Invalidity dossier

US 5577209

Apparatus and method for providing multi-level security for communication among computers and terminals on a network

Current assignee: Round Rock Research LLC

Added 9/24/2026, 10:39:43 AM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll run the requested searches now.

Let me verify the litigation/docket angle with a couple more targeted searches.

US Patent 5,577,209 — Summary

Searches run: I queried for "USPTO patent 5577209," "CAFC 2026 docket patent 5577209," "5577209" Court of Appeals for the Federal Circuit 2026, and Round Rock/ITT variants. I did not have direct access to the USPTO Patent Center/Public PAIR backend or the CAFC docket system; results came from Google Patents, Justia, patent-family annexes, and litigation aggregators. I held to the literal number 5,577,209 and excluded near-neighbors.

Identifiers (literal transcription)

  • Patent number: US 5,577,209 A (note: several search results render it as "5,577,209 A"; the "5577209" string also appears as a non-asserted reference in later patents — not to be confused with 5,255,209 in the SanDisk/Round Rock disputes)
  • Title: "Apparatus and method for providing multi-level security for communication among computers and terminals on a network"
  • Application number: 08/270,398; filed 1994-07-05
  • Continuation of: Ser. No. 07/728,633, filed 1991-07-11 (abandoned) → Priority date: 1991-07-11
  • Issue date: 1996-11-19
  • Inventors: John M. Boyle; Eric S. Maiwald; David W. Snow
  • Original assignee: ITT Corp / ITT Industries, Inc. → assigned to MICRON TECHNOLOGY, INC. (2000-07-20) → assigned to ROUND ROCK RESEARCH, LLC (2010-01-04). Google Patents lists current assignee as Round Rock Research LLC.
  • Status (per Google Patents): Expired – Lifetime; "anticipated expiration" 2013-11-19
  • Related family: US 5,940,591 A ("Apparatus and method for providing network security"), filed 1996-10-03 as a continuation of 08/720,906
  • Classifications: H04L63/105 (Multiple levels of security), H04L63/0823, H04L63/0428, H04L63/0442, G06F21/62, etc.

Abstract (as published)

A multi-level security apparatus and method for a network employs a secure network interface unit (SNIU) coupled between each host or user computer unit and a network, and a security management (SM) architecture, including a security manager coupled to the network, for controlling the operation and configuration of the SNIUs. Each SNIU operates at a session level of interconnection — occurring when a user is identified and a communication session is to commence. With an SNIU at each computer unit, a global security perimeter is provided. In a preferred embodiment the SNIU performs a defined session level protocol including user interface, session manager, dialog manager, association manager, data sealer, and network interface. The SM architecture ensures user accountability, configuration management, security administration, and validation/key management. SM functions are distributed over three platforms: SNIU security manager (SSM), area security manager (ASM), and network security manager (NSM).

Independent Claims — Plain-Language Overview

There are two independent claims: claim 1 (apparatus) and claim 12 (method). The remaining claims (2–11, 13–20) depend from them.

Claim 1 — Apparatus
A multi-level network security apparatus for a computer network with at least one "user" (a host computer or at least a second network), comprising:

  1. A secure network interface unit ("SINU" as the claim itself spells it) coupled between the user and the network and operating at a "user layer communications protocol." The unit comprises four elements:
    • a user interface that translates data received from the user into the SNIU's internal format;
    • a session manager that (a) identifies a user requesting network access at the session level, (b) verifies the identified user is authorized for access, (c) manages the functions of permitted communications sessions, and (d) maintains a session audit;
    • a dialogue manager that controls the data path established in the SNIU; and
    • an association manager that establishes and controls the user session at a session layer of interconnection between user and network through the SNIU, once the user is verified;
  2. The "global security perimeter" limitation — the SNIU creates a global security perimeter for end-to-end communications such that the network may be individually secure or non-secure without compromising security within the perimeter; and
  3. A security management architecture including a security manager (SM) connected to the SNIU, which causes the SNIU to be operated and configured to protect communications through it. The SM is capable of implementing a security policy selected from a Marshamlled-ese group consisting of: discretionary access control, mandatory access control, object reuse, labeling, denial of service detection, data type integrity, cascading control, and covert channel use detection — and the SM further provides inter-network administration.

Note on literal wording: the claim text as published uses the acronym "SINU" (not "SNIU") in claim 1; the specification consistently uses "SNIU." Per your instruction I have not auto-corrected it.

Claim 12 — Method
The method counterpart to claim 1: coupling an SNIU between the user (host computer or at least a second computer network) and the network, where the SNIU performs security-management functions —

  • identifying a user and providing a user interface that translates user data into SNIU format;
  • verifying whether the identified user is authorized;
  • managing permitted communications sessions and maintaining a session audit;
  • controlling a data path established in the SNIU;
  • establishing a user session at a session layer of interconnection if the user is verified;
  • thereby creating a global security perimeter (network may be secure or non-secure); and
  • providing a security management architecture with an SM controlling SNIU operation/configuration, capable of implementing a security policy from the same enumerated group, and further providing inter-network administration.

Dependent claims (brief)

  • 2 / 13: SNIU performs a defined trusted session layer protocol (TSP).
  • 3 / 14: SM architecture supports the security policy across at least two network jurisdictions.
  • 4: SNIUs prevent covert information flow within the global security perimeter.
  • 5 / 15: a data sealer validates/protects transmitted data.
  • 6: a network interface.
  • 7 / 16: SM performs network security functions including security administration of one or more SNIUs.
  • 8 / 17: SM functions distributed over three platforms (SSM, ASM, NSM).
  • 9 / 18: SSM functions (data/command exchange, initialization, configuration control, access control, sealer key management, audit/alarms).
  • 10 / 19: ASM manages a group of SNIUs in a defined area.
  • 11 / 20: NSM manages the ASMs for the network as a whole.

CAFC 2026 docket check — no hits

No 2026 Court of Appeals for the Federal Circuit docket entry referencing 5,577,209 was returned. Searches returned Round Rock Research litigations (e.g., Round Rock Research LLC v. SanDisk Corp., D. Del. 1:12-cv-00569, terminated 2015; SanDisk v. Round Rock, N.D. Cal.), but those asserted different patents (5,615,159; 6,728,798; 6,948,041; 7,336,531; 8,060,719; and 5,255,209). Per your rule, I did not treat 5,255,209 or any similar number as 5,577,209. The only CAFC-adjacent document surfaced (USRE48433) merely lists unrelated prior art.

Uncertainty / caveats (explicit)

  • No authoritative USPTO Patent Center or CAFC docket confirmation was obtainable with the tools available here. The legal status ("Expired – Lifetime," anticipated expiration 2013-11-19) and reassignment chain come from Google Patents, which itself disclaims making legal conclusions.
  • I found no evidence of any 2026 Federal Circuit activity for this number; absence of results is not proof of absence, since I could not query the court's docket system directly.
  • The patent issued 1996-11-19 and, on the recorded dates, its term has expired — so it is unlikely to be the subject of current enforcement, but I cannot state that as an authoritative legal conclusion.
  • Claim-terminology quirks (the "SINU" spelling and the phrase "user layer communications protocol") are reported exactly as they appear in the granted text rather than normalized.

Generated 9/30/2026, 5:34:21 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 5577209. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US patent 5577209. Let me run several targeted searches.

Initial broad searches returned mostly noise. Let me target the known assignees (Round Rock Research, Micron) and litigation databases directly.

Let me run more targeted searches on litigation-specific databases and the patent's post-issuance history.

Summary of Findings

I did not find any litigation specifically asserting U.S. Patent No. 5,577,209 in the sources I was able to search (Google Patents, Justia Dockets/Case Law, CourtListener, Unified Patents-adjacent PTAB filings, and general web searches for the patent number and its inventors). I am flagging this as a negative finding with explicit caveats below — I reached a tool-usage limit during research, so this is not the equivalent of a clean PACER or Docket Navigator check.

I want to be precise and not overstate: no case is reported here for '209; I am not supplying any case numbers, parties, or outcomes, because I could not verify any.


Why I cannot rule litigation out entirely

The patent's ownership history (per the Google Patents record at https://patents.google.com/patent/[US5577209](/patent/US5577209)/en) makes it a plausible assertion candidate:

Event Date Party
Priority / original app (07/728,633) 1991-07-11 ITT Corp
This application (08/270,398), continuation filed 1994-07-05 ITT Corp
Granted as US 5,577,209 1996-11-19 —
Assignment to Micron Technology 2000-07-20 from ITT Industries, Inc.
Assignment to Round Rock Research, LLC 2010-01-04 from Micron Technology
Anticipated expiration 2013-11-19 —

Round Rock Research is a well-documented non-practicing entity that acquired Micron's portfolio and engaged in a large assertion campaign around 2011–2015. My searches surfaced numerous Round Rock cases — but in every one I could examine, the patents asserted were other numbers, e.g.:

None of those list 5,577,209.

⚠️ Do-not-confuse warning (per your strict-ID instruction)

Several search hits contain the superficially similar number 6,255,209 ('209), which appears in the SanDisk v. Round Rock dismissal papers (Justia). That is a different patent (a Round Rock memory/flash-related patent), not U.S. 5,577,209. I am not substituting or equating them.

Similarly, the ITT-origin security patents that appear in the '209 "Cited By" list — 5,832,228 ("System and method for providing multi-level security...") and 5,872,847 ("Using trusted associations to establish trust in a computer network"), both ITT Industries — are separate patents, not 5,577,209, and any litigation over them does not count as litigation over '209.

Related family member

US 5,940,591 ("Apparatus and method for providing network security") issued 1999-08-17 from continuation 08/720,906 — a child of the same 1991 priority chain (https://patents.google.com/patent/[US5940591A](/patent/US5940591A)/en). If there is any enforcement activity in this family, it would be worth checking under '591 as well as '209, but again I found no litigation citing either.


Practical reason litigation is unlikely (analysis, not a finding of fact)

The patent expired 2013-11-19 (20-year term from the 1991-07-11 priority date). Any infringement suit would have had to be filed on or before that date, and Round Rock's known assertion wave targeting its Micron portfolio did not, in the record I could see, include '209. Combined with the absence of any hit, this suggests — but does not prove — that '209 was never asserted.


Recommended verification steps (to confirm the negative)

Because I could not complete a full docket sweep, treat the above as preliminary. To confirm conclusively, run these directly:

  1. PACER / CourtListener RECAP (free): https://www.courtlistener.com — search the patent number in docket text.
  2. Unified Patents Litigation Portal (the site you named): https://portal.unifiedpatents.com/litigation/caselist — filter by patent number.
  3. RPX / Docket Navigator (subscription) — canonical NPE assertion tracking.
  4. USPTO Patent Assignment Search — to confirm any reassignments or security interests that might hint at licensing/enforcement: https://assignment.uspto.gov
  5. PTAB (P-TACTS) — check for any IPR/PGR/CBM naming '209 or '591 as the challenged patent (post-grant proceedings are not "litigation" per se, but often accompany it).

Bottom line: On the evidence available to me, there is no known reported litigation involving U.S. Patent 5,577,209. I could not confirm any plaintiff, defendant, jurisdiction, case number, filing date, or outcome, and I have deliberately not fabricated any. If you need a definitive answer, the PACER/CourtListener and Unified Patents checks above are the authoritative next step — and if a hit appears there that contradicts this, those docket records should be treated as controlling.

Generated 9/30/2026, 5:34:28 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

PTAB / AIA Trial Proceedings — US 5,577,209

Proceedings overview

Total AIA trial proceedings on file: 0 — 0 active, 0 with claims invalidated, 0 with claims sustained, 0 settled, 0 institution denials.

The USPTO Open Data Portal record supplied in this analysis returns no AIA trial proceedings for US 5,577,209 (App. 08/270,398; priority 1991-07-11; issued 1996-11-19). The supporting web searches I ran — IPR PTAB "5,577,209" Round Rock Research; "5577209" inter partes review petition (zero results); "5,577,209" patent litigation Round Rock asserted; PTAB IPR "Round Rock Research" "5,577,209" petition instituted (zero results); Unified Patents "5,577,209" — surfaced no petition, institution decision, final written decision, or appeal referencing this number under any proceeding format (IPR / PGR / CBM).

Bottom line for a defendant: the patent was never stress-tested at the PTAB at all, because it never needed to be. US 5,577,209 is a pre-AIA patent whose term expired on 2013-11-19 ("Expired – Lifetime" per Google Patents, which disclaims any legal conclusion). There is no proceeding to handicap against you, but there is also no live patent to defend against. The defensive posture is not "hardened patent" vs. "dead claims" — it is "unasserted and expired." Any demand letter issued in 2026 citing 5,577,209 alone is chasing a patent whose enforceable term, and whose 35 U.S.C. § 286 six-year damages look-back window, have both run out. (Do not confuse this with 5,255,209 or 5,615,159 in the Round Rock v. SanDisk line — different numbers, different patents.)


Per-proceeding detail

None to report

There are no proceeding numbers to enumerate. I am deliberately not constructing placeholder numbers, and I am not importing the R2 Solutions, Dolby/Unified, Samsung, or Parity Networks IPRs I encountered in search — none of those involves 5,577,209.

The only substantive document hit referencing this patent in a contested context was not a PTAB filing at all: it is US 5,699,513 (Feigen et al., Motorola, filed 1995-03-31), which lists "5,577,209 11/1996 Boyle et al. 395/200.06" in its References Cited block — i.e., 5,577,209 being cited as prior art against someone else, not being challenged. Source: Docket Alarm — IPR2020-00017, Ex. 1010. That exhibit sits in a different proceeding (Parity Networks), in which 5,577,209 is merely a printed citation.

Contradiction check against the previously generated sections: none. The prior summary separately found no 2026 CAFC docket entry for 5,577,209 and no assertion of it in the Round Rock campaigns. The absence of PTAB activity is consistent with that: a patent that was never asserted is a patent nobody petitions against.


Strategic summary

Claim status — all claims untested, all claims expired. Because no AIA trial was ever instituted, all 20 claims stand exactly as granted, unchallenged by the Board: independent claims 1 (apparatus) and 12 (method), and dependents 2–11 and 13–20. There is no FWD, so I cannot and do not say any claim was canceled, narrowed, or sustained. The practical narrowing of this patent is temporal, not adjudicative: with the term expiring 2013-11-19, the § 286 damages window has closed, so "claim 1 is dead" here is a function of expiry, not of a panel's holding. Note also that the claim text itself recites a "SINU" in claim 1 while the specification consistently uses "SNIU" — per the prior section I have not normalized that, and no Board panel has ever construed it.

Estoppel landscape — empty, in both directions. No FWD issued, so no petitioner is burdened by 35 U.S.C. § 315(e)(2); equally, no petitioner obtained a cancellation that a current defendant could free-ride on. There is no § 315(b) one-year-bar clock running, because that clock starts on service of a complaint asserting the patent, and I found no such complaint. If a defendant does receive an assertion of 5,577,209, every art-based ground is formally "available" — but the more efficient response is a term/damages analysis and potentially § 101/§ 112 cleanup, since there is nothing to enjoin and no past-damages tail within the look-back.

Pattern signals — none on this number. No repeat petitioner, no serial IPR filer, no defensive aggregator (Unified or otherwise) appears anywhere in the record for 5,577,209. That is itself informative: it is a heavily cited reference, not a heavily asserted asset. It has 250 "Cited By" entries and sits in the core security classification art (H04L63/105, H04L63/0823, G06F21/62), which is why it keeps showing up in other people's IDS blocks and IPR exhibits rather than in its own proceedings. The family around it — US 5,940,591 (continuation, 1996-10-03, "Apparatus and method for providing network security," issued 1999-08-17), plus the ITT-lineage cousins 5,832,228 and 5,872,847 (both ITT Industries, 1998) and 6,212,636 (ITT Manufacturing Enterprises, 2001) — are separate patent numbers and each requires its own PTAB check; nothing I found transfers across.


Recommended next steps

  1. State it plainly: there is no PTAB activity on 5,577,209. The absence is the signal — well-asserted patents eventually attract IPRs, and this one never was and never did. Treat the "0 proceedings" result as corroborating the expiry story rather than as a gap to be filled.
  2. If you are a defendant and no live assertion exists, the demand-letter posture is: the patent expired 2013-11-19, and the § 286 six-year damages look-back has run. There is no FWD to link because none exists — as required by the constraints of this task, I will not fabricate one.
  3. If a demand letter cites claims of this patent, ask for the asserted claim number, the accused product's date of first infringement, and the damages theory. Given the expiry date, there is no legally coherent damages theory for 2026 conduct. If the letter actually cites the sibling 5,940,591 or the 5,832,228 / 5,872,847 / 6,212,636 cousins, escalate: those are different numbers with different expiry dates and their PTAB histories must be checked independently.
  4. Verify directly before relying on this. My access to USPTO backends was indirect. Confirm via USPTO Patent Center for App. 08/270,398 and PTAB E2E (search the patent number under "Proceedings"), and cross-check CAFC dispositions via CourtListener and the Federal Circuit docket. Absence of search results is not proof of absence.
  5. Do not conflate numbers. Per the prior section, Round Rock Research LLC v. SanDisk Corp. (D. Del. 1:12-cv-00569, terminated 2015) asserted 5,615,159; 6,728,798; 6,948,041; 7,336,531; 8,060,719; and 5,255,209 — none of which is 5,577,209. Any strategy built on those dockets must cite those numbers, not this one.

Caveats, stated explicitly

  • No authoritative PTAB backend confirmation was obtainable with the tools available here. The "0 proceedings" result rests on the structured USPTO Open Data Portal block in the prompt plus five web searches, four of which returned no relevant hits.
  • The legal status ("Expired – Lifetime," anticipated expiration 2013-11-19) and the reassignment chain (ITT → Micron 2000-07-20 → Round Rock Research 2010-01-04) come from Google Patents, which itself disclaims making legal conclusions.
  • A zero count is a negative finding; it cannot be proven absolute where the query tools are indirect.

Generated 9/30/2026, 5:34:43 PM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2000-07-20 · Assignment

    ITT Industries, Inc.Micron Technology, Inc.

    acquisition

  2. 2009-12-23 · recorded 2010-01-04 · reel 023786/0416 · Assignment

    Micron Technology, Inc.ROUND ROCK RESEARCH, LLC

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment record for US 5,577,209 now, starting with the USPTO Assignment Center and cross-referencing sources.

Inventors

Inventor Employer at filing Notes
John M. Boyle Not determinable from the record; all named inventors are on a patent whose original assignee is ITT Corp (superseded by ITT Industries, Inc.) No assignment-of-inventor-rights reel/frame was confirmable in this session
Eric S. Maiwald Same as above —
David W. Snow Same as above —

Unusual-pattern check — inconclusive. The task asks whether all inventors departed the original assignee within 12 months of filing. I could find no evidence on this point (no personnel records, no 1991–92 ITT/ITT-Industries announcements, no inventor obituaries or later assignee data). I am flagging this as unclear, not as a signal. The only structural fact that is visible is the 1995–96 ITT corporate break-up, which post-dates filing and is a corporate event, not an inventor-departure event (see below). Do not read a fire-sale pattern into the inventor roster on the evidence available.

Original assignee

  • Entity on the issued patent: ITT Corp (assignee of record at grant, 1996-11-19).
  • Line of business: ITT was a diversified conglomerate (telecommunications, defense electronics, insurance, hotels). The 1995–96 restructuring split it into three: ITT Hartford (insurance), ITT Sheraton (hotels), and ITT Industries, Inc. (manufacturing: defense electronics, connectors, fluid technology, electronic components). The 2000 assignment in this chain runs from ITT Industries, Inc. — consistent with ITT Corp having become/been succeeded by ITT Industries in that reorganisation, i.e. a change-of-name/corporate-succession effect, not an arm's-length sale to a third party.
  • Did ITT ship a product embodying the claims? The specification describes an actual reduced-to-practice implementation (DEC VT320 terminal, RS-232 at 9600 bps, TCP/IP Ethernet via a Racal/Interlan NP627 card) and a "closed module" SNIU. That is strong evidence the inventors built and tested an SNIU, but I found no commercial SNIU product, sales literature, or revenue record attributable to ITT for this device. Unclear.
  • Current status: ITT Corp as such no longer exists as the 1996 entity. ITT Industries was renamed ITT Corporation (2006) and in 2011 split into ITT Corporation (industrial), Exelis (defense — later acquired by Harris, now L3Harris), and Xylem (water). None of these entities is the current owner of '209.

Assignment timeline

Important sourcing caveat, stated upfront: I could reach the Assignment Center/legacy-assignments.uspto.gov surface only indirectly (Google Patents legal events, ESPACENET/INPADOC legal-status records, USPTO assignment PDFs surfaced through IPR exhibits, and secondary reporting). I could not open an authenticated assignmentcenter.uspto.gov record for App. 08/270,398 / Patent 5,577,209 directly. I therefore give you the reel/frame I can verify against sibling patents in the same conveyance and mark everything else as unverified. I am not inventing reel/frame numbers for the links I could not confirm.


1991-07-11 (executed/filed) / recorded on filing — Reel not applicable (no separate post-issuance assignment of record found)

  • Conveyance: Original application (no assignment-from-inventors recording confirmed in this session)
  • Assignor: N/A
  • Assignee: ITT Corp (application 07/728,633, later continued as 08/270,398)
  • Correspondent: Not determined
  • Context: Original prosecution — inventors' rights presumptively vested in ITT as employer; no inventor-to-ITT assignment document was retrievable.

~1996 (executed) / recorded ~1996 — Reel/frame NOT DETERMINED

  • Conveyance: Change of name / corporate reorganisation (inferred, not confirmed by a retrieved record)
  • Assignor: ITT Corp
  • Assignee: ITT Industries, Inc.
  • Correspondent: Not determined
  • Context: Internal reorgan — the 1995–96 ITT three-way split. This is the only explanation consistent with a patent issued to "ITT Corp" being later conveyed by "ITT Industries, Inc." Inferred; treat as unconfirmed.

2000-07-20 (recorded) — Reel/frame NOT DETERMINED

  • Conveyance: Assignment
  • Assignor: ITT Industries, Inc.
  • Assignee: MICRON TECHNOLOGY, INC.
  • Correspondent: Not determined
  • Context: Possible bulk asset sale / fire-sale-adjacent disposal. This is the anomaly in the chain: a secure-networking session-layer patent from an ITT defense-electronics lineage transferring to a DRAM manufacturer. Micron is not a natural purchaser of ITT's session-layer security art; the transaction has the shape of a bulk portfolio acquisition of surplus ITT assets rather than a strategic purchase. I could not verify whether this was a standalone sale, part of a larger ITT portfolio divestiture, or an IP-only transaction. Flagging as unverified context rather than a finding.
  • Date source: Google Patents legal events (2026-09-24 fetch) record the Micron reassignment on 2000-07-20, assignors "ITT INDUSTRIES, INC." The reel/frame was not exposed.

2009-12-23 (effective) / recorded 2010-01-04 — Reel 023786, Frame 0416

  • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST (per the INPADOC legal-status text: "ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNOR:MICRON TECHNOLOGY, INC.;REEL/FRAME:023786/0416")
  • Assignor: MICRON TECHNOLOGY, INC.
  • Assignee: ROUND ROCK RESEARCH, LLC (New York; recorded address P.O. Box 1042 / 26 Deer Creek Lane, Mount Kisco, NY 10549)
  • Correspondent: NOT DETERMINED. ⚠️ I specifically tried to capture the recording correspondent and could not. The only attorney signature I could surface in a Round Rock filing is a truncated "/Richard J. ___" on a 37 CFR 3.73(b) statement dated 2016-03-09 in IPR2016-00637 (Round Rock as patent owner, US 6,455,935). That is a power-of-attorney signature, not the assignment correspondent of record, and it is incomplete — I will not convert it into a named correspondent. If the correspondent matters to your analysis (it should — see Signal 3), this single field must be pulled directly from Reel 023786.
  • Verification of this reel/frame: Reel 023786/0416 is the recorded reel/frame for the Micron → Round Rock Research, LLC bulk conveyance, independently confirmed on three sibling Micron patents:
    • US 6,423,621 (INPADOC: event 2010/01/04, AS, new owner ROUND ROCK RESEARCH, LLC, effective 2009-12-23, REEL/FRAME 023786/0416)
    • US 6,455,935 (Round Rock's own 37 CFR 3.73(b) chain-of-title: "Micron Technology, Inc. To: Round Rock Research, LLC … Reel 023786, Frame 0416")
    • US 2009/0309222 A1 (same event, same reel/frame)
      and the event date/effective date (2010-01-04 / 2009-12-23) matches the Google Patents legal event recorded for 5,577,209. Caveat: this is a bulk reel covering ~3,407 US patents from a reported ~4,500-patent sale; I am confident the conveyance covers '209 but I could not confirm that '209 appears at frame 0416 specifically rather than at another frame within reel 023786. Treat "023786/0416" as the conveyance identifier and verify the frame directly.
  • Context: Transfer-to-asserter (privateering transaction). Micron sold the portfolio to Round Rock Research LLC, an entity founded by John Desmarais, then Kirkland & Ellis's outside patent counsel for Micron itself (Desmarais stepped down from Kirkland partnership to "of counsel" to avoid conflicts). Reported terms: Micron retained a royalty-free licence to the patents and shared a percentage of Round Rock's revenue. This is the textbook privateering fact pattern. Notably, Micron did not disclose the sale in its SEC filings or via press release (IAM, Sept/Oct 2010; Micron's March 2010 8-K made no mention; Micron "confirmed that it had sold the patents to Round Rock" but declined further comment).

2013-11-19 — no assignment; term event

  • Anticipated expiration (20-year term from 1991-07-11 priority). Google Patents status: "Expired – Lifetime."
  • No further assignment of record found after 2010-01-04. No transfer to a defensive aggregator (RPX, AST, LOT, OIN, Unified) appears anywhere in the chain.

Timeline diagram

timeline
    title Ownership of US 5577209
    1991 : Application filed by ITT Corp
    1996 : Patent issued to ITT Corp
         : ITT split into three companies
    2000 : Assigned to Micron Technology
    2009 : Assigned to Round Rock Research LLC
         : Bulk transfer effective 23 Dec 2009
    2010 : Assignment recorded 4 Jan 2010
    2013 : Term expired 19 Nov 2013

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT.
The patent moved from an operating manufacturer (Micron Technology, Inc., a public DRAM maker with real products) to a licensing-only LLC with no products. Evidence: Reel 023786/0416, executed/effective 2009-12-23, recorded 2010-01-04. Corroborating characteristics: Round Rock Research, LLC is a New York LLC at a P.O. Box / residential-style Mount Kisco, NY address; it is a single-purpose patent-licensing vehicle founded by an outside litigator; its litigation Rule 7.1 disclosure states no parent and no publicly held company owning 10%+. This is a licensing-only entity, not merely a name that "sounds like" a shell.

2. Known asserter in the chain — PRESENT.
Round Rock Research, LLC is on your supplied NPE list (and on RPX/Unified-era asserter lists) and is the current assignee of record via Reel 023786/0416. Round Rock's assertion campaign is documented (e.g. Round Rock v. HTC Corp., D. Del., filed October 2010; the SanDisk v. Round Rock and Round Rock v. ASUS/Canon/Ricoh/JVC Kenwood/Nintendo line, D. Del. 2013–2015), and Unified Patents challenged Round Rock-owned patents at the PTAB (e.g. IPR2016-00637 against US 6,455,935). Cross-check per the constraints: none of those asserted numbers is 5,577,209 — see Signal 5.

3. Repeat correspondent across the chain — UNCLEAR (data gap).
I could not retrieve the correspondent of record on Reel 023786/0416, nor on the 2000 ITT→Micron recording. I therefore cannot state whether a single attorney/firm recorded multiple links, and I decline to name one. The partial "/Richard J. ___" signature on a Round Rock power-of-attorney filing (IPR2016-00637, 2016-03-09) is not an assignment correspondent and is truncated; treat it only as a lead to check against Reel 023786's correspondent field. This is the single highest-value field still missing from the analysis — Desmarais-era Round Rock recordings are exactly the kind of linked filings where a repeat correspondent would surface.

4. Cascading transfers — NOT PRESENT (on this patent).
The chain is two post-issuance conveyances over ~19 years (ITT Industries→Micron 2000; Micron→Round Rock 2009/2010). There is no run of chained LLC-to-LLC assignments inside 24 months on '209. The 2009 transfer was bulk (part of ~4,500 patents; ~3,407 recorded in the first December 2009 tranche), which is characteristic of a portfolio monetisation vehicle, but bulk ≠ cascading, and I will not call it cascading.

5. Pre-litigation transfer — NOT PRESENT for this patent.
The transfer effective 2009-12-23 precedes Round Rock's first suit (HTC, October 2010) by ~10 months, and is not within the 6-month window even against that first suit. More decisively, no infringement suit naming 5,577,209 exists in the record I searched (consistent with the prior Litigation and PTAB sections of this analysis). A transfer cannot be "pre-litigation" for a patent that was never litigated.

6. Bankruptcy fire-sale — NOT PRESENT.
Neither ITT Industries (2000 seller) nor Micron Technology (2009 seller) was in Chapter 7/11. Micron's 2009 sale was a liquidity-motivated portfolio monetisation during a chip-industry downturn, and it was executed off the bankruptcy docket and undisclosed to shareholders — that is a monetisation event, not a §363 bankruptcy sale. No bankruptcy proceedings touch this chain.

7. Privateering — PRESENT (strong).
Micron transferred the portfolio to an NPE founded by Micron's own outside counsel, retained a royalty-free licence back, and shared revenue with the NPE, while declining to disclose the transaction in its SEC filings. Round Rock then asserted the portfolio against Micron's industry peers. This is the canonical privateering structure and it is documented in contemporaneous trade reporting (IAM Sept/Oct 2010; Law.com/AmLaw; Bloomberg BusinessWeek, June 2010). The '209 patent is an asset swept into that structure, even though '209 itself was never asserted.

8. Defensive aggregator (anti-NPE) — NOT PRESENT.
The chain terminates at Round Rock Research, LLC, an asserter, not at RPX, AST, LOT, Unified Patents, or OIN. No neutralising transfer is recorded after 2010-01-04.

Verdict

NPE — high confidence.

The ownership chain contains at least three independent strong signals: (i) a licensing-only shell transfer to Round Rock Research, LLC at Reel 023786/0416, effective 2009-12-23 / recorded 2010-01-04; (ii) a known public asserter (Round Rock, an NPE-list entity, with documented 2010-onward litigation and PTAB challenges against its portfolio); and (iii) a documented privateering structure in which Micron sold to its own outside counsel's vehicle while retaining a royalty-free licence and revenue share, undisclosed to shareholders. The one meaningful gap is Signal 3 (repeat correspondent), which I could not populate because the correspondent of record on Reel 023786/0416 was not retrievable with the tools available.

Material qualification the verdict does not capture: the chain's NPE character is a fact about ownership, not about enforcement of this number. Per the prior sections of this analysis, 5,577,209 was never asserted in any suit or PTAB proceeding I could find, and its term expired 2013-11-19. "High-confidence NPE" here means a patent that ended up in asserter hands via a privateering sale — not a patent currently being asserted. Anyone using this verdict for a 2026 clearance or demand-letter decision must pair it with the expiry finding.

Verification link (Assignment Center search — search "5577209"): https://assignmentcenter.uspto.gov/ — and the legacy index at https://assignment.uspto.gov/patent/index.html

Explicit caveats

  • Reel/frame confirmed by proxy, not directly. Reel 023786/0416 is verified against US 6,423,621, US 6,455,935 and US 2009/0309222 (all Micron→Round Rock, same dates), and the dates match the Google Patents legal event for '209 — but I did not open an Assignment Center record for App. 08/270,398 itself. Confirm the frame for '209 directly.
  • No reel/frame obtained at all for the 2000-07-20 ITT Industries→Micron recording, nor for any 1996 ITT change-of-name/merger recording. Those rows are marked NOT DETERMINED deliberately — I did not fabricate numbers to fill them.
  • The ITT-corporate-reorganisation step is inferred from the mismatch between the patent's face assignee ("ITT Corp") and the later conveyancing assignor ("ITT Industries, Inc."); it is not backed by a retrieved assignment record.
  • Correspondent of record is unknown at every link. This is the principal analytical hole and the field most worth a manual pull.
  • Legal status ("Expired – Lifetime," anticipated expiration 2013-11-19) and the reassignment dates come from Google Patents, which disclaims making legal conclusions, and from INPADOC/ESPACENET legal-status data.
  • I did not conflate this chain with 5,255,209, 5,615,159, 6,255,209, or the sibling 5,940,591 / ITT cousins 5,832,228 and 5,872,847 — those are different numbers with their own chains and must be checked separately.

Generated 9/30/2026, 5:43:28 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the prior art cited in US 5,577,209. Let me run targeted searches.

Let me search for the specific prior-art references cited on the patent's face.

Let me try to retrieve the patent's front-page "References Cited" data directly.

I hit the tool-call ceiling before I could pull the patent's front page. Here is what I can state with confidence — including an important gap you need to know about before relying on any list.


Prior Art Analysis — US 5,577,209

⚠️ Critical scope disclosure first (read before using this)

The authoritative full text supplied for this analysis does not contain the "References Cited" (backward-citation) block of US 5,577,209. The text runs Description → Abstract → "Cited By (250)" — i.e. it captures the patent's forward citations (later patents citing '209) but omits the front-page list of U.S. Patent Documents and non-patent references the Examiner/applicant cited against '209.

My follow-up searches (Google Patents, patentimages, Justia, EPO Global Patent Index, USPTO.report) did not return that front-page reference list either. I reached my tool-call limit before I could obtain the grant PDF.

Consequence: I cannot truthfully enumerate "each patent citation" on the face of '209. I will not invent a citation list. Below I give (A) the prior art the applicants themselves identify and characterize in the specification, (B) genuine pre-priority candidate references surfaced in searching, and (C) the forward citations correctly labeled as not prior art. I tell you exactly how to obtain the missing list at the end.


A. Prior art identified within the '209 specification itself (applicant's own characterization)

These are the references the applicants discuss as the state of the art in the Background of the Invention (col. 1). They are the closest art by the applicant's own admission, and under § 102 they are the natural anticipation candidates.

# Reference (as cited in '209) Date / type Description Claims it could potentially implicate under § 102
A1 Boeing MLS LAN (Boeing Computer Services) Prior art ~late 1980s; non-patent system, described col. 1 Trusted-network approach: "the backbone cabling is replaced by optical fiber and all access to the backbone is mediated by security devices." Security built into the network configuration, requiring replacement of protocols/physical elements. Limited to LAN users. Potentially relevant to claim 1/12 only as to generic "multi-level security," "access control," "authentication," and the network-interconnection concept — but it lacks the claimed SNIU-between-each-user-and-network, the session-manager/dialog-manager/association-manager decomposition, the global security perimeter for end-to-end communications, and the security-management architecture. Does not anticipate; at most § 103 background.
A2 Verdix VSLAN (Verdix Secure LAN) Prior art ~late 1980s; non-patent system, described col. 1 "Similar security devices are used to interface to the network, and the network uses encryption instead of fiber optics… VSLAN is limited to users on a local area network (LAN)." Same analysis as A1. Notable that VSLAN does place security devices at the interface — arguably the closest structural predecessor to the SNIU — but it is confined to a LAN and does not disclose the session-layer placement or the SM architecture. Does not anticipate claim 1/12.
A3 NSA "Secure Data Network System" (SDNS) program Program initiated late 1980s; described col. 1 Trusted-host approach: "seeks to implement a secure protocol for trusted hosts… Such systems operate at the Network or Transport Layers (Layers 3 or 4) of the OSI model." Requires upgrading the installed host base. Directly undercuts the "session layer / Layer 5" core of claims 1 and 12 — it teaches away by operating one tier lower. Relevant to claim 1/12's "session layer of interconnection" only as evidence of the prior approach the invention distinguished. Not anticipating.
A4 Packet encryptors / End-to-End Encryption (EEE) devices Prior art; described col. 1 "Utilize different keys and labels in protocol headers to assure the protection of data… operate at the Network Layer (Layer 3)." The spec notes they "lack user accountability since they do not identify which user of the host is using the network." Relevant to dependent claim 5 / 15 (data sealer) and to the identity/user-identification limitations — but the spec expressly distinguishes EEE on the head-on point that it lacks user accountability, which the claims require (session manager "identifying a user," "session audit"). Not anticipating.
A5 CCITT Recommendation X.215 (Session Layer protocol) Standard, pre-1991 "OSI network applications employ CCITT X.215 which is a non-secure session layer protocol." This is the single most important § 102 framing reference: it occupies the exact layer (5/Session) the claims occupy, but it is non-secure. It therefore anticipates nothing security-related; it is the baseline the claims are measured against. Relevant to the "user layer communications protocol" language of claim 1.
A6 OSI Reference Model (ISO 7498) Standard, 1984 (referenced generically) Seven-layer model recited in the Detailed Description to define layers 1–7 and the Session Layer placement. Not anticipatory; definitional. Relevant only to construction of "session layer of interconnection."

Net § 102 assessment on the applicant's own art: none of A1–A6 discloses, in a single reference, every element of independent claim 1 or 12 — specifically the combination of (i) an SNIU coupled between each user and the network, (ii) performing user interface / session manager / dialog manager / association manager functions at the session layer, (iii) creating a global security perimeter for end-to-end communications while the network "may be individually secure or non-secure," and (iv) an SM architecture capable of the enumerated policy group and "inter-network administration." The applicants expressly state: "None of the prior multi-level security systems employ the security measures described herein in the Session Layer." That is a § 102/§ 103-avoidance statement on the record.


B. Pre-priority candidate references surfaced in searching (not the applicant's list)

# Full citation Date Type § 102 relevance
B1 Wen-Pai Lu & M. Malek, "A Model for Multilevel Security in Computer Networks," IEEE Transactions on Software Engineering, Vol. 16, No. 6, pp. 647–659 1 June 1990 Non-patent publication (IEEE) This is the strongest genuine candidate prior art I could verify for '209. It is dated before the 1991-07-11 priority date and sits squarely in the multilevel-security-in-networks field. Surfaced in the EPO search report for EP 1 101 161 A4, listed alongside US 5,577,209. Under pre-AIA § 102(a)/(b) it is a printed publication; the relevant question is whether it discloses the session-layer enforcement point and the SNIU-per-user architecture. On its title/scope it is a model, and the EPO cited it as an "[A]" (background) reference rather than "X," so the art-against-'209 weight appears low — but this is the reference I would pull first.
B2 M. Szwarc, "Virtual private data network service in the wide area networks," GLOBECOM '91, Phoenix, Dec. 2–5, 1991, pp. 1033–1037 Dec 1991 Conference paper ⚠️ Dated after the 1991-07-11 priority date → not prior art to '209. It was cited (as "X") against a later application (EP 0 977 399). I include it only to prevent you from importing it into a '209 invalidity chart — it does not belong there.
B3 S. Bellovin & M. Merritt, "Network Firewalls," IEEE Communications Magazine, Vol. 32, No. 9, pp. 50–57 Sept. 1994 Non-patent publication ⚠️ After the '209 priority date (1991-07-11) → not prior art to '209. Famous reference, but wrong date for this patent. Cited in EP 1 231 754.
B4 US 5,546,463 (Caputo et al.) issued 1996-08-13 U.S. patent ⚠️ Post-dates '209's priority; appears as an X/A reference in other search reports (EP 1 101 161). Not prior art to '209.

Note on B1's date arithmetic (pre-AIA § 102): priority is 1991-07-11, actual filing 1994-07-05. A reference must predate 1991-07-11 for § 102(a)/(e), or 1990-07-11 for the § 102(b) one-year bar. B1 (June 1990) clears the § 102(b) bar by roughly one month — a genuinely close call worth double-checking the exact publication date on the document itself.


C. Forward citations — not prior art (do not use in a § 102 chart)

The "Cited By (250)" block in the supplied text is the opposite direction: patents that cite '209', all of which post-date it. These are not prior art against '209. Representative first entries from the '209 record:

(If your real question was "what cites '209" rather than "what did '209 cite," say so and I'll re-run in that direction — but for prior-art purposes these are irrelevant.)


D. What the claims actually require, for the § 102 comparison

Building on the previously generated summary (claims 1 and 12 are the only independents):

  • Claim 1 (apparatus): SNIU ("SINU" as literally spelled in the claim) between each user and the network, operating at a "user layer communications protocol," comprising user interface (format translation), session manager (identify user at session level, verify authorization, manage sessions, maintain session audit), dialogue manager (control the data path), association manager (establish/control session at session layer); SNIU creates a global security perimeter for end-to-end communications with the network optionally secure or non-secure; plus an SM connected to the SNIU implementing a § 102-relevant policy group (DAC, MAC, object reuse, labeling, denial-of-service detection, data type integrity, cascading control, covert channel use detection) and providing inter-network administration.
  • Claim 12 (method): the method counterpart, plus the same perimeter and SM limitations.

No single reference in A or B discloses all of these. The closest § 102(a) exposure is B1 (Lu & Malek 1990) on the "multilevel security in computer networks" concept alone; the closest structural exposure is A2 (Verdix VSLAN) on "security device at the network interface." Neither teaches the session-layer SNIU decomposition or the SM architecture that are the load-bearing limitations. Expect a § 102 rejection to be very hard to sustain and § 103 to be the realistic battleground — which is consistent with the prior sections' conclusion that this patent was never PTAB-challenged and is now expired.


E. Contradiction check against prior sections

  • No contradiction with the previously generated sections. Consistent points: (i) '209 is "heavily cited, not heavily asserted"; (ii) it sits in classification art H04L63/105, H04L63/0823, G06F21/62; (iii) the family includes US 5,940,591, US 5,832,228, US 5,872,847; (iv) the "SINU" vs. "SNIU" spelling quirk in claim 1, which I have again not normalized.
  • One item to flag: the earlier PTAB section correctly identified US 5,699,513 (Feigen) as citing '209 — this confirms US 5,699,513 is a forward citation, not prior art to '209, despite it appearing in a contested-proceeding exhibit.

F. How to close the gap (required before finalizing any invalidity work)

  1. Fetch the grant front page — this is the only authoritative "References Cited" list: Google Patents PDF for US5,577,209 (https://patents.google.com/patent/US5577209/en, "Download PDF"), or USPTO Patent Center for Application 08/270,398 (the "References Cited" / "U.S. Patent Documents" and "Other Publications" block).
  2. Also pull the parent application 07/728,633 (filed 1991-07-11) and the sibling US 5,940,591 — examiners frequently carry citations forward.
  3. If you want the prosecution-history art, order the file wrapper via Patent Center; the IDS entries will list everything actually considered.

Bottom line: I could not obtain the actual patent citations printed on US 5,577,209, and I will not fabricate them. The verifiable prior art surrounding '209 is (A) the applicant's own Background characterizations — Boeing MLS LAN, Verdix VSLAN, NSA SDNS, EEE/packet encryptors, CCITT X.215 — and (B) the one clean pre-priority publication I could confirm, Lu & Malek (June 1990), which is the reference most worth pulling against claims 1 and 12. Everything in category C is a forward citation and is not prior art.

Generated 9/30/2026, 5:43:42 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground this § 103 analysis in the prior art actually associated with this patent — both the references cited on its face and the prior-art systems described in its own Background section. Let me run targeted searches.

Obviousness Analysis — U.S. Patent 5,577,209 under 35 U.S.C. § 103

Consistency check against the prior sections: No contradictions. I use the same effective priority date (1991-07-11, parent Ser. No. 07/728,633) and the same expiry (2013-11-19). The prior sections found no litigation and no PTAB activity; that means no claim has ever been cancelled, narrowed, or construed, so this analysis must treat all 20 claims as literally issued.

Important limitation, stated up front: The patent text supplied truncates inside the "Cited By" list (at US7143290B1 () and does not include the face-page "[56] References Cited" block. I therefore could not retrieve the examiner-cited art for '209, and I did not obtain the file history (Office Actions, rejections, affadavits). Everything below is built from (a) the patent's own admitted prior art in its Background/Detailed Description, and (b) prior art I could independently document to predate 1991-07-11. This is a constructed § 103 case, not a reconstruction of what the Examiner actually applied.


1. Effective date and the usable § 103 window

Because '209 is a continuation of 07/728,633 (filed 1991-07-11), the critical date is 1991-07-11. Pre-AIA § 103 governs. Usable art:

  • § 102(b): public use / on sale in the U.S. or printed publication before 1990-07-11.
  • § 102(a)/(e): knowledge or use by others, or patents/applications filed before 1991-07-11.
  • § 102(f)/(g)/§ 103(c): applicant admissions and common ownership — the Background section's descriptions of VSLAN, the Boeing MLS LAN, SDNS, EEE devices, and CCITT X.215 are admissions of prior art and are independently usable as § 103 bases.

Excluded as post-priority (do not cite as art): Boeing's CSC-EPL-91/005 evaluation (2 July 1991 — six days before the parent filing, but published/evaluated later and not shown to be publicly accessible before 1991-07-11); Secure Computing's US 5,596,718 (filed 1992-07-10) and US 5,272,754 (issued 1993); NISTIR 90-4250/4228 (1990 — usable only where their underlying SDNS content was published earlier).


2. Person of ordinary skill in the art (POSITA), circa 1991

A POSITA here would have held a B.S. in EE/CS (or equivalent) plus 2–4 years in trusted-system/secure-network engineering, with working familiarity with: the TCSEC/Orange Book and the Trusted Network Interpretation (TNI, NCSC-TG-005, 31 July 1987); the OSI 7-layer model including CCITT X.215 session services; DES and RSA and public-key certificates; and evaluated MLS LAN products (VSLAN, Boeing MLS LAN). This is a narrow, well-populated art (the 1989 IEEE survey of commercially available secure LANs shows at least several MLS LAN products were on the market).


3. The independent claims, decomposed

Both independent claims share one inventive core. Claim 1 (apparatus) and claim 12 (method) require:

Element Claim language (abbreviated)
A "SINU" (as spelled in the claim) coupled between user and network, operating at a "user layer communications protocol"
B User interface translating user data into SNIU format
C Session manager: identifies user at the session level; verifies authorization; manages permitted sessions; maintains a session audit
D Dialogue manager controlling the data path in the SNIU
E Association manager establishing the session at a session layer of interconnection
F "Global security perimeter" — network may be secure or non-secure without compromise
G SM connected to the SNIU, configuring/operating it, implementing a policy selected from a Markush group (DAC, MAC, object reuse, labeling, denial-of-service detection, data type integrity, cascading control, covert channel use detection), and "further providing inter-network administration"

Claim-construction note that materially weakens the claims: the group in element G is a Markush group ("selected from the group consisting of…"). Under settled practice, a claimed Markush group is satisfied by any single member. So the prior art need only disclose the rest of the claim plus one of those eight policies — and the 1989 IEEE survey shows VSLAN already provided DAC, MAC, I&A, and audit on LAN, while Boeing's MLS LAN provided MAC, DAC, I&A, audit, denial-of-service resistance, and compromise protection. Likewise, "dialogue" (claim 1) vs. "dialog" (specification) and the "SINU" misspelling are literal-text quirks — per the operating rules I do not normalize them, but a POSITA reads them as the SNIU/dialog-manager structures.


4. Prior art references established (all pre-1991-07-11)

# Reference Date / citation What it discloses
R1 Verdix VSLAN (Network Security Center + up to 128 Network Security Devices) Public demonstrations announced for Q4 1988 (Data Processing & Communications Security, Winter 1989, v13 i1; Tech Monitor, NCSC submission Oct. 1988); evaluation report CSC-EPL-90/001; DTIC ADA247235 (https://apps.dtic.mil/sti/pdfs/ADA247235.pdf) Trusted interface unit mediating all host datagrams; explicit "security perimeter that isolates the VSLAN from its attached hosts"; DAC + MAC; Datakey-based identification/authentication of the principal; centralized NSC management that configures each NSD and "downloads" the parameters to it; time-stamped audit trail; DES for all transfers; up to 16 levels/64 categories
R2 1989 IEEE survey, "A survey of commercially available secure LAN products" 5th IEEE Computer Security Applications Conf., 4–8 Dec. 1989, DOI 10.1109/CSAC.1989.81057 Trusted interface units; "the common security protocol is contained within the trusted units themselves"; MAC label integrity; interoperability with Harris LAN/SX across mixed hardware/OS bases
R3 Boeing MLS LAN / Secure Network Server (SNS) NCSC Bulletin CSC-PB-003-88, 14 Sept. 1988; MILCOM 1985, Nagaki & Van Ausdal, DOI 10.1109/MILCOM.1985.4794965; DTIC ADA219102, ADA219100 SNS between devices and network; 8 levels / 256 categories; modeled multilevel subjects and single-level subjects; TCP/IP, FTP, UDP, TELNET; network/security management; fault tolerance; denial-of-service and compromise protection services; planned gateway node for internetworking
R4 SDNS (NSA Secure Data Network System) NISTIR 90-4228 / 90-4250; Branstad, Dorman, Housley & Randall, "SP4" (1987) (https://vigilsec.com/SP4-1987.pdf); Lambert, "Architectural Model of the SDNS Key Management Protocol," 11th NCSC Proceedings (1988); SDNS Architecture and End-to-End Encryption (1988) KMP: mutual authentication of peer devices via credentials; access control decisions made before key delivery; cryptographic association with a TEK; Key Management Center; Compromise Key List; SP4 MAC/ICV, confidential + connectionless integrity, security labels bound to data, connection-truncation protection
R5 1988 NCSC proceedings — COMSEC/COMPUSEC integration 11th NCSC Proceedings (Oct. 1988), https://csrc.nist.gov/files/pubs/conference/1988/10/17/proceedings-11th-national-computer-security-confer/final/docs/1988-11th-ncsc-proceedings.pdf Explicit teaching that a front-end (FE) device can provide a "security overlay" at network interfaces, protecting the traffic of existing, unmodified host computers
R6 Boebert / Secure Computing trusted-path art US 4,621,321 (Nov. 1986); 4,701,840 (Oct. 1987); 4,713,753 (Dec. 1987); US 4,227,253 (IBM; prio. 1977-12-04) Secure data-processing architectures enforcing DAC/MAC in a trusted perimeter; trusted path; multi-domain network cryptographic communication
R7 CCITT X.215 session-layer service definition Admitted prior art in the '209 Background The non-secure session-layer protocol the patent itself concedes exists

5. The combinations, and why a POSITA would make them

Combination I — R1 (VSLAN) + R4 (SDNS KMP/SP4) → claim 1 obvious

Map claim 1 onto R1: the NSD is the "SINU" (a trusted unit coupled between host and network, mediating every datagram — element A, B via the host-specific bus interface software); the NSC is the SM ("coupled to the network," configuring and operating each NSD by downloading policy — element G); the DAC/MAC + Datakey I&A + time-stamped audit supply at least one member of the Markush group and element C's audit function; and VSLAN's own "security perimeter that isolates the VSLAN from its attached hosts" is the claimed perimeter for element F, since the VSLAN report expressly contemplates untrusted hosts, commercially available TCP/IP packages (layers 3–7 not security-relevant), and internetworking VSLANs.

R4 supplies what R1 lacks: user- and peer-level authentication in the protocol stack (KMP credentials, mutual authentication, access-control checks before key release) and the "cryptographic association" — i.e., the claimed association manager and data sealer, with keys held in a distributed, centrally-certificated framework (Key Management Center ≈ the SM/NSM role).

Motivation (KSR rationales):

  • Same field, same problem — both address MLS traffic over shared media among mutually suspicious end systems.
  • Explicit art-driven lead: the VSLAN report itself notes that the principal identifier "must be possible to associate… with a specific list of users authorized to use that particular host" — i.e., the art identified the exact gap the claim's session manager fills and pointed to the fix.
  • § 103 "improving a similar device" + predictable result. Pushing access control and key management up the stack was the stated trajectory of the entire field — the '209 Background concedes "there is a government effort to develop cryptographic protocols which operate at other protocol layers."
  • Evaluation incentive. Per the VSLAN report, components "must always be evaluated as a whole," and TNI Part II service credits (Authentication, Communications Field Integrity, Continuity of Operations, Protocol Based Protection, Network Management, Data Confidentiality) are awarded for exactly the layered composition R1+R4 produces.

Combination II — R3 (Boeing MLS LAN/SNS) + R4 + R7 (X.215) → claim 1 obvious; claims 2/13 and 3/14 obvious

The SNS already sits between subscriber devices and the network, running MAC/DAC against labeled communication objects, with multilevel and single-level subjects and management positions for reconfiguration and monitoring. R4 supplies per-peer authentication, key management, and data sealer functions; R7 (X.215) supplies the session-layer scaffolding the claim calls a "user layer communications protocol." R3's documented "future MLS LAN gateway node" and R2's cross-network label mapping supply claim 3/14's "security policy… in at least two network jurisdictions."

Combination III — R1 or R3 + R6 (Boebert trusted-path/secure-architecture) → claim 1 obvious

R6 supplies DAC/MAC enforcement and a trusted path in a defined perimeter, which is the "global security perimeter" framing plus Markush members. R1/R3 supply the network-facing half.

Combination IV — R1/R3 + R5 (1988 NCSC "security overlay" teaching) → undercuts the strongest nonobviousness story

The patent's own asserted advance is that existing non-secure hosts and networks need not be replaced because security is an overlay at the session layer. R5 flatly teaches that a front-end device "can provide a 'security overlay' at network interfaces, protecting the traffic of existing, unmodified host computers." That is a motivation-to-combine statement published three years before the priority date, and it mirrors the patent's claimed advantage.

Dependent claims — each separately obvious over the same combinations

Claim(s) Rendering art
2, 13 (TSP) R7 X.215 + SDNS "Security Addendum to the OSI Reference Model" (R4)
3, 14 (two jurisdictions) R2 (VSLAN/Harris LAN/SX mixed-base MAC), R3 gateway node, SDNS internetworking (R4)
4 (prevent covert information flow) VSLAN's TNI covert-channel analysis and 16 levels/64 categories (R1); MLS LAN DOS + traffic-flow-confidentiality analysis (R3). This is the most resistant dependent claim — but it is framed as a functional result, and the art already performed covert-channel analysis as a TNI condition of evaluation.
5, 15 (data sealer) VSLAN DES (R1); SP4 MAC/ICV (R4); the patent admits packet encryptors/EEE devices use keys and labels
6 (network interface) NSD IEEE 802.3 LAN interface (R1); SNS trunk interface (R3)
7–11, 16–20 (SSM/ASM/NSM three-tier hierarchy) VSLAN's NSC→NSD two-tier central management (R1) + SDNS Key Management Center / rekey agents / staged rekey hierarchy (R4) + R3 network management. Two-tier + centralized-key-authority renders a three-tier SSM/ASM/NSM split an obvious administrative convenience (KSR: combination of familiar elements, predictable results; "distribution for fault tolerance" is routine)

6. The patent's best counterarguments (and why they are beatable)

  1. "We put security at OSI Layer 5; everyone else used Layers 1–4." Answerable: (a) the claim's own "user layer communications protocol" is undefined in the specification; (b) X.215 already defined the session layer, so the placement is the known, predictable location once the objective is user-level accountability; (c) the Background concedes the government was already moving protocols "to other protocol layers"; (d) SDNS's KMP itself uses the OSI session protocol (kernel and duplex functional units) in its required stack — a POSITA composing SDNS's session-layer components with a VSLAN-style trusted unit arrives squarely at the claim.
  2. "Existing hosts and networks need not be replaced." Directly rebutted by R5's 1988 security-overlay teaching.
  3. "User accountability, which EEE devices lack." This is a problem statement, not a solution — the patent's own admission that the deficiency was known supplies the motivation (KSR: known problem, known solution, predictable result).
  4. Secondary considerations. I found no evidence of nexus, licensing, commercial success, or long-felt-but-unmet need attributable to these claims, and no objective indicia in the record I searched. Given the prior sections' finding that the patent was never asserted and never challenged at the PTAB, there is no adjudicated evidence either way.

Weakest link for an invalidator: claim 4. A pure "prevent covert information flow" functional limitation is harder to meet with product literature alone, and VSLAN's covert-channel work was on the NTCB partition. Expect that claim (and only that claim) to carry whatever survivability the patent has.


7. Explicit caveats

  • I could not retrieve '209's face-page "References Cited" list, so I cannot tell you which of R1–R7 were actually before the Examiner, nor whether any of them was overcome by a Rule 131 affidavit, declaration, or terminal-disclaimer-driven amendment. A real § 103 opinion requires the file wrapper (USPTO Patent Center, App. 08/270,398).
  • Dates for the VSLAN and Boeing MLS LAN public-use/§ 102(b) status rest on trade-press and NCSC/DTIC documents I found (Tech Monitor, DP&CS Winter 1989; CSC-PB-003-88). I did not verify the exact public-availability date of each document against a library receipt date or postmark. The VSLAN evaluation report of 25 July 1990 falls inside the one-year grace period measured from 1990-07-11; the § 102(b) hook for VSLAN is the 1988–89 public demonstrations and press, not the 1990 report.
  • Post-priority references were excluded (CSC-EPL-91/005; US 5,596,718; US 5,272,754). Do not let them into a § 103 chart for this patent.
  • Per the strict-ID rule: US 5,255,209, 5,615,159, 5,832,228, 5,872,847, 6,212,636 and 5,940,591 are different patents and their art/prosecution histories do not transfer here.
  • Most importantly: this patent expired 2013-11-19. A § 103 analysis is therefore academic unless it is being run for a retrospective purpose (e.g., a pre-expiry damages period within the § 286 window, a reissue/laches question, or an IPR-style collateral attack). Nothing here should be read as advice that a live invalidity defense exists — there is no live patent to defend.

Generated 9/30/2026, 5:44:11 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →