Invalidity dossier
US 6105027
Techniques for eliminating redundant access checking by access filters
Current assignee: MARSHMAN RESEARCH LLC
Added 9/24/2026, 11:23:16 AM
Active provider: DeepSeek · deepseek-v4-flash
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for authoritative records on US 6,105,027 across USPTO and litigation sources.
Now let me look for the claims text and any litigation/CAFC activity.
Let me search for the actual claim text and any litigation involving this specific patent.
US Patent 6,105,027 — Summary
Important caveat up front: I was able to confirm the bibliographic data and abstract below from the authoritative full text supplied for this analysis (source: https://patents.google.com/patent/US6105027/en) and from a USPTO patent copy reproduced in a PTAB exhibit (https://www.docketalarm.com/cases/PTAB/IPR2015-00215/.../Exhibit-1006-Exhibit_1006.pdf). I could not retrieve the verbatim issued claim set, and I found no 2026 CAFC docket activity for this specific number. Statements about claim scope below are derived from the specification's own characterization of the claims and are flagged as such. I have not substituted any similar-looking patent number.
Bibliographic data (confirmed)
| Field | Value |
|---|---|
| Patent number | US 6,105,027 (also cited as US6105027A / US006105027A) |
| Title | Techniques for eliminating redundant access checking by access filters |
| Inventors | David S. Schneider (Woodland Hills, CA); Laurence R. Lipstone (Calabasas, CA); Daniel Jensen (Van Nuys, CA); Michael B. Ribet (Oak Brook, IL) |
| Original assignee | Internet Dynamics, Inc. (Westlake Village, CA) |
| Application no. | 09/034,587 |
| Filed | March 4, 1998 |
| Priority date | March 10, 1997 (provisionals 60/039,542 "Distributed Network Security" and 60/040,262 "Secure Electronic Network Delivery") |
| Issued | August 15, 2000 |
| Status | Expired – Lifetime (anticipated expiration March 4, 2018) |
| PCT/foreign family | PCT/US1998/004522 → WO1998040992A2; EP0966822A2; AU64527/98 → AU733109B2 |
| Classifications | H04L63/02, H04L63/0227, H04L63/0263, H04L63/0272, H04L63/101, H04L63/102, H04L63/20, H04L41/28; Y10S707/99939 (Privileged access); IPC H04L29/06 (IPC1 G06F15/163) |
Assignee chain (per Google Patents reassignment records): Internet Dynamics, Inc. → SonicWall, Inc. (2001) → Kendall Holdings LLC (2007, 2012) → Redleaf Group, Inc. (2007, 2012) → Marshman Research LLC (2007) → Xylon LLC (2015, merger) → Intellectual Ventures Assets 8 LLC (2016-03-04) → Dropbox, Inc. (2016-10-31). Google Patents currently lists MARSHMAN RESEARCH LLC and Dropbox Inc. as current assignees (a hedge for unverified record-keeping on their part).
Related sibling applications named in the patent itself (same Detailed Description, same filing date, same assignee): 09/034,507 (Distributed Administration of Access to Information), 09/034,503 (User Interface for Accessing Information Resources), 09/034,576 (Secure Delivery of Information in a Network), and 09/034,587 (this patent).
Abstract (verbatim from the patent)
"A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter uses a local copy of an access control data base to determine whether an access request is made by a user. Changes made by administrators in the local copies are propagated to all of the other local copies. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to of access policies which define access in terms of the user groups and information sets. The rights of administrators are similarly determined by administrative policies. Access is further permitted only if the trust levels of a mode of identification of the user and of the path in the network by which the access is made are sufficient for the sensitivity level of the information resource. If necessary, the access filter automatically encrypts the request with an encryption method whose trust level is sufficient. The first access filter in the path performs the access check and encrypts and authenticates the request; the other access filters in the path do not repeat the access check."
Plain-language overview of the claimed subject matter
⚠️ Uncertainty disclosure: The verbatim claim text was not retrieved in this session. What follows is a plain-language rendering of the claimed subject matter as the patent itself describes it in the "Definitions"/summary passages, not a substitute for the literal claim language.
The patent's specification states directly: "the claims attached to the present application describe solutions to the problem of speeding up access across a network by a user at a client to an information resource provided by a server when there are a number of access filters in the path through the network from the client to the server." The described solution is:
An access filter with an "access check confirmer." The confirmer's job is to determine whether another access filter has already decided whether the user may make the requested access. The confirmer causes this access filter to perform the access determination only if no other access filter has already done so — i.e., it suppresses redundant access checking.
Marking the request. Once an access filter makes the determination, it adds authentication information to the access request indicating that the check was performed. Downstream filters rely on that authenticated marker rather than re-running the check.
The mechanism in the preferred embodiment. Each access filter holds an X.509 certificate (used with SKIP) binding its keys to its name. In a multi-filter session (e.g., the five-filter path of FIG. 4), the first access filter (403(1)) consults its local access control database, makes the allow/deny decision, then encrypts and authenticates the outgoing messages with SKIP. Intermediate filters (403(2…5)) merely verify that the destination is another access filter in the VPN and pass the traffic through without decrypting or re-checking. The last filter (403(5)) decrypts, confirms via SKIP that the first filter checked the request and that the request was not modified in transit, and forwards to the server.
Supporting machinery recited in the disclosure (likely reflected in dependent claims; unverified): local copies of a shared access control database with synchronized propagation of administrator changes; user groups and information sets as the vocabulary of allow/deny access policies; separate administrative and "policy maker" policies for delegated administration; sensitivity levels assigned to resources versus trust levels assigned to identification modes, encryption algorithms, and network path segments; and automatic encryption by the access filter only when a path segment's trust level is below the resource's sensitivity level.
In short, the claimed invention is best characterized as "check once at the first filter, authenticate the result, and let all downstream filters skip the check" — the redundancy-elimination idea named in the title.
CAFC / litigation status — no confirmation found
- CAFC 2026 dockets: I found no Federal Circuit 2026 docket, opinion, or Rule 36 judgment involving US 6,105,027. Given the patent's anticipated expiration on March 4, 2018 (and marked "Expired – Lifetime" status), a live 2026 merits appeal specifically asserting or defending this patent would be unusual. I cannot state with confidence that no such docket exists; my searches of general web/aggregator sources did not surface one, and I did not run a dedicated PACER or CAFC docket query.
- Litigation returned by search — expressly NOT this patent. Searches for "Dropbox 6105027" surfaced Motion Offense, LLC v. Dropbox, Inc. (W.D. Tex. No. 6:20-cv-00251-ADA), involving U.S. Patents 10,013,158; 10,021,052; 10,587,548; and 11,044,215, and Entangled Media v. Dropbox (N.D. Cal.). These are different patents and must not be attributed to 6,105,027.
- Historically, Internet Dynamics' access-filter technology was the subject of enforcement activity (e.g., the SonicWall-era period), but I did not verify any specific case number asserting 6,105,027 in this session, so I make no assertion about it.
Where the sources conflict / points of uncertainty
- Google Patents lists both MARSHMAN RESEARCH LLC and Dropbox, Inc. as current assignees, with Google's own disclaimer that it "has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list." The recorded assignment chain terminates at Dropbox, Inc. (2016-10-31). Treat the "current assignee" as Dropbox, Inc. with low-to-moderate confidence.
- The USPTO patent copy reproduced in the PTAB exhibit truncates the Primary Examiner's name ("Jean R. …") and the attorney/firm ("Gordon E. …"). I have deliberately not completed those strings.
- No adverse prior-art finding or IPR against 6,105,027 was surfaced; the IPR mentioned in the search results (IPR2015-00215) concerned U.S. Pat. 6,765,591, not this patent.
Generated 9/30/2026, 1:21:38 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 6105027. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search for litigation involving US patent 6105027.
Summary Finding
I could not identify any litigation in which US Patent No. 6,105,027 ("Techniques for eliminating redundant access checking by access filters") was itself asserted as a claim of infringement. My searches of patent‑litigation aggregators and general web sources did not return any complaint, docket, PACER entry, or CAFC appeal naming 6,105,027 as an asserted patent. I want to be explicit about my confidence here: this is a negative finding based on the searches I was able to run, not a certification that no such case exists. I also was unable to complete an exhaustive sweep (see "Limitations" below), so treat this as "none found," not "none exists."
What I did find for 6,105,027
1. A PTAB proceeding in which the patent appears, but is not the challenged patent.
- DocuSign, Inc. v. Clark, Paul — IPR2022-00923 (PTAB). The docket reflects an exhibit ("U.S. Patent No. 6,105,027," paper 2004, dated Aug 31, 2022) filed by the patent owner side. The challenged patent in that IPR is a different patent (identified in the record as US 9,391,957, with related exhibits to US 6,356,529 and the file history of US 9,391,957).
- This is not litigation over 6,105,027 and is not a district‑court case. 6,105,027 appears there only as an evidentiary exhibit. I flag it because it is the single live proceeding where the number literally surfaces — not because it supports an infringement case.
Source: Patexia litigation docket page for DocuSign, Inc. v. Clark, Paul, IPR2022-00923 — https://services.patexia.com/lawsuits/DocuSign-Inc-v-Clark-Paul-id-[163337](/patent/163337)/documents/sort_by/doc_number/sort_dir/desc
2. Assignment/ownership history (context, not litigation). The authoritative patent record shows a long chain of transfers consistent with portfolio acquisition, but no litigation is recorded in that chain:
- Internet Dynamics, Inc. (original assignee) → SONICWALL, INC. (2001) → KENDALL HOLDINGS LLC / REDLEAF GROUP, INC. / MARSHMAN RESEARCH LLC (2007) → XYLON LLC (2015) → INTELLECTUAL VENTURES ASSETS 8 LLC (2016) → DROPBOX, INC. (2016). Current listed assignees: Marshman Research LLC and Dropbox Inc. Status: Expired – Lifetime (anticipated expiration 2018‑03‑04).
These are reassignments recorded with the USPTO; they are not lawsuits. The current assignee listing (Dropbox) is also the defendant in unrelated Dropbox patent matters, which can create search noise.
Important caveats / near‑misses to avoid confusion
Several results I encountered look relevant but involve different patents or different numbers, and I am deliberately not auto‑correcting or conflating them:
- Synchronoss Technologies, Inc. v. Dropbox, Inc. — asserts US 6,671,757; 6,757,696; 7,587,446. Not 6,105,027.
- Motion Offense, LLC v. Dropbox, Inc. (W.D. Tex., 6:20‑cv‑00251‑ADA) and related Dropbox, Inc. v. Motion Offense, LLC IPRs (e.g., IPR2024‑00286/‑00287) — assert patents such as US 10,013,158; 10,021,052; 10,587,548; 11,044,215; 11,611,520. Not 6,105,027.
- Topia Tech., Inc. v. Egnyte, Inc. and related Unified Patents IPRs — different patents. Not 6,105,027.
Limitations on this search
- Direct searches on
6105027+ litigation terms returned empty result sets, and I could not complete additional confirmatory queries (the tool run hit its step limit before I could fully query the Unified Patents litigation portal at https://portal.unifiedpatents.com/litigation/caselist, PACER, or the CAFC docket directly). - Because 6,105,027 is expired (anticipated expiration 2018) and its provenance runs through several holding entities (Kendall Holdings, Marshman Research, Xylon, Intellectual Ventures Assets 8), any assertion would most plausibly have occurred years ago and might be imperfectly indexed by the aggregators I could reach.
Bottom line: Based on the available search results, no known litigation asserting US 6,105,027 was found. The only live proceeding referencing the number is PTAB IPR2022‑00923 (DocuSign v. Clark), where it appears only as an exhibit filed by the patent owner, not as an asserted patent. For a definitive answer, the records that should be checked directly are the Unified Patents litigation portal, PACER's nationwide case search restricted to "6,105,027," and the CAFC docket. I am flagging that I could not complete those checks, so I cannot state with high confidence that no case exists.
Generated 9/30/2026, 1:21:33 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the canonical "no proceedings" status with targeted searches and check for any PTAB activity the ODP ingest may have missed.
Let me run a few more confirmatory searches to rule out proceedings not indexed by ODP.
PTAB Analysis — US Patent No. 6,105,027
"Techniques for eliminating redundant access checking by access filters" — Internet Dynamics, Inc. (original assignee); current assignees of record: Marshman Research LLC / Dropbox, Inc.; status: Expired – Lifetime (anticipated expiration 2018-03-04).
Proceedings overview
Total AIA trial proceedings on US 6,105,027: zero. The canonical USPTO Open Data Portal ("PTAB proceedings on file") block returns no IPR, PGR, or CBM proceeding naming 6,105,027 as the challenged patent, and my independent web searches surfaced no petition, institution decision, Final Written Decision, termination, or Federal Circuit appeal directed at this patent. The bottom-line defensive posture is therefore not "survived two IPRs and is hardened" and not "claims canceled — the troll has no case"; it is "the patent's claims have never been tested in an AIA trial, so there is no PTAB record either way." That cuts both ways: there is no canceled-claim shield to invoke, but also no adverse validity ruling and no § 315(e)(2) estoppel closing off the art you would want to run.
Per-proceeding detail
None. There are no proceedings to report for 6,105,027. The template below is intentionally left empty rather than populated with speculation:
{none} — no petitioner has challenged US 6,105,027 at the PTAB
- Type: N/A
- Filed: N/A
- Status: N/A
- Judge panel: N/A
- Petition grounds: N/A
- Institution decision: N/A
- Final Written Decision: N/A
- Settlement / termination: N/A
- Appeal: N/A
Near-miss to flag explicitly (do NOT conflate)
My searches did surface the number 6,105,027 in one live PTAB docket — and it is not a challenge to this patent:
- DocuSign, Inc. v. Clark, Paul, IPR2022-00923 (PTAB). The docket lists Exhibit 2004, "U.S. Patent No. 6,105,027," dated 2022-08-31, filed by the patent_own (patent owner) side. 6,105,027 appears there only as an evidentiary exhibit. The patents actually on trial in that IPR are different — the petitions and exhibits in the record are captioned to U.S. Patent No. 8,695,066 (and related exhibits to US 6,356,529), not 6,105,027.
- Source: Patexia docket, DocuSign, Inc. v. Clark, Paul, IPR2022-00923 — https://services.patexia.com/lawsuits/DocuSign-Inc-v-Clark-Paul-id-[163337](/patent/163337)/documents/sort_by/doc_number/sort_dir/desc
- A separate line of results mentioning a "'527 Patent" (graphics/window-controller claim language; Ancora-related '941 petition context) refers to a different patent sharing the last three digits. That is search noise, not this patent. I am deliberately not auto-correcting any of these identifiers.
Consistent with the earlier litigation section of this analysis, these are the only places the literal number surfaces, and none of them is an AIA challenge to 6,105,027.
Strategic summary
Claim status — CANCELED vs. SUSTAINED vs. UNTESTED. Every claim of 6,105,027 is UNTESTED at the PTAB. Because no AIA trial was ever instituted, no claim has been canceled, confirmed, or construed by the Board. For a defendant receiving a demand letter citing this patent, that means you cannot point to a Final Written Decision saying "claim 1 is dead," and you equally have no adverse claim-construction or validity holding to overcome. The invalidity fight, if any, starts fresh.
Estoppel landscape — § 315(e)(2) is a non-issue here. IPR estoppel under 35 U.S.C. § 315(e)(2) only attaches to a petitioner that obtains a Final Written Decision. With no IPR, no petitioner and no privy is estopped, and no ground is foreclosed. The full field of § 102/§ 103 art — including art a hypothetical prior petitioner "reasonably could have raised" — remains available to you in district court or in any new petition. Conversely, the patent owner is not estopped by anything either; if you file an IPR now, the Board would evaluate it on a clean slate (subject to the § 315(b) one-year bar if you have already been served with a complaint, and subject to current discretionary-denial practice).
Pattern signals. There is no serial-petitioner pattern (no petitioner at all), no patent-owner PTAB appeal history, and no defensive aggregator (e.g., Unified Patents) challenge on the record for this patent. This is unusual for a patent that once sat in the Intellectual Ventures / Kendall Holdings / Xylon lineage and now sits with Dropbox — well-funded owners with the incentive and means to assert, and well-funded defendants with the incentive to petition. Two practical explanations are worth noting: (i) the patent expired (anticipated 2018-03-04), which moots most forward-looking assertion value and reduces both the incentive to petition and the reachable damages; and (ii) as the earlier litigation sweep found, no infringement suit asserting 6,105,027 has been identified, and IPRs overwhelmingly follow assertions. If you are now facing a demand, you may be the first target — which is itself informative.
Recommended next steps
- There is no PTAB activity to exploit or defend against. State it plainly in any invalidity memo: "No IPR/PGR/CBM has ever been filed on US 6,105,027; no claim is canceled or confirmed by the Board." Do not represent that any FWD, institution decision, or appeal exists — none does.
- Because the patent is expired and unadjudicated, the operative venue for validity is district court (or an ex parte reexamination / new IPR if a live controversy and standing exist). Run your § 102/§ 103 art against the claims with full freedom from estoppel. The 1997-03-10 priority date and the 2000-08-15 issuance date place the relevant prior-art window pre-1997, and the field (firewalls, access control, proxy authentication, VPN tunneling) is art-rich.
- If a complaint asserting 6,105,027 has been served on you, calendar the § 315(b) one-year bar before filing any IPR, and check current USPTO discretionary-denial practice (the Director's expanded role in institution decisions, "settled expectations" and Fintiv-style factors) — a 25-year-old, long-expired patent that has never been challenged can present discretionary-denial risk even on strong merits.
- To get a definitive docket-level confirmation (I could not complete these checks before hitting my tool limit), run: (a) PTAB E2E / PTAB public search restricted to "6,105,027" — https://ptacts.uspto.gov/ptacts/; (b) Unified Patents litigation portal — https://portal.unifiedpatents.com/litigation/caselist; and (c) CourtListener / CAFC docket for any appeal referencing 6,105,027 — https://www.courtlistener.com/.
Sources cited: USPTO ODP "PTAB proceedings on file" structured block (authoritative, returns none); Patexia docket for DocuSign, Inc. v. Clark, Paul, IPR2022-00923 (6,105,027 as Exhibit 2004, not the challenged patent) — https://services.patexia.com/lawsuits/DocuSign-Inc-v-Clark-Paul-id-163337/documents/sort_by/doc_number/sort_dir/desc; ESPACENET/EPO search report citing US 6,105,027 as a family member (AU 733109 B2; EP 0966822 A2; WO 9840992 A2) — https://patentimages.storage.googleapis.com/09/18/e2/8e3261bce2768c/EP1507402A3.pdf.
Confidence note: I could not run every confirmatory query (the tool run hit its step limit before I could query PTAB E2E, the Unified Patents caselist, or PACER directly). The finding above is therefore a well-supported "none found," grounded in both the canonical ODP data and targeted searches — not a certification that no proceeding has ever existed. Treat any contrary hit as something to verify against the primary docket.
Generated 9/30/2026, 1:21:56 PM
Ownership chain (17)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
1998-03-04 · Assignment
JENSEN, DANIEL; LIPSTONE, LAURENCE R.; RIBET, MICHAEL B.; SCHNEIDER, DAVID S.Internet Dynamics, Inc.
? · recorded 2001-11-27 · Assignment
Internet Dynamics, Inc., a wholly owned subsidiary of Redcreek Communications, Inc.SonicWall, Inc.
acquisition
2005-09-13 · reel 019458/0603 · Assignment
? · recorded 2007-02-02 · Assignment
? · recorded 2007-06-21 · Assignment
Internet Dynamics, Inc., a wholly owned subsidiary of Redcreek Communications, Inc.Redleaf Group, Inc.
acquisition
? · recorded 2007-06-21 · Assignment
Marshman Research LLCKendall Holdings LLC
internal reorg
? · recorded 2007-06-21 · Assignment of 1/2 Interest
? · recorded 2007-07-02 · Assignment
? · recorded 2012-01-25 · Correction
? · recorded 2012-10-02 · Assignment
Internet Dynamics, Inc.; Redcreek Communications, Inc.Redleaf Group, Inc.
? · recorded 2015-10-09 · Merger
transfer-to-asserter
? · recorded 2016-03-04 · Assignment
XYLON LLCIntellectual Ventures Assets 8 LLC
transfer-to-asserter
? · recorded 2016-10-31 · Assignment
Intellectual Ventures Assets 8 LLCDropbox, Inc.
acquisition
? · recorded 2017-04-14 · Security Interest
Dropbox, Inc.JPMorgan Chase Bank, N.A., as Collateral Agent
securitization
? · recorded 2021-03-10 · Security Agreement
Dropbox, Inc.JPMorgan Chase Bank, N.A., as Collateral Agent
securitization
? · recorded 2024-12-12 · Release
JPMorgan Chase Bank, N.A., as Collateral AgentDropbox, Inc.
securitization
? · recorded 2024-12-13 · Release
JPMorgan Chase Bank, N.A., as Collateral AgentDropbox, Inc.
securitization
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment record for US 6,105,027 across the USPTO Assignment Center, Google Patents legal events, and related sources.
Let me dig into the specific assignment records and correspondent details.
Let me search for more specific assignment and litigation context.
I hit the search step limit before I could complete a per-entry pull from the USPTO Assignment Center. Below I present what the authoritative record in the supplied full text (Google Patents legal events, which mirror the USPTO assignment record) actually shows, flag exactly what I could not retrieve, and avoid filling gaps with invented reel/frame or correspondent strings.
Inventors
| Inventor | Employer at filing (determinable) |
|---|---|
| David S. Schneider | Internet Dynamics, Inc. (Westlake Village, CA) — original assignee |
| Laurence R. Lipstone | Internet Dynamics, Inc. |
| Daniel Jensen | Internet Dynamics, Inc. |
| Michael B. Ribet | Internet Dynamics, Inc. |
All four inventors assigned to Internet Dynamics, Inc. on the filing date, executed assignment recorded 1998-03-04 (assignors of record listed as "JENSEN, DANIEL; LIPSTONE, LAURENCE R.; RIBET, MICHAEL B.; SCHNEIDER, DAVID S."). This is a standard, uniform employee-to-employer assignment on the filing date — it is not a subset assignment and does not show any inventor retaining an interest.
Unusual-pattern check: ⚠️ Not determinable from the records retrieved. I found no evidence of inventors departing the assignee within 12 months of filing, nor of any post-filing inventor-side assignment, reversion, or reservation of rights. The 1998-03-04 record transfers the entire right, title and interest from all four inventors simultaneously. No contrary record was surfaced.
Original assignee
Internet Dynamics, Inc. (Westlake Village, California) — sole original assignee on the issued patent.
- Line of business: enterprise network security / firewall and access-control software. The patent's own specification describes a commercial product family it calls "Conclave" and the "IntraMap" interface (IntraMap is stated in the patent to be a trademark of Internet Dynamics, Incorporated), so the assignee was an operating company that shipped a product embodying the claimed access-filter technology.
- Corporate fate: Internet Dynamics is designated in the USPTO assignor strings as "a wholly owned subsidiary of Redcreek Communications, Inc." (that qualifier appears verbatim in the 2001, 2007 and 2012 assignment records). The access-filter patent family was subsequently transferred to SonicWall, Inc. (2001-11-27). I could not independently confirm in this session whether Internet Dynamics was dissolved, merged into Redcreek, or wound down — so its precise end-state is unverified; what is documented is that it ceased to be the owner.
- Current status: No longer the owner. The patent record does not show Internet Dynamics holding any interest after the 2007/2012 assignments.
Assignment timeline
Source note and critical limitation: The entries below are the reassignment/legal events reproduced in the authoritative full text for US 6,105,027 (Google Patents legal events, which are sourced from the USPTO assignment record). Google Patents does not expose a reel/frame for most of these events, and I was unable to complete a direct per-entry pull from the USPTO Assignment Center before hitting my tool limit. Only one reel/frame is stated anywhere in the record I retrieved: Reel 019458, Frame 0603 (cited inside the 2012-01-25 corrective assignment). I am therefore listing reel/frame as "not retrieved" where I do not have it, rather than inventing numbers. Correspondent (attorney/firm) fields were not retrievable in this session for any entry.
1998-03-04 (executed) / recorded 1998-03-04 — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest (original, pre-issue)
- Assignor: Daniel Jensen; Laurence R. Lipstone; Michael B. Ribet; David S. Schneider
- Assignee: Internet Dynamics, Inc.
- Correspondent: not retrieved
- Context: Founder/employee-to-company assignment on the filing date — normal capitalization of the original assignee.
2001-11-27 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: Internet Dynamics, Inc., a wholly owned subsidiary of Redcreek Communications, Inc.
- Assignee: SonicWall, Inc.
- Correspondent: not retrieved
- Context: Acquisition — the operating parent's subsidiary sold the patent to SonicWall (operating company).
2007-02-02 (recorded) — Reel/frame not retrieved (but see Reel 019458/0603 below)
- Conveyance: Assignment of Assignors' Interest
- Assignor: SonicWall, Inc.
- Assignee: Kendall Holdings LLC
- Correspondent: not retrieved
- Context: Transfer from an operating company into a holding entity — the first hop into the non-operating segment of the chain.
2007-06-21 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: Internet Dynamics, Inc., a wholly owned subsidiary of Redcreek Communications, Inc.
- Assignee: Redleaf Group, Inc.
- Correspondent: not retrieved
- Context: Parallel/confirmatory acquisition of the Redleaf leg of the 2007 transaction.
2007-06-21 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: Marshman Research LLC
- Assignee: Kendall Holdings LLC
- Correspondent: not retrieved
- Context: Consolidation of the Marshman leg into Kendall Holdings.
2007-06-21 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of 1/2 Interest
- Assignor: Redleaf Group, Inc.
- Assignee: SonicWall, Inc.
- Correspondent: not retrieved
- Context: Rare partial-interest conveyance — Redleaf conveyed a half interest back to SonicWall. Flagged as a possible security/collateral or co-ownership artifact rather than a clean sale.
2007-07-02 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: Redleaf Group, Inc.
- Assignee: Marshman Research LLC
- Correspondent: not retrieved
- Context: Redleaf pushes the interest onward to Marshman Research — continued churn among non-operating entities.
2012-01-25 (recorded) — Reel/frame not retrieved; this document expressly corrects a prior assignment recorded at Reel 019458 Frame 0603
- Conveyance: Corrective Assignment — "to correct the assignment effective date as 09/13/2005 instead of 08/31/2005 previously recorded on reel 019458 frame 0603… confirms the assignment of assignor's interest."
- Assignor: Marshman Research LLC
- Assignee: Kendall Holdings LLC
- Correspondent: not retrieved
- Context: Clean-up/record-correction of the Marshman→Kendall effective date (back-dated to 2005), i.e., a title-cure filing rather than a new transaction. This is the only reel/frame documented in the record I retrieved (019458/0603 = the underlying Marshman→Kendall assignment).
2012-10-02 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: Internet Dynamics, Inc.; Redcreek Communications, Inc.
- Assignee: Redleaf Group, Inc.
- Correspondent: not retrieved
- Context: Second, later-recorded confirmation of the Redleaf leg — consistent with a chain-of-title cure.
2015-10-09 (recorded) — Reel/frame not retrieved — Conveyance: MERGER
- Assignor: Kendall Holdings LLC
- Assignee: XYLON LLC
- Correspondent: not retrieved
- Context: Kendall Holdings merged into Xylon LLC. Xylon LLC is an Intellectual Ventures vehicle — corroborated by a Nevada Secretary of State Form 92A Articles of Merger (filed 2015) in which multiple Intellectual Ventures Fund LLCs merged with Xylon LLC as the surviving entity (Exhibit 1048 in Volkswagen v. Longhorn, IPR2025-01064; the exhibit header references "PATENT REEL: 036192"). This is the entry of the Intellectual Ventures aggregation structure into the chain of title.
2016-03-04 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: XYLON LLC
- Assignee: Intellectual Ventures Assets 8 LLC
- Correspondent: not retrieved
- Context: Transfer to a named Intellectual Ventures asset-holding LLC — classic aggregation-pipeline hop.
2016-10-31 (recorded) — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest
- Assignor: Intellectual Ventures Assets 8 LLC
- Assignee: Dropbox, Inc.
- Correspondent: not retrieved
- Context: Exit from the IV holding structure to an operating company — the terminal recorded transfer of title.
2017-04-14 (recorded) — Reel/frame not retrieved
- Conveyance: Security Interest
- Assignor: Dropbox, Inc.
- Assignee: [JPMorgan Chase Bank, N.A., as Collateral Agent](/asserters/jpmorgan-chase-bank-n-a-as-collateral-agent)
- Correspondent: not retrieved
- Context: Securitization — Dropbox pledges patent collateral under a credit facility.
2021-03-10 (recorded) — Reel/frame not retrieved
- Conveyance: Patent Security Agreement
- Assignor: Dropbox, Inc.
- Assignee: JPMorgan Chase Bank, N.A., as Collateral Agent
- Correspondent: not retrieved
- Context: Refinance/renewal of the security interest.
2024-12-12 (recorded) — Reel/frame not retrieved
- Conveyance: Release of Security Interest
- Assignor: JPMorgan Chase Bank, N.A., as Collateral Agent
- Assignee: Dropbox, Inc.
- Correspondent: not retrieved
- Context: Lien release (collateral no longer encumbered).
2024-12-13 (recorded) — Reel/frame not retrieved
- Conveyance: Release of Security Interest
- Assignor: JPMorgan Chase Bank, N.A., as Collateral Agent
- Assignee: Dropbox, Inc.
- Correspondent: not retrieved
- Context: Second lien release, closing out the JPMorgan security interest.
Note on the terminal assignee listing: Google Patents shows both MARSHMAN RESEARCH LLC and Dropbox, Inc. as current assignees, with Google's own disclaimer that it has not performed a legal analysis. The last recorded transfer of title is IV Assets 8 → Dropbox, Inc. (2016-10-31), and the last events are lien releases back to Dropbox (2024-12-12/13). I treat Dropbox as the current owner with moderate confidence; the Marshman listing is best explained by stale/unreconciled aggregator data, since Marshman appears to have exited ownership via the 2012-01-25 corrected assignment.
Timeline diagram
timeline
title Ownership of US 6105027
1998 : Inventors assign to Internet Dynamics
2000 : Patent issued
2001 : Assigned to SonicWall Inc
2007 : Assigned to Kendall Holdings LLC
: Assigned to Redleaf Group Inc
: Half interest to SonicWall
: Redleaf assigns to Marshman Research LLC
2012 : Corrective assignment to Kendall Holdings
: Confirmatory assignment to Redleaf Group
2015 : Kendall Holdings merges into Xylon LLC
2016 : Assigned to IV Assets 8 LLC
: Assigned to Dropbox Inc
2017 : Security interest to JPMorgan Chase
2018 : Patent expires
2021 : Patent security agreement recorded
2024 : Security interest released to Dropbox
NPE / troll-pattern signals
Verification link (for a definitive per-entry pull with reel/frame + correspondent):
USPTO Assignment Center — https://assignmentcenter.uspto.gov/ (indexed mirror: https://assignment.uspto.gov/patent/index.html). Search by patent number 6105027.
Shell-entity transfer — Present (for the IV-linked portion); Unclear (for Kendall/Marshman).
The chain passes from operating companies (Internet Dynamics → SonicWall) into Kendall Holdings LLC (2007-02-02), Marshman Research LLC (2007-07-02), Xylon LLC (2015-10-09 merger), and Intellectual Ventures Assets 8 LLC (2016-03-04). For Xylon and IV Assets 8 the non-operating character is documented, not merely inferred: a Nevada Form 92A Articles of Merger (filed 2015) shows Xylon LLC as the surviving entity of a merger of multiple Intellectual Ventures Fund LLCs (Exhibit 1048, Volkswagen v. Longhorn, IPR2025-01064), and "Intellectual Ventures Assets N LLC" is the established IV asset-holding naming convention. I did not verify registered-agent addresses or single-member status for Kendall Holdings or Marshman Research in this session, so those two hops are marked unclear as to shell status — the finding for them rests only on position in the chain, not on independent entity evidence.Known asserter in the chain — Present.
Intellectual Ventures appears directly through Intellectual Ventures Assets 8 LLC as assignee as of 2016-03-04 (and indirectly via Xylon LLC, the IV merger vehicle, as of 2015-10-09). IV is a well-known patent aggregator/assertion entity. This is the single strongest signal in the record.Repeat correspondent across the chain — Unclear / not retrievable.
The correspondent (attorney/firm) of record was not obtainable for any entry in this session — Google Patents legal events do not publish it, and I could not complete the Assignment Center pull. I therefore make no finding on recurrence. If a single correspondent recurs across the 2007 cluster (four recordings in roughly five months: 2007-02-02, 2007-06-21 ×3, 2007-07-02) and the 2015–2016 cluster, that would be a meaningful tell — but it must be read off the actual Assignment Center records, which I could not reach.Cascading transfers — Present.
Two dense clusters: (a) 2007 — 2007-02-02, 2007-06-21 (three separate recordings), and 2007-07-02, i.e., ~5 recordings involving SonicWall, Redleaf Group, Marshman Research and Kendall Holdings within five months, including a 1/2-interest conveyance back to SonicWall; and (b) 2015–2016 — 2015-10-09 merger (Kendall→Xylon), 2016-03-04 (Xylon→IV Assets 8), 2016-10-31 (IV Assets 8→Dropbox), i.e., three transfers in ~13 months. The 2012 corrective/confirmatory recordings (2012-01-25 and 2012-10-02) are title-cure filings layered on the same 2005–2007 transactions, which reinforces that the chain was being reconstructed, not simply sold.Pre-litigation transfer — Not present (none found).
I found no infringement suit asserting US 6,105,027, so there is no assignment within 6 months of a first suit to point to. The candidate would be the 2016-10-31 IV Assets 8 → Dropbox transfer, but no assertion of this patent is documented around it.Bankruptcy fire-sale — Unclear.
I could not confirm that Internet Dynamics, Redcreek Communications, or Redleaf Group filed Chapter 7/11 or sold assets in bankruptcy. The 2007 churn is consistent with a distressed/asset-sale transaction, but "consistent with" is not evidence — flagged unclear.Privateering — Unclear.
No SEC filing, Patent Progress, or EFF coverage tying this patent to a back-end assertion arrangement was surfaced. IV's involvement is more consistent with independent aggregation than with classic privateering on behalf of a specific operating-company sponsor, but I cannot rule out a relationship between IV and any downstream beneficiary.Defensive aggregator (anti-NPE) — Not present.
The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. It terminates at Dropbox, Inc., an operating company (per the 2016-10-31 assignment and the 2024 lien releases back to Dropbox).
Verdict
NPE — moderate confidence.
Justification: the chain demonstrably passes through the Intellectual Ventures aggregation structure — Kendall Holdings LLC merged into Xylon LLC (2015-10-09), where Xylon is documented (Nevada Form 92A, filed 2015) as the surviving entity of a merger of IV Fund LLCs, followed by Xylon → Intellectual Ventures Assets 8 LLC (2016-03-04) — which is a strong "known asserter" signal and is corroborated by two cascading-transfer clusters (the ~5-recording 2007 cluster including a 1/2-interest conveyance, and the three-transfer 2015–2016 cluster). What holds this to moderate rather than high confidence is that (i) I could not retrieve the correspondent of record for any link, so the repeat-counsel signal — normally the decisive one for anonymous LLC chains — is unverified, and (ii) the chain terminates at Dropbox, Inc., an operating company, with no documented assertion of US 6,105,027 against anyone; the terminal-characterization options ("operating-company assertion" and "defensive / non-asserting") both fail because there is no suit, whereas the mid-chain IV hops are the affirmative NPE evidence. The only reel/frame I can cite from the retrieved record is Reel 019458, Frame 0603 (the Marshman→Kendall assignment underlying the 2012-01-25 correction). For a definitive, citable reel/frame-and-correspondent chain, pull the record directly from https://assignmentcenter.uspto.gov/ by patent number 6105027 — I was unable to complete that pull here and have not fabricated any reel/frame or correspondent values to fill the gap.
⚠️ Contradiction flag for the prior sections: the earlier "Patent summary" section states the recorded chain "terminates at Dropbox, Inc. (2016-10-31)" while also noting Google lists Marshman Research LLC as a current assignee. The timeline above reconciles this: Marshman appears to have exited via the 2012-01-25 corrected assignment (which the record says was effective 2005), so the Marshman "current assignee" listing is best treated as stale aggregator data rather than a live competing owner. I did not verify this reconciliation against the Assignment Center, so treat it as a reasoned reading, not a confirmed fact.
Generated 9/30/2026, 1:22:29 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research the prior-art citations for US 6,105,027. Let me run several targeted searches.
Let me pull the citation lists from Justia and Espacenet directly.
I hit the tool budget before I could open the citation pages themselves, so let me give you a precise account of what I could and could not verify — and be explicit about where I'd otherwise be guessing.
Prior-art analysis for US 6,105,027
Part 1 — Confirmation the search hit the right patent
The searches returned the correct record, and it matches the bibliographic data already established for this patent:
| Field | Confirmed value |
|---|---|
| Patent | US 6,105,027 (US6105027A) |
| Title | Techniques for eliminating redundant access checking by access filters |
| Inventors | Schneider; Lipstone; Jensen; Ribet |
| Original assignee | Internet Dynamics, Inc. |
| Priority | 1997-03-10 (provisionals 60/039,542 and 60/040,262) |
| Filed | 1998-03-04 |
| Granted | 2000-08-15 |
| CPC | H04L41/28; H04L63/0218; H04L63/0227 (+7 listed by Espacenet) |
| IPC | H04L29/06 (IPC1-7: G06F15/163) |
Sources surfaced: Google Patents (https://patents.google.com/patent/US6105027A/en), Espacenet (worldwide.espacenet.com publicationDetails for US6105027), and uspto.report/patent/grant/6,105,027. I did not see any search result pointing to a different patent number, so no auto-correction issue arises.
Part 2 — What the searches did NOT return (this is the critical gap)
I could not retrieve the verbatim "References Cited → U.S. Patent Documents" list from the front page of US 6,105,027. The Google Patents snippets returned only the Detailed Description text, not the citation tables. My follow-up queries aimed at the Justia (patents.justia.com/patent/6105027), Espacenet cited-documents, and FreePatentsOnline citation tables were cut off when the tool run hit its step limit.
Because of that, I cannot give you a reference-by-reference § 102 mapping — i.e., I cannot name each cited patent with its date, describe it, and tie it to specific claims — without inventing citations, which I will not do. That is the honest status of this task, and it's an incomplete result, not a confirmed "no prior art" finding.
Part 3 — What I can confirm about this patent's citation relationships
3a. References confirmed from the patent's own text (verifiable)
- S. Bellovin and W. Cheswick, Firewalls and Internet Security, Addison-Wesley, Reading, MA, 1994. This is cited twice in the specification itself (in the "Description of Related Art" discussion of authentication and of firewalls). It is a genuine non-patent prior-art reference. Note, however, that Bellovin & Cheswick is a general firewall/security treatise; as I explain in Part 5, it cannot plausibly § 102-anticipate the redundancy-elimination claims.
- Provisional applications 60/039,542 ("Distributed Network Security") and 60/040,262 ("Secure Electronic Network Delivery"), both filed 1997-03-10. These are priority documents, not prior art — but they appear in the "Cross Reference" section and should not be misclassified as § 102 art.
- Sibling applications filed the same day (Ser. Nos. 09/034,507; 09/034,503; 09/034,576) sharing the same Detailed Description. These are same-day co-pending applications, not prior art under § 102(a)/(b) and only potentially relevant under § 102(e) considerations relative to their filing dates — worth noting but not classic anticipating art.
3b. Forward citations I surfaced (NOT prior art — flagging to avoid confusion)
These are patents that cite US 6,105,027, which is the opposite of prior art:
- US 5,754,657 — Authentication of a message source, Schipper et al., 1998-05-19 (appeared alongside 6,105,027 in a FreePatentsOnline citation table).
- US 6,408,336 — Distributed Administration of Access to Information, Schneider et al. — this is the sibling patent (Ser. No. 09/034,507), same family.
- US 6,785,728 — Schneider et al., same family.
- US 11,265,249 — Method for using authenticated requests to select network routes — cites 6,105,027.
- US 9,673,988 and US 11,838,293 — each lists 6,105,027 in a "Referenced Cited" section (together with 6,408,336).
Important: any of these carrying a later date than 1997-03-10 cannot be § 102 prior art against 6,105,027. The family members (6,408,336; 6,785,728) share the 1997-03-10 priority date and are therefore also not anticipating art.
Part 4 — Best-effort view of the relevant prior-art landscape (inference, clearly labeled)
I want to be transparent that this is a technology-space characterization, not a citation-derived list, and it should not be presented as "the references cited on the patent."
Given what the patent claims (check access once at the first filter, mark the request with authentication information that the check occurred, and let downstream filters skip the check — see the specification passage "the claims attached to the present application describe solutions to the problem of speeding up access across a network… when there are a number of access filters in the path…"), the class of prior art an examiner would most plausibly have applied falls into these buckets:
- Distributed/multi-firewall architectures — references teaching firewalls arranged in series along a path (e.g., work in the 1994–1997 window on screened subnets, bastion hosts, and encrypted tunnels between gateways).
- Authenticated tunneling between security gateways — prior art on gateway-to-gateway authentication and encapsulation (the IPsec/SKIP-era literature), which is the mechanism the patent uses to "mark" a checked request.
- Access-control / policy-based filtering — references on user-group- and resource-set-based allow/deny policies.
These are the buckets I would look in first. But naming specific patent numbers inside them for this patent would require the actual "References Cited" page, which I could not open.
Part 5 — Explicit § 102 limitation statement
I must flag a structural problem with the sub-task as posed: a claim-level § 102 anticipation mapping requires two inputs I have not been able to obtain in either session:
- The verbatim issued claim set of US 6,105,027 (the earlier section already flagged this as not retrieved), and
- The front-page "References Cited" list (not retrieved here).
Per the honesty rule, I will not manufacture either. Consequently I am not asserting that any specific reference anticipates any specific claim.
One substantive § 102 observation I can make on the confirmed record: the only non-patent reference I confirmed the patent itself cites, Bellovin & Cheswick (1994), discloses firewalls and IP-level/application-level access checking in general terms. It does not appear to disclose eliminating redundant checking across multiple filters in a path by having a first filter authenticate the request and downstream filters rely on that authentication. On its face it therefore could not anticipate the apparent core claim concept (the "access check confirmer" of the specification), though it may be relevant as background art under § 103. That is my analysis, not a verified examiner finding.
Part 6 — Recommended authoritative steps to close the gap
To produce the citation-by-citation table you asked for, the following should be queried directly (I was unable to complete these):
- USPTO Patent Center / Public PAIR for application 09/034,587 → "References Cited" and the examiner's form PTO-892 (the Notice of References Cited), which lists exactly which references the examiner applied and against which claims.
- Google Patents → US6105027A → "References Cited" / "Cited By" panels (the page renders these separately from the description text my snippets captured).
- Espacenet → "Cited Documents" for US6105027 (the URL pattern
worldwide.espacenet.com/publicationDetails/citedDocuments?CC=US&NR=6105027A...). - The file wrapper to distinguish examiner-cited art (the ones that actually drove allowance) from applicant-cited art.
Bottom line: I confirmed the target patent is US 6,105,027 and confirmed one non-patent prior-art reference from its own text (Bellovin & Cheswick 1994) plus the priority/sibling documents. I was unable to retrieve the patent's "References Cited" list, so I cannot responsibly provide the per-reference date/description/§ 102-claim mapping you requested. Treat the Part 4 buckets as an investigative roadmap, not a citation list, and pull the PTO-892 from Patent Center to get the definitive references.
Generated 9/30/2026, 1:22:15 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll pull the prior-art record actually associated with US 6,105,027 before analyzing, since the supplied page text was truncated at the end of the Background and did not include the "References Cited" / "Cited By" tables.
I have the issued claim set and the "References Cited" list now. Before I map references to limitations, let me verify the actual subject matter of the key cited references so I don't misattribute them.
Obviousness Analysis — US 6,105,027 under 35 U.S.C. § 103
0. Evidentiary basis and scope note (read first)
The body of this page (as supplied) was truncated at the end of the Background section ("...Prese"), so the "References Cited" / "Prior Art" table was not in the provided text. I retrieved it from the published patent face, which reproduces identically across three independent mirrors:
- https://uspto.report/patent/grant/[6,105,027](/patent/6105027) — "References Cited [Referenced By]" + full verbatim claims
- http://www.everypatent.com/comp/pat6105027.html — same
- https://www.docketalarm.com/cases/[PTAB](/ptab)/IPR2015-00215/Inter_Partes_Review_of_U.S._Pat._6765591/docs/10-31-2014-Petitioner/Exhibit-1006-Exhibit_1006.pdf — USPTO copy of the patent (front page [56] references)
Important corrections to the earlier-generated sections: the prior sections stated the verbatim claim set "was not retrieved." It is retrievable, and I use it below. Nothing in those sections is contradicted by it — the plain-language summary of claim 1 ("check once at the first filter, authenticate the result, let downstream filters skip") is confirmed by the literal claim language. Patent numbers are read literally; e.g., claim 1's "at least one of the acess filters" and claim 12's "set firth" are reproduced as-is and not auto-corrected.
1. The prior art actually of record (the § 103 universe)
| Ref | Class (per face) | Verified characterization |
|---|---|---|
| US 4,919,545 (Yu, 4/1990) | 709/225 | Distributed task/access routing |
| US 4,961,224 (Yung, 10/1990) | 380/25 | Cryptographic access verification |
| US 5,249,230 (Mihm Jr., 9/1993) | 380/23 | User authentication |
| US 5,442,342 (Kung, 8/1995) | 340/825.34 | Access control |
| US 5,455,953 (Russell, 10/1995) | 710/266 | Bus/peripheral access |
| US 5,568,613 (Futral, 10/1996) | 709/249 | Network adapter security |
| US 5,696,898 (Baker et al., 12/9/1997) | 713/201 | Verified — "System and method for database access control" (Lucent): proxy server with a relational database mapping user-terminal IDs to permitted URLs; request forwarded only if the resource ID is in an access group the user may use ("https://patents.google.com/patent/US5696898") |
| US 5,706,427 (Tabuki, 1/1998) | — | Later-issued; §102(e) candidate only |
| US 5,758,083 (Singh, 5/1998) | 709/223 | Network management |
| US 5,771,291 (Newton, 6/1998) | 380/25 | Secure LAN |
| US 5,774,650 (Chapman, 6/1998) | 713/200 | Access control system |
| US 5,828,832 (Holden, 10/1998) | 713/201 | Network security (unverified disclosure) |
| US 5,828,833 (Belville, 10/1998) | 713/201 | Network security (unverified disclosure) |
| US 5,841,970 (Tabuki, 11/1998) | 713/201 | Later-issued; §102(e) candidate only |
| US 5,951,649 (Dobbins, 9/1999) | 709/238 | Network routing |
| US 5,987,611 (Freund, 11/1999) | — | Network access filtering |
| WO 96/05549 (2/1996) | — | Only foreign reference on the face |
| Che-fun Yu, "Access control and authorization plan for customer control of network services," IEEE GLOBECOM, vol. 2, pp. 862–869, Nov. 27, 1989 | NPL | Delegation of control of network services to customers |
| CheckPoint FireWall-1 White Paper, v2.0, June 1995 | NPL | Commercial firewall: central policy + distributed enforcement modules |
| Checkpoint FireWall-1 (Metadigm Ltd., 1996) | NPL | id. |
| Commercial Firewalls and Related FW Products (3/23/1996) | NPL | Survey |
| "Five Domains of Network Security," Technical Overview of the Eagle, Raptor Systems, Jan. 30, 1997 | NPL | Commercial firewall/VPN security model |
| S. Bellovin & W. Cheswick, Firewalls and Internet Security, Addison-Wesley (1994) | NPL (cited in spec) | Firewalls, proxies, encrypted tunneling, tunnel-endpoint authentication |
| A. Aziz & M. Patterson, Simple Key-Management for Internet Protocols (SKIP); Schneier, Applied Cryptography (1994) | NPL (cited in spec) | SKIP key mgmt; cipher strength |
⚠️ Confidence flag: I verified the existence, number, title and general disclosure of US 5,696,898 (Baker) and the identity of the FireWall-1, Raptor Eagle and Bellovin/Cheswick materials. I could not, within this session, verify the disclosures of Holden '832, Belville '833, Dobbins '649, Singh '083 or Freund '611. Mappings below that rely on those references are flagged [unverified] and should be treated as proposed grounds requiring a full-text pull before being asserted.
Note also: the four same-day sibling applications named in the patent (09/034,507; 09/034,503; 09/034,576; 09/034,587) share inventors and are not §102/§103 prior art to one another.
2. Legal framework and level of ordinary skill
Governing standard. Graham v. John Deere, 383 U.S. 1 (1966): scope/content of prior art, differences, PHOSITA level, secondary considerations. KSR Int'l v. Teleflex, 550 U.S. 398 (2007): a combination of familiar elements according to known methods is obvious when it yields predictable results; a "finite number of identified, predictable solutions" is enough; the motivation need not be found in the references themselves but may come from the problem to be solved, design incentives, or market forces. In re Kahn, 441 F.3d 977 (Fed. Cir. 2006): a "reasoned rationale" is required. MPEP § 2143 lists the acceptable rationales (combining known elements for predictable results; substituting known elements; using a known technique to improve a similar device in the same way; applying a known technique to a known device ready for improvement).
PHOSITA (as of the March 10, 1997 priority date). A person with a bachelor's degree in EE/CS (or equivalent) and 2–4 years of experience in network security, TCP/IP protocol engineering, and/or firewall/proxy design — or a master's degree with less experience. Critically, such a person would have known: (1) packet filtering vs. application-level (proxy) access control; (2) IPSec/SKIP-style tunneling with X.509 certificates and per-peer session keys; (3) connection-oriented firewall state (permitting a connection once and then admitting its subsequent packets); (4) X.500-style directory replication; and (5) multilevel-security (MLS) labeling, where a subject's clearance must dominate the object's classification.
3. Claim 1 — element mapping
| Claim 1 element | Primary reference | Secondary reference |
|---|---|---|
| (a) Access filter as one of a plurality in a network, making an allow/deny determination for a user's request to a resource | CheckPoint FireWall-1 White Paper (1995); Raptor Eagle (1997); Bellovin & Cheswick (1994) | — |
| (b) Network with client, path including ≥1 access filter, and a server providing the resource | Bellovin & Cheswick, Figs. of screened-subnet/gateway topologies; FireWall-1 | — |
| (c) A local copy of access control information indicating whether the user may access the resource | Baker '898 — relational database at the proxy server mapping users to permitted URLs, "readily updated and modified by an administrator" | FireWall-1 rule base at each enforcement point |
| (d) An access checker employing the local copy to make the determination | Baker '898 — processor cross-references the incoming URL against the local DB | FireWall-1 inspection engine |
| (e) An access check confirmer that determines whether another access filter in the path already made the determination, and only causes the checker to act if not | FireWall-1's per-connection state (a permitted connection is not re-evaluated packet-by-packet) + Bellovin & Cheswick's tunnel-endpoint authentication (a packet from an authenticated peer over an encrypted tunnel has already been admitted by the peer) [proposed ground — see §5] | Kerberos-style "present a ticket, do not re-authenticate" |
4. Ground 1 (primary): FireWall-1 White Paper + Baker '898 + Bellovin & Cheswick
Rationale 1 (predictable combination of known elements). Baker '898 supplies elements (c) and (d) — a local, administrator-updatable access control store queried by a proxy against a resource identifier on behalf of an identified user. Bellovin & Cheswick supply the multi-filter topology (a chain of packet filter → proxy → internal network) and the authenticated-encrypted-tunnel model: the two tunnel endpoints authenticate each other and add authentication material (message digests/MACs) to the encapsulated traffic so that the far end can confirm origin and integrity. FireWall-1 supplies the commercial embodiment in which one centrally-managed security policy is enforced at multiple enforcement points.
Rationale 2 (the problem itself supplies the motivation). The patent's own background identifies the motivation: "Present-day access filters are designed on the assumption that there are only a small number of access filters between the source and destination... Where there are many, the increase in access time and the reduction in access speed caused by the filters becomes important." That is an admission that the scaling problem, and hence the desire to eliminate redundant per-hop work, was known. Under KSR, the asserted advance — performing a known check once rather than n times when the n results are provably identical — is precisely "the use of a known technique to improve similar devices in the same way."
Rationale 3 (statefulness/one-time authorization was a known firewall technique). FireWall-1's stateful inspection admitted a connection after a single policy evaluation and then passed its subsequent packets without full rule-base re-evaluation. Applying that same principle across nodes rather than across packets — i.e., extending "check once per connection" to "check once per path" — is a predictable extension once tunnel endpoints can authenticate one another (B&C).
Element (e) gap. Neither FireWall-1 nor Baker '898 literally describes a different filter confirming that another filter performed the check. The closest teaching is the general "authenticated peer ⇒ rely on the peer's admission decision" convention, which a PHOSITA would apply to avoid the redundancy the background condemns. This is the vulnerable seam of the ground and the place a patent owner will focus.
5. Alternative grounds for claim 1
Ground 2 — Baker '898 + Dobbins '649 [unverified] + Yung '224 / Mihm '230. Dobbins (709/238) is a routing reference; if it discloses forwarding decisions carried in/derived from packet headers across intermediate nodes, it can supply the "intermediate node consults path information rather than recomputing the decision" teaching, with Yung/Mihm supplying cryptographic authentication of the transferred decision. Motivation: routing efficiency and avoiding duplicate computation in multi-hop paths.
Ground 3 — Baker '898 + Che-fun Yu (GLOBECOM 1989) + FireWall-1. Yu's paper is expressly directed to access control and authorization for customer control of network services — i.e., distributed authorization over a service-provider network. Coupled with FireWall-1's central-policy/distributed-enforcement architecture, a PHOSITA would be motivated to distribute the access control information so each enforcement point can decide locally and to avoid duplicating a decision already reached at ingress. [unverified as to exact disclosure]
Ground 4 — WO 96/05549 + Baker '898. The sole foreign reference on the face. If WO 96/05549 discloses secure network access with authenticated peers, it supplies element (e)'s mechanism directly.
6. Dependent claims
Claims 2–6 (encryption / key targeting / trust-vs-sensitivity)
| Claim | Limitation | Mapping & motivation |
|---|---|---|
| 2 | Encrypt the request when the determination is "permitted" | Bellovin & Cheswick (encrypted tunneling after admission); FireWall-1 encryption modules. Motivation: confidentiality of admitted traffic. |
| 3 | Each filter holds a key; routing info identifies the last filter; encrypt with the last filter's key | SKIP (Aziz & Patterson) — a transport key derived from the destination peer's public key in its X.509 certificate; the spec itself calls SKIP "self-authenticating." Motivation: end-to-end encryption without re-keying at every hop. |
| 4 | Encrypt so the last filter in the path can decrypt | Same as claim 3; B&C's tunnel endpoint is the "furthest encryption endpoint." |
| 5 | Plurality of encryption methods; access control info associates a sensitivity level with the resource and a trust level with each method; encrypt with a method whose trust level ≥ resource sensitivity | Multilevel-security art (Bell–LaPadula / TCSEC "clearance must dominate classification"); B&C's trust model (an IP address is weakly trusted, a token strongly); Schneier, Applied Cryptography (cipher strength hierarchy). Motivation: "neither require nor provide more than is necessary" — the patent itself concedes this efficiency rationale was the design goal. Raptor Eagle's "Five Domains of Network Security" is a candidate secondary reference for graded security policy. |
| 6 | Client encrypts; the filter decrypts before the determination | Bellovin & Cheswick's remote/roaming user with an encrypted client; SKIP-enabled roamers. Motivation: authenticating and authorizing a remote user whose traffic has crossed the public Internet. |
Claim 7 (authenticator adds authentication information; confirmer reads it back)
This is the strongest structural claim and the most defensible limitation: the confirmer's answer is derived from authentication information the upstream filter added to the request.
- Mapping: SKIP's authentication header (a MAC over the whole message plus source/destination NSID/MKID identifiers) is literally "authentication information added to the request" that a downstream node uses to confirm origin and integrity. Bellovin & Cheswick describe the same added-header construction for tunneled packets.
- Motivation: to make an upstream admission decision reliably transferable, it must be cryptographically bound and non-forgeable — otherwise a downstream filter could be spoofed. KSR "predictable result."
- Caveat: the claim requires that the information be used specifically to determine whether another access filter made the determination. Prior art that merely authenticates the packet's origin will require a claim-construction argument that "from an authenticated peer ⇒ the peer checked" is the same thing. A patent owner will argue this is a distinct, non-obvious insight, and this is probably the best non-obviousness argument available on this record.
Claims 8–10 (distributed DB, editing, delegation)
| Claim | Limitation | Mapping & motivation |
|---|---|---|
| 8 | Editor makes a change in the local copy; change propagator pushes it to the others | FireWall-1's central management console distributing policy to distributed enforcement modules; distributed directory/DB replication (X.500); Singh '083 (network management) [unverified]; the patent's own background concedes multiple filters made central administration "too slow, too expensive, and too error-prone" — a direct motivation for local editing + propagation. |
| 9 | Access control info indicates whether a given user may change a predetermined part of the local copy; the access checker evaluates that change request | Che-fun Yu (1989) — authorization plans for customer control of network services (scoped administrative authority); Chapman '650 (access control system) [unverified]; role-based access control generally. |
| 10 | A user who may change a predetermined part may delegate that right | Che-fun Yu (1989) is the on-point reference: it addresses authorizing customers to exercise control over portions of a provider's network service. RBAC delegation was known. Motivation: the patent's background condemns central administration by "a small number of data security experts." |
Claims 11–14 (medium / implementation)
- 11 (data storage device containing code implementing claim 1): routine; a computer-readable medium claim adds nothing patentable over the underlying method/apparatus under In re Beauregard / In re Nuijten line of reasoning as applied to § 103.
- 12–14 (application program / OS component / router component): Dobbins '649 (router) [unverified] and the general firewall-art teaching that a firewall is a gateway program running on a general-purpose host (B&C; FireWall-1; Raptor Eagle) render these mere design choices among a finite set of known implementation loci.
7. Consolidated motivation-to-combine (MPEP § 2143 rationales)
- Known technique to improve a similar device in the same way — apply single-evaluation caching/state (FireWall-1) across nodes rather than packets.
- Avoiding redundant work — the patent's own background states the performance penalty of multiple filters; KSR permits the motivation to come from the problem itself.
- Predictable result — if two nodes hold the same access control data (Baker '898) and the upstream node's decision is cryptographically authenticated (SKIP/B&C), the downstream node's independent recomputation yields the same answer; eliminating it is a predictable optimization.
- Design incentive / market force — commercial firewalls were being pushed into multi-site, VPN-scale deployments (FireWall-1, Raptor Eagle), which created direct pressure to reduce per-hop cost.
- Efficiency in security provisioning — the MLS/TCSEC framework motivates matching cryptographic strength to data sensitivity (claim 5) and scoping administrative rights (claims 9–10).
8. Where the obviousness case is weak (the patent owner's rebuttal)
- Teach-away / defense-in-depth. The dominant security doctrine of the era — articulated squarely in Bellovin & Cheswick — is that layers should independently re-check ("hard on the outside, soft in the middle" is criticized precisely because it relies on a single check). A PHOSITA reading B&C might be dissuaded from trusting a downstream filter to forgo its own check. This is the patent owner's strongest argument and cuts directly against element (e).
- The "confirmer" as a distinct structural element. Claim 1 recites the confirmer as a component, not merely the result of skipping checks. Grounds built on "redundancy is wasteful" risk being characterized as impermissible hindsight, reconstructing the claim from the inventor's own disclosure of the problem.
- Claim 7's coupling of authentication information to the confirmer is a specific, integrated architecture. No single cited reference appears to disclose it as a unit. Expect a Kahn/Arendi-style "no reasoned rationale, only the inventor's roadmap" attack on any ground asserting claim 7 without a strong secondary reference.
- Secondary considerations. No objective indicia (commercial success, licensing, copying, long-felt need) were surfaced in this session, and I found no litigation asserting this patent (see the earlier litigation section). That absence helps the challenger by removing a secondary-considerations record, but it also means there is no KSR-era adjudicated obviousness holding to cite.
9. Bottom line
- Claims 1–6, 8 and 11–14 are, on this record, reasonably vulnerable to § 103 over a combination anchored on Baker US 5,696,898 (local access-control store + proxy-based access checker), Bellovin & Cheswick (1994) and CheckPoint FireWall-1 (1995) (multi-filter topology, per-connection state, authenticated encrypted tunnels), with Aziz & Patterson's SKIP/Schneier supplying the encryption-selection and trust/sensitivity limitations and Che-fun Yu (GLOBECOM 1989) supplying delegation.
- Claim 5 is vulnerable if the challenger can put the MLS/TCSEC trust-vs-sensitivity framework in evidence (e.g., the Raptor Eagle "Five Domains" white paper plus a TCSEC reference).
- Claim 7 is the hard claim. Its "authentication information → access check confirmer" linkage is the patent's real point of novelty; a § 103 ground should target it only with a reference that expressly ties added authentication material to suppressing a downstream authorization step, and any such ground must survive a hindsight attack.
- Every ground above rests on the examiner-cited art. Two of those references (FireWall-1 and Raptor Eagle) are non-patent commercial white papers with no verifiable publication date beyond the dates shown on the face, so their § 102(b) status should be confirmed (the FireWall-1 v2.0 paper is dated June 1995; the Raptor Eagle paper is dated Jan. 30, 1997 — both precede the March 10, 1997 priority date, but the Eagle date is only ~6 weeks before it, which should be double-checked against the provisional dates 60/039,542 and 60/040,262).
Unsolicited caveats, stated plainly: (i) I could not verify the disclosures of US 5,828,832, US 5,828,833, US 5,951,649, US 5,758,083, or US 5,987,611 in this session, and the mapping of those references above is explicitly marked [unverified]; do not file a petition or invalidity contention on those mappings without pulling the full texts. (ii) I did not locate any PTAB or district-court obviousness adjudication of US 6,105,027. (iii) The Google Patents "Cited By" entries for this patent are later documents and are therefore not prior art to it; do not use them in a § 103 ground.
Generated 9/30/2026, 1:23:09 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 10019722I'll search for authoritative information on this specific patent number. Let me search for any 2026 CAFC docket activity and additional USPTO records. US Patent 10,019,722 — Verified Bibliographic Summary Search scope note: I searched for…
- US 10241643I'll search for the specific patent number and any litigation/docket activity. No litigation hits for this specific patent yet. Let me check for claim text and any court dockets. Let me try to retrieve the actual claim text. US Patent…
- US 8387155I'll search for authoritative records on this specific patent number before summarizing. Let me pull the actual claim text and check for any 2026 appellate activity. Let me try to retrieve the actual claim language and confirm the…
- US 8127345I'll verify the patent against live sources before summarizing. Now let me pull the actual claim language and check for any 2026 activity. Let me obtain the actual claim text rather than paraphrase from memory. US Patent 8,127,345 B2 —…
- US 11659381US 11,659,381 B2 — Verification Summary Sources used: the authoritative full text of US 11,659,381 B2 supplied in this matter (Google Patents, fetched 2026-10-01), plus live web results including Unified Patents, Docket Alarm/PACER-derived…
- US 8898260I'll search for authoritative information on this specific patent number and any 2026 CAFC activity. Let me dig deeper into the 2026 docket activity and the reexamination/PTAB status specifically for the '260 patent. One more targeted…
- US 8756336I'll search for authoritative information on this specific patent number. US Patent 8,756,336 B2 — Summary I searched for the specific number 8756336 (treated literally, no auto-correction). The authoritative full text (provided) is…
- US 7289772I'll search for authoritative information on this patent, including any 2026 litigation activity. US Patent 7,289,772 — Summary Note on identifiers: I interpreted "7289772" literally as US 7,289,772 B1. I did not find any CAFC 2026 docket…