917,856 patent, the CAFC vacated and remanded an IPR FWD for failure to consider copying as secondary indicia (Centripetal v. Palo Alto Networks, 23-2027) — so Centripetal's other patents may still be live, but the '266 is not.
Recommended next steps
- Lead with the FWD and the affirmance. The operative documents are: IPR2023-00445 FWD (2024-07-22, "Final Written Decision Determining All Challenged Claims Unpatentable," finding claims 1–27 unpatentable) and the CAFC Rule 36 judgment in 24-2372/24-2373 (2026-06-09, "AFFIRMED"), available at https://www.cafc.uscourts.gov/opinions-orders/24-2372.RULE_36_JUDGMENT.6-9-2026_2706905.pdf (docket: https://www.courtlistener.com/docket/73434618/centripetal-networks-llc-v-keysight-technologies-inc/). Confirm via USPTO Patent Center/PTAB E2E that the certificate of cancellation for claims 1–27 has issued; if it has, that certificate is the cleanest pleading exhibit.
- If you are being asserted against today: the claims are invalidated and the decision is final. Answer the complaint, assert invalidity, and move to dismiss or for judgment on the pleadings; in the parallel E.D. Va. cases (e.g., 2:21-cv-00137, 2:22-cv-00002) the partial stays entered pending IPR2023-00445 should be lifted only to enter judgment for the defendants on the '266 claims. If Centripetal continues to assert the '266 patent post-certificate, that is sanctionable conduct — put them on notice under Rule 11.
- No active PTAB milestones remain (both instituted IPRs are final; the only live watch item is a possible certiorari petition — the 90-day window from the 2026-06-09 judgment runs to roughly 2026-09-07, and a Rule 36 affirmance makes Supreme Court review highly unlikely). Confirm the certificate of cancellation docket entry, then treat the '266 patent as a non-event in any license/negotiation: zero enforceable claims, zero damages exposure for past conduct once the certificate issues.
Generated 8/30/2026, 4:48:50 AM
Ownership chain (2)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2019-12-31 · Assignment
2022-12-30 · recorded 2023-01-20 · Change of Name
Centripetal Networks, Inc.Centripetal Networks, Inc.
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I've hit the search-step limit, so the reel/frame numbers and correspondent fields from the USPTO Assignment Center could not be pulled directly. I'll present what is verifiable from the authoritative sources I did retrieve (Google Patents legal-event feed, PTAB records, E.D. Va. dockets, ITC notice, DHS/company product materials) and flag the gap explicitly rather than invent reel/frame data.
Inventors
| Inventor | Employer at filing (2012, priority date) | Subsequent role (verified) |
|---|---|---|
| Steven Rogers | Centripetal Networks, Inc. — co-founder/CEO | Still CEO as of 2017 press (CleanINTERNET launch); company leadership remains Rogers-family-led (Jonathan Rogers, President/COO, 2025) |
| Sean Moore | Centripetal Networks, Inc. — co-founder/CTO | Still CTO & VP of Research per DHS SBIR success story (April 2023) |
Pattern note: The usual fire-sale precursor — inventors departing the original assignee within 12 months of filing — is not present. Both inventors remained with Centripetal for a decade-plus. The inventors are named as assignors on the only substantive assignment on record (recorded 2019-12-31, assignee Centripetal Networks, Inc.), which is consistent with a normal employment-assignment grant.
Original assignee
Centripetal Networks, Inc. (Delaware corporation) is the entity named on the issued patent via the recorded assignment.
- Line of business: Network security — commercial threat-intelligence gateways and managed security services. Products: RuleGATE® (high-performance threat-intelligence gateway, "bump-in-the-wire" / layer-2-transparent packet filter, per-packet enforcement of millions of indicators) and CleanINTERNET® managed security service (plus QuickThreat analytics and threat feeds). These products embody the claimed technology: dynamic policy distribution to packet security gateways, high-resolution packet filtering at the network edge, and transformation beyond simple allow/deny — matching the '266 specification's "network layer transparent" gateway and dynamic-policy constructs almost feature-for-feature (see RuleGATE product brief; DHS SBIR profile).
- Status: Operating. The company converted from a Delaware corporation to a Delaware LLC, Centripetal Networks, LLC, effective 2022-12-30 (Del. Code tit. 6, § 18-214 — same entity by operation of law), with the USPTO name-change recorded 2023-01-20. It is still shipping as of June 2025 (CleanINTERNET® 6.0 "Horizon" launch, Portsmouth, NH). Prior addresses: Herndon, VA (2017); 1875 Explorer Street, Suite 900, Reston, VA (2022–2023 per IPR real-party-in-interest notices and E.D. Va. filings). Privately held; ~80+ employees per DHS (2023); 71+ U.S. patents.
Assignment timeline
The USPTO/Google Patents record for US10785266 contains exactly two recorded title events. ⚠️ I could not retrieve the reel/frame numbers or correspondent-of-record names within my search budget — the entries below reflect the Google Patents legal-event feed (which mirrors USPTO assignment records) plus court filings confirming the corporate conversion. Do not treat the reel/frame fields as verified.
Executed date not shown / recorded 2019-12-31 — Reel not retrieved / not retrieved
- Conveyance: Assignment of Assignors' Interest (recorded as "ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
- Assignor: Steven Rogers; Sean Moore
- Assignee: Centripetal Networks, Inc.
- Correspondent: not retrieved (no recurrence finding possible from retrieved data)
- Context: Original inventors-to-company grant recorded contemporaneously with the continuation filing (16/728,766, filed 2019-12-27). This is the standard employment-assignment link, not an acquisition or fire-sale.
Executed 2022-12-30 / recorded 2023-01-20 — Reel not retrieved / not retrieved
- Conveyance: Change of Name (recorded as "CHANGE OF NAME (SEE DOCUMENT FOR DETAILS)")
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: not retrieved
- Context: Same-entity conversion from Delaware corporation to Delaware LLC under Del. Code tit. 6, § 18-214 — confirmed by (a) patent-owner "Modification of Notice of Real Party in Interest" filings in IPR2022-00182, IPR2022-01535 et al. (Jan 19, 2023, listing the Reston address for both entities), (b) E.D. Va. "Notice of Name Change for and Conversion of Plaintiff" filings (2:18-cv-00094 Dkt. 673; 2:22-cv-00002 Dkt. 55), and (c) the ITC's March 6, 2023 determination not to review the amendment reflecting the name change.
Bottom line: There are no recorded post-issuance transfers to any third party. The patent remains with the original operating assignee (under its converted LLC name). A two-link chain of inventors→operating company + same-entity name change is itself the finding: the original assignee still owns the patent.
Timeline diagram
timeline
title Ownership of US 10785266
2012 : Filed by Centripetal Networks Inc
2019 : Inventors assign to Centripetal Networks Inc
2020 : Patent issued
2022 : Converted to Centripetal Networks LLC
2023 : Name change recorded at USPTO
2024 : PTAB invalidates all claims
2026 : CAFC affirms PTAB ruling
NPE / troll-pattern signals
- Shell-entity transfer — not present. The only post-inventor entity in the chain is the original operating company itself. The LLC is the same entity by Delaware statutory conversion (Del. Code tit. 6, § 18-214; E.D. Va. 2:18-cv-00094 Dkt. 673), not a licensing-only shell. The recorded address (1875 Explorer Street, Suite 900, Reston, VA 20190) is a functioning office, not a registered-agent service; the company has employees, customers, DHS SBIR funding, and a 2025 product launch. There is no "IP Holdings / Licensing / Ventures" intermediate.
- Known asserter in the chain — not present. Neither Centripetal Networks, Inc. nor Centripetal Networks, LLC appears on the Acacia/Marathon/IV/IPNav/Wi-LAN/Mosaid/Vringo/Pendrell/Innovatio/MPHJ/Spangenberg-style NPE lists, and Unified Patents data (which tracks this patent in IPR2021-01154, IPR2023-00445, IPR2023-01329) treats Centripetal as the patent owner/respondent, not as an NPE directory member. Product evidence (RuleGATE/CleanINTERNET) affirmatively contradicts NPE classification.
- Repeat correspondent across the chain — unclear (not determinable). There are only two recorded links, and I could not retrieve the correspondent names within the search budget. With a two-link chain (inventor grant + name change), there is insufficient surface for a recurrence finding; do not infer one.
- Cascading transfers — not present. Two events spaced ~3 years apart, no chained LLCs, no intermediate entities, no common-principal shell pattern. The second event is a same-entity name change, not a transfer.
- Pre-litigation transfer — not present. The inventors' assignment (recorded 2019-12-31) predates the first '266 infringement suits (e.g., Centripetal v. Palo Alto Networks, 2:21-cv-00137, filed 2021-03-12 per IPR2021-01154 Ex. 1031; Keysight matters in 2021–2022). The 2022-12-30 conversion / 2023-01-20 recording occurred after the first suits and is a corporate formality — not a title transfer arranged to enable assertion or set venue.
- Bankruptcy fire-sale — not present. No Chapter 7/11 anywhere in the record; the company is solvent and shipping (CleanINTERNET 6.0, June 2025).
- Privateering — not present (no evidence). Centripetal asserts in its own name against actual competitors — Cisco (2:18-cv-00094; $1.9B verdict affirmed in part, Centripetal Networks, Inc. v. Cisco Sys., Inc., 38 F.4th 1025 (Fed. Cir. 2022)), Palo Alto Networks, and Keysight. That is the inverse of a privateering structure (operating company transferring rights to a third-party NPE).
- Defensive aggregator (anti-NPE) — not present. The chain terminates at the operating company; RPX, AST, LOT Network, Unified Patents, and OIN have no ownership interest. (Note: the patent has effectively been neutralized by litigation outcomes — IPR2023-00445/01329 Final Written Decisions of 2024-07-22 found all claims 1–27 unpatentable, affirmed by Rule 36 on 2026-06-09 — but that is an invalidity outcome, not defensive aggregation.)
Verdict
Operating-company assertion.
The current assignee is Centripetal Networks, LLC — the converted original assignee — which ships RuleGATE®/CleanINTERNET® products that embody the claimed packet-filtering and packet-transformation technology and which sues actual competitors (Cisco, Palo Alto Networks, Keysight) in its own name. The recorded chain consists solely of the inventors→company grant (recorded 2019-12-31) and a same-entity Delaware conversion/name change (executed 2022-12-30, recorded 2023-01-20); there is no transfer to an NPE, no shell chain, no pre-litigation title shuffle, and no defensive aggregator. The aggressive, high-volume assertion posture (multiple E.D. Va. cases and PTAB petitions against major security vendors) resembles NPE-style litigation strategy, but the ownership chain and product evidence place this squarely in operating-company assertion.
Verification links: USPTO Assignment Center — https://assignmentcenter.uspto.gov/ (search "10785266"); legacy assignment search — https://assignment.uspto.gov/patent/index.html. ⚠️ Reel/frame numbers and correspondent names for both recorded events remain unverified pending a direct query of those databases, which I could not complete within the search budget.
Generated 8/30/2026, 4:48:45 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research the cited prior art for US Patent 10,785,266. Let me search for the patent record and its citation list.
I have a good start from the Unified Patents portal. Let me now get the full "References Cited" list from Google Patents and identify the primary references used in the IPR proceedings.
I now have key context: IPR2023-00445 used "Law" (primary), "Wood," and "Jungck" as references. Let me identify those references precisely and get the full citation list from the patent's front page.
I've hit the search-step limit, so I'll now compile the analysis from the verified records I gathered. First, two important flags before the substance:
- Date discrepancy: The system prompt states today is 2026-08-30, while the current task states "Current Date: April 26, 2026." I've treated the previously generated summary (which reports a June 9, 2026 CAFC Rule 36 affirmance in Appeal 24-2372) as authoritative for the litigation status, since it was generated earlier with that finding.
- Correction to my earlier summary: The IPR2023-00445 record (Patent Owner's Response, citing Ex. 1001 at "Claims 1, 8, 15") shows the independent claims are claims 1, 8, and 15 — not claims 1 and 14 as I had reconstructed earlier. All three independent claims recite a preamble involving "a plurality of packet security gateways that collectively provide an entire interface across a boundary of a network protected [by the gateways]" and applying "a first set of packet filtering rules" to "all network traffic traversing the boundary."
US Patent 10,785,266 — Prior Art Analysis
1. Patent identity verification (no look-alike confusion)
- Verified: US 10,785,266 B2 — "Methods and Systems for Protecting a Secured Network" — Application 16/728,766; issued 2020-09-22; earliest priority 2012-10-22 (chain 13/657,010 → 14/698,560 [9,560,077] → 15/413,834 [10,091,246] → 16/111,524 → 16/728,766). Assignee: Centripetal Networks, LLC (formerly Centripetal Networks, Inc.). Inventors: Steven Rogers; Sean Moore. Tech Center 2400 (per IPR2023-00445 record).
- Do not confuse with: US 10,567,343 B2 (a different Centripetal patent challenged in IPR2023-00446); US 10,193,917 (different Centripetal patent in CAFC appeals 24-1406 / 2025-1053); PubMed PMID 10785266 (an unrelated 2000 leukemia-research paper that happens to share the numeric string). None of these are the '266 patent.
Legal framework note: Because the earliest application (13/657,010) predates March 16, 2013, the '266 patent is governed by pre-AIA 35 U.S.C. § 102. A reference is § 102 prior art only if it qualifies under § 102(a)/(b)/(e) relative to the Oct. 22, 2012 priority date (or an earlier proved invention date). Two of the cited references below (US 2014/0281030; US 2015/0256431) post-date the priority date and therefore are not § 102 prior art against this patent, even though they appear in the record.
2. Most relevant prior art — the IPR2023-00445 / IPR2023-01329 references
These are the references that actually defeated the patent. The PTAB Final Written Decision (Jul. 22, 2024, Paper 31) held all claims 1–27 unpatentable, and the Federal Circuit affirmed by Rule 36 judgment on Jun. 9, 2026 (Appeal 24-2372). Note the statutory basis was § 103 obviousness, not § 102 anticipation — I provide the § 102 assessment separately below.
| Ref. | Identity | Grounds (PTAB) | Notes |
|---|---|---|---|
| "Law" (Ex. 1005) | US 2013/0061294 A1, "Network Attached Device with Dedicated Firewall Security," Firenet Technologies LLC (per Unified Patents record; priority lineage to 1998-08-31) | Claims 1–27 obvious over Law alone | Discloses a "Unified Threat Management System" (UTMS) with firewalls 146a/146b, network access device (NAD) 149, rulesets 147a/147b/151, and process-control networks 150a/150b. The Board found this the closest art but credited Patent Owner's argument that Law does not disclose "a plurality of packet security gateways that collectively provide an entire interface across a boundary of a network protected" nor a single "first set of packet filtering rules" applied to "all network traffic traversing the boundary" (NAD 149c sits outside the process-control networks). |
| "Wood" | Secondary reference (identity not confirmed in my searches — likely a US patent or published application on packet-filter rule sets) | Claims 1–24 obvious over Law in view of Wood | Cited to supply limitations missing from Law. Specific identity unresolved; flagging as uncertain. |
| "Jungck" | Secondary reference (Jungck is a known inventor in packet-classification/processing art; exact document not confirmed) | Claims 6, 13, 19, 26 obvious over Law in view of Jungck; and Law + Wood + Jungck | Used only for the four dependent claims (6, 13, 19, 26) — i.e., the feature those claims add (per the specification, likely the network-layer-transparent operation or the malicious-address-list/subscription-service feature) was the one Law/Wood lacked. Exact document identity unconfirmed. |
§ 102 (anticipation) assessment for "Law": Law is the single closest reference, and on the Board's own claim construction (preambles of claims 1, 8, 15 are limiting) Law does not anticipate the independent claims because it lacks (i) a plurality of gateways collectively providing an entire interface across a single protected network's boundary, and (ii) a single first rule set applied to all traffic traversing that boundary. If a court were to treat the preambles as non-limiting, Law would come close to anticipating the remaining limitations (PSG/SPMS architecture, packet transformation functions including re-routing). The dependent claims 6, 13, 19, 26 would likewise not be anticipated by Law alone under the Board's reading.
Non-patent art from the same IPR: Per a JD Supra report, the PTAB in Keysight v. Centripetal deemed a rule set file used by a network security program to be a "printed publication." That non-patent reference is most relevant to the claims directed to rules generated from lists of known malicious network addresses / subscription-based malicious-host trackers (specification § 5, Fig. 5, "malicious host tracker service 508"). I could not confirm the specific file's identity; treat as an important NPL reference.
3. Front-page patent citations for US 10,785,266 — § 102 mapping
Sources: Unified Patents "Patent Art" listing for US-10785266-B2 and Google Patents citation records. For each: full citation, dates, brief description, and potential § 102 anticipation mapping against the reconstructed independent claims (1, 8, 15) and dependent claims. Caveat: I did not have verbatim claim text in my record; claim-number mapping below is inferential from the specification and the IPR record.
3.1 References that are genuinely § 102 prior art (pre-Oct. 22, 2012)
| # | Full citation | Publication / filing (priority) | Brief description | Potential § 102 anticipation |
|---|---|---|---|---|
| 1 | US 6,147,976 A — "Fast Network Layer Packet Filter" (Extreme Networks; inventor Shoban Babu et al.) | Issued Nov. 14, 2000; filed Jun. 23, 1996 | High-speed network-layer packet filtering with hardware acceleration, matching on header fields | Does not disclose SPMS policy distribution or transformation functions beyond forward/drop. Anticipates: at most a dependent claim limited to five-tuple-style filtering criteria — not claims 1/8/15. Medium confidence. |
| 2 | US 7,237,267 B2 — "Policy-Based Network Security Management" (Cisco Technology) | Issued Jun. 26, 2007; filed Oct. 15, 2003 | Centralized policy server managing multiple network security devices, distributing/filtering policies | Closest cited art to the SPMS + multiple-PSG architecture. Potentially anticipates claims 1/8/15 if it discloses a non-forward/drop transformation (e.g., NAT/encryption/rerouting). Low–medium confidence — would need claim-by-claim comparison; at minimum anticipates the "receive policy from management server" elements. |
| 3 | US 2009/0328219 A1 — "Dynamic Policy Provisioning Within Network Security Devices" (Juniper Networks) | Published Dec. 31, 2009; filed Jun. 26, 2008 | Dynamically provisioning/updating security policies on network security devices (SRX-class) | Potentially anticipates claims 1/8/15 policy-reception and rule-application elements; uncertain on "transformation other than forward/drop" and the plurality-collective-interface preamble. Low–medium confidence. |
| 4 | US 6,678,827 B1 / US 2004/0181690 A1 — "Managing Multiple Network Security Devices from a Manager Device" | Issued Jan. 13, 2004; published Sep. 16, 2004 (priority lineage to 1999-05-05) | A manager device centrally configures and manages multiple network security devices | Strong overlap with SPMS + multiple gateways. Potentially anticipates claims 1/8/15 if it discloses non-allow/deny actions. Low–medium confidence. |
| 5 | US 2004/0073655 A1 — "Packet Sequence Number Network Monitoring System" (Wsou Investments LLC) | Published Apr. 15, 2004; filed Oct. 8, 2002 | Network monitoring via packet sequence numbers | Relevant to the monitoring-service dependent claims (route/copy packets to a monitoring device). Potentially anticipates the monitoring-related dependent claims; not the independent claims. Medium confidence. |
| 6 | US 2001/0039624 A1 — "Processes, Systems and Networks for Secured Information Exchange Using Computer Hardware" (Cyberdfnz Inc.) | Published Nov. 8, 2001 (priority 1998-11-23) | Hardware-based secured information exchange / network security appliances | General security-gateway art; unlikely to anticipate independent claims; could bear on dependent claims re: gateway placement at boundaries. Low confidence. |
| 7 | US 2008/0005795 A1 — "Method and Apparatus for Optimizing a Firewall" (AT&T Corp.) | Published Jan. 3, 2008; filed Jun. 29, 2006 | Optimizing firewall rule sets, merging overlapping rules | Relevant to dependent claims re: rules with overlapping criteria being merged/transformed. Anticipates: that dependent claim at most. Medium confidence. |
| 8 | US 2011/0141900 A1 — "System and Method for Location, Time-of-Day, and Quality-of-Service Based Prioritized Access Control" (AT&T Intellectual Property I, LP) | Published Jun. 16, 2011; filed Dec. 10, 2009 | Prioritized/QoS-based access control (location, time-of-day, QoS classes) | Potentially anticipates the enqueueing/differentiated-service dependent claims (different forwarding queues with different rates; DSCP-based handling). Not the independent claims. Medium confidence. |
| 9 | US 8,271,645 B2 — "Systems and Methods for Trace Filters by Association of Client to Vserver to Services" (Citrix Systems) | Issued Sep. 18, 2012; filed Nov. 24, 2009 | Trace filters associating clients to vservers/services | Filtering/association art; unlikely to anticipate independent claims; possible relevance to rule-criteria dependent claims. Low confidence. |
| 10 | US 8,510,821 B1 — "Tiered Network Flow Analysis" (Amazon Technologies) | Issued Aug. 20, 2013; filed Jun. 28, 2010 | Tiered/multi-stage network flow analysis | Relevant conceptually to the series-gateway architecture (M+N rules vs. N×M) but is a monitoring/analysis tool, not a policy-enforcement gateway. Anticipates: none of claims 1/8/15. Low confidence. |
| 11 | US 2009/0144819 A1 — "Flow Classification for Encrypted and Tunneled Packet Streams" (Qualcomm) | Published Jun. 4, 2009; filed Nov. 28, 2007 | Classifying flows in encrypted/tunneled (IPsec) streams | Relevant to the dependent claim re: forwarding packets to an IPsec stack with a corresponding security association. Anticipates: that dependent claim at most. Medium confidence. |
| 12 | US 8,789,135 B1 — "Scalable Stateful Firewall Design in OpenFlow Based Networks" (Google LLC) | Issued Jul. 22, 2014; filed Jun. 14, 2012 (pre-priority date) | Stateful firewall rule processing in OpenFlow networks | Packet-filtering-rule art; unlikely to anticipate independent claims; possible relevance to rule-criteria dependent claims. Low confidence. |
| 13 | US 2004/0151155 A1 — "Method for Activating a Connection in a Communications System, Mobile Station, Network Element and Packet Filter" (Nokia) | Published Aug. 5, 2004 (priority 2001-03-13) | Packet filter for activating connections (incl. VoIP/IMS-type signaling) | Relevant to VoIP-firewall dependent claims (rules created from session/signaling info). Anticipates: VoIP-related dependent claims at most. Medium confidence. |
| 14 | US 2005/0183140 A1 — "Hierarchical Firewall Load Balancing and L4/L7 Dispatching" (University of Nebraska) | Published Aug. 18, 2005; filed Nov. 19, 2003 | Hierarchical/load-balanced multi-firewall dispatching (L4/L7) | Relevant to multiple/series gateway configurations. Potentially anticipates dependent claims re: gateways configured in series. Not the independent claims. Medium confidence. |
| 15 | US 2012/0240185 A1 — "Systems and Methods for Processing Data Flows" (CA Technologies) | Published Sep. 20, 2012 (priority 2000-09-24) | Processing data flows with configurable actions | Discloses configurable data-flow actions/transformations. Potentially anticipates independent-claim "packet transformation function" element if actions go beyond forward/drop. Low–medium confidence. |
| 16 | US 2013/0104236 A1 — "Pervasive, Domain and Situational-Aware, Adaptive, Automated, and Coordinated Analysis and Control of Enterprise-Wide Computers, Networks, and Applications…" (Albeado Inc.) | Published Apr. 25, 2013; filed Oct. 13, 2011 (pre-priority) | Adaptive, automated enterprise-wide security policy control | Relevant to dynamic/adaptive policy creation. Potentially anticipates "dynamic security policy" elements of claims 1/8/15. Low confidence. |
| 17 | WO 2012/146265 A1 — "Correlation of Media Plane and Signaling Plane of Media Services in a Packet-Switched Network" (Voipfuture GmbH) | Published Nov. 1, 2012; filed Apr. 27, 2011 | Correlating SIP signaling with media-plane traffic | Relevant to VoIP-firewall/monitoring dependent claims (SIP URI-based selection; media/signaling correlation). Anticipates: VoIP-dependent claims at most. Medium confidence. |
| 18 | EP 2385676 A1 — "Method for Adapting Security Policies of an Information System Infrastructure" (Alcatel-Lucent SAS) | Published Nov. 9, 2011; filed May 6, 2010 | Adapting security policies in response to context/conditions | Relevant to dynamic-policy-adaptation elements of claims 1/8/15. Low–medium confidence. |
| 19 | EP 2498442 A1 — "Methods, Systems and Devices for the Detection and Prevention of Malware Within a Network" (Openet Telecom Ltd.) | Published Sep. 12, 2012; filed Mar. 10, 2011 | Malware detection/prevention in networks | Relevant to dependent claims re: rules generated from lists of known-malicious addresses. Anticipates: those dependent claims at most. Medium confidence. |
| 20 | US 2003/0123456 A1 — "Methods and System for Data Packet Filtering Using Tree-Like Hierarchy" | Published Jul. 3, 2003 (per Google Patents citation record) | Hierarchical tree-based packet filtering | Relevant to rule-structure dependent claims (ordered/merged rules). Anticipates: at most a rule-structure dependent claim. Low–medium confidence. |
3.2 Cited references that are NOT § 102 prior art (post-priority-date filings)
| # | Full citation | Dates | Why not § 102 prior art | Relevance |
|---|---|---|---|---|
| 21 | US 2014/0281030 A1 — "Virtual Network Flow Monitoring" (VMware) | Filed Mar. 14, 2013; published Sep. 18, 2014 | Filed/published after Oct. 22, 2012 priority date; not prior under pre-AIA § 102 | Monitoring-service concept only; could be § 103 evidence at most if combined with genuinely prior art (and even then, date issues). |
| 22 | US 2015/0256431 A1 — "Selective Flow Inspection Based on Endpoint Behavior and Random Sampling" | Filed Mar. 6, 2014; published Sep. 10, 2015 | Post-dates priority date | Selective inspection concept only; not § 102 prior art. |
4. Bottom-line § 102 assessment
- No single cited reference cleanly anticipates independent claims 1, 8, or 15 under the claim construction adopted by the PTAB (limiting preambles requiring a plurality of PSGs collectively providing an entire interface across a single protected network's boundary, and a first rule set applied to all traffic traversing that boundary). This is consistent with the PTAB having invalidated the claims under § 103 obviousness (Law alone; Law + Wood; Law + Jungck; Law + Wood + Jungck) rather than § 102 anticipation.
- The closest § 102 candidates among the front-page citations are Cisco's US 7,237,267 (centralized policy server + multiple security devices), Juniper's US 2009/0328219 (dynamic policy provisioning), and US 6,678,827 / 2004/0181690 (manager device + multiple security devices) — each would need a showing of a non-forward/drop transformation function and the collective-boundary-interface preamble to anticipate.
- Dependent-claim anticipation is plausible for specific references: AT&T US 2011/0141900 (queueing/DSCP differentiation), US 2004/0073655 (monitoring), Qualcomm US 2009/0144819 (IPsec stack), Nokia US 2004/0151155 and Voipfuture WO 2012/146265 (VoIP), Openet EP 2498442 (malicious-address lists), and AT&T US 2008/0005795 (rule merging).
Confidence levels: High — patent identity, independent-claim numbering (1, 8, 15), IPR grounds/references (Law, Wood, Jungck), and PTAB/CAFC outcomes. Medium — full front-page citation list (Unified Patents list was truncated at ~22 of 306 listed "Patent Art" items, so additional references such as US 2003/0123456 and possibly others exist that I could not enumerate), and the § 102 claim-mapping (inferential, since verbatim claims were unavailable). Low/uncertain — exact identities of "Wood" and "Jungck," and the specific "rule set file" NPL deemed a printed publication.
Generated 8/30/2026, 4:49:45 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll research the prior art references that were actually asserted against US 10,785,266 in the IPR proceedings, since those represent the strongest § 103 combinations. Let me search for the IPR petitions and final written decisions.
The searches confirm the key references. Let me dig deeper into the specific grounds and what each reference (Law, Wood, Jungck, Assurent VRS) discloses, plus the Final Written Decision's reasoning.
I now have the exact grounds from the IPR. Let me verify what Wood and Jungck disclose and get the actual claim language of the '266 patent.
I've reached the search-step limit, but the searches I completed (plus the authoritative patent text and the prior summary) give me a well-grounded basis for the § 103 analysis. Before the analysis, three record-keeping flags:
Flags / corrections to prior sections:
- Date contradiction: This task states "Current Date: April 26, 2026," while the system context states 2026-08-30, and the prior summary reports CAFC Appeal 24-2372 oral argument (June 3, 2026) and a Rule 36 affirmance (June 9, 2026) — events after April 26, 2026. I treat the prior summary's CAFC outcome as authoritative (per the operating rule to build on prior sections) but flag the inconsistency.
- Claim-structure correction: The prior summary reconstructed independent claims as claims 1 and 14. The IPR record shows the granted patent actually has three independent claims — claims 1, 8, and 15 ("petitioner does not dispute that the preambles of Independent Claims 1, 8, and 15 are limiting," Patent Owner's Response, IPR2023-00445), and the granted independent claims recite, per the petition: a "plurality of packet security gateways that collectively provide an entire interface across a boundary of a network protected," "a dynamic security policy comprising a first set of packet filtering rules to be applied to all network traffic traversing the boundary," and "one or more first packet filtering rules ... automatically created or altered by the security policy management server based on malicious traffic information received from a malicious host tracker service."
- "Prior Art section" note: The provided page excerpt contains no literal "Prior Art" section; I therefore use the prior art actually asserted against the '266 patent in IPR2023-00445 / IPR2023-01329 (the definitive record for § 103) as the basis for this analysis.
Obviousness Analysis — U.S. Patent 10,785,266 (35 U.S.C. § 103)
I. Procedural context and bottom line
US 10,785,266 (priority date assumed Oct. 22, 2012) was challenged in two inter partes reviews on obviousness grounds:
- IPR2023-00445 (Keysight Technologies, filed Jan. 6, 2023; instituted July 24, 2023)
- IPR2023-01329 (Palo Alto Networks, filed Aug. 21, 2023; instituted with joinder Feb. 22, 2024; grounds identical to IPR2023-00445)
The PTAB's Final Written Decision (July 22, 2024) found all 27 challenged claims unpatentable as obvious. On appeal (CAFC No. 24-2372), the Federal Circuit affirmed — per the prior summary, by Rule 36 summary affirmance (June 9, 2026). The practical answer to "would the claims be obvious" is therefore: yes — this is not merely a theoretical analysis; the claims were administratively and on appeal finally held obvious over the combinations below.
II. Legal framework
Obviousness under pre-AIA § 103 (applicable here given the 2012 priority date) requires showing the claimed invention as a whole would have been obvious to a person of ordinary skill in the art (POSITA) at the time of invention, per Graham v. John Deere: (1) scope and content of the prior art; (2) differences between the prior art and the claims; (3) level of ordinary skill; (4) secondary considerations. Under KSR Int'l Co. v. Teleflex, the motivation to combine need not be found in an express teaching-suggestion-motivation; it can arise from design need, market pressure, common sense, and the predictable results of combining known elements. A POSITA here would be someone with a computer science/engineering degree and several years of network-security/firewall/packet-processing experience (per the Jacobson declaration in the IPR).
All references below published before the Oct. 22, 2012 priority date and are § 102(b) prior art (dates per the Keysight petition): Law — Mar. 24, 2011; Wood — May 3, 2007; Jungck — Oct. 22, 2009.
III. The primary reference: Law (US 2011/0072506 A1, "Integrated Unified Threat Management for a Process Control System," Fisher-Rosemount)
Law is the backbone of every ground. It discloses:
- A Unified Threat Management System (UTMS) for process control networks, with network devices (firewalls 146a/146b, network access device 149c) configured to receive network traffic and apply rulesets (147a, 147b, 151c) received from an external source.
- Rulesets containing rules defining conditions to accept or deny traffic (policy-based and signature-based rulesets; default-allow and default-deny).
- A third-party cyber-security risk management firm 305 that "collect[s] threat data 310 from a plurality of various sources 315 to construct the various rulesets, validate the rulesets, verify, and distribute" them — i.e., a server-side entity that generates and pushes rulesets to boundary devices.
- A "perpetual service" that "proactively supplies the devices with rulesets to meet the latest security threats," and automatic ruleset updates triggered by detection of network conditions (Law ¶ 83).
Element mapping (Petitioner's, adopted by the Board): Law's firewalls/NAD = the claimed "packet security gateways"; firm 305's server = the "security policy management server" external to the protected network; Law's "sources 315" of threat data = "malicious host tracker service(s)"; Law's rulesets = the "dynamic security policy comprising a first set of packet filtering rules"; Law's accept/deny rules = the "packet transformation functions." Law's own stated purpose — proactively keeping pace with evolving threats in a distributed multi-network system — supplies the design rationale for centrally generated, automatically updated, boundary-enforced filtering rules.
Why Law alone was found to render all claims 1–27 obvious: The Board credited the petition's showing that Law's global ruleset concept, the plurality of network devices deployed at network boundaries (firewalls 146a/146b and network access device 149c), and firm 305's automatic construction/distribution of rulesets from aggregated threat data satisfy the independent-claim limitations, including the "automatically created or altered ... based on malicious traffic information received from a malicious host tracker service" limitation (Law's sources 315, per the FWD). Patent Owner's counterarguments (e.g., that NAD 149c sits outside the networks and thus the devices do not "collectively provide an entire interface across a boundary"; that firm 305 is a commercial entity, not a "server") did not carry the day before the Board or the Federal Circuit.
IV. The combinations and motivation to combine
Ground 1 — Law alone (claims 1–27)
As above. Motivation is inherent in Law: the reference's central teaching is that a process-control network's boundary devices should receive continuously updated rulesets from a central service that aggregates threat data from multiple third-party sources — exactly the architecture of the independent claims.
Ground 2 — Law + Wood (US 2007/0097976 A1, "Suspect Traffic Redirection") (claims 1–24)
What Wood adds: Wood discloses receiving "suspect traffic information pertaining to possible network threats"; "one or more suspect address sources 210" that provide a feed/list of suspect addresses 206 (communicated over the Internet) determined to be associated with malicious/suspect traffic; a router that detects and redirects suspect traffic to an interrogation module; and updating the suspect-traffic information and reconfiguring the router accordingly.
Element mapping: Wood's "suspect address sources 210" = the claimed "at least one third party malicious host tracker service ... that comprises network addresses that have been determined ... to be associated with malicious network traffic" — the exact limitation added to the independent claims during prosecution to overcome the prior art, and the limitation that was the focus of the Examiner's allowance.
Motivation to combine: This is a textbook KSR combination. (i) Law already discloses that firm 305 "collect[s] threat data 310 from a plurality of various sources 315"; Wood's suspect-address source is simply another instance of the very category of source Law already contemplates — the Petitioner's expert put it directly: "A POSITA would have recognized the suitability of Wood's 'suspect address sources 210' as another such source among Law's plurality of various sources 315." (ii) Wood's suspect-address feed is communicated over the Internet, so no system modification of Law is required for firm 305 to receive it. (iii) Both references are in the same field (network security/threat mitigation) and pursue the same goal (blocking or redirecting traffic associated with known-malicious hosts), making the combination of a threat-feed source (Wood) with a ruleset-generation/distribution system (Law) a predictable design choice. (iv) Wood's updating teaching ("the suspect address list should be updated ... to provide notice of possible threats," Wood ¶¶ 34, 36) maps directly onto Law's automatic-update mechanism, and a POSITA would find it obvious that firm 305 "would have created updated rulesets to reflect the information in the suspect address list, including adding blocking rules for packets matching IP addresses in the updated suspect address list" (Petition, Ground 2). (v) Wood's redirection of suspect traffic to an interrogation module also supplies the "packet transformation function other than forwarding or dropping" that the '266 specification emphasizes (rerouting/encapsulating packets to a monitoring device), giving Wood independent relevance beyond the tracker-service limitation.
Ground 3 — Law + Jungck (US 2009/0262741 A1) (claims 6, 13, 19, 26)
Claims 6, 13, 19, and 26 — the dependent claims the petition mapped to the third-party threat-information features — were challenged over Law in view of Jungck. Per the petition, Jungck, like Wood, discloses providing threat information (Law's "threat data 310") to a network security device. The motivation to combine Jungck with Law is the same as for Wood: Law expressly receives threat information "from a plurality of various sources 315," and Jungck is disclosed as another such source; adding it requires no modification to Law's architecture and yields the predictable benefit of broader threat coverage. (⚠️ Caveat: I could not verify Jungck's full disclosure before the search limit; the record confirms only that the petition characterized Jungck as disclosing provision of threat information and that the Board found the Law+Jungck and Law+Wood+Jungck combinations sufficient for claims 6/13/19/26. Treat the specific Jungck teachings as per the petition's characterization.)
Ground 4 — Law + Wood + Jungck (claims 6, 13, 19, 26)
The three-reference combination adds nothing structurally new: because Law's firm 305 already ingests threat data from "a plurality of various sources 315," and both Wood and Jungck are independent, known threat-information providers, the POSITA would aggregate both into Law's system for the same reasons given above. As the petition put it, "both Wood and Jungck disclose providing threat information 310, and Law discloses receiving threat information 310 from a plurality of various sources 315" — a POSITA would have been motivated to combine both because Law's design invites a multiplicity of sources, and each additional source improves threat coverage without system redesign. This is the classic "known, predictable solution to a known problem" combination under KSR.
Supplemental reference — Assurent VRS (Ex. 1007, Feb. 2, 2007 webpage printout)
Palo Alto's petition also placed into evidence the Assurent Vulnerability Research Service (VRS) printout — a subscription-based threat/vulnerability intelligence service. This supports the dependent-claim feature of a "subscription service that aggregates information associated with malicious network traffic" (the '266 specification at 14:17–28 describes exactly this: updates "as part of a subscription" from a malicious host tracker service). Motivation: subscription threat-intelligence feeds were a well-known commercial mechanism in 2007–2012; substituting a subscription-based aggregator for Law's "sources 315" (or Wood's "suspect address sources 210") is an obvious implementation choice, not an inventive step.
V. Why the combinations render the claims obvious as a whole
All claim elements are accounted for. For the independent claims (1, 8, 15): plurality of boundary gateways (Law's firewalls/NAD); policy received from an external management server (Law's firm 305 server); first set of rules applied to all traffic traversing the boundary (Law's boundary rulesets 147a/147b/151c); rules automatically created/altered based on third-party malicious-traffic information (Law's sources 315, filled in by Wood's/Jungck's suspect-address feeds and Assurent's subscription service); packet transformation functions including non-forward/drop actions (Law's accept/deny; Wood's redirection to an interrogation module). For the dependent claims (2–5, 7, 9–12, 14, 16–18, 20–25, 27): the petition mapped features such as the suspect-address list updating (Wood ¶¶ 34, 36 → claims 2, 9, 16, 23) and the aggregated multi-address malicious-traffic information (Wood's multiple suspect address sources → claims 3–4, 10–11, 17, 23–24) to the same references, with the Board agreeing.
The combination is a simple aggregation of known components serving their known purposes. Law already teaches the system (central ruleset authority + boundary enforcement devices + aggregated third-party threat feeds); Wood and Jungck merely supply better-specified instances of the threat-feed component Law already names ("a plurality of various sources 315"). No unexpected result, no new function — the combination operates exactly as each component was designed to operate.
Strong design-need/market-pressure rationale. The '266 Background itself concedes the industry problem: reactive security is inadequate, and proactive high-resolution filtering was thought unscalable. Law's "perpetual service" is the prior art's own answer to that problem; the claimed invention is, at bottom, the same answer with a more granular threat-feed source. A POSITA seeking to improve Law's UTMS with better threat data would turn to known threat-feed providers such as Wood's suspect-address sources, Jungck's threat-information service, or Assurent VRS — an obvious "known options" selection, not invention.
Secondary considerations do not rescue the claims. While Centripetal has elsewhere (in other patents, e.g., the 9,917,856 IPR) obtained a remand on copying evidence, for the '266 patent the record's secondary-considerations arguments were insufficient: the PTAB found all 27 claims unpatentable, and the Federal Circuit affirmed without opinion (Rule 36, per the prior summary). There is no substantiated nexus-based copying or long-felt-need showing in the '266 record that would overcome the prima facie case.
VI. Conclusion
The claims of US 10,785,266 would be obvious under § 103 over the combinations actually asserted and adjudicated: (1) Law alone (claims 1–27); (2) Law + Wood (claims 1–24); (3) Law + Jungck (claims 6, 13, 19, 26); and (4) Law + Wood + Jungck (claims 6, 13, 19, 26), with Assurent VRS available to bolster the subscription-service dependent limitations. The motivation to combine is compelling under KSR: Law already contemplates a plurality of third-party threat-data sources feeding a central ruleset service, and Wood, Jungck, and Assurent are precisely such sources; integrating them is a predictable, design-driven improvement with no modification to Law's architecture. This conclusion is not merely analytical — it is the outcome reached by the PTAB in its July 22, 2024 Final Written Decision (all 27 claims unpatentable) and upheld by the Federal Circuit (CAFC No. 24-2372), making the obviousness of the '266 patent the established legal result as of the record before me.
Confidence levels: High — ground structure, reference identities/dates, element mappings for Law/Wood, and the FWD outcome (verified via PTAB/docket records). Medium — Jungck's specific teachings (verified only via the petition's characterization) and the verbatim text of the granted claims (reconstructed from the IPR record, since the full claims text was not in the provided excerpt).
Generated 8/30/2026, 4:49:18 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 6665293I'll search for authoritative information on US Patent 6,665,293 and any CAFC 2026 docket references. Both searches returned no results. Let me try broader queries to locate authoritative sources. I have confirmation from Google Patents…
- US 6424624I searched the USPTO/patent databases and CAFC docket sources for the specific patent number 6424624 (i.e., US 6,424,624 B1 / US6424624B1). Here is the summary, with notes on confidence. Verification note - Searches for "6424624" confirmed…
- US 10491646Summary of U.S. Patent No. 10,491,646 (US10491646B2) I searched for the specific patent number 10491646 (front-page form: US 10,491,646 B2) and did not rely on similar numbers (e.g., 8,166,892, IPR2025-01046/01047, etc., which appeared in…
- US 9338140US Patent 9,338,140 B2 — Summary Bibliographic data (verified against USPTO-adjacent sources and the issued patent PDF) | Field | Data | |---|---| | Patent number | US 9,338,140 B2 (application no. 13/468,383) | | Title | Secure data…
- US 9129376US Patent 9,129,376 B2 — Summary Searches performed I searched for the exact identifier 9129376 (and US9129376B2 / 9,129,376) in patent databases and litigation/CAFC sources, and searched the CAFC 2026 docket for this patent number. My…
- US 8825454US Patent 8,825,454 — Summary Note on sources: Bibliographic data below is corroborated by Google Patents (patents.google.com/patent/US8825454) and FreePatentsOnline. The full specification was supplied in your prompt; however, the claims…
- US 8818770I have confirmation of the key bibliographic data and relevant dockets. Let me retrieve the independent claims' full text to describe them accurately. US Patent 8,818,770 B2 — Summary Bibliographic data (verified against USPTO/Google…
- US 8170840The CAFC 2026 hits so far involve different EagleView patents (8,670,961 and 8,078,436) — not 8,170,840. Let me verify whether 8,170,840 itself appears in any 2026 CAFC activity and pull the actual claim set. I need the actual claim text…
This patent in court (8)
8 tracked lawsuits name US 10785266.