Invalidity dossier
US 5850516
Method and apparatus for analyzing information systems using stored tree database structures
Current assignee: BT Americas Inc
Added 9/29/2026, 3:26:17 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for authoritative information on this specific patent number.
Let me check specifically for any litigation or CAFC activity involving this patent.
Let me retrieve the full claim set to identify all independent claims.
US Patent 5,850,516 — Summary
Source basis: The authoritative full text provided in this session (fetched from Google Patents, https://patents.google.com/patent/[US5850516](/patent/US5850516)/en), corroborated by Unified Patents (https://portal.unifiedpatents.com/patents/patent/US-5850516-A) and Justia (https://patents.justia.com/patent/5850516).
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 5,850,516 A |
| Title | Method and apparatus for analyzing information systems using stored tree database structures |
| Inventor | Bruce Schneier |
| Application number | US 08/772,413 |
| Filing date | 1996-12-23 (priority date 1996-12-23) |
| Issue date | 1998-12-15 |
| Original assignee | Individual (Bruce Schneier) |
| Current assignee | BT Americas Inc. (parent company: British Telecommunications PLC) |
| Status | Expired – Lifetime; anticipated expiration 2016-12-23 |
| Cited classifications | H04L63/14, G06F21/57, H04L9/40, G06F2211/007, Y10S707/99939 |
Assignment chain: (1) 2000-10-27 — assigned to Counterpane Internet Security, Inc. (assignor: Schneier, Bruce, d/b/a Counterpane Systems); (2) 2010-09-10 — BT Counterpane Internet Security, Inc. (merger); (3) 2016-02-01 — BT Americas Inc. (merger).
⚠️ Data discrepancies I will not silently reconcile (per your instruction to interpret identifiers literally):
- Unified Patents lists the priority date as 1996-12-22, grant date 1998-12-14, and expiration 2016-12-22; the Google Patents record and the full text say 1996-12-23 / 1998-12-15 / 2016-12-23. I treat the Google Patents/full-text dates as authoritative here, but the one-day offset is unexplained and worth noting.
- Unified Patents lists two examiners (Elisca, Pierre Eddy; Decady, Albert). I have not independently confirmed which is primary.
Abstract
A computer-implemented method and apparatus electronically represent and quantify the security of a system as a logical tree structure ("attack tree") including leaf nodes representing attacks against the system and intermediate nodes representing logical combinations of attacks necessary to mount a successful overall attack. Overall security is quantified in the value of the root node. Node values may be Boolean or continuous (e.g., feasible/infeasible, cost, time, probability), and nodes may represent defenses as well as attacks. Uses include calculating cost/time/probability of attack, listing security assumptions, comparing competing systems, evaluating modifications, subsystem analysis, and allocating a security budget.
Plain-language overview of the independent claims
Claim 1 — the method (the only independent claim fully verified in the authoritative text). A computer-implemented method for evaluating the security of a system, with four steps:
- (a) receive an identifier of the particular system to be evaluated;
- (b) store, in a computer-readable medium, a logic tree data structure representing a security model of that system, the tree having (i) multiple leaf nodes, each representing a particular security attribute of the system, (ii) a root node representing an overall indication of the system's security, and (iii) at least one intermediate node between the leaves and root representing a logical relationship between at least two of those security attributes;
- (c) receive values for the leaf nodes quantifying those attributes; and
- (d) compute a value of the root node that provides an indication of the overall security of the system.
⚠️ Uncertainty about the remaining independent claims
The authoritative text provided to me lists 76 claims total, but the retrieved claim text truncates after the opening words of claim 19 ("...where at least one of said logical relationships include"). A Justia snippet confirms claims 2–31, all of which depend (directly or indirectly) on claim 1 — e.g., claim 2 (Boolean attribute), claim 3 (continuous), claims 4–6 (cost of attack/defense), claim 7 (time), claims 8–12 (probability/likelihood, including attacker awareness), claims 13–16 (countermeasures, including a node pointing to a separate attack tree against the countermeasure), claims 17–19 (algebraic / relational / Boolean logical relationships), claims 20–24 (OR nodes = minimum of children; AND nodes = sum or value exhibited by all children), and claims 25–31 (root indicating attackability/defendability, cost or probability).
I do not have authoritative text for claims 32–76, so I cannot confirm whether additional independent claims exist (e.g., a parallel apparatus/system claim or a computer-readable-medium claim, which the abstract's "method and apparatus" framing suggests). Any statement about those claims would be speculation, and I am flagging that rather than fabricating claim language.
CAFC 2026 docket search result
No CAFC 2026 docket or appellate activity involving U.S. Patent 5,850,516 was found. Consistent with this, the patent is recorded as expired as of 2016-12-23 (term had run), which makes live 2026 appellate litigation on this specific number unlikely.
Two important non-matches to avoid confusion:
- US 8,904,516 (VirnetX/Larson family) is a different patent that has been heavily litigated and appealed. It is not US 5,850,516 despite the shared "516" suffix.
- US 7,895,641 and related BT Americas patents were subject to PTAB proceedings (IPR2023-00889; IPR2019-01325) involving BT Americas and citing Schneier materials — but those proceedings concern other patents in the BT/Counterpane portfolio, not 5,850,516 itself.
If you need the verified full text of claims 32–76 (or confirmation of any additional independent claims), I'd recommend pulling the claim set directly from USPTO PatentCenter or the Google Patents "Claims" tab, since the extract available to me cut off mid-claim 19.
Generated 9/29/2026, 3:26:36 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 5850516. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search litigation databases for this specific patent number.
The initial searches returned only unrelated "516" patents (Ariad, VirnetX, etc.). Let me run more targeted queries.
Bottom line
I found no litigation — none at all — involving U.S. Patent No. 5,850,516. Every search I ran returned either (a) the patent's own bibliographic record, or (b) cases involving different patents whose numbers merely look similar. I did not locate a single district-court case, ITC investigation, PTAB proceeding, or CAFC appeal in which US 5,850,516 was the patent-in-suit or was otherwise adjudicated.
Because that is a negative finding, I want to be precise about what I searched and what I could and could not verify.
What I searched
| Query type | Sources surfaced | Relevant hit for 5,850,516? |
|---|---|---|
| "US 5,850,516 patent litigation" | CourtListener RECAP dockets (Ariad/Lilly), SEC filings, CAFC Rule 36 judgments | No — all hits were other "516" patents |
"5850516" patent lawsuit defendant plaintiff |
Unified Patents patent record for US-5850516-A | No litigation data — bibliographic record only |
| Unified Patents litigation/caselist for US-5850516-A | Unified portal patent page | No associated cases listed |
| Counterpane / Schneier / BT Counterpane infringement suits | BT Americas v. Palo Alto Networks (D. Del. 1:22-cv-01538); IPR2023-00889; IPR2019-01325 | No — these concern the Schneier Patents '237 and '641, not '516 |
| "attack tree" patent litigation | None on point | No |
The most substantive "Schneier patent" enforcement activity I found is BT Americas, Inc. and British Telecommunications plc v. Palo Alto Networks, Inc., D. Del. Case No. 1:22-cv-01538-CJB (JURY TRIAL DEMANDED; Schneier declaration filed 03/20/2023). The complaint (available via PTAB petition exhibits and CourtListener) expressly defines the "Schneier Patents" as U.S. Patent Nos. 7,159,237 and 7,895,641 — the Counterpane network-intrusion-detection patents. 5,850,516 is not among them. Likewise, IPR2023-00889 (Palo Alto Networks v. BT Americas) and IPR2019-01325 concern the '237/'641 family. I flag these only so they are not mistaken for litigation on the '516 patent.
Non-matches I explicitly ruled out (to prevent confusion)
Per your instruction to interpret identifiers literally, these are different patents despite matching or containing "516":
- U.S. Patent 5,850,516 — the patent at issue here. No litigation found.
- Ariad Pharmaceuticals' '516 patent — the NF-κB patent litigated in Amgen Inc. v. Ariad Pharmaceuticals, Inc., D. Del. 1:06-cv-00259-MPT (and related Massachusetts actions; ultimately Ariad Pharms., Inc. v. Eli Lilly & Co., 560 F.3d 1366 (Fed. Cir. 2009)). Different patent, different field.
- U.S. Patent 8,904,516 (VirnetX/Larson family) — heavily litigated and subject to IPR2016-01585. Different patent.
- U.S. Patent RE42,893 / RE'516 (Cephalon) — appears in FTC v. Cephalon. Different patent.
- U.S. Patent 8,794,516 (Racz et al.) — subject of a CBM review. Different patent.
None of these is US 5,850,516, and I have not treated them as such.
Why a null result is credible here
This is consistent with the patent's status already established in the prior sections of this analysis:
- Status: Expired – Lifetime; anticipated expiration 2016-12-23 (Google Patents; full text).
- An expired patent generates no live infringement litigation, and an assertion campaign would have had to occur during the ~18-year enforceable term (1998–2016).
- The BT/Counterpane enforcement activity that did occur (Fortinet, Palo Alto Networks) targeted the later Counterpane patents ('237/'641), not this 1996-era Schneier patent.
So the absence of litigation on 5,850,516 is not merely a search gap — it is consistent with the record.
Caveats / confidence level
- Confidence that no litigation exists: moderate-to-high, not absolute. I could not directly query PACER (paywalled) or run a full Docket Navigator / Lex Machina docket query. My conclusion rests on open sources: Unified Patents' patent page (which lists no cases), CourtListener, and targeted web searches.
- PTAB/CAFC check: None found. Because 5,850,516 expired in 2016, post-grant challenges (IPR/CBM, available only from 2012) and 2026 appellate activity are unlikely; the CAFC 2026 docket contains no appeal on this number.
- No auto-correction applied: I did not fold in the '237/'641 or other "516" matters.
If you need a definitive negative, the authoritative check would be a paid docket search (Docket Navigator or Lex Machina) keyed strictly to 5,850,516, plus a PACER "patent number" search across all district courts and the Federal Circuit. On the open record I have, the answer is: no known litigation involving US 5,850,516.
Sources cited
- Google Patents, US5850516A — https://patents.google.com/patent/US5850516/en (status: Expired – Lifetime; expiration 2016-12-23)
- Unified Patents patent page, US-5850516-A — https://portal.unifiedpatents.com/patents/patent/US-5850516-A (no litigation listed)
- BT Americas, Inc. v. Palo Alto Networks, Inc., D. Del. 1:22-cv-01538-CJB — https://www.courtlistener.com/docket/66536720/23/bt-americas-inc-v-palo-alto-networks-inc/ (Schneier Patents = '237 and '641, not '516)
- PTAB petition exhibits identifying the Schneier Patents as '237/'641 — https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1553979](/patent/1553979)/...
Generated 9/29/2026, 3:30:58 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the structured "no PTAB activity" default against live sources before producing the analysis.
Let me run more targeted checks, including CBM and specific trial-number patterns.
Let me check for any litigation/reexam context and confirm the Google Patents record shows no AIA trials tab.
PTAB / AIA Trial Analysis — U.S. Patent No. 5,850,516
Proceedings overview
Total AIA trial proceedings on this patent: ZERO. The canonical structured block in this prompt states plainly that "The USPTO ODP API returns no AIA trial proceedings for this patent as of the most recent ingest," and my independent web verification found no IPR, PGR, or CBM naming U.S. 5,850,516 as the challenged patent — so the breakdown across the requested categories (active / claims invalidated / claims sustained / settled / institution denied) is 0 / 0 / 0 / 0 / 0. The bottom-line defensive posture is unusual for a defendant: this is not a "hardened" patent that survived attack, and it is not a "dead-claims" patent narrowed by an FWD — it is an untested, expired patent, where every one of the 76 claims (including claim 1) stands with its original validity presumption intact but with zero remaining term. The defensive playbook is therefore not IPR-driven at all; it is patent-term-expiration and damages-limitation driven (see Strategic summary).
Verified sources for the "zero" count:
- Structured USPTO ODP block supplied in this prompt (canonical).
- Google Patents, US5850516A — the record shows no AIA trial adjudication, no adverse validity determination, and no asserted-claim cancellation.
- Unified Patents patent page, US-5850516-A — no PTAB trial listing.
- RPX Insight, US5850516A — status "Expired due to Term," no PTAB tab content.
⚠️ Near-misses I confirmed are NOT proceedings against this patent
Because this is a highly-cited Schneier patent, several search hits look like PTAB activity on 5,850,516 but are not. I flag these explicitly so a defendant's outside counsel does not mis-brief them:
| Hit | What it actually is | Why it is not an AIA trial on '516 |
|---|---|---|
| IPR2023-00889, Palo Alto Networks, Inc. v. BT Americas Inc. (FWD, 2024-11-07) | IPR on a different BT/Counterpane-family patent (Counterpane MSM "threat detection" claims 1 and 18) | Challenged patent is not 5,850,516; the FWD references Counterpane MSM and Schneier only as background/objective-indicia evidence |
| CBM2015-00006 (Epicor Software Corp. v. U.S. Pat. 8,402,281) | CBM trial on US 8,402,281; exhibit 1002 is a Declaration of Bruce Schneier filed by the petitioner | Schneier appears as a testifying expert against someone else's patent, not as patent owner defending '516 |
| Various IPRs citing "Schneier" as prior art (e.g., the '602-patent petition referring to US 5,978,475 to Schneier et al.) | Use of a different Schneier patent ('475) and/or the Applied Cryptography textbook as § 102/§ 103 art | The '475 patent and the textbook are separate works; '516 is not the challenged patent |
| Lippmann et al. application family (e.g., US 10/734,083) | Prosecution rejection of claims 1–31 etc. under pre-AIA § 103(a) "as being anticipated by Schneier (U.S. Patent Number 5,850,516) in view of Steffan et al." | This is ex parte examination at the examiner level, not an AIA trial — but it is strategically useful (see below) |
I did not find any PTAB proceeding number to report, and I have deliberately not invented one.
Strategic summary
Claim status — CANCELED vs. SUSTAINED vs. UNTESTED. There is no claim-level adjudicative record for 5,850,516 anywhere in the AIA trial system. All 76 claims are UNTESTED before the PTAB; zero are canceled; zero are sustained by any PTAB decision. If you are being asserted against, you cannot say "claim 1 is already dead" — but you also cannot be met with "this patent has survived two IPRs and is hardened." The secondary section of this analysis flagged that the authoritative text truncates mid-claim 19 and that claims 32–76 (which likely include parallel apparatus / computer-readable-medium claims, given the abstract's "method and apparatus" framing) are unverified; that gap matters for a defendant because the asserted claim may well live in the unretrieved range. Pull the certified claim set from USPTO PatentCenter before responding to any demand letter.
Estoppel landscape (§ 315(e)(2)) — a clean slate. Because no AIA petition was ever filed, there is no § 315(e)(2) estoppel binding anyone, no § 325(d) "same art previously presented" discretionary-denial ammunition generated by a prior petitioner, and no RPI/privity chain to trace. A defendant today retains the full universe of § 102/§ 103 art, including art that a prior petitioner would have been estopped from re-raising. This is the one genuine upside of the zero count. Note also that the CBM statutory window closed on 2020-09-16, so CBM is no longer available at all; PGR is unavailable because the patent has pre-AIA priority; and IPR is the only remaining AIA vehicle (see below).
Pattern signals. No petitioner has ever filed against this patent (so no serial-filer pattern). The patent owner side is BT Americas Inc. (via Counterpane → BT Counterpane → BT Americas mergers), and BT/Counterpane has been a PTAB respondent on other patents (IPR2023-00889; IPR2019-01325 per the prior section) — meaning the portfolio, not this patent, absorbed the attacks. No defensive aggregator (e.g., Unified Patents) appears anywhere in the chain for '516; Unified's page is merely informational. The patent owner has never prosecuted a PTAB appeal on this number, consistent with the prior section's finding of no CAFC 2026 docket activity.
The dominant fact is expiration, not validity. Term ran on 2016-12-23 (Google Patents/full text; Unified shows a one-day offset, 2016-12-22 — unresolved, and flagged in the prior section). An expired patent can still be the subject of a suit for past infringement, but recovery is capped by 35 U.S.C. § 286, which bars damages for infringement occurring more than six years before the complaint is filed. A complaint filed on or after 2022-12-23 cannot reach any infringement after expiration, and a complaint filed in 2026 cannot reach conduct before 2020 — by which time the patent had already been expired for over three years. In plain terms: "patent expired 2016-12-23" is the dispositive defense here, and it is stronger than any IPR could be.
Recommended next steps
If you are a defendant receiving an assertion letter on 5,850,516:
- Lead with § 286, not validity. Demand the plaintiff identify the specific accused acts and their dates. Any accused conduct on or after 2016-12-23 is outside the patent term. Any conduct more than six years before the complaint is § 286-barred. On the timeline of an expired-2016 patent asserted in 2026, this is very likely dispositive before validity is even reached — and no PTAB decision exists to cite because none was needed.
- Do not file an IPR on autopilot. There is no categorical bar to IPR of an expired patent, and the Board has instituted such proceedings, but the practical return is limited to defeating past damages. Weigh cost against the § 286 defense, and note that Board practice applies Phillips claim construction to expired-claim IPRs. If you do file, remember § 315(b)'s one-year bar from service of the complaint.
- If expedited validity cover is wanted, use ex parte reexamination instead — it is not subject to the AIA trial timelines, and the patent has never been through any post-issuance validity challenge, so there is no estoppel or § 325(d) baggage.
- Weaponize '516 as prior art. The Lippmann prosecution record shows examiners applying Schneier US 5,850,516 in § 103 rejections against later attack-tree/security-modeling claims. If the plaintiff's other patents in the portfolio are in play, '516 is a ready-made § 102(e)/§ 102(b)-era reference.
- Verify the claim set. Obtain the certified copy of all 76 claims from USPTO PatentCenter (or the Google Patents "Claims" tab) so the truncation after claim 19 in this analysis does not leave you guessing at the asserted claim.
- Confirm the assignment/demand is from the right party. Current assignee of record is BT Americas Inc. (parent: British Telecommunications PLC), per the 2016-02-01 merger filing. A demand from an entity purporting to hold '516 outside that chain should be challenged.
Trial-stage milestones: Not applicable — there are no pending proceedings, so there is no institution-decision deadline, no oral hearing, and no statutory 1-year FWD due date to calendar.
Plain statement of the absence: There is no PTAB activity on US 5,850,516. Per the instruction in the task, I note the signal: the absence is explained by expiration in 2016, not by the patent being unassailable. A patent this broadly cited in security-analysis literature, if it had meaningful remaining term, would almost certainly have attracted an IPR; it did not, because by the time AIA trials became routine the patent had already lapsed.
Confidence and limitations (stated plainly, not fabricated):
- High confidence in the zero count: it rests on the canonical ODP block plus three independent corroborating sources and multiple targeted searches.
- Medium confidence on the § 286 timing arithmetic: this is a straightforward application of the statute to the recorded expiration date, but I have not seen the actual complaint/s, and the operative filing date drives the result.
- Not verified: the full text of claims 32–76, and whether any non-AIA vehicle (ex parte reexamination, district court validity holding) touched this patent. I found none, but absence of evidence in my searches is not proof of absence.
- Unresolved discrepancy carried forward from the prior section: Unified Patents shows priority/grant/expiration one day earlier (1996-12-22 / 1998-12-14 / 2016-12-22) than the Google Patents full text (1996-12-23 / 1998-12-15 / 2016-12-23). I used the full-text dates; the one-day gap is unexplained and, at a term-expiration boundary, worth confirming against the certified file wrapper.
Generated 9/29/2026, 3:31:14 PM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2000-10-27 · Assignment
Schneier, Bruce, d/b/a Counterpane SystemsCounterpane Internet Security, Inc.
internal reorg
? · recorded 2010-09-10 · Merger
Counterpane Internet Security, Inc.BT Counterpane Internet Security, Inc.
internal reorg
? · recorded 2016-02-01 · Merger
BT Counterpane Internet Security, Inc.BT Americas Inc.
internal reorg
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment record for US 5,850,516 across the sources you specified.
Let me dig into the assignment reel/frame specifics and the Google Patents legal events.
Assignment Record — US 5,850,516 (Schneier)
Scope / evidence caveat (read first). The authoritative full text supplied in this session gives me the substance of the ownership chain via the Google Patents "legal events" block (assignor, assignee, conveyance type, and event dates). I was not able to retrieve the reel/frame numbers or the correspondent-of-record for any of the three events. My Assignment Center queries returned no indexed reel/frame data in this session, and the Assignment Search endpoints at
assignmentcenter.uspto.gov/assignment.uspto.govwere not directly reachable. Per your constraint against fabrication, I am not inventing reel/frame numbers or attorney names. Everything below that is a recorded assignment comes from the legal-events block; everything about correspondents is marked not retrievable. Treat the chain as directionally reliable and the identifiers as needing verification at the Assignment Center.
Inventors
| Inventor | Employer at filing | Notes |
|---|---|---|
| Bruce Schneier (sole named inventor) | Counterpane Systems — his own security-consulting practice, run as a sole proprietorship (Oak Park, IL / Minneapolis, MN). He lists "1993–1999, President, Counterpane Systems" in his sworn IPR2019-01324 declaration. | At the 1996-12-23 filing date, Counterpane Internet Security, Inc. did not yet exist — he co-founded it with Tom Rowley in summer 1999. So the corporate entity that later took the patent was not the filer's employer. |
Unusual-pattern check: Not present. There is no multi-inventor group to fragment. Schneier did not depart within 12 months of filing — he stayed through the Counterpane/BT years and, per his own declaration, "continued to work at Counterpane after its acquisition by BT until 2012." The classic "all inventors bolt, then fire-sale" precursor is absent. The only notable structural fact is a solo inventor filing personally and later contributing the patent to the company he founded.
Cross-reference: this corroborates the "Inventor" field in the previously generated bibliographic section; no contradiction.
Original assignee
- Google Patents records the original assignee as "Individual" — i.e., no corporate assignee named on the issued patent. The patent issued (1998-12-15) owned personally by Bruce Schneier, consistent with him operating as the sole proprietorship Counterpane Systems.
- Product embodying the claims: No evidence of a shipped product practicing claim 1 at or before issue. Counterpane Systems was a consulting practice, not a product company; the attack-tree methodology was Schneier's analytical work. The managed-security service that eventually used related Schneier technology came later (2000 onward, per his declaration) and is tied to the '237 and '641 patents, not to the '516 claims.
- Primary line of business: information-security consulting (sole proprietorship).
- Current status: N/A for the sole proprietorship. The successor corporate entity, Counterpane Internet Security, Inc. (formed 1999), launched a commercial managed-security-monitoring service, was acquired by BT Group in 2006 (Schneier declaration; BT M&A case study), rebranded BT Counterpane, and was absorbed into BT Americas Inc. — the current assignee of record. BT Americas is an operating subsidiary of British Telecommunications plc.
Assignment timeline
Three recorded post-issuance events appear in the Google Patents legal-events record. Reel/frame and correspondent are not retrievable in this session and are flagged as such rather than guessed.
2000-10-27 (recorded) — Reel not retrievable / frame not retrievable
- Conveyance: Assignment
- Assignor: Schneier, Bruce, d/b/a Counterpane Systems
- Assignee: Counterpane Internet Security, Inc.
- Correspondent: not retrievable
- Context: Transfer to the operating company Schneier co-founded in 1999 — housekeeping to align the personally held patent with the new corporate vehicle. Not a shell transfer: assignee was a live operating company.
2010-09-10 (recorded) — Reel not retrievable / frame not retrievable
- Conveyance: Merger
- Assignor: Counterpane Internet Security, Inc.
- Assignee: BT Counterpane Internet Security, Inc.
- Correspondent: not retrievable
- Context: Internal corporate reorganization following BT Group's 2006 acquisition of Counterpane — merger, not a sale to a third party.
2016-02-01 (recorded) — Reel not retrievable / frame not retrievable
- Conveyance: Merger
- Assignor: BT Counterpane Internet Security, Inc.
- Assignee: BT Americas Inc.
- Correspondent: not retrievable
- Context: Internal reorganization absorbing BT Counterpane into BT Americas Inc. — the current assignee of record.
Cross-references and one discrepancy to flag: Schneier's 2022 declaration in BT Americas, Inc. v. Palo Alto Networks, Inc. (D. Del. 1:22-cv-01538) states Counterpane "was acquired by BT Group plc in 2006, and eventually merged into BT Americas, Inc. in 2011." The recorded legal events show the BT-Counterpane merger recorded 2010-09-10 and the BT Americas merger recorded 2016-02-01. The declaration's "2011" is inconsistent with the recorded 2010/2016 dates — most likely the declaration is speaking loosely to the corporate merger timeline while the record dates reflect assignment-recording dates, but I cannot reconcile them further without the reel/frame documents. This is flagged, not silently corrected. (The same one-day priority/grant/expiration discrepancy noted in the prior section — 1996-12-22 vs 1996-12-23 in Unified Patents vs Google Patents — also stands unresolved.)
Timeline diagram
timeline
title Ownership of US 5850516
1996 : Filed by Bruce Schneier
1998 : Patent issued to Schneier
2000 : Assigned to Counterpane Internet Security
2010 : Merged into BT Counterpane
2016 : Merged into BT Americas Inc
2016 : Patent term expires
NPE / troll-pattern signals
| # | Signal | Call | Basis |
|---|---|---|---|
| 1 | Shell-entity transfer | Not present | Every link is an operating entity: Schneier d/b/a Counterpane Systems → Counterpane Internet Security, Inc. → BT Counterpane → BT Americas Inc. No "IP/Holdings/Ventures" suffix, no registered-agent-service address, no single-member LLC. |
| 2 | Known asserter in the chain | Not present | None of the assignees matches the NPE directories (Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, etc.). Terminal owner BT Americas is an operating subsidiary of British Telecommunications plc. |
| 3 | Repeat correspondent across the chain | Unclear | Correspondent-of-record could not be retrieved for any of the three recordings, so recurrence cannot be assessed. This is the signal most worth re-checking at the Assignment Center — see verification note. |
| 4 | Cascading transfers (<24 mo through chained LLCs) | Not present | The three transfers are spaced ~10 years (2000), then ~5.4 years (2010), then ~5.4 years (2016). Two of the three are mergers, i.e., corporate reorganizations, not serial shell pass-throughs. |
| 5 | Pre-litigation transfer | Not present | No infringement suit naming 5,850,516 was found. The BT Americas assertion activity that exists (v. Palo Alto Networks, D. Del. 1:22-cv-01538) concerns the '237 and '641 patents, not this one, and post-dates the last assignment by ~6 years. |
| 6 | Bankruptcy fire-sale | Not present | No bankruptcy by any assignor; the transfers were an acquisition and two mergers, not distressed sales. |
| 7 | Privateering | Not present | BT is the ultimate owner of the portfolio through ordinary corporate acquisition; there is no evidence of an operating company parking assets with an NPE to assert on its behalf. |
| 8 | Defensive aggregator (anti-NPE) | Not present | Chain does not terminate at RPX, AST, LOT, Unified, or OIN — it terminates at an operating telecom subsidiary. |
Net: on the evidence available, zero affirmative NPE signals. The two ambiguous items are (3) correspondent — unretrievable, and the date discrepancies already flagged.
Verdict
Operating-company assertion (closest fit; with an express caveat).
Justification: the ownership chain runs from the solo inventor personally (issued 1998-12-15 as "Individual") to the operating company he founded, then through two recorded mergers — 2010-09-10 (Counterpane Internet Security, Inc. → BT Counterpane Internet Security, Inc.) and 2016-02-01 (BT Counterpane → BT Americas Inc.) — landing at an operating subsidiary of British Telecommunications plc. There is no shell entity, no known NPE, no cascading LLC pass-through, and no fire-sale, so no NPE verdict is supportable. The caveat: the strict definition of "operating-company assertion" (current owner suing actual competitors on this patent) is not evidenced for 5,850,516 — no suit naming it was found, and the patent expired 2016-12-23. In substance this is an expired, non-asserted operating-company asset in the BT/Counterpane portfolio; the BT Americas enforcement campaigns run on sibling patents ('237, '641).
Verify at: the Assignment Center search page for this patent — https://assignmentcenter.uspto.gov/ (search patent number 5850516) and the mirrored index https://assignment.uspto.gov/patent/index.html. Request the reel/frame and correspondent fields for all three events to close out signal (3) and to confirm the exact execution vs. recording dates against the 2010/2016 discrepancy.
Generated 9/29/2026, 3:31:14 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll search for the citation record of US 5,850,516, focusing specifically on that number and its cited references.
Let me dig deeper for the citation record specifically.
Let me pull the front-page citation data and the Google Patents "Patent Citations" table for this specific number.
Scope note and a hard limitation I must flag first
I ran the searches you asked for, targeted narrowly at US 5,850,516 (Schneier). Two things you should know before the analysis:
I could not retrieve the front-page "References Cited" list for US 5,850,516. The authoritative full text provided in this session begins at the "Definitions/Background" body text and omits the front page entirely — i.e., it does not contain the "U.S. Patent Documents," "Foreign Patent Documents," or "Other Publications" lists that appear in columns 1–2 of the printed patent and under the "Patent Citations" tab on Google Patents. My follow-up searches for that specific table were cut off before returning it. I will not invent patent numbers to fill that table. Per your rule ("if you do not know something with high confidence, say so explicitly rather than fabricating"), I am flagging the gap rather than papering over it.
The identifier was not confused. Every result I relied on resolves to US 5,850,516 (App. 08/772,413, filed 1996-12-23, issued 1998-12-15, inventor Bruce Schneier). I discarded hits on the similarly numbered US 8,904,516 (VirnetX/Larson) and I did not treat "516"-suffixed references from other families as this patent.
⚠️ Contradiction check vs. the prior section: Nothing here contradicts the earlier summary. The Unified Patents one-day offset re-appeared (Unified: priority 1996-12-22 / grant 1998-12-14 / expiration 2016-12-22, vs. Google Patents and the printed patent: 1996-12-23 / 1998-12-15 / 2016-12-23). I continue to treat the Google/printed-patent dates as authoritative and the offset as unexplained.
What I could actually verify about "citations for 5850516"
The citation picture for this patent has three distinct populations, and only one of them is prior art. Conflating them is the main error risk in this task.
Population 1 — References cited in the 5,850,516 specification (applicant-cited, from the authoritative text)
These are the only "references cited" I can ground in the authoritative document. All appear in the Background of the Invention as context for the problem, not as anticipatory art.
| # | Full citation (as it appears in the patent) | Date | Brief description | Source/confidence |
|---|---|---|---|---|
| 1 | Bruce Schneier, Applied Cryptography, 2nd Edition, John Wiley & Sons, 1996, pp. 65–68 | 1996 | Introduction to formal cryptographic-protocol analysis (BAN logic, GMY logic, NRL Protocol Analyzer). | Authoritative text (confirmed) |
| 2 | Ken Wong & Steve Watt, Managing Information Security, Elsevier Science Publishers, 1990, Ch. 5 | 1990 | Information-security risk management reference. | Authoritative text (confirmed) |
| 3 | K. M. Jackson & J. Hruska, Computer Security Reference Book, Butterworth-Heineman, 1992, Ch. 21 | 1992 | Risk-analysis reference. | Authoritative text (confirmed) |
| 4 | Philip Fites & Martin Katz, Information Systems Security, Van Nostrand Reinhold, 1993, Ch. 3 | 1993 | Risk-analysis reference. | Authoritative text (confirmed) |
| 5 | Zella Ruthberg & Harold Tipton, Handbook of Information Security Management, Auerbach Publishers, 1993, Ch. 1-3-1 | 1993 | Risk-analysis reference. | Authoritative text (confirmed) |
| 6 | Zella Ruthberg & Harold Tipton, Handbook of Information Security Management, 1994–95 Yearbook, Auerbach, 1994, Ch. 1-3 | 1994 | Risk-analysis reference. | Authoritative text (confirmed) |
| 7 | FIPS 65 — U.S. Government document (basis for quantitative risk analysis; assets/threats + cost × frequency → formula). | Not stated in patent | Quantitative risk-analysis methodology the patent criticizes as "highly formal" but "highly inflexible." | Authoritative text names FIPS 65; exact title/date not stated in the patent text I hold — I believe it is NBS FIPS PUB 65, Guideline for Automatic Data Processing Risk Analysis, but I am not high-confidence on the exact title/year and will not assert it. |
Named (but not formally cited) background tools/techniques that could be developed into prior art if you pursue this further: BAN logic (Burrows/Abadi/Needham), GMY logic (Gong/Needham/Yahalom), NRL Protocol Analyzer (Meadows) — formal protocol-analysis tools; and the risk-analysis packages RISKCALC (Hoffman Business Associates, Bethesda, MD), BDSS (Pickard, Lowe and Garrick, Newport Beach, CA), RISKWATCH, IST/RAMP, LAVA, RISKPAC, MARION, CRAMM, and the Buddy System. I can date these only from general knowledge (BAN ~1990; GMY ~1990; NRL ~1991; CRAMM mid-1980s), so treat those dates as low/medium confidence and verify before relying on them.
📌 Unified Patents reports "Non-Patent Literature (12)" for this patent (https://portal.unifiedpatents.com/patents/patent/US-5850516-A). I have enumerated ~7 from the body text; the remaining NPL items live on the front page I could not retrieve.
Population 2 — Forward citations ("Cited By"): NOT prior art
Google Patents shows US 5,850,516 cited by many later documents, e.g.:
- Mu Dynamics / Spirent patents: US 8,095,983; US 8,359,653; US 8,590,048; US 7,958,560; US 8,631,499; US 8,316,447; US 9,172,611 (protocol/security analysis platforms) — see https://patents.google.com/patent/US20060021046A1 ("Cited By (57)").
- MIT / Lippmann et al.: US 7,971,252 and US 2009/0293128 A1, "Generating a multiple-prerequisite attack graph" (application 10/734,083).
- US 2006/0021046 A1 ("Techniques for determining network security") and US 2006/0021049 A1 ("Techniques for identifying vulnerabilities in a network").
- US 7,017,185 ("Method and system for maintaining network activity data for intrusion detection"), which lists 5,850,516 among its own 9 patent citations.
These post-date 1996-12-23 by construction and therefore cannot be § 102 prior art against 5,850,516. Unified Patents lists Referenced By (68); the typeset.io record shows ~100 forward citations. They are useful only as evidence of the field's development.
Population 3 — Third-party use of 5,850,516 as prior art against later applications
This is where 5,850,516 actually functioned as a reference, and it's worth recording because it tells you what the Office considered the closest art around it:
- In the prosecution of Lippmann et al. application 10/734,083, claims were rejected under 35 U.S.C. § 103(a) "as being anticipated by Schneier (U.S. Patent Number 5,850,516) in view of Steffan et al ("Collaborative Attack Modeling")." (https://ia800109.us.archive.org/20/items/gov.uspto.patents.application.[10734083](/patent/10734083)/10734083-2006-04-11-00005-REM_text.pdf)
- A related office action shows a combination of "Adler, Cline and Schneier" further in view of Swiler: "The rejection of Claims 11-12 and 69-70 under 35 U.S.C. § 103(a) as being unpatentable over Adler, Cline and Schneier and further in view of Swiler is hereby traversed…" (https://archive.org/download/gov.uspto.patents.application.10734083/10734083-2005-12-02-00009-REM_text.pdf)
- Note the notable admission: "The Examiner also tentatively agreed that Schneier does not show a root node at a start of an attack but is the goal of the attack."
⚠️ These are not prior art to 5,850,516 — Steffan, Swiler, and the Adler/Cline references all post-date 1996. They matter only as a signal of which other art the Office paired with Schneier. (I am not confident about the identity of the "Adler" and "Cline" references — I won't guess inventor names or dates for them.)
§ 102 anticipation analysis of the references I can verify
The controlling question: does any verified reference disclose all of claim 1's elements —
(a) receive an identifier of a system; (b) store a logic tree data structure having (i) leaf nodes each representing a security attribute, (ii) a root node representing overall security, (iii) an intermediate node representing a logical relationship between ≥2 attributes; (c) receive values for the leaf nodes quantifying the attributes; (d) compute a root-node value indicating overall security?
| Reference | § 102 status | Reasoning |
|---|---|---|
| FIPS 65 / quantitative risk analysis family (IBM method, RISKCALC, BDSS, RISKWATCH, IST/RAMP) | No anticipation of any claim. Possible § 103 background only. | These compute an "annual loss expectancy" from assets + threats + cost + frequency via a single rigid formula. There is no logic tree with leaf/root/intermediate nodes, no leaf-node values mapped to security attributes, and no root node representing overall security. The patent itself frames these as the problem, expressly criticizing the approach as "highly formal" but "highly inflexible." |
| Wong & Watt (1990); Jackson & Hruska (1992); Fites & Katz (1993); Ruthberg & Tipton (1993, 1994–95) | No anticipation. § 103 background at most. | General risk-management texts. Nothing establishes a stored attack/logic tree with computed root-node security value. Applicant-cited as describing the state of risk analysis. |
| Applied Cryptography, 2nd Ed. (1996), pp. 65–68 | No anticipation. | Describes BAN/GMY/NRL-style formal cryptographic-protocol checking — the analyst encodes a protocol as formal-logic statements, and the machine concludes security/insecurity. No attack tree, no security-attribute leaf nodes, no computed overall-security root value. Also authored by the inventor (Schneier), so its § 102(b)/§ 103 value even as art is attenuated. |
| BAN logic (Burrows/Abadi/Needham), GMY logic (Gong/Needham/Yahalom), NRL Protocol Analyzer (Meadows) | No anticipation. § 103 background. | Symbolic protocol-reasoning tools examining the protocol "in its ideal mathematical state"; the patent expressly distinguishes them from attack trees that "look at the entire system, as it is installed and used." |
Bottom line on § 102: On the record I can verify, no reference anticipates claim 1 or any dependent claim. The patent's own background admits the generic idea of formal security/risk evaluation (which is why the claims are drafted around the stored logic-tree structure with logic nodes and a computed root value), and the cited art lacks that structure. The realistic invalidity theory, if one existed, is § 103 over the quantitative-risk-analysis art (FIPS 65 family) in view of tree/graph data-structure art — not § 102.
What is missing, and exactly how to close it
To satisfy "each patent citation for 5850516" literally, someone must pull the front page. Recommended sources, in order:
- USPTO PatentCenter for application 08/772,413 — the "References Cited" / "IDS" documents give the exact U.S. patent documents, foreign documents, and 12 NPL items, plus who cited them (applicant vs. examiner). This is the only fully authoritative source.
- Google Patents "Patent Citations" tab for US5850516A (https://patents.google.com/patent/US5850516A/en) — convenient front-page reproduction, but provenance (examiner vs. applicant) can be ambiguous.
- Espacenet record for US5850516 (cited documents + family).
- USPTO Patent Full-Text (Patent Public Search / patft) for the front-page "References Cited."
Once you have that list, the same § 102 template above applies — and I'd predict the outcome will hold: with a 1996 priority date in an era when attack trees were nascent, the front-page patent citations are likely to be general-purpose database/tree data-structure and risk-analysis patents cited for context, none of which would contain the leaf-/root-/intermediate-node + attribute-value + computed-root limitation as a whole.
If you can paste the front-page "References Cited" block (U.S. Patent Documents, Foreign Patent Documents, Other Publications) for 5,850,516, I will run the full per-reference § 102/§ 103 table on it immediately, with claim-by-claim mapping.
Generated 9/29/2026, 3:31:23 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll research the prior art actually associated with this patent before building the § 103 analysis.
Let me pull the specific cited references and the key fault-tree prior art documents.
Obviousness Analysis — U.S. Patent 5,850,516 (Schneier)
0. Threshold caveats (read first)
I do not have a "Prior Art section" from a page. No prior-art table, examiner citation list, or IDS extract was supplied in this session. What I have is (a) the authoritative full text you provided, and (b) web-search results. So this analysis rests on the two things I can actually ground:
- The specification's own admitted prior art. The Background of the Invention is a self-contained prior-art survey (FIPS 65, RISKCALC, BDSS, RISKWATCH, IST/RAMP, LAVA, RISKPAC, MARION, CRAMM, the Buddy System, BAN logic, GMY logic, the NRL Protocol Analyzer, and Applied Cryptography 2d ed. at pp. 65–68). Under §103 an applicant's own characterization of the field is usable against the claims, so this is the strongest available material.
- Fault tree analysis (FTA). Corroborated as a long-standing AND/OR logic-gate methodology with top/intermediate/basic events and bottom-up quantification (https://patents.google.com/patent/EP4105749A1/en, https://patents.google.com/patent/WO2015151014A1, https://patents.google.com/patent/CN116010886B/en — all post-dating the patent and therefore not prior art themselves, but evidence that the FTA construct is conventional).
What I could not retrieve: the front page's cited-art list. Unified Patents records "Patent Art (2)" and "Non-Patent Literature (12)" (https://portal.unifiedpatents.com/patents/patent/US-5850516-A) but my fetches did not return those 14 items. I also could not retrieve the Google Patents "References Cited" tab. I am therefore not naming the two cited U.S. patents, because I cannot verify them and will not fabricate them. Recommend pulling them from USPTO PatentCenter before relying on this.
Statutory posture: priority 1996-12-23 → pre-AIA §103 applies (no AIA §102(d)/§103 changes). A pre-AIA "by another" and §102(b) analysis governs each reference's date.
Scope limits: Claims 1–31 are addressed (all dependent on claim 1 per the prior section). Claims 32–76 were unavailable in the truncated text, so any independent apparatus/CRM claim in that range is unanalyzed. Also note the unresolved one-day date discrepancy already flagged in the Patent Summary (Unified: 1996-12-22/1998-12-14; Google/text: 1996-12-23/1998-12-15). I use the Google/text dates.
One search result must be actively excluded as prior art: Schneier's "Attack Trees," Dr. Dobb's Journal, Dec. 1999 (https://www.schneier.com/academic/archives/1999/12/attack_trees.html). It postdates the 1996 filing by three years, and its figures (the safe tree, the PGP tree, the Windows-95 message tree, the costs, the intrusive/non-intrusive projection) are the very examples in this patent — it is a downstream publication of this patent, not art against it. Multiple search hits conflate the two; do not let that leak into the analysis.
1. PHOSITA
At December 1996, in the field of information-security assessment: a person with a bachelor's degree in computer science, electrical engineering, or a related discipline and roughly 2–3 years' experience in security risk assessment and/or safety/reliability analysis, or equivalently a practicing security analyst familiar with quantitative risk-analysis methodologies (FIPS 65-class methodologies, CRAMM, RISKPAC) plus working knowledge of formal logic-tree techniques from reliability engineering (fault trees, event trees). The patent's own hardware disclosure (§A) requires nothing more exotic than a Pentium P54C workstation, so no special software skill beyond routine programming is implicated.
A useful framing: this is a two-person team — a security/risk analyst (domain) and a reliability/systems engineer (tree formalism). That team is the PHOSITA for combination purposes.
2. Distilling the point of novelty
Stripped of applications, claim 1 requires: (a) take a system ID; (b) store a tree with leaves = security attributes, root = overall security, ≥1 intermediate node = logical relation between ≥2 attributes; (c) take leaf values; (d) compute the root.
The only element not squarely conventional in 1996 is the application of the familiar logic-tree formalism to adversarial/security attributes. Everything structural (leaves, root, AND/OR interior nodes, stored in a computer, bottom-up quantification) is textbook FTA, and everything quantitative (cost, frequency, probability, ALE-style system-level aggregate, countermeasure cost-benefit) is textbook quantitative risk analysis that the patent itself concedes. That asymmetry drives the whole §103 picture: this is a combination-of-known-elements case, and it should be litigated as one.
3. Claim 1 — element mapping
| Claim 1 element | Disclosed by | Notes |
|---|---|---|
| (a) receive identifier of a particular system | FIPS 65 methodology; CRAMM; any QRA tool | Patent's own Background: QRA tools "isolate areas of risk within an organization." Spec step 500 ("user identifies the system") is admitted as conventional. |
| (b) tree stored in computer-readable medium | FTA computer codes (e.g., PREP/KITT, KITT, SETS, FTAP, SAPHIRE — names unverified in session) | FTA was computer-implemented and tree-database-driven well before 1996; §A of the spec treats "stored tree database" as routine. |
| (b)(i) leaf nodes = security attributes | FTA basic events/initiators + risk-analysis threat lists | Structural correspondence is direct. "Security attribute" is the only re-labeling. |
| (b)(ii) root = overall security | FTA top event; FIPS 65 "annual loss expectancy" | Both references yield a single system-level scalar. |
| (b)(iii) intermediate node = logical relation between ≥2 attributes | FTA AND/OR gates (NUREG-0492; IEC 1025:1990) | Explicit, verbatim correspondence. |
| (c) receive leaf values quantifying attributes | FTA basic-event probabilities; FIPS 65 costs + frequencies | Both. FIPS 65: "assign cost values to the assets and determine frequency of occurrence of the threats." |
| (d) compute root value | FTA bottom-up quantification; FIPS 65 formula/ALE | Both. |
Gap: no single reference of record applies the tree to security attributes. That gap is what the obviousness case must close.
4. Grounds of rejection
Ground 1 (primary) — FTA in view of FIPS 65 (or a FIPS-65-class QRA tool such as RISKCALC/BDSS)
KSR rationales: (A) known methods combined to yield predictable results; (C) known technique to improve a similar method in the same way; (D) known technique applied to a known device ready for improvement; (G) problem-driven motivation.
Motivation to combine — and it is unusually well supplied, because the patent articulates it:
- The Background frames the problem as QRA being "highly formal but highly inflexible," and qualitative methods being "flexible but lacking the formalism necessary for rigorous system analysis." FTA is precisely a formal, rigorous, decomposable, quantitative formalism — the missing half. The motivation is therefore derived from a known problem in the field at the time of invention, which KSR expressly permits.
- The Background also complains that risk analysis "often concentrate[s] on the broad risk faced by large system, at the expense of consideration of the individual attacks that are aggregated to build up to the larger picture." That sentence concedes both (i) that aggregation of individual attacks into a system-level picture was known, and (ii) that the unmet need was a rigorous way to do it. A logic tree is the conventional rigorous way.
- FIPS 65 already computes the system-level quantity from asset-and-threat inputs and already evaluates "the effect of countermeasures on individual assets" — so countermeasure-valued nodes (claims 13–16) are supplied too.
Predictability: for counting metrics the composition rules are arithmetic and follow mechanically (AND = sum; OR = min/max in the cost/time direction). No unpredictability to rebut.
The "success tree" point (this is the key rebuttal to the patentee's best argument): the patentee's strongest non-obviousness argument is orientation — FTA's root is a failure, whereas claim 1's root is an attacker's goal. But reliability engineering has long recognized the dual "success tree" (the tree of the complement of the top event, obtained by de Morgan duality, with AND and OR gates swapped). Reorienting the tree from "system fails" to "attacker succeeds" is an application of a known duality, i.e., KSR rationale (B) (substitution of a known element with predictable results) or (C). The patent's own §D.5 (Boolean/continuous tree-combining; treating intrusive attacks as "infinite cost") is just de Morgan-style manipulation of the same structure.
Ground 2 (secondary) — FTA in view of BAN logic / GMY logic / NRL Protocol Analyzer
KSR rationale (F): prompting from one field to another, and (A).
These are the patent's own cited formal tools. They disclose: represent a security problem as formal-logic statements and use a computer to derive conclusions about security or insecurity. That supplies the "second field" whose workers were already doing computerized formal security reasoning — reinforcing the motivation to make QRA formal. Their utility is mainly for claims 17–19 (algebraic / relational / Boolean logical relationships), which are squarely formal-logic operators.
Ground 3 — FTA in view of the patent's admitted-art Background alone
Because the Background is the applicant's admission, an examiner can reject much of claims 1, 13–16, 20–24, and the budget/cost-benefit applications using the specification's own admissions as the primary reference, with FTA only for the tree-structure element. This is the cleanest route vis-à-vis any argument that the commercial QRA tools are non-analogous art.
Ground 4 — The "min/sum AND-OR tree" evaluation (claims 20–24)
Evaluating an AND/OR tree where OR = minimum of children and AND = sum (or all-children value) is the standard min-sum evaluation of an AND/OR graph — the same operation as shortest-path/AND-OR graph search and as minimax over game trees, all standard computer-science fare well before 1996. Independently, the specification's own G4/G4.1.2/G4.1.2.4 worked example (§C.2) is a mechanical min/sum computation. These claims are, in my assessment, very likely obvious; their only content beyond claim 1 is arithmetic.
Ground 5 — Probabilistic claims (claims 8–12)
The specification's probability discussion (§C.3) recites textbook material: OR = addition, AND = multiplication under independence; and, when dependent, P(A or B) = P(A) + P(B) − P(A and B) and P(A and B) = P(A|B)·P(B). This is standard probability and standard quantitative FTA (which propagates probabilities through gates and requires cut-set/independence handling). A probability or reliability text alone, or FTA quantification literature, renders these obvious.
Flag: there is an internal inconsistency worth noting for the record. The claim set (as summarized) appears to tie OR to "minimum of children" for continuous nodes, while the specification's probabilistic section uses OR = addition. If the probability claims import the min rule, they are arguably inoperable/unsupported under §112 as to probability; if they instead import the addition/multiplication rules, they are squarely textbook. Either way, not a §103 rescue.
Ground 6 — Shared/reused subtrees (the asterisk/G8 mechanism)
The G8 example's "* means the node was previously expanded elsewhere" mechanism — nodes with multiple parents (G8.2.1.3.4.1 = G8.1.1.2; and G8.2.2 sharing G8.1.1.2's six children) — corresponds directly to FTA transfer gates and repeated-event/common-cause modeling, which exist to avoid re-drawing a shared subtree. Any claim reciting a node pointing to / re-using a separate tree (e.g., claim 16's "points to a separate attack tree against that countermeasure") is closely matched by this.
5. Dependent claims 2–31
| Claims | Feature | §103 assessment |
|---|---|---|
| 2, 3 | Boolean / continuous attribute | Obvious. FTA supports both qualitative (Boolean cut-set) and quantitative (probability) evaluation; CRAMM/FIPS 65 span binary and continuous measures. |
| 4–6 | Cost of attack / cost of defense | Obvious. FIPS 65 admitted; cost-benefit analysis admitted in Background. |
| 7 | Time as the metric | Obvious. KSR (B) mere substitution of one counting parameter for another; patent admits "cost, time, etc." are interchangeable. |
| 8–11 | Probability of occurrence / attack / defense | Obvious over FTA probability propagation + FIPS 65 frequency estimates. |
| 12 | Probability reflecting attacker's awareness of the attack | Weakest of the probability claims. But it is only a parameterization of the leaf-value semantics; a POSITA modeling attacker choice would include awareness/attempt-probability (the spec's own G4″ distinguishes "will attempt" from "will succeed"). Moderate. |
| 13–15 | Nodes reflect countermeasures (leaf or intermediate) | Obvious. FIPS 65 evaluates countermeasure effect; Background concedes tools "suggest countermeasures." |
| 16 | Countermeasure node points to a separate tree against the countermeasure | Moderate–strong obvious. FTA transfer gates + hierarchical/modular decomposition; patent's own §D.4 treats plug-in subsystems as the point. |
| 17–19 | Algebraic / relational / Boolean logical relationships | Obvious over formal-logic protocol tools (BAN/GMY/NRL) + standard Boolean/algebraic operator sets. |
| 20–24 | OR = min / AND = sum or all-children value | Very strong obviousness (see Ground 4). |
| 25–31 | Root indicates attackability/defendability; cost or probability | Obvious; a root value's interpretation is a labeling choice with no structural content. |
Net: no dependent claim in 2–31 adds a limitation that, on its face, distances the claim from a two-reference combination of (i) a logic-tree/AND-OR formalism and (ii) the admitted QRA art. Whether the unspecified claims 32–76 contain anything stronger — particularly "unknown attack" nodes (the G5 embodiment) or the probability-semantics limitations — is the single most important open question, because the unknown-attack node is the feature most resistant to a two-reference attack: it is a model-completeness device, not a structural or arithmetic one, and the specification gives a bespoke estimation heuristic for it.
6. Testing the theory: the patentee's best rebuttals
A neutral record requires stating these; several are stronger than examiners typically credit.
- Different problem class / no reasonable expectation of success. FTA models unintelligent, independent random failures; security models an adaptive adversary. The patent foregrounds this distinction ("intelligent attacker" vs. "entropy as the attacker"). Because FTA's quantification assumes independence, its arithmetic is arguably inapt for correlated, deliberate, multi-stage attack — so a POSITA might not expect success. Force: moderate at best. It is badly undercut by the specification itself, which immediately says "the mechanism of analysis can be exactly the same." That is a candidate §103 admission and likely disposes of a teaching-away argument (a reference "teaches away" only if it criticizes/discredits the path; here the patent's own text asserts equivalence).
- Orientation (failure root vs. goal root). Answered by the success-tree/dual-tree concept (Ground 1). Force: weak.
- No reference suggests the specific applications. Subsystem plug-in, budget allocation, and modification-impact are admitted in the Background as known risk-analysis goals (cost-benefit analysis; effect of countermeasures). Applications of a known analytical tool are not separate inventive contributions. Force: weak.
- Hindsight. The real hindsight risk is reconstructing the G5/G8/G10 examples (unknown attacks, modular re-use, the "*" mechanism) out of FTA terminology. For claim 1 and claims 20–24 this is not a serious objection; for the unknown-attack and shared-subtree features it is a genuine vulnerability of any Ground 4/6 theory.
- Secondary considerations — see below.
Teaching-away / criticality checks: FTA literature does not criticize using logic trees for adversarial modeling (it simply hadn't been done), so no teaching away. Non-analogous art: a patentee might argue FTA (nuclear/aerospace reliability) is non-analogous to information security. This is answerable — same field of endeavor (quantitative system risk assessment), and "reasonably pertinent to the particular problem" (the patent's own stated problem: formalism without rigidity). But it is the argument most likely to be pressed, and it is worth pre-empting with evidence that the same practitioners/treatises spanned both (FIPS 65's own lineage; risk-analysis texts of the Wong & Watt / Fites & Katz / Ruthberg & Tipton type cited in the Background).
7. Secondary considerations
- Long-felt need: the patent's Background itself documents it (existing tools "either formal but excessively rigid, or flexible but lacking the formalism"). Favorable to the patent owner, but note the need was framed as unmet within risk-analysis practice, and the "failure of others" is partially offset by the fact that FIPS 65 and the FTA community were adjacent and active.
- Industry praise / adoption: the concept became a de facto standard. Nexus is the problem — much of the praise attaches to Schneier's 1999 article and books (post-priority), and to the applications, not to claim 1's structural limitations. Expect a nexus fight.
- Commercial success: any Counterpane-related success must be tied to the claimed features, not to Schneier's reputation or to the services business.
- Copying / failure of others: no strong record identified in this session.
I found no litigation, PTAB, or CAFC record on this patent (consistent with the expiry noted in the Patent Summary), so there is no adverse or favorable administrative record to leverage.
8. Bottom line
| Claim group | Strongest ground | Confidence in §103 |
|---|---|---|
| 1 | FTA (NUREG-0492-class) + FIPS 65/RISKCALC/BDSS | Moderately strong — turns on the FTA-to-security motivation and the analogous-art point |
| 2–7, 13–15, 17–19, 25–31 | Same, plus admitted Background + formal-logic tools | Strong |
| 20–24 | Min-sum AND/OR tree evaluation (standard CS) | Very strong |
| 8–11 | Standard probability + FTA quantification | Strong |
| 12 | Parameter choice only | Moderate |
| 16 | FTA transfer gates + modular decomposition | Moderate–strong |
| Unknown-attack nodes; any claim 32–76 | Not assessable | Unknown — highest-value target for the patentee |
The combination is not a clean single-reference anticipation. It is a classic KSR "familiar elements arranged to predictable ends" case, and its weak point for a challenger is not claim 1 but the unsupplied claims 32–76 and the unknown-attack modeling. I would not opine beyond "a well-constructed combination rejection is viable for claims 1–31 as summarized" without (i) the actual front-page cited-art list, (ii) a verified copy of NUREG-0492/IEC 1025 to cite by pin and date, and (iii) claim text for 32–76.
9. Flags and corrections for the record
- "Prior Art section" not supplied. No prior-art listing was present in the materials given to me; the analysis above substitutes (a) the specification's admitted prior art and (b) independently corroborated FTA. If a prior-art section exists on your page, its contents were not transmitted and my analysis should be re-run against it.
- Unexplained date positions unchanged from the earlier summary (1996-12-22 vs -12-23; 1998-12-14 vs -12-15; 2016-12-22 vs -12-23). No new contradiction found; I did not reconcile them.
- Schneier's Dec. 1999 "Attack Trees" article is not prior art to this patent and is in fact derivative of it. Any search-derived analysis that cites it as art would be erroneous.
- Post-1996 fault-tree documents surfaced by search (EP 4105749 A1; WO 2022/263130 A1; WO 2015/151014 A1; JP 6712921 B2; CN 116010886 B) are not prior art to a 1996 priority date; they are cited here only as evidence that AND/OR-gate fault trees with bottom-up quantification are conventional.
- I could not verify the NUREG-0492 bibliographic details, the FIPS 65 issue date (commonly cited as 1979), or the CRAMM inception date in this session; treat those as needing confirmation before use in a filing. Likewise the identities of the two front-page cited patents are unconfirmed and deliberately not named.
- This is a technical analysis, not legal advice or a validity opinion.
- Minor: your task header says April 26, 2026 while the session metadata says 2026-09-29; immaterial to a priority-date-locked pre-AIA analysis.
Sources: US5850516 full text (https://patents.google.com/patent/US5850516/en); patent PDF front matter (http://patentimages.storage.googleapis.com/5b/5c/2a/ce26ad582f9b0f/US5850516.pdf); Justia (https://patents.justia.com/patent/5850516); Unified Patents (https://portal.unifiedpatents.com/patents/patent/US-5850516-A); Schneier, "Attack Trees," Dr. Dobb's Journal (Dec. 1999) (https://www.schneier.com/academic/archives/1999/12/attack_trees.html) — post-dating, excluded as art; FTA AND/OR gate corroboration (https://patents.google.com/patent/EP4105749A1/en, https://patents.google.com/patent/WO2015151014A1, https://patents.google.com/patent/CN116010886B/en) — all post-dating, excluded as art.
Generated 9/29/2026, 3:32:02 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 9978413I'll verify the patent details and check for any litigation or CAFC docket activity. Let me check for any 2026 appellate activity. US 9,978,413 B2 — Verified Summary Search scope / confidence note. I searched Google Patents, the USPTO…
- US 6587858I'll verify current docket/litigation status before summarizing. US Patent 6,587,858 B1 — Analyst Summary Verification note: I could not reach the USPTO PatentCenter/Public PAIR or CAFC docket systems directly in this session. The…
- US 5974550I'll verify current records for US 5974550 before summarizing. Let me check the litigation/PTAB history and any 2026 appellate activity specifically for this patent. US Patent 5,974,550 — Verification Summary Bottom line up front: I…
- US 5991399I'll search for docket and USPTO records for this specific patent number. Let me search more specifically for current litigation and any 2026 appellate activity. Let me check specifically for any 2025–2026 Federal Circuit activity or…
- US 9697264I'll research US patent 9697264 across the USPTO and CAFC dockets. Let me run several searches. Let me dig into the specific claims of 9697264 and the CAFC litigation docket. US Patent 9,697,264 — Analyst Summary Confidence note up front…
- US 8996579I'll run searches against the specific patent number and related docket/litigation records. US 8,996,579 B2 — Verified Data (as of April 26, 2026) Note on method: I searched for the literal identifier 8996579 and cross-checked the…
- US 8370393I'll search for authoritative information on this specific patent number. Let me dig deeper into the litigation and CAFC history. Let me verify recent 2026 activity and the status of any new proceedings. US Patent 8,370,393 — Summary Note…
- US 9436354I'll search for authoritative information on US patent 9436354, including any 2026 CAFC docket activity. Let me check the litigation history and any 2026 CAFC activity more specifically. Let me check for any 2026 court activity and confirm…