Invalidity dossier

US 10931797

Correlating packets in communications networks

Current assignee: Centripetal Networks LLC

Added 8/30/2026, 4:49:31 AM

At a glanceNo PTAB challenges4 lawsuits on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Based on my searches of the USPTO/Google Patents records, the PTAB docket (PGR2021-00108), and CAFC/EDVA dockets, here is a concise summary of U.S. Patent No. 10,931,797 (US10931797B2). I have interpreted all identifiers literally as provided and did not auto-correct any numbers (note: the patent number is 10,931,797 B2, often written as "US10931797" in databases).

Bibliographic Data (from the patent front page and USPTO records)

Field Value
Title Correlating packets in communications networks
Patent No. US 10,931,797 B2
Application No. 16/854,094
Filing date April 21, 2020
Issue date February 23, 2021
Priority date February 10, 2015 (earliest; via continuation chain from 14/618,967, now US 9,264,370)
Assignee (original) Centripetal Networks, Inc., Portsmouth, NH (later renamed Centripetal Networks, LLC in 2023)
Inventors David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH); Pierre Mallett, III (Herndon, VA); Sean Moore (Hollis, NH); Robert T. Perry (Ashburn, VA)
Attorney/Agent Banner & Witcoff, Ltd.
Examiner Obaidul Huq
Claims / Figures 20 claims; 7 drawing sheets
Prior publication US 2020/0252486 A1 (Aug. 6, 2020)
Status Active; maintenance fee paid Aug. 9, 2024 (4th year, small entity); subject to a terminal disclaimer. Google Patents lists anticipated expiration as 2035-02-10.

Continuation chain: 16/854,094 → continuation of 16/554,293 (US 10,659,573) → continuation of 15/413,947 (US 10,530,903) → continuation of 14/714,207 (US 9,560,176) → continuation of 14/618,967 (US 9,264,370).

Abstract

"A computing system may identify packets received by a network device from a host located in a first network and may generate log entries corresponding to the packets received by the network device. The computing system may identify packets transmitted by the network device to a host located in a second network and may generate log entries corresponding to the packets transmitted by the network device. Utilizing the log entries corresponding to the packets received by the network device and the log entries corresponding to the packets transmitted by the network device, the computing system may correlate the packets transmitted by the network device with the packets received by the network device."

Plain-Language Overview of the Invention

The patent addresses the problem that network devices (e.g., NAT devices, proxies, VPN/tunneling gateways, or other "flow-transforming" devices) alter packets as they pass through, obscuring which packets belong to which communication flow — a problem that can be exploited by malicious entities (e.g., man-in-the-middle attacks). The solution uses tap devices placed on both sides of the transforming network device:

  1. A tap on the ingress side identifies packets received by the network device from a host in a first network and generates log entries for them (e.g., network-layer, transport-layer, application-layer data, and timestamps).
  2. A tap on the egress side identifies the corresponding (altered) packets transmitted by the network device toward a host in a second network and generates log entries for those.
  3. A "packet correlator" compares the two sets of log entries — using payload/header data, correlation scores, timestamps, or latency thresholds — to correlate transmitted packets with received packets, thereby revealing the underlying flow and the true source host (e.g., identifying a host behind NAT that communicated with a malicious entity).
  4. Based on the correlation, the system can generate messages/notifications and provision updated filtering rules (e.g., to drop traffic from a compromised host).

Independent Claims (with caveats)

The full claim text was not reproduced in the materials I have (the Google Patents extraction cut off before the claims; the claims were also not in the PTAB excerpts), so the following is reconstructed from the PGR2021-00108 petition's claim-construction discussion and the family-member patent US 10,530,903. Treat claim wording details as approximate.

  • Claim 1 (method) — A method for correlating packets in a communications network, generally comprising: (a) determining a first plurality of log entries corresponding to packets received by a network device from a host in a first network; (b) determining a second plurality of log entries corresponding to packets transmitted by the network device to a host in a second network; (c) correlating the transmitted packets with the received packets based on a comparison of the first and second pluralities of log entries; and (d) based on the determined correlation, provisioning/generating rules configured to identify packets (e.g., received from or transmitted to identified hosts), with rule generation optionally including receiving user input defining the rules. (Claim 1 is a method claim; per the PGR petition it covers elements such as "determining…a first plurality of log entries," "determining…a second plurality of log entries," "provisioning…based on the determined correlation," and "receiving user input defining the one or more rules.")

  • Claim 11 (system) — An apparatus/system claim (the only other independent claim, based on the PGR challenge grouping: claims 1–10 and 12–20 are dependent on claims 1 or 11) reciting a computing system (e.g., the packet correlator) with one or more processors and memory configured to perform the same core operations: generating first log entries for packets received by the network device from a first-network host, generating second log entries for packets transmitted by the network device to a second-network host, correlating transmitted packets with received packets using the log entries (e.g., by comparing packet data and/or timestamps), and outputting/provisioning rules or notifications based on the correlation.

Uncertainty note: I did not have access to the verbatim text of claims 1 and 11. The characterization above is based on (i) the specification's described method (FIG. 4 steps 402–410), (ii) the PGR2021-00108 petition's claim charts (which map Paxton/Sutton/Ivershen to the "first/second plurality of log entries," "correlation," and "provisioning rules" limitations), and (iii) the family-member '903 patent. If you need exact claim language, the authoritative source is the USPTO Patent Center or the PDF at patents.google.com/patent/US10931797B2/en.

Litigation / PTAB Status (as of the search date)

  • PGR2021-00108Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (PTAB): Petition for post-grant review of claims 1–20 of the '797 patent filed Aug. 3, 2021; institution DENIED Feb. 22, 2022 (Board decision by APJ Bryan F. Moore; panel included APJs Stacey G. White and Aaron W. Moore). Petitioner's rehearing request was not granted; the case shows status "Institution Denied / Terminated."
  • District courtCentripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137 (E.D. Va., Norfolk Div., filed Mar. 12, 2021; Judge Elizabeth W. Hanes). US10931797 is listed among 13 patents-in-suit (along with 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10749906, 10757126, 10785266).
  • CAFC appealsCentripetal Networks, LLC v. Palo Alto Networks, Inc., Nos. 25-1167 (lead) and 25-1168 (member), filed Nov. 13, 2024, appealing the E.D. Va. case; consolidated as appeal/cross-appeal; deactivated pending post-judgment motions and reactivated per E.D. Va. docket entry 1017 (Dec. 22, 2025). Google Patents also lists a CAFC case 26-1359 associated with the patent family, but I could not retrieve details on that docket — uncertain whether the specific '797 patent is at issue in 26-1359 or in the 25-1167/25-1168 appeals (the district case includes 13 patents, and the CAFC dockets do not clearly itemize which patents are on appeal).

Confidence note: Bibliographic data, the abstract, the PTAB proceeding, and the EDVA case listing are well corroborated by multiple sources (Google Patents, Docket Alarm, RPX, Patexia, Justia). The verbatim independent-claim language is the one item I could not confirm from the available search results, so I flagged it as approximate.

Generated 8/30/2026, 12:45:57 PM

Cases on file (4)

Group view →

Specific litigation cases in our database that name US patent 10931797. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2021: 3 cases3'21'22'232024: 1 case'24
Cases asserting US 10931797, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Based on my searches, here is the known litigation involving US Patent 10,931,797 (US10931797B2, "Correlating packets in communications networks," owned by Centripetal Networks, LLC, f/k/a Centripetal Networks, Inc.). I have only included matters that specifically involve this exact patent number (the '797 patent). Note: I excluded the Keysight Technologies IPR/appeal matters (IPR2022-01097; CAFC 2024-1406/2024-1473) because those concern US Patent No. 10,193,917 — a different patent — not 10,931,797.


1. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — E.D. Va. (District Court)


2. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — CAFC Appeal No. 25-1167 (Palo Alto's appeal)


3. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — CAFC Appeal No. 25-1168 (Centripetal's cross-appeal)


4. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — CAFC Appeal No. 26-1359


5. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — PTAB PGR2021-00108 (post-grant review)


6. Ex parte reexamination 90/019,561 (USPTO administrative proceeding — not court litigation)


Summary table

# Case Court / Forum Case No. Filed Status
1 Centripetal v. Palo Alto Networks E.D. Va. 2:21-cv-00137 03/12/2021 Jury verdict for Centripetal ($151.1M); JMOL granted in part/denied in part; closed 10/17/2024; on appeal
2 Centripetal v. Palo Alto Networks CAFC 25-1167 11/13/2024 Consolidated w/ 25-1168; reactivated 12/2025; pending
3 Centripetal v. Palo Alto Networks CAFC 25-1168 11/13/2024 Consolidated cross-appeal; pending
4 Centripetal v. Palo Alto Networks CAFC 26-1359 01/20/2026 Pending
5 Palo Alto Networks v. Centripetal PTAB PGR2021-00108 08/03/2021 Institution denied 02/22/2022; appealed (2022-145)
6 Ex parte reexamination of '797 USPTO 90/019,561 07/01/2024 Granted (claims 1, 12, 17); ongoing

Caveat: For the CAFC appeals (25-1167, 25-1168, 26-1359) and the reexamination, I could not confirm final merits decisions from the available public docket data as of today (April 26, 2026); the appeals appear still pending, and the reexamination is ongoing. The district court case outcome (item 1) is the most fully documented, with the jury verdict and post-trial rulings confirmed by multiple sources.

Generated 8/30/2026, 12:45:51 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

The USPTO Open Data Portal (ODP) block on file reports zero AIA trial proceedings, but that appears to be an ingest lag: the Google Patents metadata embedded in this patent's record and independent web research surface one PGR — PGR2021-00108 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc., filed 2021-08-03, in which the Board denied institution on the merits (terminated 2022-02-22). Breakdown by status: 0 active, 0 claims invalidated, 0 claims sustained via Final Written Decision, 0 settled, 1 institution denied. Bottom line for a defendant: no claim of US 10,931,797 has ever been canceled, and the patent has never gone through a PTAB trial — the only AIA challenge was thrown out at the threshold, which makes the patent "hardened" against the specific art Palo Alto Networks raised, but leaves all 20 claims substantively untested by an IPR/PGR merits decision.


PGR2021-00108 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.

  • Type: Post-Grant Review
  • Filed: 2021-08-03
  • Status: Institution Denied (Board Paper 9, "Decision Denying Post-Grant Review" under 37 C.F.R. § 42.208, entered 2022-02-22; proceeding terminated same day; filing fee refund approved 2022-11-04). Google Patents' litigation metadata labels it "Not Instituted - Merits." Plain-English gloss: the PGR never got off the ground — no trial was ever instituted, so no Final Written Decision exists.
  • Judge panel: Bryan F. Moore (Administrative Patent Judge, author of the institution decision), Stacey G. White, and Aaron William Moore (per the decision and RPX/Patexia records).
  • Petition grounds (challenging claims 1–20 of US 10,931,797, with the Akl declaration, Ex. 1003):
    • § 103 obviousness over Paxton (US 2014/0280778) + Sutton (US 8,413,238) → claims 1, 2, 7, 8, 10, 12, 13, 17, 18;
    • § 103 over Paxton + Sutton + Ivershen (US 8,219,675) → claims 3–6, 14–16, 19, 20;
    • § 103 over Paxton + Sutton + Deschênes (US 2013/0262655) → claim 9;
    • § 103 over Paxton + Sutton + Roese (US 2006/0048142) → claim 11;
    • § 112(b) indefiniteness → claims 1–20 (attack on "determining… a first plurality of log entries" and the alleged circularity of the "provisioning… rules… to identify the first plurality of packets" limitations);
    • § 112(a) written description / enablement → claims 1–20.
  • Institution decision: Denied — 2022-02-22. The Board was "not persuaded by Petitioner's argument and evidence" on the lead Paxton–Sutton obviousness ground, specifically as to the "generating… based on the determined correlation, one or more rules…" and "provisioning a packet-filtering device…" limitations of independent claims 1, 12, and 17. Patent Owner's Preliminary Response had also pressed discretionary denial under the Fintiv factors (advanced E.D. Va. litigation, Centripetal Networks, Inc. v. Palo Alto Networks, Inc., No. 2:21-cv-00137) and under § 325(d) (Ivershen and materially similar motivation-to-combine arguments had already been considered during prosecution and in the family IPRs IPR2018-01654 / IPR2018-01655 directed to parent US 9,560,176). Caveat: only partial text of Paper 9 was retrievable in this research pass; the decision is public on the PTAB docket for exact ground-by-ground reasoning.
  • Final Written Decision: None. No claim was instituted, tried, or canceled.
  • Settlement / termination: No settlement. The proceeding terminated by operation of the institution denial (2022-02-22). Palo Alto Networks filed a Request for Director Rehearing (Paper 10, 2022-03-17); the USPTO declined to accept requests for Director review of institution decisions, and the fee was refunded.
  • Appeal: No FWD to appeal. The related Federal Circuit matter is In re Palo Alto Networks, Inc., No. 22-145 (Fed. Cir. 2022) — a petition for writ of mandamus (not an appeal) seeking to compel the USPTO to accept Director rehearing of the institution denials in PGR2021-00108 and IPR2021-01151. The Federal Circuit denied the writ in a precedential opinion (2022-08-16, panel of Dyk, Reyna, Chen), holding that the Director's delegation of institution authority to the PTAB and the policy of not accepting party-filed Director rehearings of institution decisions do not violate the Appointments Clause under Arthrex. (Separately, the district-court litigation docket shows CAFC appeals 25-1167, 25-1168, and 26-1359, but those arise from the E.D. Va. case, not from this PTAB proceeding.)
  • Defensive value: Limited and double-edged. The denial means the patent owner successfully fended off the only PTAB attack, and the specific Paxton/Sutton/Ivershen/Deschênes/Roese combination has now been rejected at the Board — a § 325(d)-flavored headwind for anyone re-running that exact art. But because institution was denied, there is no estoppel (§ 325(e)) and no merits holding of patentability; a defendant cannot cite a FWD canceling claims, and the same or different art can be re-raised in district court or a fresh, differently-constructed petition.

Strategic summary

Claims CANCELED vs. SUSTAINED vs. UNTESTED. No claim of US 10,931,797 has ever been canceled. No claim has ever been "sustained" by a PTAB Final Written Decision either — because no trial was ever instituted. All 20 claims (1–20) are UNTESTED in any AIA trial on the merits. The patent remains fully in force (status: Active; anticipated expiration 2035-02-10), and the only PTAB contact it has had is a PGR that was denied at the institution stage. The parent-family IPRs (IPR2018-01654/01655 on US 9,560,176) are on a different patent in the same chain and do not cancel anything in the '797 itself, though the Board's § 325(d) logic in the PGR treated that family history as evidence the art was already considered.

Estoppel landscape. Because PGR2021-00108 ended in an institution denial, neither § 325(e) (PGR estoppel) nor § 315(e) (IPR estoppel) attaches, and Palo Alto Networks (and its privies) are not barred from re-litigating any ground. A defendant today is free to raise Paxton, Sutton, Ivershen, Deschênes, Roese, and the § 112 indefiniteness/written-description theories in district court — and to file a new PGR/IPR petition with different primary references, different claim constructions, or additional evidence. The practical caveats are (i) the § 315(b) one-year bar runs from service of your infringement complaint, so file early, and (ii) the Board has already signaled skepticism of the Ivershen-based and Paxton+Sutton-based narratives via § 325(d), so a new petition should lead with genuinely new art (e.g., Copeland, McDonald, Bharali, Prenger, Kasralikar, Kapoor, or Jarvis — all of which were in PAN's exhibit list but never advanced as primary grounds).

Pattern signals. The sole PTAB challenger has been Palo Alto Networks, and its attack was bundled into a broader, coordinated campaign against the Centripetal family (parallel IPRs on sibling patents — e.g., IPR2021-01147/01148/01149/01150/01152/01157/01158, IPR2022-00182, IPR2022-01097 — several of which were instituted and went to FWD, including family patents invalidated over Sourcefire). The '797 PGR is notable as the one that failed to institute. The patent owner (Centripetal Networks, Inc., now LLC) has litigated aggressively — E.D. Va. 2:21-cv-00137, ITC Inv. No. 337-TA-1314 — and fought procedural battles up to the Federal Circuit (the In re Palo Alto Networks mandamus, 22-145). Note a data-hygiene flag: the Google Patents litigation block attributes PGR2021-00108 to "Unified Patents" — but that is Unified Patents' data-licensing attribution, not the petitioner; the actual petitioner of record is Palo Alto Networks, Inc. (Unified Patents is not in the chain as petitioner here).


Recommended next steps

  • There is no FWD to cite and no canceled claim to leverage. If your demand letter cites claims 1–20 of the '797, do not assume any of them are dead — all remain presumptively valid under 35 U.S.C. § 282. Your strongest PTAB-related talking point is procedural: the only PGR (PGR2021-00108) was denied institution on 2022-02-22, meaning Palo Alto Networks is not estopped, and a fresh petition grounded in new art not previously considered (rather than the Paxton/Sutton/Ivershen line the Board already rejected) remains the viable path. Pull Paper 9 from the PTAB docket (DocketAlarm mirror: Institution Decision — Deny) and the precedential mandamus ruling (In re Palo Alto Networks, Inc., 22-145, CourtListener) before drafting.
  • No active PTAB proceeding is pending, so there are no institution-deadline, oral-hearing, or 12-month trial-deadline milestones to track. The live battleground is the E.D. Va. case (2:21-cv-00137) and its CAFC appeals (25-1167, 25-1168, 26-1359) — monitor those dockets for validity rulings that could collaterally estop or inform a future PTAB petition.
  • On the ODP "no proceedings" default: treat it as an ingest artifact. The ODP block is stale relative to PGR2021-00108, which is confirmed by the PTAB decision itself, RPX, Patexia, and DocketAlarm. The absence of a successful IPR/PGR, however, is itself a signal: this is a heavily-asserted Centripetal patent that has already survived one threshold challenge — a defendant should expect the patent owner to argue the art is "old and considered," and should bring genuinely new, non-cumulative prior art rather than recycling PAN's grounds.

Generated 8/30/2026, 12:46:32 PM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2020-04-21 · Assignment

    David K. Ahn, Peter P. Geremia, Pierre Mallett III, Sean Moore, Robert T. PerryCentripetal Networks, Inc.

  2. ? · recorded 2023-01-20 · Change of Name

    Centripetal Networks, Inc.Centripetal Networks, Inc.

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Assignment & Ownership Analysis — US 10931797 B2 ("Correlating packets in communications networks")

Verification caveat: I was able to confirm the recorded-assignment events through Google Patents legal-event data, USPTO PTAB filings, and litigation records, but I could not retrieve the USPTO Assignment Center reel/frame numbers or the recorded correspondent names through the searches available in this session. Where a field (reel/frame, correspondent) is not recoverable from the evidence at hand, I say so explicitly rather than estimate. The authoritative page to confirm is: https://assignmentcenter.uspto.gov/ (search "10931797").


Inventors

Inventor Employer at filing (determinable)
David K. Ahn Centripetal Networks, Inc. — assignor of record on the recorded assignment (per Google Patents legal event)
Peter P. Geremia Centripetal Networks, Inc. — assignor of record
Pierre Mallett, III Centripetal Networks, Inc. — assignor of record
Sean Moore Centripetal Networks, Inc. — assignor of record (also Centripetal's CTO in public coverage of the Cisco litigation)
Robert T. Perry Centripetal Networks, Inc. — assignor of record

Pattern check: No unusual departure pattern. All five inventors assigned to the original assignee (Centripetal Networks, Inc.) on the same recorded instrument — a standard employee/inventor assignment into the employer. Sean Moore remained a Centripetal principal well past filing (he is publicly identified with the company through the Cisco/Palo Alto/Keysight litigation era), so no "inventors fled within 12 months" fire-sale precursor is present.


Original assignee

  • Entity on the issued patent: Centripetal Networks, Inc. (later converted to Centripetal Networks, LLC).
  • Products: Yes — Centripetal ships network-security / packet-filtering appliances and services (CleanINTERNET, RuleQUEST, ThreatARMOR, DataGuardian product line). Per COO Jonathan Rogers's June 2022 Congressional testimony, the company operates two offices, employs 100+ people, serves ~100 major customers, and has invested ~$200M in R&D.
  • Line of business: Cybersecurity — rule-based network threat detection, packet filtering, and network traffic correlation (the claimed subject matter of this patent).
  • Current status: Operating. Centripetal Networks, LLC is active and litigating (ITC 337-TA-1314, E.D. Va. cases, Federal Circuit appeals 25-1167 / 25-1168 / 26-1359). The corporate form changed from Inc. to LLC effective 2022-12-30 (name change only; same Reston, VA address: 1875 Explorer Street, Suite 900).

Assignment timeline

The USPTO Assignment Center does contain records for this patent, but my search access did not surface the reel/frame or correspondent fields. The two recorded events below are corroborated by the Google Patents legal-event feed and by Centripetal's own PTAB filings (IPR2022-01097 and IPR2022-00182, "Modification of Notice of Real Party in Interest," filed 2023-01-19, which state that a recordation of the name change "for the patent at the USPTO" was filed).

  • 2020-04-21 (recorded) — reel/frame not retrievable from available sources

    • Conveyance: Assignment of Assignors' Interest
    • Assignor: David K. Ahn, Peter P. Geremia, Pierre Mallett III, Sean Moore, Robert T. Perry (inventors)
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not retrievable from available sources
    • Context: Standard inventor-to-employer assignment recorded on the filing date of the continuation application (US 16/854,094) that matured into this patent. No red flag.
  • 2023-01-20 (recorded) — reel/frame not retrievable from available sources

    • Conveyance: Change of Name
    • Assignor: Centripetal Networks, Inc.
    • Assignee: Centripetal Networks, LLC
    • Correspondent: not retrievable from available sources
    • Context: Pure corporate conversion (Inc. → LLC, effective 2022-12-30) at the same Reston, VA address; disclosed to the PTAB in the patent owner's modification-of-RPI notices. No change in beneficial ownership and no transfer of the patent out of the operating company.

No other recorded assignments exist (no transfers to licensing LLCs, no security agreements, no mergers). The chain is two links and both are unremarkable.


Timeline diagram

timeline
    title Ownership of US 10931797
    2015 : Priority filing by Centripetal Networks Inc
    2020 : Continuation filed
         : Inventors assign to Centripetal Networks Inc
    2021 : Patent issued
    2022 : Corporate name change to LLC
    2023 : Name change recorded at USPTO

NPE / troll-pattern signals

  1. Shell-entity transfernot present. The only post-inventor event is an Inc.→LLC conversion of the same operating company at the same address. The assignee ships actual products (CleanINTERNET, RuleQUEST, ThreatARMOR), employs 100+ people, and has ~100 customers. No transfer to a licensing-only LLC, no registered-agent-service address, no single-purpose LLC.

  2. Known asserter in the chainnot present against the specified lists. Neither Centripetal Networks, Inc. nor Centripetal Networks, LLC appears on the Acacia / Marathon / Intellectual Ventures / IPNav / Wi-LAN / Conversant / Vringo / Pendrell / Innovatio / MPHJ / Lumen View / Round Rock / Document Generation Corp / Spangenberg-entity lists. (Unified Patents has challenged Centripetal — PGR2021-00108, not instituted — and Centripetal is a high-frequency plaintiff, but the question is whether the assignee matches a known NPE list; it does not.)

  3. Repeat correspondent across the chainunclear. The correspondent-of-record fields could not be retrieved from the sources available in this session. No finding either way; I decline to speculate.

  4. Cascading transfersnot present. Exactly two recorded events, separated by ~2.5 years, one of which is a name change. No chained LLC transfers, no common-principal shell ladder, no rapid-fire assignment sequence.

  5. Pre-litigation transfernot present. The inventor assignment was recorded 2020-04-21; the first infringement suit naming this patent (Centripetal Networks, Inc. v. Palo Alto Networks, Inc., E.D. Va. 2:21-cv-00137) was filed 2021-03-12 — roughly 11 months later, and the assignment was the routine employer-inventor recordation at filing. The 2023 name change postdates all first-wave litigation. No assignment was timed to set venue or standing for assertion.

  6. Bankruptcy fire-salenot present. Centripetal has not filed Chapter 7/11 and no patent sale in a bankruptcy proceeding is recorded.

  7. Privateeringnot present. This is the inverse pattern: the operating company itself asserts its own patents against competitors (Cisco, Palo Alto Networks, Keysight) and even defended the famous ~$2.75B Cisco verdict (reversed in part on appeal, CAFC). No operating-company-to-NPE transfer occurred.

  8. Defensive aggregator (anti-NPE)not present. The chain terminates at Centripetal Networks, LLC, which is an asserting operating company — not RPX, AST, LOT, Unified Patents, or OIN.


Verdict

Operating-company assertion.

The recorded chain is trivial — inventors → Centripetal Networks, Inc. (recorded 2020-04-21) → Centripetal Networks, LLC via name change only (recorded 2023-01-20) — with no transfer to any licensing entity, no cascading shell assignments, and no pre-litigation timing games. The current assignee is a 100+-employee cybersecurity vendor that ships products embodying the claimed packet-correlation/filtering technology and asserts this patent directly against competitors (e.g., Palo Alto Networks in 2:21-cv-00137; the family has also been asserted against Cisco and Keysight). None of the eight NPE signals is affirmatively present, and the only "unclear" item (correspondent identity) is a data-availability gap, not evidence of a shell structure.

Confirm at the USPTO Assignment Center: https://assignmentcenter.uspto.gov/ (search patent number 10931797; the two recorded events — inventor assignment 2020-04-21 and change of name 2023-01-20 — should appear, with reel/frame and correspondent fields I could not retrieve in this session).

Generated 8/30/2026, 12:46:08 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

Prior Art Analysis — U.S. Patent No. 10,931,797 B2 ("Correlating Packets in Communications Networks")

1. Patent Identification (verified)

Field Value
Patent No. US 10,931,797 B2 (application 16/854,094)
Title Correlating packets in communications networks
Assignee Centripetal Networks, Inc. (later Centripetal Networks, LLC)
Inventors David K. Ahn; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry
Priority date 2015-02-10
Filed 2020-04-21
Granted / published 2021-02-23
Status Active; anticipated expiration 2035-02-10
Source https://patents.google.com/patent/US10931797/en

Continuity chain (all same title, all Centripetal): US 14/618,967 → US 9,264,370 B2 (granted) → US 14/714,207 → US 9,560,176 B2 → US 15/413,947 → US 10,530,903 B2 → US 16/554,293 → US 16/854,094 → US 10,931,797 B2 → US 17/177,572 → US 11,683,401 B2 → US 18/199,490 → US 11,956,338 B2 → US 18/588,655 (US 2025/0039284 A1).

Relevant proceedings (from the Google Patents record):

  • PGR2021-00108Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (filed Aug. 3, 2021) — Not Instituted (merits).
  • E.D. Va. 2:21-cv-00137 — Centripetal Networks v. Palo Alto Networks.
  • CAFC appeals 25-1167, 25-1168, 26-1359.
  • An ex parte reexamination request asserted "a substantial new question of patentability affecting claims 1, 12, and 17" of the '797 patent (DocketAlarm, Doc. 993-4, E.D. Va. 2:21-cv-00137).

2. Important caveat on the citation set

The Google Patents full-text snapshot provided to me (fetched 2026-08-30) does not include the front-page "Patent Citations" (References Cited) section, and I was unable to complete a USPTO Patent Center pull of the face-of-patent citation list within the step limit. The reference list below is compiled from (a) the Unified Patents patent record for 10931797 (which aggregates 298 items of "Patent Art" associated with the family), and (b) the PGR/reexamination record. I flag with medium confidence which references were examiner-cited on the face of the '797 patent versus merely cited in a family member or in an IDS. The definitive list must be confirmed on USPTO Patent Center (bibliographic data / "References Cited" tab). I have interpreted every number literally, with no auto-correction.


3. Prior-art references identified and § 102 analysis

The independent claims at issue appear to be claims 1, 12, and 17 (method / system / computer-readable medium in the standard three-part pattern used throughout the Centripetal family — an inference, not verified claim text). The claimed core method is: (i) identify packets received by a network device from a host in a first network; (ii) generate log entries for those received packets; (iii) identify packets transmitted by the network device to a host in a second network; (iv) generate log entries for those transmitted packets; and (v) correlate transmitted packets with received packets using the log entries — overcoming obfuscation by NAT/proxy/tunneling devices.

3.1 Continuity "citations" (listed on the face of the patent but not § 102 prior art)

These appear in the record as citations but cannot anticipate under § 102 due to the § 102(b)(2)/continuity exceptions and common ownership:

Reference Dates Description § 102 potential
US 9,264,370 B2 (14/618,967) filed 2015-02-10; granted 2016-02-23 Parent application, same title/spec None — parent of record
US 9,560,176 B2 (14/714,207) filed 2015-05-15; granted 2017-01-31 Intermediate continuation None — common assignee/continuity
US 10,530,903 B2 (15/413,947) filed 2017-01-24; granted 2020-01-07 Intermediate continuation None — common assignee/continuity

3.2 Third-party references from the patent-family art record

The following references appear in the aggregated art record for the family. Each is analyzed against the claim features above; the "likely claims" column assumes claims 1, 12, 17 are the independent claims and that the dependent claims add data-type, timestamp, correlation-score, and remediation features described in the specification.

Reference (full citation as listed) Publication / filing date Brief description Which claims it potentially anticipates (§ 102)
US 9,137,205 B2 — "Methods and Systems for Protecting a Secured Network" (Centripetal family art) priority 2012-10-21 Rule-based packet filtering/security gateway that inspects and logs packets at network ingress/egress Potentially claims 1, 12, 17 for the log-entry generation and packet identification steps; likely fails the cross-tap "correlating transmitted with received" step unless it discloses paired-tap correlation
US 2011/0055916 A1 — "Methods, Systems, and Computer Readable Media for Adaptive Packet Filtering" (Great Wall Systems) filed 2009-08-27; pub. 2011-03-10 Adaptive packet filtering with rule sets on filtering devices — relevant to tap-device provisioning with rules (spec steps 1–3) Potentially claims 1, 12, 17 (partial), and dependent claims reciting rule-based identification criteria
US 2006/0195896 A1 — "Method, Systems, and Computer Program Products for Implementing Function-parallel Network Firewall" (Wake Forest Univ.) filed 2004-12-21; pub. 2006-08-31 Parallel firewall processing of packet flows with logging Potentially dependent claims directed to generating log entries; less likely to disclose cross-device correlation
CA 2,600,236 A1 — "Methods, Systems, and Computer Program Products for Network Firewall Policy Optimization" filed 2005-03-27 Firewall policy optimization; related to rule generation Potentially dependent claims directed to rule generation/provisioning
US 2003/0145225 A1 — "Intrusion Event Filtering and Generic Attack Signatures" (Trend Micro) filed 2002-01-27; pub. 2003-07-31 Intrusion-event filtering using signatures Potential anticipation of dependent claims on filtering/logging criteria; unlikely to reach the correlation step
US 2010/0082811 A1 — "Filtering Unwanted Data Traffic Via a Per-customer Blacklist" (AT&T) filed 2008-09-28; pub. 2010-04-01 Per-customer blacklist filtering Relevant to the post-correlation "drop packets from host 114" claims (e.g., later dependents)
US 2003/0005122 A1 — "In-kernel Content-aware Service Differentiation" (IBM) filed 2001-06-26; pub. 2003-01-02 Content-aware packet handling in-kernel Marginal; potentially dependent claims on application-layer header parsing
US 8,789,135 B1 — "Scalable Stateful Firewall Design in OpenFlow Based Networks" (Google) filed 2012-06-14; granted 2014-07-22 Stateful firewall flow tracking in SDN/OpenFlow Potentially claims 1, 12, 17 for flow/state correlation; likely lacks the two-sided (ingress/egress tap) log-entry correlation
US 2007/0147380 A1 — "Systems and Methods for Implementing Protocol-aware Network Firewall" (Verizon) filed 2005-11-07; pub. 2007-06-28 Protocol-aware firewall inspection Dependent claims on protocol-layer (network/transport/application) log data
US 2009/0150972 A1 — "Apparatus and Method for Managing P2P Traffic" (ETRI) filed 2007-12-06; pub. 2009-06-11 P2P traffic management/correlation Potentially claims 1, 12, 17 (flow correlation); dependent claims on flow identifiers
US 2008/0101234 A1 — "Identification of Potential Network Threats Using a Distributed Threshold Random Walk" (Juniper) filed 2006-10-29; pub. 2008-05-01 Threat identification via distributed correlation Relevant to post-correlation threat-notification claims (steps 26–29)
US 2011/0277034 A1 — "System and Method for Three-dimensional Visualization of Vulnerability and Asset Data" (Tenable) filed 2010-05-05; pub. 2011-11-10 Asset/vulnerability visualization Marginal; remediation/messaging dependents
US 2013/0254766 A1 — "Offloading Packet Processing for Networking Device Virtualization" (Microsoft) filed 2012-03-20; pub. 2013-09-26 Packet processing offload — relevant to network-device transformation context (NAT/proxy) Potentially claims 1, 12, 17 where the network device alters packets
US 2015/0373043 A1 — "Collaborative and Adaptive Threat Intelligence for Computer Security" (HPE) filed 2014-06-22; pub. 2015-12-24 Threat-intelligence correlation and sharing Post-correlation notification/drop dependents
US 2013/0059527 A1 — "Relay Device" (Fujitsu) filed 2010-03-09 (priority); pub. 2013-03-07 Relay device that alters/forwards packets — NAT/proxy/tunnel context Potentially claims 1, 12, 17 for received-vs-transmitted packet handling; likely lacks two-sided log correlation
US 2008/0086435 A1 filed 2006-10-08; pub. 2008-04-10 Network security/management art in the family record Marginal

3.3 References most likely to be the examiner's primary § 102 basis

Based on the specification's problem statement (correlating packets across a flow-transforming device such as a NAT, proxy, or VPN/tunneling gateway), the strongest § 102 candidates are:

  1. US 2011/0055916 A1 (Great Wall Systems) and US 9,137,205 B2 — both disclose rule-driven packet identification and logging at network devices; the gap is the explicit two-sided (ingress tap + egress tap) log-entry correlation. If either discloses comparing ingress/egress logs to associate transformed packets, it would potentially anticipate claims 1, 12, and 17.
  2. US 8,789,135 B1 (Google) and US 2013/0059527 A1 (Fujitsu) — stateful/relay-based flow correlation across devices that transform packets; potentially anticipate the independent claims if the paired log-entry comparison is disclosed.
  3. US 2013/0254766 A1 (Microsoft) — offloaded packet processing with device-side transformation; relevant to the "network device alters packets" limitation.

4. Litigation/PTAB relevance (context for § 102/§ 103 exposure)

  • PGR2021-00108 (Palo Alto Networks v. Centripetal, filed 2021-08-03): not instituted — the Board did not reach the merits, so the petition's asserted art (which typically includes the family's own earlier-filed applications and third-party filtering/correlation references) was not validated as a § 102/§ 103 challenge.
  • Ex parte reexamination: a request asserted a substantial new question of patentability as to claims 1, 12, and 17 — i.e., the independent method, system, and computer-readable-medium claims — meaning the cited art in that proceeding maps most directly onto those three claims.
  • E.D. Va. 2:21-cv-00137 (Centripetal v. Palo Alto Networks) and the CAFC appeals are where the validity of the '797 patent is being actively contested; the asserted art there would be the most current, claim-charted § 102/§ 103 positions.

5. Confidence and verification notes

  • High confidence: bibliographic data for US 10,931,797 B2; continuity chain; PGR2021-00108 non-institution; reexamination SNQ directed to claims 1, 12, and 17; active E.D. Va. litigation.
  • Medium confidence: that the § 3.2 references are the front-page cited references of the '797 patent specifically (they come from the aggregated family art record, not a verified face-of-patent pull).
  • Not verified (explicit): the exact text of claims 1, 12, and 17 (the provided patent snapshot omits the claims section), and the examiner's A/N (allowed/not-allowed) classification of each cited reference. A rigorous per-claim § 102 mapping requires (a) the USPTO Patent Center "References Cited" list for 16/854,094, and (b) the claim language. I did not fabricate claim charts I could not source.

Recommended next step: pull the USPTO Patent Center bibliographic data for application 16/854,094 (References Cited tab) to confirm the examiner-cited set, and pull the PGR2021-00108 petition and the E.D. Va. 2:21-cv-00137 expert reports for the current claim-charted art positions.

Generated 8/30/2026, 12:46:15 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of U.S. Patent No. 10,931,797 B2 ("Correlating Packets in Communications Networks")

Scope and evidentiary basis

This analysis is based on (a) the patent text supplied, (b) the claims as retrieved from RPX Insight, (c) the citation ("Prior Art") information associated with the patent and its family on Google Patents / Unified Patents, and (d) the record of PGR2021-00108, Palo Alto Networks, Inc. v. Centripetal Networks, Inc., which is the most directly on-point post-issuance challenge to this exact patent.

I flag up front one important limitation: I could not retrieve the full-text disclosures of every secondary reference (notably Paxton, Sutton, Ivershen, Deschenes, and Roese) within the available search budget. The claim-to-reference mappings below reflect the grounds actually asserted in the PGR petition (which I did retrieve) and standard § 103 reasoning; where a reference's internal disclosure is not verified, I say so explicitly.


1. The patent and its claims

  • Patent: US 10,931,797 B2, "Correlating packets in communications networks," Centripetal Networks LLC, granted Feb. 23, 2021; earliest priority date Feb. 10, 2015 (chain: US 14/618,967 → US 9,264,370 → US 14/714,207 → US 9,560,176 → US 15/413,947 → US 10,530,903 → US 16/554,293 → US 16/854,094).
  • Claims: 20 claims; independent claims 1 (method), 12 (computing device/system), and 17 (non-transitory computer-readable media).

Claim 1 (representative), as retrieved from RPX Insight:

  1. A method comprising: determining, by a computing system, a first plurality of log entries corresponding to a first plurality of packets received by a network device from a first host located in a first network; determining a second plurality of log entries corresponding to a second plurality of packets transmitted by the network device to a second host located in a second network; correlating, by the computing system, the second plurality of packets transmitted by the network device with the first plurality of packets received by the network device by comparing at least a first portion of the first plurality of log entries with at least a second portion of the second plurality of log entries; determining a correlation based on correlating the first plurality of packets and the second plurality of packets; generating, by the computing system and based on the determined correlation, one or more rules configured to identify packets received from the first host; and provisioning a packet-filtering device with the one or more rules.

Claims 12 and 17 mirror this as a system and as computer-readable media. Dependent claims add (per the EP sibling's claim set and the file history found in the search results): timestamp-based correlation and latency-threshold comparison (claims 3–6, 14–16, 19–20); proxy embodiments comparing request data (claim 10/18-type); gateway/tunneling embodiments comparing encapsulated data (claim 11/19-type); and malicious-entity messaging/dropping (claim 20/21-type).

The core inventive concept: correlate "pre-transformation" packets entering a network device (NAT box, proxy, VPN/tunneling gateway) with "post-transformation" packets leaving it, using log entries, so that a host behind the transformation can be identified and then blocked via rules provisioned to a packet-filtering device.


2. The prior-art landscape (the "Prior Art" section of the patent record)

The Google Patents family record for the '797 patent (e.g., US 9,560,176) lists 140 citations, and the Unified Patents portal lists ~298 pieces of "Patent Art." The face-of-the-patent art is dominated by conventional firewall/packet-filtering references, including:

  • US 9,137,205 B2 (Centripetal's own "Methods and Systems for Protecting a Secured Network");
  • US 2011/0055916 A1 ("Adaptive Packet Filtering");
  • US 2006/0195896 A1 (function-parallel network firewall);
  • CA 2600236 A1 (firewall policy optimization);
  • US 8,789,135 B1 (stateful firewall in OpenFlow-based networks);
  • US 7,143,438 B1 (firewall with multiple domain support);
  • US 2010/0082811 A1 (per-customer blacklists); and numerous others.

These citations show that packet-filtering, rule provisioning, and flow/packet logging were all well-developed arts before February 2015. That is important for § 103: the individual building blocks of the claimed method were not novel, and the question is purely whether their combination was obvious.


3. The most probative obviousness challenge: PGR2021-00108

Palo Alto Networks petitioned for post-grant review of all claims 1–20 of the '797 patent on August 3, 2021, asserting § 103 obviousness on the following grounds (as summarized in the AI-Lab/PTAB docket record):

Ground Combination Claims
1 Paxton (US 2014/0280778 A1) + Sutton (US 8,413,238 B2) 1–2, 7–8, 10, 12–13, 17–18
2 Paxton + Sutton + Ivershen (US 8,219,675 B2) 3–6, 14–16, 19–20
3 Paxton + Sutton + Deschenes (US 2013/0262655 A1) 9 (encrypted-packet correlation)
4 Paxton + Sutton + Roese (US 2006/0048142 A1) 11 (user input to define generated rules)

The petition also noted that these primary references and combinations were never presented to or considered by the Examiner during prosecution — a significant point, because it means the cited-art review on the face of the patent did not test the actual strongest combinations.

All of Paxton (published Sept. 25, 2014), Sutton (issued Apr. 2, 2013), Ivershen (issued July 10, 2012), Deschenes (published Oct. 3, 2013), and Roese (published Mar. 2, 2006) predate the Feb. 10, 2015 priority date, so each qualifies as prior art under AIA § 102(a)(1)/(a)(2).

Procedural status (important caveat): The PTAB denied institution on February 22, 2022 (Institution Decision, PGR2021-00108, Paper 9). Google Patents labels the case "Not Instituted – Merits." Because institution was denied, there is no final written decision on the merits, and the denial does not establish that the claims are patentable. The case is also part of broader litigation: Centripetal Networks, Inc. v. Palo Alto Networks, Inc., No. 2:21-cv-00137 (E.D. Va.), with appeals at the Federal Circuit (Nos. 25-1167, 25-1168, 26-1359).


4. Why the combinations would have been obvious to a PHOSITA

4.1 Ground 1 — Paxton + Sutton (independent claims 1, 12, 17 and their direct dependents)

What Paxton contributes (per the petition's theory): the correlation framework — determining log entries for packets received by a network device from a first host in a first network, determining log entries for packets transmitted by the network device to a second host in a second network, and correlating the transmitted packets with the received packets by comparing the log entries.

What Sutton contributes (per the petition's theory): rule-based packet identification and provisioning of packet-filtering devices with rules configured to identify packets from a particular source (here, the first host).

Motivation to combine — this is the heart of the § 103 analysis:

  1. Same field, complementary teachings. Both references are in network security/packet filtering. Paxton solves the "who is really talking to whom through a transforming device" problem (NAT/proxy/gateway obfuscation); Sutton solves the "how do we operationalize a rule by pushing it to a filtering device" problem. A PHOSITA combining them gets a complete pipeline: correlate → identify the offending host → generate a blocking rule → provision the filter. That is precisely the claimed invention, and it is a textbook combination of two known elements performing their known functions to achieve a predictable result (KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007)).

  2. Known problem, known solution. The patent's own Background admits the "need for correlating packets" because network devices "may alter packets associated with a flow and in doing so may potentially obfuscate the flow." Firewall policy management (Sutton-type rule provisioning) and traffic correlation (Paxton-type) were mature arts; joining them to automate containment of a correlated host is an obvious design choice, not an inventive leap.

  3. Reasonable expectation of success. Because each piece performs its established function in a conventional network (log generation at tap points; rule distribution to filtering devices), a PHOSITA would have a high expectation that the combination would work without undue experimentation.

4.2 Ground 2 — adding Ivershen (claims 3–6, 14–16, 19–20)

These dependents add timestamp-based correlation: generating receipt timestamps for received packets and transmission timestamps for transmitted packets, computing differences, and comparing the differences against a threshold latency value (optionally updated from previously correlated packet pairs). Ivershen was relied on to supply the timing/correlation-accuracy feature. The motivation is straightforward: timing information is the most basic and reliable way to pair packets across a transforming device (packets that enter and leave in close succession, within a latency bound, belong to the same flow). Using latency thresholds to disambiguate concurrent flows was a routine technique, and updating the threshold from observed latencies is an obvious refinement. I note that I did not verify Ivershen's full disclosure, so the precise mapping should be confirmed against the reference before reliance.

4.3 Claim 9 — adding Deschenes (encrypted-packet correlation)

The claim adds correlating packets whose association is obfuscated by encryption (e.g., correlating encapsulated/encrypted traffic). Deschenes allegedly teaches correlation of encrypted packets. The motivation: by 2015, the inability to inspect encrypted traffic was a widely recognized security gap, and a PHOSITA would naturally extend a correlation engine to operate on encrypting/decrypting gateways (the patent itself describes the VPN/tunneling-gateway embodiment as routine). Again, I could not verify Deschenes' internal disclosure and flag that limitation.

4.4 Claim 11 — adding Roese (user input to define generated rules)

The claim adds receiving user input to define/refine the generated rules. Roese allegedly teaches administrator input for rule definition. The motivation is obvious: security products routinely expose rule-authoring to administrators; adding a user-input interface to a rule-generation-and-provisioning system is a predictable enhancement with no surprising technical effect. (Same caveat on full-text verification.)


5. Secondary considerations and counterpoints

  • No secondary considerations were shown to overcome the combination in PGR2021-00108, and the PTAB never reached them because institution was denied. In the parallel Centripetal family, the Federal Circuit (in Centripetal Networks, Inc. v. Cisco Systems, Inc., 2020-1635, decided Mar. 10, 2021) affirmed PTAB obviousness findings against Centripetal patents (the '552 and '713 patents) and gave little weight to Centripetal's objective-indicia evidence for lack of nexus. While those IPRs involved different claims, the Federal Circuit's treatment is informative context: Centripetal's packet-filtering patents have not fared well on § 103 at the Board.
  • The PGR denial is not a merits finding. The denial of institution (Feb. 22, 2022) could reflect procedural discretion (e.g., § 325(d)) or an insufficient threshold showing; it does not adjudicate patentability of claims 1–20.
  • The strongest independent-claim case is Paxton + Sutton. The dependent claims add only known refinements (timestamps/latency, encrypted traffic, user input) supplied by Ivershen, Deschenes, and Roese — each a classic "known technique applied to a known problem" scenario under KSR.

6. Bottom line

Under 35 U.S.C. § 103, the most credible obviousness case against US 10,931,797 is:

  1. Claims 1–2, 7–8, 10, 12–13, 17–18 — obvious over Paxton (US 2014/0280778 A1) in view of Sutton (US 8,413,238 B2): Paxton supplies the dual log-entry determination and packet correlation; Sutton supplies the responsive rule generation and provisioning to a packet-filtering device. A PHOSITA would combine them to automate identification and containment of hosts communicating through transforming network devices.
  2. Claims 3–6, 14–16, 19–20 — obvious over Paxton + Sutton + Ivershen (US 8,219,675 B2) for timestamp/latency-threshold correlation.
  3. Claim 9 — obvious over Paxton + Sutton + Deschenes (US 2013/0262655 A1) for encrypted-packet correlation.
  4. Claim 11 — obvious over Paxton + Sutton + Roese (US 2006/0048142 A1) for user-input-defined rules.

The motivation to combine in each case rests on: (i) the same field of art (network security/packet filtering); (ii) complementary, non-conflicting teachings; (iii) a known problem (flow obfuscation by NAT/proxy/gateway devices) with a predictable solution architecture; and (iv) routine enhancement techniques for the dependent limitations. These are precisely the grounds Palo Alto Networks asserted in PGR2021-00108 — though the PTAB declined to institute, and I could not verify the full text of each secondary reference in this session, so element-by-element claim charts should be confirmed against the actual references before formal use.

Key sources

Generated 8/30/2026, 12:46:35 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (4)

4 tracked lawsuits name US 10931797.