Invalidity dossier

US 12126695

Enhancing security of a cloud deployment based on learnings from other cloud deployments

Current assignee: Fortinet Inc

Added 10/1/2026, 4:00:08 AM

At a glanceActive PTAB challengeNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for the specific patent number and any 2026 CAFC docket activity, then build the summary from the authoritative full text.

Let me retrieve the actual claim text, since the provided full text was truncated before the claims section.

US Patent 12,126,695 — Analyst Summary

Identifier-handling note (read literally)

I treated the number as 12,126,695 exactly as given and did not auto-correct it. Two look-alike hits were discarded, not substituted:

  • A UK London Gazette listing (... 12126695 16/11/2021 ...) — here "12126695" is an unrelated GB publication/application token dated 16/11/2021, months before the US patent's 2024 issue and inconsistent with its data. Not this patent.
  • A 2026 UPC order (Maxell v. Samsung, EP 2 403 266) — different patent, different jurisdiction. Not this patent.

Date discrepancy — flagging explicitly

The task header states "Current Date: April 26, 2026," but my environment's operating date is 2026-10-01, and my searches returned content dated after April 26, 2026 (e.g., a UPC order issued 5 May 2026). A "2026 docket" check therefore covers a longer window than the task header implies. If your cutoff matters, treat my 2026 coverage as through early October 2026.


Bibliographic data

Field Value
Patent number US 12,126,695 B1
Title Enhancing security of a cloud deployment based on learnings from other cloud deployments
Inventors Úlfar Erlingsson; Yijou Chen
Current assignee Fortinet, Inc. (assignment from Lacework, Inc. recorded 2024‑10‑07)
Original assignee Lacework, Inc. (assignment recorded 2023‑08‑01)
Application no. 18/361,748
Filing date 2023‑07‑28
Issue (grant) date 2024‑10‑22
Earliest priority 2017‑11‑27 (provisional 62/590,986; further provisionals 62/650,971 · 3/30/2018)
Continuity Continuation of US 10,581,891 (from 16/134,794); later continuation 18/425,759 → US 12,537,884
Anticipated expiration 2038‑09‑18
Status Active
Representative CPC G06F16/9024, G06F21/577, H04L63/1433, H04L63/20, G06F16/2456, G06F9/5072, H04L41/5054

Sources: Google Patents (https://patents.google.com/patent/US12126695/en), Espacenet (https://si.espacenet.com/publicationDetails/biblio?...CC=US&NR=[12126695B1](/patent/12126695B1)), Golden wiki, Justia (https://patents.justia.com/patent/12126695).

Abstract (verbatim)

"Learning from other cloud deployments to combat security threats, including: identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to utilize for cross-customer learning; receiving information describing a security threat to one or more of the additional cloud deployments; receiving information describing configuration settings used to combat the security threat; and identifying, based on the information describing configuration settings used to combat the security threat, one or more configurations to adopt for the first cloud deployment."

(Verified identical across Google Patents, Espacenet, Golden, and Justia.)


Independent claims — plain-language overview ⚠️

Important caveat you asked for: the authoritative full text supplied to me was truncated at the specification (it ends mid-sentence at "Query service 166") and did not include the "What is claimed is:" section. My searches did not retrieve the verbatim, granted claim set either. I therefore cannot quote claim numbers or claim boundaries with confidence, and I will not invent them.

What I can state with reasonable confidence, grounded in the abstract and the FIG. 9–12 disclosure, is the inventive core that the independent claims almost certainly recite. Treat this as a reconstruction, not a claim chart:

  1. Core computer-implemented method (presumed claim 1 type). At a platform monitoring a first cloud deployment, identify which other cloud deployments are suitable for cross‑customer learning; receive threat information (a security threat observed in those other deployments); receive information describing configuration settings used to combat that threat; and identify/write one or more configurations to adopt for the first deployment based on those settings. FIG. 9 (902/908) and FIG. 11 (908) map to this.

  2. Related "normal behavior / similar or highly-rated deployment" variants. FIG. 5–8 describe: determining normal behavior for components in the first deployment and in other deployments, then recommending a change to the first deployment based on the other deployments' normal behavior; identifying similar deployments (FIG. 5), identifying highly-rated deployments (FIG. 6), ranking the first deployment and comparing trajectories (FIG. 7). These are likely dependent-claim subject matter, though a second independent claim could be drafted around the ranking/trajectory angle.

  3. Configuration-drift / misconfiguration detection. FIG. 12 discloses identifying a component (e.g., a server) as "abnormally configured based on its deviation from typical configurations observed in the additional cloud deployments" (1206) — e.g., detecting that an authentication server was bypassed, since other deployments always route through one. This reads like independent-claim or high-level dependent-claim material.

  4. Likely parallel statutory classes. Given the filing style and the abstract's phrasing, a corresponding system/apparatus claim and a non-transitory computer-readable-medium / computer-program-product claim are probable, but I could not verify their existence or wording. Sources: patents-review.com analysis of app. 18/361,748 (FIG. 5–12 narrative) — https://www.patents-review.com/a/18361748-enhancing-security-cloud-deployment-based-learnings-cloud.html

To close this gap, pull the granted claim set directly from USPTO PatentCenter (application 18/361,748) or the patent PDF (patentimages.storage.googleapis.com, US12126695). I did not have authoritative access to it in this session.


USPTO / CAFC 2026 docket search results

  • CAFC 2026 docket: No hits for US 12,126,695. Targeted queries for "12,126,695" / "12126695" + Federal Circuit / appeal returned zero relevant results. No appeal, mandamus, or CAFC order naming this patent appeared.
  • USPTO proceedings: My searches surfaced no PTAB (IPR/PGR) or reexamination record for this patent. I did not reach a live PatentCenter/PTAB API within my step budget, so this is absence-of-evidence, not a certified negative.
  • Carry-over from the earlier litigation section (not repeated): the Google Patents record still shows the family-level "Family has litigation" banner (Darts‑ip family 82611851). That flag attaches to the family, not to 12,126,695 specifically, and the underlying paywalled Darts‑ip case data remains unresolved. My 2026 searches did not tie any case back to this patent.
  • Requested table (unchanged):
Plaintiff(s) Defendant(s) Jurisdiction Case No. Filing date Status/outcome
— none identified — — — — — No 2026 CAFC docket or USPTO proceeding located for US 12,126,695

Uncertainties I will not paper over

  1. Verbatim claims unavailable — my independent-claim overview is inferred from the abstract/specification, not read off granted claims.
  2. Date-window mismatch between the task header (Apr 26, 2026) and my operating date (Oct 1, 2026).
  3. No live USPTO/PTAB API confirmation — my "no proceeding" finding rests on web search, which under-indexes PTAB.
  4. Family-level litigation flag unresolved — requires Darts‑ip / Docket Navigator / Lex Machina access keyed to family 82611851, plus a PACER patent-number sweep.

If you can supply the granted claim text (or authorize a PatentCenter pull), I can replace section "Independent claims" with a verified, element-by-element claim chart.

Generated 10/1/2026, 4:01:28 AM

Cases on file (0)

Specific litigation cases in our database that name US patent 12126695. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I found a promising lead — a CourtListener docket entry in Netskope v. Fortinet referencing "12,126,695". Let me confirm it and look for related cases.

Litigation involving US Patent 12,126,695 — findings

Short answer: yes, there is litigation — but only one dispute, on one side of the "v." US 12,126,695 appears as a Fortinet-asserted patent in counterclaims filed against Netskope, Inc. in the Northern District of California. I found no case where 12,126,695 is the lead patent-in-suit against any other defendant, no ITC action, and no Federal Circuit appeal naming it.

⚠️ Date-window flag (repeated from the earlier sections, still live): the task header says April 26, 2026, but my operating date is 2026-10-01, and the most probative source I found (the severance order) is dated 2026-08-18 — i.e., after the header date. If your cutoff is genuinely April 26, 2026, then rows 1(b) and the severance disposition below fall outside it. I am reporting them because they are the current ground truth in the sources.


Table of known litigation tied to US 12,126,695

Plaintiff(s) Defendant(s) Jurisdiction Case No. Filing date Outcome / current status
Fortinet, Inc. (counterclaim-plaintiff; patent owner via Lacework acquisition) Netskope, Inc. U.S. District Court, N.D. Cal., Oakland Division — Judge Haywood S. Gilliam, Jr. 4:25-cv-02360-HSG (counterclaims within) Original complaint 2025-03-07; Fortinet's counterclaims asserted 2025 Pending / severed. Fortinet's counterclaims assert U.S. Patent Nos. 11,449,623; 11,290,527; 12,126,695 (list appears truncated in the retrieved text). Markman hearing held 2026-02-06. On 2026-08-18 the Court granted Netskope's motion to sever Fortinet's counterclaims but retained them.
Fortinet, Inc. Netskope, Inc. U.S. District Court, N.D. Cal. — Judge Haywood S. Gilliam, Jr. 4:26-cv-08886 (docketed as Fortinet, Inc. v. Netskope, Inc.) 2026 (day obscured in the retrieved PACER Monitor record; the severance order precedes it) Pending. This is the severed-counterclaim vehicle. Nature of suit 830 (patent, 35 U.S.C. § 271). Counsel of record include Quinn Emanuel (Netskope side) and Gish PLLC / Sheppard Mullin (per the docket). I could not verify from the retrieved snippet that 12,126,695 is pleaded in this new case number specifically — the patent is confirmed in the 4:25-cv-02360 counterclaim pleading; the severance order is the bridge between them.

Primary source for the patent-to-case link: CourtListener, Netskope, Inc. v. Fortinet, Inc., N.D. Cal. 4:25-cv-02360, Docket No. 151 (Order on Stipulation), which recites "…Fortinet's counterclaims for patent infringement of U.S. Patent Nos. 11,449,623; 11,290,527; 12,126,695; …" — https://www.courtlistener.com/docket/69716023/151/netskope-inc-v-fortinet-inc/
Severance: CourtListener, Docket No. 185 (filed 2026-08-18) — "The Court GRANTS Netskope's motion to sever Fortinet's counterclaims but will retain…" — https://www.courtlistener.com/docket/69716023/185/netskope-inc-v-fortinet-inc/
The severed case: PACER Monitor, Fortinet, Inc. v. Netskope, Inc., 4:26-cv-08886 (N.D. Cal., Gilliam, J.) — https://www.pacermonitor.com/public/case/66442323/Fortinet,_Inc_v_Netskope,_Inc


Related proceedings that do not involve 12,126,695 (listed so you don't mis-attribute them)

These surfaced in the same searches and concern the same parties or the same patent family, but the patent numbers do not match 12,126,695. I am not counting them as litigation "involving" the patent:

  • Netskope, Inc. v. Fortinet, Inc., 4:25-cv-02360-HSG — Netskope's affirmative case asserts nine Netskope-owned patents ('336, '710, '639, '983, '426, '936, '282, '153, '697). None of those is 12,126,695. Fortinet's invalidity contentions are directed at those nine. This is the same case number as the counterclaim, but the asserted-patent sets are different.
  • Netskope's earlier declaratory-judgment action, 3:22-cv-01852 (N.D. Cal.) — concerns Fortinet's '282, '734, and '301 patents. Not 12,126,695.
  • Sulaco Enterprises LLC v. Fortinet Inc., 2:25-cv-01187 (E.D. Tex.) — voluntarily dismissed 2026-02-20/24 (CourtListener docket 71991341). No indication it names 12,126,695; excluded.
  • In re Fortinet, Inc. Securities Litigation / Oklahoma Firefighters Pension & Retirement System v. Fortinet, Inc., 25-cv-08037 (N.D. Cal.) and the consolidated derivative action 3:25-cv-08592 — securities cases about the FortiGate "refresh cycle," not patent litigation; excluded.
  • Fortinet, Inc. v. United States et al., 1:2026cv00403 (Ct. Int'l Trade) — customs matter; excluded.
  • The UK London Gazette entry listing "12126695 16/11/2021" — an unrelated GB publication/application token, not US 12,126,695. Excluded (consistent with the identifier-handling note in the earlier summary).

PTAB (not litigation, but the parallel front): the IPR identified in the earlier section — IPR2026-00515, Netskope, Inc. v. Fortinet, Inc., filed 2026-09-30 against 12,126,695 — is the administrative counterpart to this district-court fight. It is not a "case" in the PACER sense and is already covered above; I do not repeat it here.

Family-level flag: Google Patents still shows the Darts-ip family 82611851 "Family has litigation" banner. That attaches to the family (which includes US 10,581,891 and US 12,537,884), not to 12,126,695 specifically.


Negative findings (stated as absence-of-evidence, not certified negatives)

  • No CAFC / Federal Circuit docket naming 12,126,695 was located.
  • No ITC Section 337 investigation naming it.
  • No Unified Patents litigation-caselist entry for 12,126,695 (searches against portal.unifiedpatents.com returned family-adjacent Lacework/Fortinet material such as US 10,419,469 but nothing keyed to this number).
  • No litigation outside the Netskope/Fortinet dispute — i.e., no other defendant has been sued on 12,126,695 as far as public sources show.

Confidence and caveats

  • High confidence: 12,126,695 is asserted by Fortinet in its counterclaims in 4:25-cv-02360-HSG. The patent number appears verbatim in a court document.
  • Medium confidence: that the severed case 4:26-cv-08886 carries those same counterclaims. The severance order and the new case number are both real, and severance is the natural explanation for the new Fortinet-v.-Netskope docket — but I could not retrieve a snippet of the 4:26-cv-08886 pleading itself, so confirm by pulling the new complaint/counterclaim from PACER.
  • Unresolved: the counterclaim patent list in Docket 151 is truncated in the retrieved text; there may be additional Fortinet patents in that list beyond the three shown.
  • Unresolved: the exact filing date of 4:26-cv-08886 (day obscured) and whether it was randomly reassigned or retained by Judge Gilliam.
  • Not verified: the infringement theories, accused products, and asserted claims of 12,126,695 — no infringement contentions for the Fortinet side were retrieved.

If you want the Fortinet-side contentions nailed down, the two documents to pull are the Docket 151 stipulation/order (for the full counterclaim patent list) and the 4:26-cv-08886 complaint (to confirm 12,126,695 is pleaded there and to see the asserted claims and accused products).

Generated 10/1/2026, 4:01:53 AM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

1 active

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll verify the one proceeding on file and check for any related activity, then build the analysis.

Let me search more specifically for the docket and any related papers.

PTAB / AIA Trial Analysis — US Patent 12,126,695 B1

Source-integrity note (read first). My proceeding list is taken verbatim from the canonical structured "PTAB proceedings on file" block supplied with this task. I did not reach the PTAB E2E / PTAB API or the USPTO Open Data Portal directly in this session, and my web searches returned no petition papers, no POPR, no notice of accord, no institution decision, no panel assignment, and no exhibit list for the single proceeding below. Everything specific to IPR2026-00515 in this report comes from the structured block. Where I could not verify something, I say so rather than filling the gap. Nothing below is invented.

⚠️ Date-window flag (carried forward, still live). The task header says 2026-04-26; my operating date is 2026-10-01. The one proceeding on file was filed 2026-09-30 — i.e., it falls outside the header's window. If your cutoff is genuinely 2026-04-26, then there is no PTAB activity on this patent within your window, and the entire report below is post-cutoff.


Proceedings overview

Exactly one AIA trial proceeding is on file for US 12,126,695 — IPR2026-00515 (Netskope, Inc. v. Fortinet, Inc.), filed 2026-09-30, status "Pending," with no institution decision, no FWD, no settlement, and no appeal — so nothing has been canceled, nothing has been sustained, and every claim of this patent is currently UNTESTED at the PTAB, which means a defendant facing assertion today gets neither the benefit of a cancellation nor the comfort of a patent that has been hardened by surviving review.

Proceeding Type Petitioner Filed Status Claims canceled Claims sustained
IPR2026-00515 IPR Netskope, Inc. 2026-09-30 Pending none none

Breakdown by status: active/pending = 1; claims invalidated = 0; claims sustained = 0; settled = 0; institution denied = 0. § 318 FWDs issued = 0. Federal Circuit appeals = 0.

Bottom line for a defendant: Neither of the prompt's two archetypes applies. The patent has not "survived two IPRs and is hardened," and no claims have been canceled. It has been challenged once, one business day ago (as of 2026-10-01), and the challenge is still in the preliminary phase. Do not treat the existence of IPR2026-00515 as a merits signal in either direction.


IPR2026-00515 — Netskope, Inc. v. Fortinet, Inc.

(List truncated to one entry: it is the only proceeding on file, so it is simultaneously the most- and least-impactful.)

  • Type: Inter Partes Review (IPR), 35 U.S.C. §§ 311–319. (Not a PGR — no PGR appears in the canonical list. Not a CBM — the CBM transitional program is long expired and no CBM appears.)

  • Filed: 2026-09-30. "Last modified 2026-09-30" per the structured block, consistent with a freshly docketed petition. This is one calendar day before my operating date, so an unusually small public record is expected — and I found none at all.

  • Status: Pending (verbatim from the structured data). Plain-English gloss: petition filed; no notice of accord, no POPR, no institution decision, no trial. No statutory deadline has yet been missed.

  • Judge panel: Not public / not retrieved. Panels are typically identified only in the Notice of Accord of Filing Date or in the institution decision, neither of which I could verify exists. I will not guess APJ names.

  • Petition grounds: Not retrieved — and I will not reconstruct them. I could not retrieve the petition, its asserted grounds table, its exhibit list, the challenged-claim set, or the statutory basis (§ 102 / § 103 / § 112). Two things follow:

    1. I cannot tell you which claims of 12,126,695 are challenged. Not even whether the challenge covers all claims, only the independent claims, or a subset.
    2. I cannot tell you which art is asserted. My earlier prior-art section flagged a substantial open question about whether the issued claims are entitled to the 2017-11-27 priority date or only to the ~2021 filings; if the petitioner litigates effective filing date, that is the pivotal issue — but I have no evidence the petition does so. Treat that as a risk to check, not as a finding.
  • Institution decision: None issued. Under 35 U.S.C. § 314(b) the institution determination is due within 3 months of a POPR (a POPR is typically due ~3 months from the notice of accord) or within 6 months of the filing date if no preliminary response is filed — i.e., a § 314(b) backstop of roughly 2027-03-30. Note that under the Director's current interim processes, institution decisions are routed through Director review of discretionary and merits briefings, so the practical timing may differ from the bare statute. I am stating the statutory clock, not predicting the outcome.

  • Final Written Decision: None. Under 35 U.S.C. § 316(a)(11), a FWD would be due within 12 months of the institution decision — i.e., on the order of 2028 if the trial is instituted on the normal schedule. No claim-level verdict exists to quote. I will not state a claim-level disposition for a decision that has not issued.

  • Settlement / termination: None. No termination, no adverse judgment, no request for adverse judgment, no refund/termination order appeared. Nothing is confidential-stateable because nothing has happened.

  • Appeal: None. No FWD → nothing appealable → no Federal Circuit docket. Independently, no CAFC docket naming 12,126,695 was located in my earlier searches.

  • Defensive value: Low but non-zero, and asymmetric. The filing tells a defendant three real things: (1) a well-resourced, sophisticated security vendor (Netskope) has decided the patent is worth attacking rather than merely designing around or licensing; (2) the petitioner is subject to the § 315(b) one-year clock and evidently believed it was still within it; and (3) if trial is instituted and runs to an FWD, § 315(e)(2) estoppel will bar the petitioner and its privies from re-raising at trial any ground raised or reasonably raisable — which is a coupon only Netskope can redeem. For a different defendant, this proceeding confers no estoppel benefit at all and no claim is off the table. Do not build a defense on it yet.


Verified surrounding context (distinct patents — do not mis-attribute)

Everything in this subsection is a different patent from 12,126,695. I include it only so you can read the parties' PTAB postures correctly:

  • Netskope, Inc. v. Fortinet, Inc., IPR2023-00030, U.S. Patent No. 10,826,941 B2 — Final Written Decision entered 2024-04-08 (Paper 37), panel Calve, Giannetti, and Ogden, APJs, holding all of claims 1–22 unpatentable under § 318(a). This is a Fortinet patent, not 12,126,695. Source: FWD PDF (Banner Witcoff mirror). Relevance: it establishes that Netskope has previously taken a Fortinet patent to a final judgment of unpatentability — context, not precedent.
  • Fortinet's October 2025 IPR wave against Netskope's patents — IPR2026-00025 ('639, claims 1–27), -00026 ('426, claims 1–13), -00027 ('936, claims 1–22), -00031 ('697, claims 1–25), -00040 ('336, claims 1–20), -00041 ('282, claims 1–35), and -00042 ('710, claims 1–20), filed 2025-10-07/08/10/13, accompanied by broadened "Sotera Plus" stipulations. Source: Fortinet's Notice of Sotera Plus Stipulation filed in N.D. Cal. 4:25-cv-02360-HSG. None of these patents is 12,126,695.
  • IPR2026-00031 (Fortinet v. Netskope, U.S. 8,635,697) was terminated 2026-02-03 on Director discretionary denial, with a refund noticed 2026-03-04. Source: Docket Alarm case mirror, https://gaeflexstaging-dot-docketupdate.appspot.com/cases/PTAB/IPR2026-00031/Fortinet_Inc._v._Netskope_Inc/. Different patent.
  • IPR2026-00474 — a trade-press item reports Netskope filed an IPR on 2026-09-15 opening docket IPR2026-00474, with the target patent and owner unidentified. Source: LegalTechMonitor, Sept. 2026. I could not verify which patent it challenges, so I do not count it as a proceeding on 12,126,695. It is a plausible sibling challenge in the same campaign and worth a five-minute check.
  • Parallel district court: Netskope, Inc. v. Fortinet, Inc., N.D. Cal. 4:25-cv-02360-HSG (Judge Haywood S. Gilliam, Jr.) asserts Netskope's patents; Fortinet's counterclaims there assert 12,126,695 among others; those counterclaims were severed on 2026-08-18 into Fortinet, Inc. v. Netskope, Inc., 4:26-cv-08886. Sources: CourtListener docket 69716023, Docket 151 and Docket 185.

Strategic summary

Claim status: all untested. There is no canceled claim and no sustained claim of 12,126,695. The patent issued 2024-10-22, is a continuation of US 10,581,891, claims 2017-11-27 priority, and carries an anticipated expiration of 2038-09-18 — roughly twelve more years of life. The surviving claim set is therefore the full issued claim set as granted (method, system, and any CRM claims), until and unless an FWD says otherwise. I cannot give you a "surviving claims" list because nothing has been eliminated. My earlier prior-art section could not verify the granted claim text, and I still cannot: treat the "which claims survive" question as identical to "which claims issued."

Estoppel landscape: currently empty, with a contingent trap. § 315(e)(2) estoppel attaches only after a final written decision, and only against the petitioner, its real parties in interest, and privies. With no institution and no FWD:

  • No estoppel exists today — not against Netskope, and certainly not against any other party.
  • Grounds available to a defendant are, as of now, the entire field: any § 102 or § 103 combination based on patents or printed publications, plus § 101 and § 112 grounds that the PTAB could not have reached absent a PGR. Netskope's own available grounds are likewise unconstrained — unless and until trial is instituted, at which point Netskope (and only Netskope) will be barred from re-asserting at trial what it raised or reasonably could have raised.
  • Practical corollary: because you are likely not in privity with Netskope, you cannot free-ride on their IPR. If IPR2026-00515 is instituted and succeeds, you still need your own § 282 invalidity case or your own petition. Conversely, if it fails, you are not bound by it either.
  • One live threshold risk to check: § 315(b). Fortinet's counterclaim asserting 12,126,695 was served on Netskope in the 4:25-cv-02360 litigation, and the decision to sever those counterclaims into 4:26-cv-08886 (2026-08-18) creates a genuine question about which service event starts the one-year clock and whether re-service of a severed complaint restarts it. The petition's 2026-09-30 filing date is close enough to the likely anniversary that this is the single most likely basis for a motion to dismiss the petition as time-barred — and I emphasize that I am flagging the question, not asserting the petition is barred. I could not retrieve the counterclaim service date with precision.

Pattern signals. (1) Same petitioner, new posture: Netskope is a repeat PTAB player against Fortinet — but historically as petitioner against Fortinet's patents (IPR2023-00030, FWD 2024-04-08) and as patent owner in Fortinet's early-2026 IPR wave. IPR2026-00515 is consistent with a two-front campaign, not with a serial NPE. (2) No multiple IPRs on this patent: the canonical list shows one petition against 12,126,695 — no parallel/companion IPRs, no joinder, no follow-on. (3) No patent-owner appeal aggressiveness to measure: Fortinet has never had a 12,126,695 FWD to appeal. (4) No defensive aggregator in the IPR chain: the only aggregator link I found anywhere near this fight is RPX's 2020–2024 ownership of Netskope's '936 patent (per Fortinet's discretionary-denial opposition), which concerns a Netskope patent, not 12,126,695 — and Fortinet used it offensively in briefing, not as a defense to this patent. (5) Discretionary-denial exposure is real on both sides: the Director's current practice produced a denial in IPR2026-00031 (2026-02-03) on settled-expectations and duplicativeness grounds, and the informative decision in Tesla, Inc. v. Bulletproof Property Mgmt. (PTAB 2026-06-15) holds that patents issued 2024–2025 have not had time to build strong settled expectations. That cuts against Fortinet's ability to win discretionary denial here, since 12,126,695 issued in October 2024. It does not tell us anything about the merits.


Recommended next steps

If you are a defendant being asserted on 12,126,695 (or considering a demand response):

  1. Do not cite IPR2026-00515 as invalidating anything. No claim has been canceled and no FWD exists. Any statement to the contrary is unsupportable.
  2. Pull the petition itself, today. It is the highest-value document in the entire file and it was not retrievable in this session. Retrieve it at PTAB E2E / Patent Trial and Appeal Board public search — https://ptacts.uspto.gov/ptabweb/ (PTAB decisions index: https://www.uspto.gov/patents/ptab/decisions) — under IPR2026-00515. What you need from it: the exact challenged-claim list, the grounds table (reference-by-reference, § 102 vs. § 103), the exhibit list, the real-party-in-interest statement, and whether the petitioner seeks to displace the 2017-11-27 priority date.
  3. Same-day check on § 315(b). Get the service date of Fortinet's counterclaim asserting 12,126,695 from the 4:25-cv-02360 docket (see CourtListener docket 69716023, and the March/April 2026 entries) and the service date of the 4:26-cv-08886 complaint. If the anniversary falls before 2026-09-30, the petition is time-barred and the whole proceeding evaporates on a motion.
  4. Trial-stage milestones to diarize (statutory; may shift under Director-review practice):
    • POPR due ~3 months from the notice of accord of filing date (typically ~2026-12-30 if the accord issues promptly).
    • Institution decision — § 314(b): within 3 months of the POPR, or as a backstop by ~2027-03-30.
    • FWD — § 316(a)(11): within 12 months of institution, i.e., on the order of 2028.
    • Discretionary-denial briefing — under current Office practice the patent owner may file a standalone discretionary-denial brief; watch for it, and watch for whether Netskope files a Sotera/Sotera-Plus stipulation, which is the single fact the Director has most consistently credited against discretionary denial in 2026.
  5. Do not assume estoppel will help you. Unless you are in privity with Netskope, § 315(e)(2) gives you nothing. Preserve your own § 101/§ 112 and system-art defenses, which an IPR cannot reach, regardless of how IPR2026-00515 resolves.
  6. Confirm the sibling filing. Verify what IPR2026-00474 (Netskope, 2026-09-15) actually challenges — if it targets a family member of 12,126,695 (e.g., US 10,581,891 or US 12,537,884), the two petitions together reveal the full scope of the invalidity theory and the priority-date attack, and they should be read as a package.
  7. Verify the Darts-ip family-literature badge independently (family 82611851) if your risk model depends on other defendants' exposure — earlier sections flagged that the Google Patents "Family has litigation" flag attaches to the family, not to 12,126,695, and it remains unverified as to case, parties, and date.

Explicit non-findings (absence of evidence, not certified negatives)

  • No Post-Grant Review on 12,126,695. No CBM. No second or follow-on IPR on this patent. No joinder. No FWD. No adverse judgment. No settlement or termination. No Federal Circuit appeal.
  • I did not obtain the petition, POPR, notice of accord, panel assignment, exhibit list, claim-by-claim grounds table, or any institution decision for IPR2026-00515. Those gaps are the substance of this report's uncertainty, not an oversight I can paper over.
  • The Judge panel, Petition grounds, and Final Written Decision fields above are therefore recorded as unretrieved, consistent with your instruction not to fabricate. Nothing in this analysis should be quoted as a claim-level PTAB outcome, because no such outcome exists.

Generated 10/1/2026, 4:02:43 AM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2023-08-01 · Assignment

    Yijou Chen; Úlfar ErlingssonLacework, Inc.

  2. ? · recorded 2024-10-07 · Assignment

    Lacework, Inc.FORTINET, INC.

    acquisition

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment chain for US 12,126,695, focusing on reel/frame records and correspondents of record.

Let me pull the Google Patents legal-events record and search for the specific reel/frame entries.

Assignment / Chain-of-Title Reconstruction — US 12,126,695 B1

Source-access disclaimer (read first). I attempted to query the USPTO Assignment Center (https://assignmentcenter.uspto.gov/) and its legacy index (https://assignment.uspto.gov/patent/index.html) for this patent. I could not reach either interface within this session, and no search result returned a USPTO Assignment Abstract of Title page for US 12,126,695. Accordingly:

  • All reel/frame numbers are UNRETRIEVED for this patent.
  • All correspondent-of-record names are UNRETRIEVED for this patent.
  • Everything below is reconstructed from (a) the patent's own front-matter/legal-events data supplied in the authoritative full text, (b) the Google Patents legal-events block reproduced in the patent text, and (c) Espacenet bibliographic data. Where a field is missing I mark it UNRETRIEVED rather than guess.

I flag this up front because the prompt's highest-value field — the correspondent of record — is precisely the field I could not obtain. Any NPE-pattern conclusion touching signal #3 is therefore incomplete by construction.

⚠️ Date-window flag (carried forward from the summary, litigation, PTAB, prior-art and obviousness sections). The task header date and my operating date (2026-10-01) diverge. Nothing in this assignment chain post-dates the header window except the litigation/PTAB events already reported; the two recorded assignments both predate April 26, 2026, so this section is unaffected by the window problem.


Inventors

Inventor Employer at time of filing Basis
Úlfar Erlingsson Lacework, Inc. (applicant of record on 18/361,748; executed assignment in favor of Lacework) Espacenet lists applicant as LACEWORK INC [US]; the family chain runs to Lacework
Yijou Chen Lacework, Inc. (same) Same

Pattern notes:

  • Both inventors are Lacework personnel, not outside/nominal inventors, and both executed the original assignment to Lacework (Google Patents legal events: "Assigned to Lacework, Inc. … Assignors: CHEN, YIJOU, Erlingsson, Úlfar"). This is an ordinary employee-invention assignment, not an inventor-held-then-sold structure.
  • Erlingsson background (context only, not a chain-of-title fact): he is a long-tenured systems/security researcher with an earlier patent corpus attributed to Microsoft (patentleaderboard lists a "56 Patents at Microsoft" profile that includes US 12,126,695). That profile attribution is a third-party aggregation and the Microsoft listing for this particular patent is inconsistent with the recorded assignee; treat the Microsoft label as a portfolio-attribution artifact, not ownership. It does not change the chain.
  • "All inventors departing within 12 months of filing" pattern: NOT OBSERVABLE. I found no evidence of inventor departure at or near the 2023-07-28 filing date. The related corporate event — Fortinet's acquisition of Lacework — closed 2024-08-01, roughly 12.1 months after this application was filed, which lands just outside the 12-month window and is a company-level event, not an inventor-level one. I could not verify either inventor's post-acquisition status.

Original assignee

Lacework, Inc. (Delaware; Mountain View, CA), named as applicant on the issued patent and as the assignee in the first recorded assignment.

  • Primary line of business: cloud-native application protection platform (CNAPP) — CSPM, CWPP, CIEM, CDR, code security, later DSPM — built on behavioral-baseline / anomaly-detection analytics. Founded 2015; raised >$1.8B in venture funding; peaked at an $8.3B valuation (Nov 2021).
  • Did they ship a product embodying the claims? Yes. The patent family's disclosure (agent-based telemetry ingestion, polygraph/behavioral baselines, cross-deployment learning per FIGS. 9–12) is the architecture of Lacework's shipping platform, which was commercially available and, at acquisition, served ~1,000 customers.
  • Current status: Acquired — no longer an independent operating entity. Fortinet announced the acquisition 2024-06-10 and closed it 2024-08-01. The product was rebranded FortiCNAPP (GA October 2024; "Lacework FortiCNAPP" branding through 2025); lacework.com now redirects to Fortinet. Reported 225 patents/applications transferred, bringing Fortinet's portfolio past 1,800. Not a bankruptcy, not a dissolution-by-failure — a solvent strategic acquisition.

Assignment timeline

Two (2) recorded assignments are visible on the patent's face/legal-events record. No security interests, licenses, mergers, name changes, or corrections appear in the visible record.

1. Inventors → Lacework, Inc.

  • Executed 2023-07-28 or earlier (exact execution date UNRETRIEVED) / recorded 2023-08-01 — Reel UNRETRIEVED/UNRETRIEVED
    • Conveyance: Assignment (assignment of assignors' interest) — per Google Patents legal events: "ASSIGNMENT OF ASSIGNORS' INTEREST (SEE DOCUMENT FOR DETAILS)."
    • Assignor: Yijou Chen; Úlfar Erlingsson (joint inventors)
    • Assignee: Lacework, Inc.
    • Correspondent: UNRETRIEVED
    • Context: Routine employee invention assignment at the time of filing — the inventors conveyed to their employer/applicant of record. Not a sale, not a fire-sale.

2. Lacework, Inc. → Fortinet, Inc.

  • Executed ~2024-08-01 (acquisition close; execution date UNRETRIEVED) / recorded 2024-10-07 — Reel UNRETRIEVED/UNRETRIEVED
    • Conveyance: Assignment (per Google Patents legal events: "ASSIGNMENT OF ASSIGNORS' INTEREST (SEE DOCUMENT FOR DETAILS)." This is the label the patent's legal-events block uses; whether the underlying instrument is styled an assignment, a merger, or a bill of sale is UNRETRIEVED — for a stock acquisition of this type it is frequently an IP assignment ancillary to a merger agreement.)
    • Assignor: Lacework, Inc.
    • Assignee: FORTINET, INC.
    • Correspondent: UNRETRIEVED
    • Context: Strategic acquisition — Lacework's ~225-patent cloud-security/AI portfolio conveyed to Fortinet as part of Fortinet's completed acquisition of Lacework. Operating company → operating company; not a transfer to an NPE.

Unverified lead, explicitly labeled as such: in a different matter's USPTO filing (a § 3.73 statement appearing in a PTAB petition document hosted on ptacts.uspto.gov), a chain-of-title entry cites Reel 047636, Frame 0855 as the inventor-to-assignee assignment. That document is not confirmed to relate to US 12,126,695 and the reel number is inconsistent in vintage with a 2023-08-01 recordation. I am not attributing that reel/frame to this patent. It is a lead worth five minutes of checking because a 2020-era Lacework reel would imply an earlier, unrecorded-on-the-face conveyance (e.g., an inventor assignment executed in a parent application in the 16/134,794 or 16/665,961 chain, with the child application inheriting title without a separate recording). If that is the case, the chain may contain prior links not visible on the '695 face.

Verification link

Assignment Center search page for the patent: https://assignmentcenter.uspto.gov/ (search by patent number 12126695) — see the "Assignment Abstract of Title" for the authoritative reel/frame, correspondent, and any hidden chain links.


Timeline diagram

timeline
    title Ownership of US 12126695
    2017 : Earliest priority date
    2018 : Parent application filed
    2023 : Application 18 361 748 filed
         : Inventors assign to Lacework Inc
    2024 : Patent issues October 22
         : Fortinet closes Lacework acquisition
         : Recorded assignment to Fortinet Inc

NPE / troll-pattern signals

# Signal Call Evidence
1 Shell-entity transfer Not present Both assignees are operating companies. No "IP/Licensing/Holdings/Ventures" suffix in the chain; no registered-agent service address surfaced; Lacework had ~1,000 customers and a shipped CNAPP product; Fortinet is a NASDAQ-listed operating company (FTNT) with a >1,800-patent portfolio.
2 Known asserter in the chain Not present Neither Lacework, Inc. nor Fortinet, Inc. matches any entity on the listed NPE rosters (Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). Fortinet appears in Unified Patents' and RPX's databases as an operating-company defendant/petitioner, not as a high-frequency plaintiff entity of the NPE type.
3 Repeat correspondent across the chain Unclear — data unavailable This is the material gap in this report. I could not retrieve the correspondent of record for either recording, so I cannot test recurrence within this chain or against other patents. Note the structural pointer: both recordings are the same conveyance type and both show the same "ASSIGNMENT OF ASSIGNORS' INTEREST (SEE DOCUMENT FOR DETAILS)" event label, which is consistent with an in-house/outside-counsel docketing group handling a corporate portfolio recording — but that is a shape observation, not evidence of a repeat NPE correspondent, and I do not treat it as a finding.
4 Cascading transfers Not present Two links, ~14 months apart (recorded 2023-08-01 → 2024-10-07). No chained LLCs, no <24-month multi-hop chain, no shared correspondent address demonstrated.
5 Pre-litigation transfer Not present The transfer to Fortinet was recorded 2024-10-07; Fortinet's counterclaim asserting 12,126,695 against Netskope was served in the 4:25-cv-02360-HSG action (filed 2025-03-07; counterclaims asserted 2025) — roughly 6–8 months after the recording, and the transfer was a whole-company acquisition executed a year earlier, plainly not arranged to enable assertion of this patent. No venue/standing-manufacturing inference available.
6 Bankruptcy fire-sale Not present Lacework was a solvent strategic acquisition (undisclosed price; ~$8.3B peak valuation; Fortinet NASDAQ: FTNT). No Chapter 7/11, no 363 sale, no distress.
7 Privateering Not present Fortinet retained and is asserting the patent itself (as counterclaim-plaintiff in its own name in N.D. Cal.), not through a proxy NPE. This is direct operating-company assertion, the opposite of privateering.
8 Defensive aggregator Not present Chain terminates at Fortinet, Inc., an operating company actively asserting the patent in litigation and defending it in IPR2026-00515. No RPX/AST/LOT/Unified/OIN terminus.

Cross-reference note (no contradiction): this reconciles cleanly with the earlier Litigation section — the same Fortinet that took title in October 2024 is the counterclaim-plaintiff asserting 12,126,695 against Netskope. There is no corporate-structure overlay (no holding company, no IP subsidiary) interposed between Fortinet and the patent that would need to be pled for standing. The earlier PTAB section's observation that Fortinet is a repeat PTAB player against Netskope is a litigation-conduct pattern, not a chain-of-title NPE signal; do not conflate the two.


Verdict

Operating-company assertion.

Justification (2–3 sentences): The chain is exactly two recorded links — inventors Chen and Erlingsson → Lacework, Inc. (recorded 2023-08-01) → Fortinet, Inc. (recorded 2024-10-07) — with no shell entity, no licensing-only LLC, no known asserter, no cascading LLC hops, and no defensive-aggregator terminus. The current assignee, Fortinet, is a NASDAQ-listed operating company that ships the accused-relevant product (FortiCNAPP, the rebranded Lacework platform embodying this family's claims) and is asserting the patent in its own name against a direct competitor (Netskope) in N.D. Cal. 4:25-cv-02360-HSG / 4:26-cv-08886 — the textbook profile of ordinary operating-company assertion rather than NPE behavior.

Confidence: moderate-to-high on the verdict; LOW on completeness. The verdict rests on the two recorded links and on assignee identity, both of which are well corroborated (patent face, Espacenet, Google Patents legal events, and press/SEC-adjacent coverage of the Fortinet–Lacework deal). It does not rest on the correspondent-of-record analysis, which I could not perform. To upgrade to high confidence, pull the Assignment Abstract of Title for 12126695 from https://assignmentcenter.uspto.gov/ and capture (i) both reel/frames, (ii) both correspondents, and (iii) whether any third recording exists — particularly any 2018–2020-era Lacework recording carried over from parent application 16/134,794 (cf. the unverified Reel 047636/0855 lead above). If a third recording to a Lacework holding entity surfaces, re-run signals #1 and #4 before finalizing.

Generated 10/1/2026, 4:03:13 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll search for the specific patent and its citation record.

Let me pull the citation records from Justia and the Google Patents citation tabs.

Prior-Art / §102 Anticipation Analysis — US 12,126,695 B1

Identifier discipline (read first). Every number below is reproduced literally. I did not auto-correct anything. Two look-alikes surfaced during the search and are excluded, not substituted:

Surfaced token Why excluded
US 12,126,643 B1 ("Leveraging Generative Artificial Intelligence ('ai') for Securing a Monitored Deployment") One-digit transposition of 12,126,695. A different patent — and in fact a sibling in the same Lacework/Fortinet family. Not this patent.
US 12,323,449 B1, US 12,095,796 B1, US 12,120,140 B2 Different numbers in the same portfolio neighborhood. Not this patent.

0. Bottom line — I could not honestly complete the literal request

You asked me to (a) search the USPTO database for 12126695, and (b) for each patent citation on that patent, give full citation, dates, description, and the claim(s) it potentially anticipates under §102.

I completed a partial answer and I am going to be explicit about the two gaps rather than fill them with plausible-looking text:

  1. I could not retrieve the verified "References Cited" set for US 12,126,695. The USPTO Assignment/PatentCenter interfaces and the Google Patents Citations tab did not return their citation tables into my search results, and my search budget was exhausted before I could pull the patentimages PDF (whose front page carries the examiner's Form PTO/SB/08 list) or the Justia #15 anchor with confidence.
  2. The granted claim set is still not in hand. This was flagged in the earlier Obviousness section and the gap is not cured here. §102 anticipation is a claim-by-claim, element-by-element test ("a single prior art reference discloses each and every limitation, arranged as in the claim"). Without verbatim claim language, I cannot assign a claim number to any reference. I will not guess claim numbers.

Below is what I did recover, the legal gating analysis that must precede any §102 statement, and the exact documents that close the gap.

⚠️ Date-window flag (carried forward). Task header says 2026-04-26; my operating date is 2026-10-01. Nothing in the prior-art section turns on this, but the IPR referenced in §6 was filed 2026-09-30 — one day before my operating date and outside the header window.


1. The threshold question that disposes of most candidate references before §102 even applies

For US 12,126,695, the effective filing date of each claim controls which references are §102 art at all. Under AIA §102:

  • §102(a)(1) — art "patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date."
  • §102(a)(2) — art in a U.S. patent or published application that was effectively filed before the effective filing date (i.e., its own priority date must predate the critical date).
  • §102(b)(1)(A) — the grace-period exception for the inventors' own disclosures within one year.

Three candidate effective dates are in play (developed in the earlier Obviousness section — I do not repeat it, only apply it):

If the claims are supported by… Critical date Consequence for §102
prov. 62/590,986 (2017-11-27) / 62/650,971 (2018-03-30) 2017-11-27 / 2018-03-30 Only art effectively filed before late 2017 can anticipate. Any §102 reference must predate this.
16/134,794 (2018-09-18 → US 10,581,891) 2018-09-18 Adds 2018 art.
the 2021–2022 filings (63/243,013 · 2021-09-10; 17/504,311 · 2021-10-18; 17/671,199 · 2022-02-14) 2021-09-10 – 2022-02-14 The whole 2018–2022 CSPM/cloud-security wave becomes §102(a)(1) art.

Why this matters for the list below: the candidate numerics I recovered skew 2020–2023 (e.g., US 10,776,191; US 10,885,452; US 11,153,339; US 11,575,693). Patents in that vintage cannot be §102 art against a 2017-11-27 critical date unless their own effective filing date predates it — which for most of them it plainly does not. That date profile is itself the strongest evidence that the list I recovered is not an examiner §102 citation set for a 2017-priority claim. It reads far more like a citation-network / "Referenced By" / Similar-Documents list. Flagging that as an analytical inference, not a verified fact.


2. What I actually retrieved — documents Google Patents ties to US12126695B1

These two appeared in Google Patents tables bearing US12126695B1 (en) | 2017-11-27 | 2024-10-22 | Fortinet, Inc. | Enhancing security of a cloud deployment based on learnings from other cloud deployments. Direction unresolved (backward citation vs. Cited By vs. Similar Documents) — I could not distinguish which table they came from, and I will not assert it.

# Full citation (as surfaced) Pub./filing date Description §102 claim mapping
1 US 2018/0139200 A1 — "Revoking sessions using signaling" 2018 publication series; exact pub. date and filing date NOT RETRIEVED; assignee NOT RETRIEVED Session-revocation via in-band signaling in a network session. Title is all I have; I did not verify the specification or assignee, so I cannot exclude that it is the patent owner's own earlier work (which would defeat it as §102(a) art or trigger §102(b) exceptions). Cannot assess. Chronologically it could be §102(a)(1) art against a 2017-11-27 critical date only if published before that date — a 2018 series publication by definition postdates 2017-11-27, so it is not §102(a)(1) art on that date; it could only be §102(a)(2) art if its own effective filing date precedes the critical date (unverified).
2 US 2019/0158524 A1 — "Anomaly detection based on information technology environment topology" 2019 publication series; exact pub. date and filing date NOT RETRIEVED; assignee NOT RETRIEVED Topology-based anomaly detection for IT environments — topically cognate to the '695 specification's polygraph/baselining disclosure. Cannot assess. Same analysis as #1 and worse: a 2019 publication cannot anticipate a claim with a 2017-11-27 or 2018-09-18 critical date under §102(a)(1), and its §102(a)(2) eligibility depends entirely on an unverified effective filing date. If the critical date is instead 2021–2022, both references become live §102(a)(1) candidates and must be charted.

Honest status: neither reference can carry a §102 ground today. I lack (i) verified dates, (ii) verified assignees, and (iii) the claim text. Both are flagged as leads to verify, not as invalidity positions.


3. Candidate "References Cited" numerics — recovered, but with a serious reliability caveat

The earlier Obviousness section reported a bare numeric list rendered at https://patents.justia.com/patent/12126695#15 and explicitly declined to attribute disclosures to it. That was the right call, and I still cannot cure it. I am re-presenting the list in compliance with your request for "each patent citation," but with two integrity labels on every row:

Caveat A — direction unverified. I could not confirm whether this is the patent's References Cited (backward, = potential §102 art) or Referenced By (forward, = not art at all).
Caveat B — contents unverified. I did not retrieve titles, abstracts, or disclosures for these numerics. I therefore attribute no disclosure to any of them.

Numeric Inventor as listed Numeric Inventor as listed
10,776,191 Zheng et al. 11,153,339 Kapoor et al.
10,788,570 Wilson 11,194,849 Lassoued et al.
10,791,131 Nor et al. 11,212,299 Gamble et al.
10,797,974 Giura et al. 11,233,821 Yadav et al.
10,812,497 Venkatramani et al. 11,258,807 Muddu et al.
10,824,675 Alonso et al. 11,281,519 Krishnaswamy et al.
10,824,813 Smith et al. 11,314,789 Goldfarb
10,885,452 Garg 11,411,966 Muddu et al.
10,904,007 Kim et al. 11,431,735 Shua
10,904,270 Muddu et al. 11,463,464 Zadeh et al.
10,911,470 Muddu et al. 11,489,863 Shua et al.
10,951,648 Doron 11,494,787 Erickson et al.
10,986,114 Singh et al. 11,544,138 Kapish et al.
11,036,716 Griffith et al. 11,575,693 (inventor truncated in source)
11,036,800 Kayyoor et al.
11,044,264 Durairaj et al.
11,048,492 Jain et al.
11,080,392 Bennett
11,082,289 Dang et al.
11,120,343 Das et al.
11,126,533 Knowles et al.

One analytically significant row, and it is a warning sign for the whole list:

  • US 11,153,339 (Kapoor et al.) is not third-party art — it is a same-family Lacework patent. I independently corroborated that US 11,153,339 issued from application 16/665,961, filed 2019-10-28, which the US11792284 front page identifies as a continuation of 16/134,794 — i.e., US 10,581,891, the direct parent of US 12,126,695. Co-inventor on that Lacework family is Yijou Chen, who is also an inventor of US 12,126,695.

    Consequence: a list containing a same-family, same-inventor sibling cannot be a pure examiner-cited §102 art set — a reference cannot be prior art against a claim whose specification it shares, and it would trigger the §102(b)(1)(A)/(b)(2)(A)-(C) exceptions. Its presence is further evidence that Caveat A is real and that this list is a citation network / "Referenced By" aggregate, not the Form PTO/SB/08 art set.


4. What I will not do, and the framework for doing it properly

I will not assign claim numbers. The reason is mechanical, not stylistic: §102 anticipation requires that one reference disclose every limitation. The '695 independent claims are not in my possession; the earlier Obviousness section reconstructed only an abstract-level four-element scope, which is not a claim chart and cannot support a §102 statement.

When the claims arrive, the mapping should be run against this element grid (reconstructed from the abstract and FIGS. 9–12 — contingent, not verified):

Element Scope (abstract-level) What a §102 reference would need to disclose
(i) Identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to use for cross-customer learning Peer-group selection across different customers' deployments
(ii) Receiving information describing a security threat to those additional deployments Threat intel tied to observed events in those deployments
(iii) Receiving information describing configuration settings used to combat that threat The remediation/config, not merely an indicator
(iv) Identifying, based on (iii), configurations to adopt for the first deployment Output of a concrete configuration set for the first deployment

Fatal-disclosure test to apply per reference: if a reference discloses threat indicators without the configuration settings of element (iii), or discloses configuration hardening without element (i)'s cross-customer peer selection, it cannot anticipate under §102 and can only be a §103 combination — which is exactly why the earlier section's combinations (Grounds A–D) are the realistic route, not §102.


5. References that are not §102 art for this patent (do not mis-assign)

Reference Relationship Why it is not §102 art
US 10,581,891 B1 (Kapoor et al.) Direct parent of 12,126,695 (16/134,794 → 18/361,748) Same family / same specification. Not prior art; it is the priority vehicle.
US 11,153,339 B2 (Kapoor et al.; from 16/665,961) Family sibling — same chain back to 16/134,794; co-inventor overlap with '695 Same-family, same-inventor; §102(b) exceptions apply. Despite appearing in the bare list of §3.
US 11,792,284 B1 (Nanduri, Jalan, Vanninen, Ekbore, Nirmala, Yijou Chen) — "Using data transformations for monitoring a cloud compute environment" Lacework family, common inventor Yijou Chen Same-family / common-inventor.
US 11,785,104; US 11,894,984 B2; US 11,818,156 B1; US 2022/0247769 A1 Same-priority family members ("Learning from similar cloud deployments"; "Configuring cloud deployments based on learnings…") Same family. Usable only for priority/§112(a) support analysis, never as §103 art.
US 12,126,643 B1 Adjacent Lacework/Fortinet sibling (one-digit transposition) Different patent number. Excluded per the identifier rule.
US 12,537,884 B1 (later continuation, 18/425,759) Child of this patent Not art; means '695 has a live continuation line.

6. The highest-value actual source of the art — and it is not the patent's face

For purposes of answering "what is the most relevant prior art for US 12,126,695," the examiner's citation list is the second-best source. The best source, now on file, is:

  • IPR2026-00515, Netskope, Inc. v. Fortinet, Inc., filed 2026-09-30 — attacking this patent. Its petition will contain a §102/§103 grounds table, claim-by-claim, an exhibit list, and a declaration. That is a professional, litigated statement of the best art against these exact claims — including whether the petitioner attacks the 2017-11-27 priority date. Per the earlier PTAB section, the petition, POPR, panel, grounds table and exhibit list are all unretrieved; I did not obtain them here either. Pull at PTAB E2E / PTACTS: https://ptacts.uspto.gov/ptabweb/.
  • Related but different patents (context only, do not mis-attribute): Netskope v. Fortinet, IPR2023-00030, US 10,826,941 B2, FWD 2024-04-08 (all claims 1–22 unpatentable) — a Fortinet patent, not this one. And the Fortinet Oct-2025 wave: IPR2026-00025/-00026/-00027/-00031/-00040/-00041/-00042 against Netskope's '639, '426, '936, '697, '336, '282, '710 — none is 12,126,695.

7. Verification checklist — exactly what closes this out

  1. Granted claim set, all claims, verbatim — USPTO PatentCenter, application 18/361,748; or the patent PDF at patentimages.storage.googleapis.com for US12126695. Everything above is abstract-level until this lands.
  2. The real "References Cited" (backward) list — PatentCenter file wrapper Form PTO/SB/08 and the examiner's search notes; Google Patents Citations tab; Justia References Cited (distinct from Referenced By, and I could not separate them here). This is the list your question actually asks for, and I did not verify it.
  3. Directional disambiguation — for each numeric in §3, confirm whether it appears under References Cited (backward) or Referenced By (forward). Given US 11,153,339's presence and the 2020–2023 date profile, I expect a substantial portion to be forward/similar, i.e., non-art.
  4. Titles, abstracts, and a key-figure read of each verified backward citation.
  5. Prosecution history of 18/361,748 and of parents 16/134,794 / 16/665,961 / 17/504,311 / 17/671,199 — any §103 rejection actually made there is the cheapest and most defensible starting point, and it reveals which art the examiner treated as closest.
  6. Claim-by-claim §112(a) priority mapping against prov. 62/590,986 and 62/650,971 — this decides whether the 2020–2023 references become §102(a)(1) art.
  7. Inventor-overlap check on the family's 2022 A1 publications, to test §102(b)(1)(A) grace-period exceptions.

Confidence statement

  • High confidence: the bibliographic data, the parentage (16/134,794 → US 10,581,891 → US 12,126,695), the existence of US 11,153,339 as a same-family Lacework sibling, and the fact that the 2017-11-27 priority date is the pivotal variable governing which references are §102 art.
  • Low confidence / explicitly unverified: the full References Cited set; the direction (backward vs. forward) of the Justia numerics; the dates and assignees of US 2018/0139200 A1 and US 2019/0158524 A1; and the disclosures of every numeric in §3. I attributed no disclosure to any reference, because I did not verify one.
  • Cannot state at all: which claims any reference anticipates. That requires the granted claim text, which I do not have.

Generated 10/1/2026, 4:04:21 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll start by grounding this analysis in the actual record for US 12,126,695 — its claims and the references cited against it — since the pasted page text is truncated before any "Prior Art"/Citations section.

The pasted page text is truncated before any Citations/"Prior Art" listing, so I need to retrieve (a) the actual claim set of US 12,126,695 and (b) the references on its face and in its citation list.

I have the abstract and priority data. Now I need the exact claim language (the pasted page text stops before the claims) and the reference lists, which Google Patents/Justia render in the Citations section.

Important scope caveat before the analysis

Two things I was instructed to rely on are not present in the material available to me, and I will not invent them:

  1. The claim set of US 12,126,695 is not in the pasted page text. The text you supplied runs continuously through the specification and terminates mid-sentence at "Query service 166." It contains the abstract, the figure list, and the description, but no "What is claimed is" section. I therefore do not have verbatim claim language, claim numbering, or dependent-claim scope.
  2. The page you pasted contains no "Prior Art" section. Google Patents does not render a section literally titled "Prior Art"; it renders Citations (backward patent citations), Cited By (forward citations), and Similar Documents, plus the auto-extracted "Prior art keywords / Prior art date" sidebar fields. None of those blocks survived into the text you pasted.

Per the operating rule to say so explicitly rather than fabricate: I could not retrieve the verbatim claims or the full citations list within my tool budget. What I recovered is below, and the §103 analysis is expressly mapped to the abstract-level / FIG. 9–12-level scope, which I flag as contingent.


1. Verified record facts (grounded)

Item Value Source
Patent US 12,126,695 B1, "Enhancing security of a cloud deployment based on learnings from other cloud deployments" pat. text; Justia
Inventors Úlfar Erlingsson; Yijou Chen pat. text; Espacenet
Applicant / assignee chain Lacework, Inc. (assignment recorded 2023-08-01) → Fortinet, Inc. (assignment recorded 2024-10-07) pat. text
Application 18/361,748, filed 2023-07-28 pat. text
Granted 2024-10-22 pat. text
Earliest priority 2017-11-27 (prov. 62/590,986); chain: 62/650,971 (2018-03-30); 16/134,794 (2018-09-18) → US 10,581,891 B1; 16/665,961 (2019-10-28); 63/243,013 (2021-09-10); 17/504,311 (2021-10-18); 17/671,199 (2022-02-14) Espacenet priority list
Google "Prior art date" 2017-11-27 (assumption, not a legal conclusion) pat. text
Anticipated expiration 2038-09-18 (20 yrs from the 2018-09-18 parent filing) pat. text
Family litigation flag "First worldwide family litigation filed" (Darts-ip family 82611851) pat. text
Auto-extracted prior art keywords data; user; configuration settings; cloud; information describing pat. text

Abstract (the best proxy I have for claim 1's scope): "identifying, for at least a portion of a first cloud deployment, one or more additional cloud deployments to utilize for cross-customer learning; receiving information describing a security threat to one or more of the additional cloud deployments; receiving information describing configuration settings used to combat the security threat; and identifying, based on the information describing configuration settings used to combat the security threat, one or more configurations to adopt for the first cloud deployment." (Espacenet abstract; Golden wiki; confirms FIG. 9–12 are the "learning from similar cloud deployments" flowcharts.)

References-cited list (numerics only, as rendered at https://patents.justia.com/patent/[12126695](/patent/12126695)#15, snippet excerpt): 10,776,191 (Zheng et al.); 10,788,570 (Wilson); 10,791,131 (Nor et al.); 10,797,974 (Giura et al.); 10,812,497 (Venkatramani et al.); 10,824,675 (Alonso et al.); 10,824,813 (Smith et al.); 10,885,452 (Garg); 10,904,007 (Kim et al.); 10,904,270 (Muddu et al.); 10,911,470 (Muddu et al.); 10,951,648 (Doron); 10,986,114 (Singh et al.); 11,036,716 (Griffith et al.); 11,036,800 (Kayyoor et al.); 11,044,264 (Durairaj et al.); 11,048,492 (Jain et al.); 11,080,392 (Bennett); 11,082,289 (Dang et al.); 11,120,343 (Das et al.); 11,126,533 (Knowles et al.); 11,153,339 (Kapoor et al.); 11,194,849 (Lassoued et al.); 11,212,299 (Gamble et al.); 11,233,821 (Yadav et al.); 11,258,807 (Muddu et al.); 11,281,519 (Krishnaswamy et al.); 11,314,789 (Goldfarb); 11,411,966 (Muddu et al.); 11,431,735 (Shua); 11,463,464 (Zadeh et al.); 11,489,863 (Shua et al.); 11,494,787 (Erickson et al.); 11,544,138 (Kapish et al.); 11,575,693 (… Feb. 7, 2023).

Caveat: that Justia snippet is a bare numeric list; I could not verify (a) whether it is the patent's own References Cited or a forward Referenced By list, nor (b) the titles/contents of those documents. I therefore do not attribute any specific disclosure to any of those numbers below. That is the single biggest gap in this analysis and it must be closed before any invalidity contention is served.

Family members (same priority, same inventors — relevant to the date analysis, not usable as §103 art): US 11,785,104 ("Learning from similar cloud deployments"); US 11,894,984 B2 ("Configuring cloud deployments based on learnings obtained by monitoring other cloud deployments"); US 11,818,156 B1 (spec text quoting FIG. 6 "identifying… highly rated cloud deployments" and "recommending… a change to the first cloud deployment based on the normal behavior for the highly rated cloud deployments"); US 2022/0247769 A1; plus the Lacework/Fortinet siblings identified in the family listing (11,637,849; 11,677,772; 11,882,141; 11,909,752; 12,034,750; 12,095,794; 12,095,796; 12,095,879; 12,120,140; 12,126,643; 12,130,878).


2. The threshold issue that drives everything: effective filing date per claim

Under AIA §102/§103, a claim gets the 2017-11-27 date only if the provisional(s) provide §112(a) written-description support for that claim. The "cross-customer learning" subject matter is described in this family in applications filed 2021-09-10, 2021-10-18, and 2022-02-14 (see the Espacenet priority list and the sibling patents US 11,785,104 / US 11,894,984, both directed to learning from other deployments). That is strong circumstantial evidence that the cross-customer-learning concepts were added to the family in the 2021–2022 filings, not in the 2017/2018 provisionals.

Scenario Effective date of the '695 claims Art available
Claims fully supported by 62/590,986 or 62/650,971 2017-11-27 / 2018-03-30 Must predate late-2017; the "cross-customer learning" art is thin — nonobviousness is plausible
Claims supported only by 16/134,794 (2018-09-18) 2018-09-18 Adds 2018 art (AWS Config conformance packs, GCP Security Command Center)
Claims supported only by the 2021/2022 filings 2021-09-10 – 2022-02-14 (or the 2023-07-28 filing) Adds the entire 2018–2021 CSPM/benchmarking wave — this is where a §103 case becomes viable

Also note the grace-period nuance: family A1 publications dated just inside one year before the effective date may be excepted under §102(b)(1)(A) only if the disclosure was made by the inventors or by someone who obtained it from them; a same-family publication naming different Lacework inventors is not automatically excepted and could be §102(a)(1) art. Verify inventor overlap on US 2022/0247769 A1, US 2022/0311794 A1, and the other 2022 A1 publications before relying on this.

Bottom line: the first §103 task is not "find references," it is "prove up the priority date." If the cross-customer-learning limitations are only supported by the 2021–2022 filings, examiners/petitioners get three extra years of art.


3. §103 framework applied (Graham / KSR / MPEP 2143)

Claim-scope reconstruction (contingent, from the abstract and FIG. 9–12): four steps — (i) identify one or more other cloud deployments to use for cross-customer learning, for at least a portion of a first deployment; (ii) receive information describing a security threat to those deployments; (iii) receive information describing configuration settings used to combat that threat; (iv) identify, based on (iii), one or more configurations to adopt for the first deployment. Note the claim as abstracted appears to be purely functional and result-oriented — it recites what is learned, not how the learning, correlation, or selection is performed. Such breadth (a) makes §103 easier because any art hitting the inputs/outputs reads on it, and (b) raises a real §112(b) indefiniteness / §101 "results-oriented" attack that a validity challenger should preserve as an alternative.

Level of ordinary skill: a software/cloud-security engineer with ~2–3 years of cloud security operations experience, familiar with cloud provider configuration services, threat-intelligence feeds, and hardening guides.

Claim-element → art-category map (categories are verifiable; specific mappings require the claim text and reference titles):

Claim element (per abstract) Art category that would disclose it Confidence
Identify other deployments for cross-customer learning Peer-group / similar-tenant selection, benchmarking cohorts, collaborative filtering, provider-side multi-tenant telemetry High (category)
Receive info describing a security threat to the other deployments Threat-intelligence sharing platforms and feeds (STIX/TAXII-based sharing, ISACs, MAPP-style pre-disclosure of threats and mitigations, MDR/MSSP telemetry) High (category)
Receive info describing configuration settings used to combat the threat Hardening guides/benchmarks (CIS Benchmarks), provider remediation guidance, conformance packs / auto-remediation rule sets, secure-score recommendations, IR playbooks High (category)
Identify configurations to adopt for the first deployment Policy/remediation recommendation engines; "secure score" recommendation lists; IaC/config scanners producing fix lists High (category)

4. Combinations that would render the claims obvious (and the motivations)

Because I could not verify the contents of the numerics on the face of the patent, I present these as grounds to be built and verified, ordered by strength, with the motivation (the part that decides §103) fully reasoned.

Ground A — Threat-intelligence sharing ⊕ configuration-baseline/remediation recommendation

References: a threat-intelligence sharing system that disseminates both (a) indicators/descriptions of an attack seen at one organization and (b) the mitigations/configuration changes that defeated it; in view of a configuration-management/security-posture system that generates a list of specific configuration settings to change for a given environment (CIS Benchmark conformance, provider auto-remediation, secure-score recommendations, IaC fix lists).

Why a POSITA would combine (KSR, "known technique, known method, predictable result"):

  • The problem "an attack suffered by one organization is a preview of the attack on everyone" was the express economic premise of threat-sharing (ISACs, STIX/TAXII, MAPP-style pre-disclosure of vulnerabilities with mitigation guidance) years before 2017. Disseminating the fix, not just the indicator, is the natural and obvious completion of that premise.
  • Applying a security setting that is known to have defeated a specific attack in a comparable environment, to one's own comparable environment, is a predictable, mechanical use of a known technique with an expected result — and both references are in the same field (network/cloud security).
  • Additional objective motivations available on the record: reducing mean-time-to-remediation, avoiding re-deriving mitigations per tenant, and the provider's natural position as a multi-tenant observer (see Ground C).

Weakness to attack: if all the applied art stops at disseminating threat indicators and does not expressly tie them to configuration settings adopted elsewhere, the "combat" linkage must be supplied by rationale (recognized problem + predictable result), which is exactly where a Patent Owner will argue hindsight. Expect to need a reference that pairs an attack with its mitigation.

Ground B — Peer-deployment selection (clustering/collaborative filtering) ⊕ Ground A

References: a system that clusters or groups deployments/entities by behavior or attributes and identifies similar peers (the art predating 2017 includes behavioral clustering of monitored entities and machine-learning similarity; note the '695 specification itself describes clustering monitored entities, which is evidence that this was known) in view of Ground A.

Motivation: once you decide to learn from other deployments, the only sensible subsets are those that are similar (same industry, same architecture, same services) or best-in-class. Selecting peers by similarity is the standard way to benchmark, and the "identify which deployments to learn from" step is the classic collaborative-filtering "neighborhood selection" problem. This addresses step (i) cleanly and undercuts the argument that step (i) is an inventive selection.

Ground C — Provider-side multi-tenant telemetry ⊕ Ground A

References: a cloud service provider's centralized security monitoring/analytics across many tenants or accounts (any agent-based multi-tenant monitoring platform; and note the '695 specification at Fig. 1A/1B–1D describes exactly such an architecture — a platform ingesting agent data from many customers' cloud environments and analyzing "data associated with a first entity and use the results… to perform one or more operations with respect to a second entity"). That last sentence is in the specification itself, and an applicant's admission about what the architecture does is usable as evidence of what was known/obvious, though it is not itself "prior art."

Motivation: the provider already holds cross-tenant visibility; aggregating observations across tenants to derive a recommended configuration is the straightforward, low-cost use of data already in hand ("market demand / obvious use of prior art elements"), and it is the same-field, same-problem combination that KSR treats as obvious. The claim's "at least a portion of a first cloud deployment" and "additional cloud deployments to utilize" language reads directly on multi-tenant account grouping.

Ground D — Cross-organization security benchmarking/rating services

References: services that score and compare organizations' security posture against peer groups (pre-2018 commercially available), in view of Ground A. Motivation: peer comparison is the recognized way to decide what to change; the score/recommendation step supplies element (iv).


5. Arguments the Patent Owner will make (prepare counter-evidence now)

  1. No reasonable expectation of success / cross-customer data-mixing risk. An argument that sharing configuration data across customers raises privacy, tenancy, and confidentiality problems, so a POSITA would not have combined threat-intel sharing with cross-tenant configuration data. Rebut with evidence that (a) anonymized/aggregated telemetry sharing was routine, (b) the claim recites "configuration settings," not customer data, and (c) the spec's own architecture already contemplated cross-entity analysis.
  2. Priority. The strongest Patent Owner move is to lock the 2017-11-27 date and then argue that no 2017-era art teaches cross-customer learning about cloud deployment configurations (as opposed to classic network threat feeds). Anticipate this by pre-building the §112(a) priority record — i.e., show that the provisionals do not describe "cross-customer learning" — which independently expands the art and may also create a priority/§112 problem for the Patent Owner.
  3. Hindsight. Every rationale must be tied to an express problem statement in the references themselves or to art-identified needs (MPEP 2144.1), not to the patent's own disclosure.
  4. Secondary considerations. Look for licensing, industry praise, copying, and nexus. Note the Lacework→Fortinet acquisition (assignment recorded 2024-10-07) and the family litigation flag ("First worldwide family litigation filed," Darts-ip family 82611851) — commercial-success and licensing evidence is likely to be asserted, and validity challenges in this family are plausibly already in motion.

6. What I need to complete this to filing-quality (verification checklist)

  1. Verbatim claims of US 12,126,695 (all claims). Everything above is at abstract-level scope until then; the "portion of a first cloud deployment," "cross-customer learning," and "one or more configurations to adopt" constructions will decide the case.
  2. The actual Citations/"References Cited" and Cited By lists (Google Patents Citations / Cited By tabs; Justia References Cited / Referenced By; USPTO PatentCenter file wrapper Form PTO/SB/08 and the examiner's search notes).
  3. Titles, abstracts, and key figures for the numerics in §1 — I deliberately did not attribute disclosures to them.
  4. Prosecution history of 18/361,748 and of parents 16/134,794, 16/665,961, 17/504,311, 17/671,199 — to see what the examiner actually relied on and what was argued (any §103 rejection there is the cheapest starting point).
  5. §112(a) support mapping for each limitation against prov. 62/590,986 and 62/650,971, to fix the effective filing date claim-by-claim.
  6. Inventor overlap on the family's 2022 A1 publications, to test the §102(b)(1)(A) grace-period exception.

Confidence statement: I am highly confident about the bibliographic/priority data and the abstract-level claim scope; I am not able to state which specific reference discloses which limitation, and I have not done so. Once the claims and the citations list are supplied, I can convert §4 above into element-by-element charts with column/line cites.

Generated 10/1/2026, 4:02:00 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →