Invalidity dossier

US 5548721

Method of conducting secure operations on an uncontrolled network

Current assignee: Cufer Asset Ltd LLC

Added 9/25/2026, 3:16:16 PM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for litigation and docket information on this patent, then summarize.

US 5,548,721 — Verified Summary

Searches run: Google Patents full text (authoritative), Justia, FreePatentsOnline, EveryPatent, PatentImages PDF, PlusSite USPTO docket, PTAB/PTActs, plus a targeted CAFC docket sweep for 2026 and general district-court/PACER-adjacent queries for the number.

Bibliographic data

Field Value
Patent number US 5,548,721 A (rendered "US5548721A" by Google Patents)
Title Method of conducting secure operations on an uncontrolled network
Inventor David L. Denslow, Rochester, NY (US)
Original assignee Harris Corporation, Melbourne, FL
Application no. 08/234,947
Filed 1994-04-28 (assignment effective date recorded as 1994-04-27)
Issued 1996-08-20
Examiner / Art Unit Robert W. Beausoliel, Jr. (Primary); Albert Decady (Assistant); Group Art Unit 2413; Class/subclass 395/187 (now CPC G06F 21/31, G06F 21/34, H04L 63/04, H04L 63/0853)
Attorney/agent Rogers and Killeen
Claims 11 total; independent claims 1, 3, 11
Family None — EPO/UK search annexes state "NONE" for foreign family members
Status Expired – Lifetime; anticipated expiration 2014-04-28. Certificate of correction recorded 1997-02-18.
Assignments of record Harris Corp. (1994) → W.D. BURGEON, LIMITED LIABILITY COMPANY, recorded 2007-09-25, effective 2007-08-23 (Reel/Frame 019864/0864)

Assignee caution: Google Patents' Current Assignee field lists "Cufer Asset Ltd LLC." I did not find a recorded assignment from W.D. Burgeon to Cufer Asset in the documents surfaced. Google itself disclaims the accuracy of that field, and the last assignment on the face of the record is to W.D. Burgeon LLC. A separate search hit shows Cufer Asset Ltd. L.L.C. as a defendant in a 2026 D. Del. declaratory-judgment suit filed by The Hartford against Intellectual Ventures entities (reported 2026-04-09), but I found no document tying patent 5,548,721 specifically to that case. Treat the Cufer Asset listing as unverified.

Abstract (as issued)

A method of conducting secure operations on an uncontrolled network in which authorized users are provided with a personal identifier and with a portable, electronically readable card having part of a system key thereon. The system key is created by a secure network access port (SNAP) at the workstation and, when used in combination with the personal identifier, uniquely identifies the user so that the card and identifier may be used to conduct secure operations from any workstation in the network. Operational keys are provided from a network security manager to a workstation in response to a validated request for access, in an encrypted communication using an initialization key unique to the workstation and known to the manager.

Plain-language overview of the independent claims

Claim 1 — Home-workstation secure session (the core method).

  1. Give a user a personal identifier, and give the user a "cryptographic ignition key" (CIK) card holding a randomly selected portion of an authorization record. The authorization record is the personal identifier combined with a system key created by a first workstation.
  2. Every secure workstation gets a SNAP containing (a) a card reader, and (b) storage for the remainder of the record/key plus a workstation-unique initialization key. Critically, that initialization key lets the workstation talk securely to the manager but not to other workstations.
  3. The manager stores the complete record and system key.
  4. To get on the network, the user supplies the personal identifier and swipes the CIK card at the SNAP.
  5. The SNAP itself evaluates the identity and, if matched, sends the authorization record/system key to the manager encrypted with that workstation's initialization key.
  6. If the manager validates, it returns an operational key (again encrypted under the initialization key), which enables secure operations on the network.

Claim 2 (dependent on 1) — Remote-workstation enrollment. Adds the "roaming" case: at a second workstation the SNAP recognizes the user is not locally authorized, assigns a second system key, sends the record/identifier/second key to the manager under the second workstation's initialization key; if approved, the manager returns an operational key, and the new record is again split — a random portion on the CIK card, the remainder in the second workstation's SNAP.

Claim 3 — Broadened "split-record" framing (independent). Drops the SNAP/system-key specifics: give each authorized user a portable recording device containing an electronically readable portion of an authorization record that includes the user's personal identifier; the first workstation stores the portion not on the device and is given a reader; the manager stores the entire record. Authorization is validated at both the workstation and the manager by evaluating the combined portions.

Claim 11 — Multi-workstation variant (independent). The portable device holds, for each of several workstations where the user is authorized, a portion of that workstation's authorization record, and the record includes a different key per workstation. Each of those workstations stores its own remainder, and the manager stores the complete record for each. Validation again occurs at each workstation and at the manager using the combined portions.

Dependent claims 4–10 add: a system key combined with the identifier (4); a purely unique biometric-style identifier used as the record (5); encryption of the stored record (6); transmission to the manager under the workstation initialization key (7); return of an operational key (8); second-workstation record splitting (9); and a second system key for the second workstation (10).

Litigation / CAFC status

  • No CAFC 2026 appeal involving 5,548,721 was found. I reviewed the CAFC's published July 2026 scheduled-cases list (July 2, 2026 revision) and ran targeted docket queries; nothing matched this number.
  • No district-court complaint or PTAB proceeding asserting or challenging 5,548,721 was surfaced; the only USPTO-side docket hit is the original prosecution file (Application No. 08/234,947, PlusSite docket "Method Of Conducting Secure Operations On An Uncontrolled Network," examiner Albert Decady).
  • Because it expired 2014-04-28, active enforcement in 2026 is unlikely, but I cannot rule out a historical suit without a full PACER/Docket Navigator check — treat this as "not found," not "confirmed none."

Identifier-confusion warnings (kept literal per instructions)

Several unrelated things share the digits "5548721" and must not be conflated with this patent:

  • JP 5548721 B2 — a Konami Digital Entertainment game system patent (Japanese filing 2012-80687), a completely different document.
  • IPR2025-00068 concerns US 9,954,872 B2 (GoSecure v. CrowdStrike) — one digit away, unrelated.
  • Mongolia company registration No. 5548721 (Erdenes Oyu Tolgoi LLC) and a Florida FEI No. 45-5548721 — non-patent identifiers.

Relevance note

This patent is of interest largely as prior art: it is cited in the EP 1 404 083 search report (Harris's own later Removable cryptographic ignition key system and method family, which became US 7,761,904) and appears in the prior-art lists of Round Rock Research / Micron's mixed-enclave network security patents (e.g., US 8,874,768).

Confidence: High on all bibliographic and claim content (drawn from the full authoritative patent text). Low/uncertain on the current assignee (Cufer Asset) and on the absence of litigation, which reflects the limits of the searches run rather than a definitive negative.

Generated 9/25/2026, 6:45:30 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 5548721. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US patent 5548721 through specialized patent litigation sources.

The initial results were polluted by unrelated patents ending in "872." Let me search with precise formats and targeted litigation databases.

Litigation Search Results: U.S. Patent No. 5,548,721

Bottom line: After targeted searching, I found no evidence of any litigation — filed, pending, or concluded — that asserts, challenges, or otherwise involves U.S. Patent No. 5,548,721. I state this with the caveat that my searches reached a step limit, and I identify below the sources checked and the residual uncertainty.

Patent identification (confirmed, matches your record)

  • Patent: U.S. 5,548,721 — "Method of conducting secure operations on an uncontrolled network"
  • Inventor: David L. Denslow
  • Application: 08/234,947; filed 1994-04-28; granted 1996-08-20
  • Original assignee: Harris Corporation
  • Assignment history: Harris Corp. → W.D. Burgeon, Limited Liability Company (recorded 2007-09-25); Google Patents lists the current assignee as Cufer Asset Ltd LLC (this is the source's listing, which I have not independently verified)
  • Status: Expired – Lifetime; anticipated expiration 1994-04-28 + 20 years = 2014-04-28

Sources searched and results

Source Result
Unified Patents litigation portal (attempted) No responsive case data retrieved for this patent
Google Patents "Litigation" / Related sections for US5548721 No litigation events listed
CourtListener / RECAP, Justia, RPX Insight, PACER Monitor (via web search) No hits tying case numbers to 5,548,721
CAFC opinions (Justia/cafc) No hits
General web search on the patent number and title No litigation references

Important caution — false positives I had to discard

Generic searches for "5548721" / "'721" are heavily contaminated by unrelated patents and identifiers. I expressly excluded the following, none of which involve U.S. 5,548,721:

  • U.S. 9,935,872 ("the '872 patent") — VoIP‑Pal; subject of DJ actions (e.g., Twitter v. VoIP‑Pal, No. 21‑cv‑02769‑LHK, N.D. Cal.; Apple DJ, No. 20‑cv‑02460‑LHK) and W.D. Tex. suits.
  • U.S. 10,189,872 ("the '872 patent") — W.R. Grace & Co.-Conn. v. Elysium Health (D. Del., No. 20‑1098‑GBW‑JLH).
  • U.S. 8,046,721 / 7,704,721 ("'721 patents") — Apple v. Samsung; Genzyme v. Sarepta.
  • U.S. 3,113,872 ("'872") — Milton G. Waldbaum Co. v. Roberts Dairy Co., 325 F. Supp. 772 (D. Neb. 1971).
  • JP 5548721 B2 — a Japanese patent number (numerically coincident), not the U.S. patent.

The only genuinely on‑point document I found relating to this patent is the search report on EP 1 404 083 (Harris Corp., "Removable cryptographic ignition key system and method," family member US 7,761,904), which cites US 5 548 721 A (Denslow) as prior art. That is a citation, not litigation.

What I could not confirm

  • Whether W.D. Burgeon, LLC or Cufer Asset Ltd LLC (typical patent-holding/monetization-type entities) ever asserted this patent. The 2007 assignment to an LLC is a red flag warranting further inquiry, but I found no case where either entity (or Harris) sued on the '721 patent.

Recommended next steps to close the gap

  1. Unified Patents (portal.unifiedpatents.com/litigation) — search the exact patent number; it harvests district-court and PTAB data.
  2. RPX Insight / Lex Machina — search 5,548,721 in the patent filter (not the "'721" shorthand).
  3. USPTO Patent Center / Assignment records — confirm the full assignment chain (Harris → W.D. Burgeon → Cufer Asset) and see whether any litigation-related documents accompany it.
  4. PTAB (PTAB‑E2E / Docket Alarm) — check for IPR/PGR/CBM/reexam challenges (none surfaced in my search).
  5. PACER/EDTX + D. Del. dockets for the named assignees as plaintiffs.

If you'd like, I can run dedicated queries against Unified Patents and PACER for "W.D. Burgeon" and "Cufer Asset" as plaintiffs to determine whether this patent was part of any assertion campaign.

Generated 9/25/2026, 6:45:27 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll verify the canonical "no proceedings" default against web sources before reporting.

Let me run additional targeted checks on the assignee names and PTAB docket variants before concluding.

Proceedings overview

Zero AIA trial proceedings are on file for US 5,548,721. The USPTO Open Data Portal (ODP) structured block reports no PTAB AIA trial proceedings for this patent, and my independent web checks surfaced none — 0 active, 0 instituted, 0 claims canceled, 0 settled, 0 institution denials. Every claim of the patent — independent claims 1, 3, and 11 and dependent claims 2, 4–10 — is untested at the Board.

Two structural facts dominate the defensive posture. First, all 11 claims remain live as a matter of PTAB record — nothing has been canceled, so there is no "dead claim" argument to hand a defendant. Second, and more decisively, the patent expired on 1994-04-28 + 20 years = 2014-04-28, and its legal status is Expired – Lifetime. A patent that expired over a decade ago cannot be asserted for prospective infringement, and there is no live IPR to defend. The practical defensive posture is therefore: this is a prior-art reference, not an assertion target — the terminal disclaimer is the calendar, not the Board.


No proceedings to report

Because the canonical source returns an empty set and no web source contradicts it, I am not fabricating proceeding numbers or outcomes. Any entry I wrote here would be invented. Instead, here is the verification record:

Source checked Query Result
USPTO ODP structured block (canonical) Patent number 5,548,721 No AIA trial proceedings
PTAB E2E / PTAB public-information petitions "5548721" + Denslow / Harris / "uncontrolled network" No petition, institution, or FWD documents
Google Patents (US5548721) Related / litigation sections No PTAB or litigation events listed
Justia / FreePatentsOnline (US5548721) Prosecution and family pages Prosecution history only; no AIA trial records
Assignee-name sweep "W.D. Burgeon" / "Cufer Asset" + IPR/PTAB No hits tying either entity to a PTAB proceeding
CAFC / CourtListener Appeals from FWDs No FWD exists, so no appeal exists

What the absence means. IPRs are filed against live, asserted patents — typically within § 315(b)'s one-year window after an infringement complaint. A patent that (a) never appears in a district-court docket I could find and (b) expired in 2014 has no path to an AIA trial. The IPR deadline for any hypothetical defendant would have run long before expiration, and the Board's statutory trial deadline (1 year from institution) plus the § 315(b) bar make a 2026 filing legally and practically moot. There is no upcoming institution deadline, no oral hearing, and no FWD date to calendar.

Do not confuse this patent with these near-misses, all of which did generate PTAB activity or numeric hits in my searches:

  • US 9,954,872 B2 — the subject of IPR2025-00068 and IPR2025-00070, where the Board denied institution (see the institution decision at patentlyo.com). One digit away; entirely unrelated. The earlier sections already flagged this.
  • US 10,686,871, US 11,012,827, US 10,812,646 — unrelated patents from 2025 IPR petitions that appear in generic "‘721"/"‘871" searches.
  • JP 5548721 B2 (Konami game system), Brazilian JUcec business registration No. 5548721, and a QuantiModo variable ID 5548721 — non-patent identifiers that pollute number-based searches.

Strategic summary

Claim status: all 11 claims UNTESTED. Because no AIA trial ever reached an institution decision on US 5,548,721, there is no claim-level record of cancellation, no certificate of cancellation of claims under § 318(b), and no estoppel-producing FWD. Independent claims 1, 3, and 11 — the three method claims covering (i) the home-workstation SNAP/CIK session, (ii) the broadened split-record framing, and (iii) the multi-workstation variant — stand exactly as issued in 1996, subject only to the 1997-02-18 certificate of correction noted in the record. Note the earlier sections' claim mapping is the authoritative one: claim 1 requires a randomly selected portion of the authorization record on the CIK card and a workstation-unique initialization key that enables encrypted communication with the manager but not with other workstations — a narrowing limitation that any invalidity theory should be built around if this patent ever mattered.

Estoppel landscape: § 315(e)(2) is a non-issue. No petitioner has been through an FWD on this patent, so no party is estopped from raising any ground. Correlatively, no ground has been "used up" — if there were a hypothetical live dispute, the entire field of prior art would remain available, including the 14 references cited on the face of the patent (e.g., US 4,649,233 to IBM on composite session keys; US 4,850,017 on generating-station control values; US 5,103,478 on key management with control vectors; US 5,273,754 to Secure Computing on a secure computer interface) plus the substantial art cited against the later Harris CIK family — notably the EP 1 404 083 search report, which cites Denslow's US 5,548,721 as category "A" prior art against claims 1–27 of Harris's own later application. That is a citation, not a proceeding, and it cuts against the patent's novelty rather than establishing its validity.

Pattern signals: none of the classic IPR indicia are present. There is no repeat petitioner, no patent-owner PTAB appeal history, and no defensive aggregator (Unified Patents or similar) in the chain. The assignment trail — Harris Corp. (1994) → W.D. Burgeon, LLC (recorded 2007-09-25, effective 2007-08-23, Reel/Frame 019864/0864) → a Google-flagged but unverified "Cufer Asset Ltd LLC" — shows a patent that moved into holding-entity hands but, on my searches, was never weaponized. That combination (holding entity + zero litigation + zero IPR) is consistent with a patent acquired for portfolio or defensive purposes rather than an assertion campaign. Treat the Cufer Asset listing as unconfirmed, per the earlier section's caution.


Recommended next steps

You do not need an IPR defense — you need a calendaring check.

  1. Confirm expiration and non-assertability. The patent's anticipated expiration is 2014-04-28 and its ODP legal status is Expired – Lifetime. Damages for infringement after that date cannot accrue. If a demand letter or complaint cites US 5,548,721 for ongoing or prospective conduct, that theory is facially deficient; ask for the pre-expiration accused acts and the six-year § 286 damages lookback window (which closed in 2020).

  2. If any demand letter cites "US 5548721," verify the number. The most likely explanation for a 2026 assertion notice bearing this number is number confusion with an active relative — most plausibly US 9,954,872 (IPR2025-00068/-00070, institution denied, decision PDF) or another "‘872"/"‘721" patent. Confirm the patent number on the face of any assertion before responding on the merits.

  3. Run the two authoritative negative checks to lock this down. Search PTAB E2E (ptacts.uspto.gov) by application number 08/234,947 and by patent number, and search CourtListener/RECAP for "5,548,721" and for "W.D. Burgeon" as plaintiff. A null result on both confirms the picture above.

  4. If the patent is ever re-surfaced as prior art (its most likely real role — it is cited in US 8,874,768 and other Round Rock/Micron mixed-enclave patents, and in the EP 1 404 083 search report), remember that the 1994-04-28 priority date makes it § 102(b)/§ 102(a) art against anything filed after that date, with the 1996-08-20 issue date making it a printed publication under § 102(b) for post-1997 filings. Its 11 claims are untested but its disclosure is intact and fully citable.

Bottom line for a defendant: The Board has never touched this patent, and it never will — it expired in 2014. There is no FWD to link, no canceled claim to exploit, and no estoppel to worry about. If you are facing an assertion of "5548721" today, the first question is not which claims survived IPR (none were challenged), but whether the number on the demand is even correct.

Generated 9/25/2026, 6:45:51 PM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 1994-04-27 · recorded 1994-04-28 · reel 007332/0733 · Assignment

    David Lawrence DenslowHARRIS CORPORATION

  2. 2007-08-23 · recorded 2007-09-25 · reel 019864/0864 · Assignment

    HARRIS CORPORATIONW.D. Burgeon, Limited Liability Company

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment chain for this patent, building on the bibliographic work already done.

Let me dig into the specific assignment records and correspondents.

I was unable to retrieve the recorded correspondent fields from the USPTO Assignment Center in this session (the search tool hit its step limit before those detail pages resolved), so I flag that gap explicitly below rather than fill it. Everything else is grounded in the authoritative patent text you supplied plus the searches that did complete.

Inventors

Inventor Employer at filing Basis
David L. Denslow (sole inventor) Harris Corporation, Melbourne, FL Recorded "ASSIGNMENT OF ASSIGNORS INTEREST" from "DENSLOW, DAVID LAWRENCE" to Harris, Reel 007332/0733, effective 1994-04-27, recorded 1994-04-28
  • No co-inventors are named anywhere in the document.
  • Residence discrepancy to flag: the authoritative full text does not state the inventor's residence. The earlier summary section recorded "Rochester, NY"; I could not re-verify that from the authoritative text in this pass, so treat "Rochester, NY" as unconfirmed.
  • Unusual-pattern check: none observed. This is a single-inventor, garden-variety employment assignment executed the day before the 1994-04-28 filing, with no reversion and no subsequent Denslow-side recorded instrument. There is no evidence of inventor departure within 12 months of filing, and no evidence of a later inventor-originated transfer.

Original assignee

  • Entity on the issued patent: Harris Corporation (33737), Melbourne, Florida — a large, publicly traded defense/communications-electronics company (tactical radios, RF communications, encryption/secure communications, and broadcast equipment).
  • Product embodying the claims: The claimed subject matter — a "secure network access port" (SNAP) with a crypto module, key-management module, and a crypto ignition key (CIK) card used to unlock secure sessions on an untrusted LAN — is squarely within Harris's secure-communications/COMSEC line of business. That said, I did not find evidence of a specific commercial Harris product that embodies these claims, so I cannot confirm commercial embodiment. (This is a lower bar than "no products" — I simply lack affirmative evidence either way.)
  • Current status of the original assignee: Harris Corporation no longer exists as an independent company; it merged with L3 Technologies in 2019 to form L3Harris Technologies (NYSE: LHX), an operating defense contractor. Harris did not enter bankruptcy. Note, however, that Harris had already divested this patent in 2007 — well before the L3 merger — so the merger is not part of this patent's ownership chain.

Assignment timeline

There are post-issuance records for this patent: two recorded assignments.

  • 1994-04-27 (executed) / recorded 1994-04-28 — Reel 007332/0733

    • Conveyance: Assignment ("Assignment of Assignors Interest")
    • Assignor: David Lawrence Denslow
    • Assignee: Harris Corporation (Florida)
    • Correspondent: Not retrieved. ⚠️ I could not pull the recorded correspondent field for this reel/frame in this session. Do not confuse this with the prosecution attorney of record on the patent face, which the earlier section listed as Rogers and Killeen — that is a different role (prosecution, not recording).
    • Context: Ordinary inventor-to-employer assignment at filing (employment/obligation), the necessary step to give Harris standing as applicant.
  • 2007-08-23 (executed) / recorded 2007-09-25 — Reel 019864/0864

    • Conveyance: Assignment
    • Assignor: Harris Corporation
    • Assignee: W.D. Burgeon, Limited Liability Company (a Delaware LLC — the assignment record itself recites Delaware)
    • Correspondent: Not retrieved. ⚠️ Same gap as above; this is the single most valuable missing datum for the NPE analysis and should be pulled from Assignment Center directly.
    • Context: Transfer of the patent out of the operating company into an opaque Delaware holding LLC, ~13 years after issuance and ~7 years before expiration. On its face this is a transfer-to-a-holding-entity / monetization-type disposition, but the absence of the correspondent and of any product/address data for W.D. Burgeon means I cannot upgrade this from "transfer out of an operating company" to a confirmed shell-entity finding.

Unrecorded/uncertain third link. Google Patents' Current Assignee field lists "Cufer Asset Ltd. LLC." I found no recorded assignment from W.D. Burgeon to Cufer Asset in the materials available. Per your operating rules I am keeping this literal: the last assignment on the face of the record is to W.D. Burgeon LLC (Reel 019864/0864). The Cufer listing is unverified as to this patent and could be a source error. I flag it because it materially changes the verdict if true (see Signals 2 and the Verdict).

No security agreements, mergers, name changes, licenses, releases, or corrections appear in the assignment chain; the only other legal events are fee payments and a 1997-02-18 certificate of correction.

Timeline diagram

timeline
    title Ownership of US 5548721
    1994 : Filed by Denslow
         : Assigned to Harris Corporation
    1996 : Patent issues as US 5548721
    2007 : Assigned to W.D. Burgeon LLC
    2014 : Patent expires by term

NPE / troll-pattern signals

  1. Shell-entity transfer — unclear (leaning present). Concrete evidence: the patent moved from operating company Harris Corporation to a Delaware LLC, "W.D. Burgeon, L.L.C.," recorded 2007-09-25 at Reel 019864/0864 (effective 2007-08-23). That is a real transfer out of an operating company. However, the classic tells are not established on the evidence I retrieved: the assignee name carries no "IP / Patents / Licensing / Holdings / Ventures" suffix, I found no registered-agent address and no product information for W.D. Burgeon, and it is not shown to be single-member. Per your rule, naming/timing alone is not a finding — so this stays unclear, with the transfer itself being the only hard fact.

  2. Known asserter in the chain — unclear (potentially present). W.D. Burgeon, LLC does not match any public NPE list I can cite (Acacia, Marathon, IV, IPNav, Wi-LAN, Conversant/Mosaid, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). However, the Google Patents current-assignee entry — Cufer Asset Ltd. LLC — does resolve to a known asserter family in 2026 filings: in Intellectual Ventures I LLC v. American Airlines, Inc., E.D. Tex. 4:24-cv-00980, IV itself alleges "Cufer Asset Ltd. LLC is a wholly owned subsidiary of the IV entities," and Cufer Asset is named a defendant in The Hartford's April 2026 D. Del. declaratory-judgment action against multiple IV entities. If the Cufer listing for '721 is accurate, this is a known-asserter-in-the-chain finding. Because no recorded W.D. Burgeon → Cufer assignment was found, I mark it unclear, not present.

  3. Repeat correspondent across the chain — not determinable. ⚠️ I could not retrieve the correspondent of record for either recorded assignment (Reel 007332/0733 or Reel 019864/0864). This is the specific tell you asked me to capture, and it is the gap I most want closed next. (A lead, not a finding: an unrelated Cufer Asset assignment on plainsite — Cubic Wafer, Inc. → Cufer Asset, Assignment 21434/247 — shows an address at "Verex Plaza, 150 East Gilman Street, Madison, WI 53703." That is a different patent and a different recording; I have not connected it to '721 and present it only as a possible correspondent/agent address worth checking against Reel 019864/0864.)

  4. Cascading transfers — not present (on the record). Only one post-issuance assignment is recorded, and the two recorded links are ~13 years apart (1994 → 2007). There is no <24-month chained-LLC sequence in the record. (A W.D. Burgeon → Cufer transfer, if it exists, would add one more hop but still is not a rapid cascade on any date visible to me.)

  5. Pre-litigation transfer — not present. The transfer is dated 2007; the patent expired 2014-04-28, and no infringement suit naming 5,548,721 was surfaced (consistent with the litigation section). No assignment sits within 6 months of a first suit.

  6. Bankruptcy fire-sale — not present. Harris Corporation did not file Chapter 7/11; it merged into L3Harris in 2019. There is no bankruptcy proceeding in this chain.

  7. Privateering — not present / no evidence. I found no SEC 10-K/8-K disclosure, Patent Progress, or EFF coverage tying a Harris→NPE transfer of this patent to a coordinated assertion campaign. Absence of evidence only; not a reached negative.

  8. Defensive aggregator — not present. The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. If the Cufer listing is right, it terminates at an Intellectual Ventures entity — an asserting family, the inverse of a defensive aggregator.

Verdict

NPE — moderate confidence.

The chain is short and mostly documented: Denslow → Harris Corporation (Reel 007332/0733, 1994) and Harris Corporation → W.D. Burgeon, L.L.C. (Reel 019864/0864, recorded 2007-09-25) — i.e., the patent definitively left its operating-company owner and landed in an opaque Delaware LLC with no products or address I could verify. That is one weak signal (shell-entity transfer) plus a second weak signal from the Google-listed current assignee, Cufer Asset Ltd. LLC, which 2026 court filings identify as a wholly owned Intellectual Ventures subsidiary — a known asserter — though I could not find a recorded assignment effecting that transfer. Two weak signals support "moderate," but the verdict would harden to high confidence with the Reel 019864/0864 correspondent (a repeat NPE-side filing attorney) or would collapse to "Insufficient data" if the Cufer listing proves to be a source error, since the recorded chain would then end at the unexamined W.D. Burgeon LLC.

Verify at: USPTO Assignment Center — https://assignmentcenter.uspto.gov/ (search patent number 5548721); legacy interface https://assignment.uspto.gov/patent/index.html. Pull the correspondent fields for 007332/0733 and 019864/0864, and search for any W.D. Burgeon → Cufer Asset recording.


Cross-check against prior sections (no contradictions): the earlier "Patent summary" and "Litigation summary" both flagged the Cufer Asset listing as unverified and the W.D. Burgeon LLC assignment (2007-09-25) as the last recorded link. This section is consistent with both and adds only the assignment-task framing (reel/frame, executed-vs-recorded dates, and the signal analysis). The one item I could not corroborate in this pass is the inventor's "Rochester, NY" residence — carried over from the prior summary, so I have marked it unconfirmed rather than repeating it as fact.

Generated 9/25/2026, 6:46:20 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll verify the patent against USPTO sources and pull details on each cited reference.

Let me verify the remaining cited references.

Scope note and one contradiction flagged up front

Date discrepancy: Your task header says "Current Date: April 26, 2026," but my working date for this session is 2026‑09‑25. That is a minor inconsistency but I'm flagging it because it affects nothing here except date-stamping — none of the art below changed status in between.

Contradiction with the previously generated summary: The prior "Patent summary" section labels the 14 references as "Citations (14)" and separately lists "Cited By (41)." The Google Patents full text I was given lists them under "Patent Citations (14)" with the asterisk convention (" Cited by examiner")*, which is the correct legal significance: all 14 are references the examiner considered during prosecution of 08/234,947 — not third‑party art pulled from elsewhere. That distinction matters for the anticipation analysis below and I build on it rather than repeat it.


1. USPTO record confirmation (literal, number-exact)

Searching the exact string 5548721 returns the correct document; I discarded every numerically-similar hit.

Field Confirmed value
Number US 5,548,721 (Google Patents renders "US5548721A")
Title Method of conducting secure operations on an uncontrolled network
Inventor David L. Denslow (Rochester, NY)
Appl. No. 08/234,947
Filed / Priority 1994-04-28
Granted 1996-08-20
Assignee Harris Corporation (original); W.D. Burgeon, LLC (2007 assignee of record)
Examiner / GAU Albert Decady presiding; Group Art Unit 2413; Class 395/187 (per the USPTO docket record at PlainSite, docket 1igqw035k — "Method Of Conducting Secure Operations On An Uncontrolled Network," Application No. 08234947)
Claims 11 (indep. 1, 3, 11)

Identifier-confusion filters applied (do NOT merge with '721): JP 5548721 B2 (Konami game system); US 9,954,872 (GoSecure/CrowdStrike IPR2025‑00068); WO 2012/177872 (Nielsen); US 10,277,438; US 8,874,768 (which cites the '721 as background, the reverse direction). None is prior art to the '721.


2. Legal standard applied

The '721 has a priority date of 1994‑04‑28, so pre‑AIA 35 U.S.C. §§ 102/103 govern. For each cited reference I distinguish:

  • §102(b) — publication/issue more than one year before 1994‑04‑28 (i.e., on or before 1993‑04‑27).
  • §102(e) — US patent granted on an application filed before the applicant's invention date (the practical route for the late-1992/1993/1994-issuing US patents here).
  • §103 — most of these references are background or secondary art; they do not disclose the invention in a single reference.

Anticipation requires a single reference disclosing every element of a claim, arranged as claimed. The claims require, in substance: (i) a portable card carrying a randomly-selected portion of an authorization record (PIN + workstation-created system key); (ii) a SNAP storing the remainder plus a workstation-unique initialization key usable with the manager but not with peer workstations; (iii) the complete record at the manager; (iv) two-stage validation (workstation + manager); and (v) an operational key returned under that initialization key.


3. The 14 cited references — citation, dates, description, claim relevance

# Full citation Filed Issued §102 date basis Brief description Claims it potentially anticipates under §102
1 US 4,649,233 A — Bass, Matyas & Oseas; IBM — Method for establishing user authentication with composite session keys among cryptographically communicating nodes 1985‑04‑11 1987‑03‑10 §102(b) Each node holds a pre-established cross-domain key; nodes exchange encrypted random numbers, form a parameter from both nodes'/users' identity attributes, and combine with an interim key to produce a session key that is valid for one session and simultaneously authenticates the participants. None. No card, no split record, no manager-issued operational key. §103 art for claim 1's "combine system key + personal identifier into an authorization record" concept.
2 US 4,665,396 A — U.S. Philips Corp. — Validation check for remote digital station 1982‑03‑16 1987‑05‑12 §102(b) Validation/verification of a remote digital station (terminal) before allowing it to operate in the system; challenge-response style station validation. None. Background for the terminal-validation element only; §103. (Description from title; not independently re-verified — tool step limit reached.)
3 US 4,850,017 A — IBM — Controlled use of cryptographic keys via generating station established control values 1987‑05‑29 1989‑07‑18 §102(b) Key-management scheme in which a generating station supplies control values governing how keys may be used (control-vector-style key control and distribution). None. §103 background for key management/SNAP key handling. (Title-level description; not re-verified.)
4 US 4,924,513 A — Digital Equipment Corp. — Apparatus and method for secure transmission of data over an unsecure transmission channel 1987‑09‑25 1990‑05‑08 §102(b) Encrypting/decrypting data for transmission over a channel assumed unsecured, with key exchange between stations. None. §103 background for the "encrypt over the uncontrolled medium" limitation of claim 1. (Title-level; not re-verified.)
5 US 4,965,568 A — Atalla, Martin M. — Multilevel security apparatus and method with personal key (EP 0 385 400; CA 2010345) 1989‑03‑01 1990‑10‑23 §102(b) Two-level enrollment/authorization: (a) enrollment — a personal key code is generated and encoded onto the customer's card, plus an identifying code; the customer's PIN is combined with the personal key by an irreversible algorithm to make a "PIN transmission number," which is further combined with an institutional key to make a "PIN verification number" stored in the institution's records; (b) transaction — card is read, PIN entered, a candidate number is generated at the terminal and transmitted over a network to the remote processing system, which regenerates a candidate verification number and compares it to the stored one to authorize the transaction. The strongest card+record-split-flavored reference among the 14 — potentially relevant to claim 3 and claim 5 (identifier-based record), and §103 for claims 1 and 4. But it does not anticipate: the card carries a personal key code, not "a randomly selected portion" whose remainder is stored at the first workstation; there is no SNAP-resident remainder, no workstation-unique manager-only initialization key, and no operational-key return step.
6 US 5,103,478 A — IBM — Secure management of keys using control vectors with multi-path checking 1989‑04‑27 1992‑04‑07 §102(b) Key management using control vectors, including multi-path checking to validate key use. None. §103 background only. (Title-level; not re-verified.)
7 US 5,196,840 A — Stevens & Leith; IBM — Secure communications system for remotely located computers (EP 0 484 686) 1990‑11‑05 1993‑03‑23 §102(b) Host generates a random number, enciphers it under the user's PIN, sends it to the remote PC; the PC deciphers under the PIN to obtain a session key, re-enciphers under the PIN, returns it, and the host deciphers and compares to validate the user; the random number then serves as the session ciphering key. Explicitly: no cipher key is stored at the PC, so "the user can communicate from any personal computer." User ID is sent under a one-way function. Most dangerous §103 reference for claim 1 and for the claim‑2 "roaming" concept ("communicate from any personal computer"). No §102 anticipation: there is no portable recording device, no split authorization record, and no card at all.
8 US 5,241,594 A — Hughes Aircraft Co. — One-time logon means and methods for distributed computing systems 1992‑06‑02 1993‑08‑31 §102(e) (issued <1 yr pre‑priority) Single ("one-time") logon across a distributed computing system so one authentication serves multiple nodes. None directly. §103 relevance to the multi-workstation/roaming subject matter of claims 2, 9 and 11. (Title-level; not re-verified.)
9 US 5,253,295 A — Bull S.A. — Process for authentication, by an outside medium, of a portable object connected to that medium via a transmission line and system for carrying out the process 1991‑12‑19 1993‑10‑12 §102(e) Authentication of a portable object (card) by an outside medium to which the card is connected over a transmission line — i.e., the card is authenticated by a remote/server device rather than trusting the local terminal. Conceptually closest to the "SNAP/manager authenticates the card" relationship; §103 for claim 1 and claim 3, and possibly a §102 argument against the broadest reading of claim 3. Does not anticipate — no split of a record between card and workstation, no manager-stored complete record, no operational-key distribution. (Title-level; not re-verified.)
10 US 5,256,863 A — Comark Technologies, Inc. — In-store universal control system 1991‑11‑05 1993‑10‑26 §102(e) Retail/financial in-store controller system (POS/terminal control, card/PIN-driven). None. Generic background for card/PIN terminals on a shared in-store network; §103 only if paired with a network-security reference. (Title-level; not re-verified.)
11 US 5,272,754 A — Secure Computing Corp. — Secure computer interface 1991‑03‑28 1993‑12‑21 §102(e) User nodes and computer nodes on a standard unsecured medium, each through a terminator (user-side / computer-side). To gain access a user must insert a token containing his name and access-authorization level into the user-side terminator and enter a password; a secure computer node verifies the user and restricts activity to the token's authorization level. Traffic is end-to-end encrypted (one-time pad) in Trusted Path mode; a "countersign" guards against reproduced tokens. Second-strongest §103 reference; best §102 candidate against claim 3. Token + password at a terminator + remote verification + encryption over an unsecured medium maps onto elements of claims 1 and 3. Still not anticipatory: the token carries name/authorization level rather than a randomly selected portion of an authorization record; there is no remainder stored at the local terminator, no manager-stored complete record, and no manager-supplied operational key under a workstation-unique initialization key.
12 US 5,329,623 A — The Trustees of the University of Pennsylvania — Apparatus for providing cryptographic support in a network 1992‑06‑17 1994‑07‑12 §102(e) A hardware cryptographic-support module attached to network nodes to provide encryption services within the network. None. §103 background for the "crypto module inside/beside the workstation" element of claim 1. (Title-level; not re-verified.)
13 US 5,363,707 A — Hewlett-Packard Co. — Headspace sampling system 1992‑05‑01 1994‑11‑15 §102(e) (if applicable) Analytical-chemistry instrumentation — headspace sampling for gas chromatography. None. Not prior art to any claim. This is a spurious citation in the search/face record; it has zero bearing on the authentication, key-management or network-security subject matter of claims 1–11. I flag it rather than silently dropping it, per your instruction to treat identifiers literally.
14 US 5,371,797 A — BellSouth Corp. — Secure electronic funds transfer from telephone or unsecured terminal 1993‑01‑19 1994‑12‑06 §102(e) Conducting secure financial transactions from an ordinary telephone or otherwise unsecured terminal, using encryption/PIN-based authorization. None as anticipation. §103 background for the core premise ("secure operation initiated from a terminal you do not control") of claims 1 and 3. (Title-level; not re-verified.)

4. Bottom line on anticipation

No single one of the 14 cited references anticipates any of claims 1–11 as issued — and that is unsurprising, because all 14 were considered by the examiner and the claims were allowed over them. The two-stage split-record architecture (card portion / SNAP remainder / manager complete copy) with a manager-only workstation initialization key and an operational-key return is not disclosed in any one of them.

The realistic risk picture, if this patent were ever challenged on this art:

  1. Claim 3 is the most exposed claim (it is the broadest independent claim — it drops the SNAP, the system key, the initialization key and the operational-key limitations and recites only: portable device with a portion of an authorization record including a personal identifier + first workstation storing the remainder + manager storing the whole + validation by combining portions). The best §102 candidates against it are US 4,965,568 (Atalla) and US 5,272,754 (Secure Computing) — but each fails the "remainder stored at the workstation / complete record at the manager" split. Expect §103 instead.
  2. Claim 1 is best attacked under §103 by combining US 5,196,840 (PIN-encrypted random number → session key, user validated by the host, "communicate from any personal computer") with US 5,253,295 (portable object authenticated by an outside medium over a transmission line) and/or US 5,272,754 (token + password verified by a remote secure node over an unsecured medium).
  3. Claims 2, 9 and 11 (roaming / multi-workstation, per-workstation keys) invite US 5,241,594 (one-time logon in distributed systems) and the "any personal computer" teaching of US 5,196,840.
  4. US 5,363,707 is irrelevant; do not cite it as prior art.
  5. The remaining six (§102(b) key-management/encryption references 1–4, 6, and 10, 12, 14) are background at most and support §103 motivations (why one would encrypt on an unsecured LAN, why key control matters, why a hardware crypto module is conventional), not anticipation.

5. Residual uncertainty and caveats (stated rather than papered over)

  • Verification level: I directly retrieved and read the disclosure of US 4,649,233, US 4,965,568, US 5,196,840 and US 5,272,754. My tool-step budget ran out before I could pull the full texts of US 4,665,396, US 4,850,017, US 4,924,513, US 5,103,478, US 5,241,594, US 5,253,295, US 5,256,863, US 5,329,623 and US 5,371,797. For these nine, the citations, dates and titles come from the authoritative patent face text, while the short descriptions rest on the titles plus general art knowledge — treat those descriptions as medium confidence and the anticipation assessments as preliminary.
  • Nothing was found that anticipates. I found no reference (among the 14 or in the "Cited By" trail) that discloses all elements of any independent claim in one document.
  • Direction of citations: US 5,548,721 is later cited by third parties (e.g., Round Rock Research/Micron mixed-enclave family via US 8,874,768, and the EP 1 404 083 search report for Harris's own US 7,761,904). Those are the '721 acting as prior art — they are not prior art against the '721 and should not be listed as such.
  • Assignee mismatch (carried forward, still unresolved): Google Patents' Current Assignee field says Cufer Asset Ltd LLC, but the last assignment of record in the documents I saw is Harris → W.D. Burgeon, LLC (Reel/Frame 019864/0864). Per the operating rules I did not auto-correct either value; treat the Cufer listing as unverified.
  • Litigation: consistent with the earlier section, I found no district-court or PTAB proceeding asserting or challenging US 5,548,721. This remains "not found," not "confirmed none."
  • Status: Expired – Lifetime (anticipated expiration 2014‑04‑28), with a certificate of correction recorded 1997‑02‑18. Any §102 analysis here is retrospective/hypothetical rather than enforcement-driven.

Generated 9/25/2026, 6:46:33 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground this analysis by pulling abstracts/content for the key prior-art references cited on the face of US 5,548,721, so the element mapping is accurate rather than title-based.

Obviousness Analysis — U.S. Patent No. 5,548,721 under 35 U.S.C. § 103

Built on the prior summary and litigation sections. The claim text, bibliographic data, and the identity of the fourteen examiner-cited references come from those sections and the authoritative full text; I do not repeat them.

Note on a date contradiction: the task header states "Current Date: April 26, 2026," while the operating banner says 2026‑09‑25 and the earlier sections reference a 2026‑04‑09 filing and a "July 2026" CAFC list. Flagging it, not resolving it; nothing in the analysis turns on it.


1. Framework and level of ordinary skill

Under Graham v. John Deere and KSR v. Teleflex, obviousness asks whether the claimed subject matter as a whole would have been obvious to a person of ordinary skill at the 1994‑04‑28 priority date. As of that date the field already contained a mature body of key‑distribution art (IBM's Common Cryptographic Architecture line, ANSI X9.17, the Matyas/Meyer literature), token‑based access control, and end‑to‑end encryption over unsecured media. I would set the PHOSITA as a cryptographic systems engineer with a bachelor's degree in electrical engineering or computer science and roughly 2–4 years' experience in key management and secure terminal design — consistent with the credential profile of the named inventor (who assigned to Harris, a COMSEC vendor).

Scope of the prior art to consider. Only the fourteen references on the face of the patent are unambiguously § 102(b)/§ 103 prior art. Critically, the 41 "Cited By" entries are not prior art: their earliest priority dates (e.g., Fujitsu '143 at 1994‑08‑01) post‑date the '721 priority date. They are admissible only as evidence of what the field looked like, not as § 103 references. Same for the "Similar Documents" list, except where a listed document predates 1994 (e.g., U.S. 4,799,258, "Apparatus and methods for granting access to computers," 1989) — but that item is not in the IDS.


2. What the cited references actually teach

Ref Title / teaching (verified from text where retrieved) Role in a § 103 theory
US 4,965,568 (Atalla) Two‑stage scheme: enrollment issues a card encoded with a personal key code and a PIN; PIN + identifying code + personal key code are combined by an irreversible algorithm into a PIN transmission number, further combined into a PIN verification number stored in the institution's records. At transaction, the system senses the card, the user enters the PIN, a candidate number is generated at the terminal and transmitted over a computer network to a remote processing center that compares against stored records. Primary reference for personal identifier + portable card + combination‑into‑record + central storage + remote verification.
US 5,272,754 (Secure Computing) A user‑side terminator and computer‑side terminator form a "secure computer interface" to an unsecured medium. To gain access, the user "must insert a token containing his name and access authorization level into the user‑side terminator … and then enter a password." End‑to‑end encryption over unsecured media; a countersign limits access by an agent using a reproduced token. Primary reference for the SNAP (card reader + per‑workstation secure interface on an unsecured network).
US 4,850,017 (IBM, Matyas/Meyer) A generating station generates and distributes cryptographic keys to designated using stations. "Each using station has a unique secret transport key shared with the generating station," and keys are generated so they "can be recovered or regenerated only by the designated using station possessing the correct secret transport key." The transport key "ensures that keys prepared for using stations i and j cannot be recovered or regenerated at some other using station k." Also uses control values to govern who may use a key and how. The single most damaging reference: it discloses a per‑station unique transport key used only with the central generator (the claimed "initialization key … with the network manager but not with other secure workstations") and central distribution of a usable operational key.
US 4,649,233 (IBM, Bass/Matyas/Oseas) Establishes a session key commutatively between nodes and concurrently authenticates node/user identities; the key is built from "combining … a random number and authentication indicia"; a cross‑domain key encrypts the random numbers exchanged; key is valid only for one session; new key each session defeats playback. Teaches combining key material with authentication indicia to yield a per‑session record; supports the "randomly selected"/random‑number aspects and the encrypted key exchange.
US 5,196,840 (IBM, Stevens) Remote‑user authorization and session‑key establishment where no key is stored at the remote PC and the PIN is never sent in the clear; the host generates a random number, ciphers it under the PIN, and the derived value becomes the session key. Explicitly frames its advance over '233 as suiting "a remote user personal computer system" and enabling the user "to communicate from any personal computer." Direct support for the remote/roaming‑workstation feature of claim 2 and its motivation.
US 5,253,295 (Bull) Authentication, by an outside medium, of a portable object connected via a transmission line (title‑level only; full text not retrieved). Portable‑object authentication à la the CIK card.
US 5,371,797 (BellSouth) Secure electronic funds transfer from a telephone or unsecured terminal (title‑level). Secure operations initiated from an unsecure point.
US 4,665,396 (Philips) Validation check for a remote digital station (title‑level). Remote‑station validation.
US 5,241,594 (Hughes) One‑time logon for distributed computing systems (title‑level). Single logon across a distributed network.
US 5,329,623 (Penn) Apparatus for providing cryptographic support in a network (title‑level). Network crypto module (the "crypto module 26").
US 4,924,513 (DEC) Secure transmission of data over an unsecure channel (title‑level). The uncontrolled‑network premise.
US 5,103,478 (IBM) Secure key management using control vectors with multi‑path checking (title‑level). Key‑usage control.
US 5,256,863 / US 5,363,707 In‑store control system; headspace sampling. Not pertinent; no bearing.

3. Grounds of rejection

Ground 1 — Claims 1, 3, 4, 6, 7, 8 obvious over Atalla '568 in view of Secure Computing '754, further in view of IBM '017

Claim 1 element mapping:

Claim 1 limitation Where taught
Personal identifier for the user Atalla '568 (PIN selected by/issued to customer); '754 ("enter a password")
CIK card bearing part of an authorization record = personal identifier + system key Atalla '568 (card encoded with personal key code; PIN + personal key code combined by algorithm to produce the transmission/verification number)
Authorization record built with a random component '233 (session key formed from secret random numbers combined with authentication indicia)
Per‑workstation secure port with card reader (SNAP) '754 (user‑side terminator that reads the inserted token, sitting between the terminal and the unsecured medium)
Storage of the portion not on the card Atalla '568 (verification number stored in institution records); '017 (using station stores encrypted keys / its secret transport key in its cryptographic facility)
Workstation‑unique initialization key usable with the manager but not other workstations '017 ("each using station has a unique secret transport key shared with the generating station"; keys for stations i,j "cannot be recovered or regenerated at some other using station k")
Manager stores the complete record/system key Atalla '568 (remote center holds the verification number); '017 (generating station originates and holds keys); '840 (host holds user ID/PIN)
Access request via personal identifier + card read Atalla '568; '754; '840
SNAP evaluates identity, then sends record/key to manager encrypted under the workstation initialization key '754 (the secure node verifies the user before activity); '017 (keys distributed encrypted under the station's transport key); '233 ('cross‑domain key' encryption)
Manager returns an operational key under the initialization key '017 (generating station distributes an operational/data key recoverable only by the designated station); '840/'233 (session key returned to the terminal)

Claim 3 (broad split‑record framing) is met essentially by Atalla '568 alone once one accepts the card/store division of the record; claim 4 (system key combined with the identifier) is '233 + Atalla; claims 6–8 (encryption of the stored record; transmission under a workstation initialization key; return of an operational key) map to '754 and '017 as above.

Ground 2 — Claim 2 (remote‑workstation enrollment) obvious over Ground 1 further in view of IBM '840 (optionally with BellSouth '797 and Philips '396)

'840 supplies the precise motivation and mechanism for the roaming case: a remote user with no stored key authenticates to a central host and receives a session key, expressly so the user can "communicate from any personal computer." BellSouth '797 (secure transfer from an unsecured terminal) and Philips '396 (validation of a remote station) reinforce both the problem and the solution. The claim's "recognize not authorized here → assign second system key → send to manager → receive operational key → re‑split the record" is the routine application of '017's per‑station transport‑key distribution to a second station, plus '840's remote‑access flow.

Ground 3 — Claims 5, 11 obvious over Atalla '568 in view of '233/'840

Claim 5 (a unique biometric/one‑and‑only identifier is the record) reads on using the personal identifier itself as the authentication record, with '233/'840 teaching that the identifier is "folded" into the key material. Claim 11 (a different key per workstation, each split on the same card) is the straightforward extension of '017 (per‑station keys) and the patent's own Example 3, and is a predictable aggregation of known elements.


4. Motivation to combine

A PHOSITA would have been motivated, with a reasonable expectation of success, to combine these references:

  1. Same field, same problem. All of '568, '754, '017, '233, and '840 address authentication and key distribution for terminals communicating over unsecured or uncontrolled channels — the exact problem the '721 specification recites ("when secure information is communicated on the network, it can be heard by anyone").
  2. '754 + '017 is a natural pairing. '754 provides the per‑node secure interface on an unsecured medium; '017 provides the central key‑generation/distribution scheme that a network of such nodes requires. '017's explicit "cannot be recovered at some other using station" feature is precisely the claim's manager‑only initialization key — an artisan seeking to keep a shared operational key out of peer workstations would adopt it.
  3. '840 supplies the expressed desire to roam. '840 criticizes '233 as unsuited to remote PCs and solves it, stating the goal of letting a user "communicate from any personal computer." That is the motivation for claim 2's remote‑workstation procedure.
  4. The examiner already treated these as pertinent. All fourteen references sit in the '721 IDS; several are the art that the very same IBM cryptographic family itself cited (e.g., '017 discussing Ehrsam '253 and Matyas '738; '840 discussing '233).
  5. KSR. Combining a known token/reader access front end ('754, Atalla) with known per‑station transport‑key distribution ('017) yields nothing more than the predictable sum of the parts; the "operational key … enables secure operations" is '017's and '840's stated result. Design incentive alone (secure roaming) would have driven the combination.

5. Rebuttals a patentee would raise — and how strong they are

(This section matters because the earlier sections established no PTAB/IPR ever tested these claims; the validity question is therefore open, not adjudicated.)

  • "Random splitting of the record across card and workstation is not taught." This is the patentee's best argument. Atalla '568 stores a complete verification number at the institution and a different personal key code on the card; '017 stores encrypted keys per station. None of the cited references expressly teaches randomly dividing a single authorization record into two complementary halves that must be recombined (a secret‑sharing concept, cf. Shamir). If the "randomly selected portion" language is given weight as an ordered‑combination limitation, this feature is the strongest non‑obviousness hook.
  • "The initialization key must not enable peer workstations." Weak as a distinction: '017 states this property almost verbatim ("keys prepared for using stations i and j cannot be recovered … at using station k").
  • "The manager stores the complete record and system key." Weak: Atalla's institutional records and '017's generating station both hold the full material.
  • Secondary considerations. None is documented in the record I have. No evidence of commercial success, long‑felt need, or unexpected results attributable to the "random split" appears in the patent or in the searches; without such evidence this prong adds little.

Bottom line: Claims 1, 3, 4, 6, 7, and 8 would plausibly be held obvious over Atalla '568 + Secure Computing '754 + IBM '017 (with '233 for the random/combination aspects); claim 2 would plausibly be held obvious further in view of IBM '840 (with '797 and '396 as corroboration); claims 5 and 11 are predictable extensions. The only limitation with a genuine non‑obviousness argument is the random two‑part split of the authorization record; if the patentee can show the cited art does not fairly suggest random division (as opposed to mere storage in two places), that limitation could carry the claims.


6. Confidence and caveats

  • High confidence on the teachings of US 4,965,568, US 5,272,754, US 4,850,017, US 4,649,233, and US 5,196,840 — I retrieved their actual text/abstracts and quoted them.
  • Title‑level only (could not retrieve full text before exhausting search steps): US 5,253,295, US 4,665,396, US 5,241,594, US 5,329,623, US 5,371,797, US 4,924,513, US 5,103,478, US 5,256,863, US 5,363,707. My treatment of these is necessarily conservative; a full‑text review could only strengthen, not weaken, the grounds.
  • No PTAB or court has ever construed these claims (per the earlier sections), so all claim‑element mappings above are my own § 103 readings, not an adjudicated construction.
  • "Cited By" references are not prior art to the '721 patent (earliest priority 1994‑08‑01, after 1994‑04‑28); I excluded them.
  • I did not locate any later art (e.g., U.S. 4,916,738, Chandra/IBM "Remote Access Terminal Security," which text I did see and which recites transporting "different portions of the key over independent paths and then combining them at the destination") on the '721 face. That teaching bears directly on the "random split" limitation but is not an IDS reference and would have to be qualified as analogous art if used.

Generated 9/25/2026, 6:46:45 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Log in to generate
Not generated yet. Log in to request this analysis.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Log in to generate
Not generated yet. Log in to request this analysis.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →