Invalidity dossier
US 6317837
Internal network node with dedicated firewall
Current assignee: FireNet Technologies, LLC
Added 9/11/2026, 11:07:42 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll run targeted searches to check for any current USPTO records or 2026 CAFC activity on this exact number before summarizing.
Let me check specifically for any 2026 Federal Circuit activity and the current owner/enforcement status.
Scope note on what I could and could not verify
I searched for the exact identifier 6317837 (and the formatted forms 6,317,837 / US6317837B1) across patent databases and litigation sources. Results for US 6,317,837 B1 were returned consistently; I did not substitute any similar-looking number. Two caveats up front:
- No 2026 Court of Appeals for the Federal Circuit docket activity for 6,317,837 was found. My searches for a 2026 CAFC appeal tied to this number returned no results, and no CAFC appeal appeared in any record I retrieved. I cannot affirmatively state that a 2026 CAFC matter does not exist — I can only state that I found none. Treat "no 2026 CAFC activity located" as a search limitation, not a verified negative.
- The bibliographic data below is grounded in the patent document itself (authoritative, provided in the record) plus Google Patents' machine-generated assignment/litigation metadata, which is explicitly disclaimed as not a legal conclusion.
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 6,317,837 B1 |
| Title | Internal network node with dedicated firewall |
| Application number | 09/144,954 |
| Inventor | Stacy Kenworthy |
| Original assignee | Applianceware LLC (per Google Patents); first recorded assignee was Realm Information Technologies, Inc. (assignment recorded 1998-09-01) |
| Priority date | 1998-09-01 |
| Filing date | 1998-09-01 (no earlier priority claim — the application is the priority document) |
| Publication / grant date | 2001-11-13 |
| Status | Expired – Lifetime; anticipated expiration 2018-09-01 |
| Classification | H04L63/02, H04L63/0209, H04L63/0218 (distributed firewalls), H04L63/0281 (proxies), G06F16/951, G06F21/6218, Y10S707/99939 |
| Claims | 90 total |
Assignee chain (from the assignment/reassignment records): Realm Information Technologies, Inc. (1998) → Applianceware, Inc. (2000 merger/name change) → Applianceware, LLC (2001) → Optifacio, Inc. (2002) → Opticaute, Inc. (2004) → Robust Networks, LLC (2007) → Mineral Lassen LLC (2015) → Intellectual Ventures Assets 57 LLC (2017) → IQ Holdings, LLC (2018) → Firenet Technologies, LLC (2018-04-13).
⚠️ Inconsistency to flag: Google Patents' "Current Assignee" field lists three names simultaneously — Applianceware Inc, Firenet Technologies LLC, and Applianceware LLC — which is internally contradictory and likely a metadata artifact. Separately, a 2019 district court corporate disclosure (FireNet Technologies, LLC v. Citrix Systems, Inc., N.D. Ga. 1:19-cv-03199) identified FireNet's affiliate as Intelleq Holdings, LLC. The precise current ownership record should be confirmed against USPTO Assignment records rather than the Google Patents summary.
Abstract (verbatim)
A network attached device server for implementing a network attached device and firewall management system (NADFW-MS). The NADFW-MS provides a multiple direction firewall that is dedicated for the protection of one or more associated NADs. The firewall is considered to be multiple directional because it filters data packets based on the network interface used to transport the data packets. The firewall is also able to filter data packets based on any other information contained in a data packet header. A data packet that does not penetrate the firewall is discarded and the reason for discarding the data packet is recorded in a log file. A data packet that does pass through the firewall is sent to a data management system that is responsible for providing access to the appropriate associated NAD. The data management system uses network protocol programs and interface mechanisms to process the data packet and to communicate the data packet to the appropriate NAD. The data management system may also function as a proxy server and generate a new data packet that is forwarded to another NAD server.
Plain-language overview of each independent claim
The patent has nine independent claims: 1, 37, 58, and 79–84. They convey the same core idea in four claim formats — arrangement, method, apparatus, and device-specific apparatus.
Claim 1 — Network arrangement
A network with an internal group of nodes (a LAN) and an external group of nodes, joined by an intermediate node that runs a bastion firewall protecting the internal network from outside traffic. The recited improvement is inside the internal network: (a) a network attached device (NAD), and (b) a NAD node that must receive every request to access that NAD originating at any other node in the whole arrangement. That NAD node stores computer-executable instructions that (i) receive the access request, (ii) decide whether it is authorized, (iii) grant access if authorized, and (iv) deny access if not. The net effect: the NAD is protected by a dedicated NAD firewall at the NAD node, standing against unauthorized requests from the intermediate node, other internal nodes, and external nodes.
Claim 37 — Method
The method counterpart of claim 1, applied to the same bastion-firewall network arrangement containing a NAD. The steps are (a) determining — for each and every request for access to the NAD — whether it is authorized, (b) providing access when authorized, and (c) denying access when not. The stated result is the same: the NAD is protected by a dedicated NAD firewall against unauthorized requests originating at the intermediate, internal, and external nodes.
Claim 58 — Apparatus (internal node)
An apparatus that is an internal node of an internal network. The node contains a NAD plus a computer with computer-readable media holding instructions to (a) communicate over the network, including receiving access requests for the NAD, (b) determine whether each request is authorized, (c) grant access if authorized, and (d) deny access if not. The NAD is thereby protected from unauthorized network access by a dedicated firewall of the apparatus — note this claim does not require a separate bastion firewall or a separate node, which is the broadest framing of the four.
Claims 79–84 — Device-specific apparatus claims
These six claims take the claim 58 structure and substitute a specific device type as the protected internal node, each with the same four-step instruction set (receive request / determine authorization / provide access / deny access) and each ending with the same "protected from unauthorized network access by a dedicated firewall of the apparatus" language:
- Claim 79 — a CD-ROM server, receiving requests for access to a CD.
- Claim 80 — a network storage server, receiving requests for access to network storage.
- Claim 81 — an audio device, receiving requests for access to functions of the audio device.
- Claim 82 — a video device, receiving requests for access to its functions.
- Claim 83 — a facsimile machine, receiving requests for access to its functions.
- Claim 84 — a printer, receiving requests for access to its functions.
Representative dependent claims (context for scope)
The dependent claims are highly repetitive across the four families (2–36 from claim 1; 38–57 from claim 37; 59–78 from claim 58; 85–90 from claims 79–84). Recurring limitations worth noting:
- Header-based filtering: authorization is determined by filtering the data packet on IP addresses and other information in the packet header (claims 19, 39, 73, 86).
- Header completeness as to source, destination, and route (20, 40, 74, 87).
- Authorized network interface test (21, 41, 75, 88) — this is the limitation that gives the firewall its "multi-directional" character in the specification.
- Valid source address (22, 42, 76, 89) and valid destination address (23, 43, 77, 90).
- Proper port test, then passing to the proper port and using a network protocol program and interface mechanism to reach the NAD (24, 44, 78).
- Architectural split: a firewall component wrapping the dedicated firewall exclusively around the NAD, and a data management component that accepts authorized requests and provides access (9, 71).
- NAD types: storage drive (with ZIP, JAZ, CD-ROM, DVD, optical, tape, and hard drive variants), printer, audio device, video device, facsimile machine (25–36, 45–57, 59–70).
- Claim 85 is a multiple-dependent claim referencing claims 79, 80, 81, 82, 83, or 84 — a form that survived pre-AIA practice.
Family and continuations
Family ID 22510924, four U.S. applications, all claiming the 1998-09-01 priority:
| Application | Patent | Filed | Title |
|---|---|---|---|
| 09/144,954 | 6,317,837 | 1998-09-01 | Internal network node with dedicated firewall |
| 09/951,877 | 7,739,302 | 2001-09-11 | Network attached device with dedicated firewall security |
| 12/773,716 | 8,306,994 | 2010-05-04 | Network attached device with dedicated firewall security |
| 13/665,523 | 8,892,600 | 2012-10-31 | Network attached device with dedicated firewall security |
The '302 is a continuation of the '837; the '994 and '600 continue that chain.
Litigation and enforcement posture (as of the search date)
Google Patents lists five district court matters flagged on the '837 record:
- N.D. Cal. 3:18-cv-06502 and 3:19-cv-00798
- N.D. Ga. 1:19-cv-03199 (FireNet Technologies, LLC v. Citrix Systems, Inc. — US 6,317,837 was Exhibit A to the complaint, alongside the '302, '994, and '600)
- E.D. Tex. 2:18-cv-00270 (FireNet Tech LLC v. Fujitsu Ltd.)
- S.D.N.Y. 1:18-cv-05564 (FireNet Technologies, LLC v. KEMP Technologies Inc.)
Two important qualifications:
- The '837 appears to have been the tail of the assertion set, not the lead. In the N.D. Ga. and E.D. Tex. matters, the detailed infringement charts reference the '302 and '600 (e.g., '302 claim 1, '600 claims), not '837 independent claims. The one document I retrieved that maps a '837 claim element-by-element (Ex Parte's analysis of the Fujitsu complaint) charts independent claim 37 — the method claim — against the accused "Access Control function."
- PTAB challenges in this family targeted a sibling patent, not the '837. In IPR2020-00471 (Unified Patents, LLC v. Firenet Technologies, LLC, filed 2020-03-13, terminated 2021-03-18), the challenged patent was US 8,892,600, claims 1–17 and 19–23. US 6,317,837 appears in that proceeding only as Exhibit 1013 (a copy of the '837 specification, cited as "Kenworthy '837"), used as background/priority evidence alongside the '302 and '994. I found no IPR petition challenging 6,317,837 itself.
Expiration is the key practical fact: the '837 reached its anticipated expiration on 2018-09-01 and carries status Expired – Lifetime. Any enforcement would be limited to pre-expiration conduct, which is consistent with the 2018 filings and would explain why the later-filed matters (2019) pivoted to the still-unexpired continuation patents.
Stated uncertainties
- No 2026 CAFC docket entry for 6,317,837 was located. My targeted searches returned zero results. This is an absence of evidence, not proof of absence; a PACER/CAFC docket check on the specific appellate case number would be needed to confirm.
- Ownership is contradictory in the metadata. Google Patents lists three "current assignees" and separately lists Firenet Technologies, LLC; the last recorded assignment on the face of the record is IQ Holdings → FireNet Technologies (2018-04-13). There is also a 2019 security-interest assignment naming Brightwood Loan Services LLC as collateral agent with KEMP Technologies Inc. as assignor, released 2022-01-24 — a KEMP-side asset transaction that does not, on its face, change ownership of the '837. Verify against USPTO Assignment records.
- The patent text contains apparent OCR artifacts in the Summary of the Invention — the interface mechanisms are rendered as "ODE. SCSO. EODE, Fiber Channel." I have quoted these literally rather than normalizing them (they likely correspond to IDE/SCSI/EIDE, but the record as provided does not say so). Likewise, Figure 1's "video codes 116c" in the specification text versus "video codec" elsewhere, and claim 66's "hard d rive."
- Claim-set composition note: I treat claims 1, 37, 58, and 79–84 as independent based on the claim text. Claim 85 is multiple-dependent on 79–84 and is not independent despite its claim-like recitation of "each request … contained in a data packet."
Generated 9/12/2026, 12:45:43 AM
Cases on file (5)
Group view →Specific litigation cases in our database that name US patent 6317837. The free-form analysis below may also discuss cases beyond this list.
Lawsuits filed per year
- FireNet Technologies, LLC v. Citrix Systems, Inc.filed Jul 12, 20191:19-cv-03199N.D. Ga. (Judge Leigh Martin May)terminated Oct 17, 2019closed
Defendants: Citrix Systems, Inc.
- FireNet Technologies, LLC v. Fortinet Inc.filed Feb 14, 20193:19-cv-00798N.D. Cal. (Judge James Donato)terminated Aug 9, 2019closed
Defendants: Fortinet Inc.
- FireNet Technologies, LLC v. A10 Networks, Inc.filed Oct 24, 20183:18-cv-06502N.D. Cal. (Judge Vince Chhabria)terminated Jan 22, 2019dismissed (settled)
Defendants: A10 Networks, Inc.
- FireNet Technologies, LLC v. Fujitsu Ltd. et al.filed Jul 5, 20182:18-cv-00270E.D. Tex. (Judge Rodney Gilstrap; referral to Mag. J. Roy S. Payne)terminated Sep 27, 2019dismissed with prejudice
Defendants: Fujitsu Ltd., Fujitsu America, Inc.
- FireNet Technologies, LLC v. KEMP Technologies Inc.filed Jun 20, 20181:18-cv-05564S.D.N.Y. (Judge Andrew L. Carter, Jr.)not confirmed beyond filing
Defendants: KEMP Technologies Inc.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US patent 6317837 using the litigation sources you specified.
Let me dig deeper into the specific cases, including one I haven't identified yet (3:18-cv-06502).
Litigation Involving U.S. Patent No. 6,317,837
Patent: US 6,317,837 B1 ("Internal network node with dedicated firewall"), filed Sep. 1, 1998, granted Nov. 13, 2001. Inventor Stacy Kenworthy. The patent is part of a family that also includes US 7,739,302; US 8,306,994; and US 8,892,600 (all sharing the Sep. 1, 1998 priority date).
Key context on the plaintiff: Nearly all identified district court cases were brought by FireNet Technologies, LLC (of Peachtree Corners, GA), the assignee entity that acquired the patent family. FireNet asserted the '837 patent together with related family members, so I flag where the '837 was expressly identified.
Identified District Court Cases
| # | Plaintiff | Defendant(s) | Jurisdiction | Case No. | Filed | Status/Outcome |
|---|---|---|---|---|---|---|
| 1 | FireNet Technologies, LLC | KEMP Technologies Inc. | S.D.N.Y. (Judge Andrew L. Carter, Jr.) | 1:18-cv-05564 | June 20, 2018 | Not confirmed beyond filing; case appears in later IPR record as prior litigation |
| 2 | FireNet Technologies, LLC | Fujitsu Ltd. and Fujitsu America, Inc. | E.D. Tex. (Judge Rodney Gilstrap; referral to Mag. J. Roy S. Payne) | 2:18-cv-00270 | July 5, 2018 | Dismissed with prejudice — consent motion granted; order of dismissal signed Sept. 27, 2019 (docketed Sept. 30, 2019); preceded by a stay for settlement (June 2019) |
| 3 | FireNet Technologies, LLC | A10 Networks, Inc. | N.D. Cal. (Judge Vince Chhabria) | 3:18-cv-06502 | Oct. 24, 2018 | Dismissed – Settled; closed Jan. 22, 2019 (docket updated through Feb. 4, 2019) |
| 4 | FireNet Technologies, LLC | Fortinet Inc. | N.D. Cal. (Judge James Donato) | 3:19-cv-00798 (also docketed as 4:19-cv-00798) | Feb. 14, 2019 | Closed Aug. 9, 2019 (docket entry dated Aug. 13, 2019). The AO 120 patent-report filing expressly lists 6,317,837, 7,739,302, 8,306,994, 8,892,600. Specific disposition (dismissal/settlement) not confirmed |
| 5 | FireNet Technologies, LLC | Citrix Systems, Inc. | N.D. Ga. (Judge Leigh Martin May) | 1:19-cv-03199 | July 12, 2019 | Closed Oct. 17, 2019 (98 days in litigation). Docket includes "Exhibit A – US Pat 6,317,837." Specific disposition (dismissal/settlement) not confirmed |
Case 1 note: The KEMP complaint is confirmed to have asserted the same four-patent family; the IPR exhibit record references "FireNet Technologies, LLC v. KEMP Technologies, Inc., Civ. No. 1:18-cv-05564, ECF 3 (S.D.N.Y filed June 20, 2018)." I could not confirm the final disposition from the sources retrieved.
Related Administrative Proceeding (not district court litigation)
- Unified Patents, LLC v. Firenet Technologies, LLC, IPR2020-00471 (USPTO Patent Trial and Appeal Board). Petitioner Unified Patents filed an inter partes review. The record includes Unified Exhibit 1013 = U.S. Patent 6,317,837 ("Kenworthy '837"). This is an administrative challenge at the PTAB, not court litigation.
Important Caveats
- Family-wide assertion. FireNet's complaints generally asserted the four-patent family ('837, '302, '994, '600). Not every case above is guaranteed to have included the '837 patent, though cases 1 and 4 expressly list it (and case 5's docket includes an '837 exhibit).
- Outcomes are partially incomplete. For KEMP, Fortinet, and Citrix, I confirmed the courts, case numbers, and (where available) closure dates, but I could not confirm from the retrieved sources whether dismissal was with/without prejudice or the precise settlement terms. The Fujitsu case is the clearest: dismissed with prejudice after settlement.
- Source limitations. These results come from Google Patents' litigation links, Unified Patents' litigation portal, RPX Insight, Justia Dockets, Patexia, and PacerMonitor. I did not independently retrieve PACER/CAFC primary documents for every case, so treat "closed" dates as docket-derived rather than judicially verified. No CAFC appeal appears associated with these cases in the sources retrieved.
- No auto-correction applied. Case numbers and patent numbers are reported exactly as they appear in the sources (e.g., the Fortinet case appears under both 3:19-cv-00798 and 4:19-cv-00798; the Google Patents litigation links show 3:19-cv-00798).
Summary: At least five district court cases are known, all filed 2018–2019 by FireNet Technologies, LLC against KEMP, Fujitsu, A10 Networks, Fortinet, and Citrix. The Fujitsu and A10 Networks cases are confirmed resolved (dismissed with prejudice / dismissed-settled, respectively); the others show closure in 2019. A related PTAB inter partes review (IPR2020-00471) was filed by Unified Patents in 2020.
If you need me to drill into PACER for the exact disposition language of the KEMP, Fortinet, and Citrix cases, or to pull the PTAB Final Written Decision for IPR2020-00471, let me know.
Generated 9/12/2026, 12:45:28 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: FireNet Technologies, LLC
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the structured-data default against live sources before writing the report.
The '600 patent IPR isn't the '837 — but note Exhibit 1013 was the '837. Let me check for IPRs directly against the '837.
Proceedings overview
Zero AIA trial proceedings are on file against US 6,317,837. The USPTO Open Data Portal structured block (the canonical list) reports no IPR, PGR, or CBM involving this patent, and my live searches surfaced no petition directed at the '837 — not by KEMP, not by Unified Patents, not by anyone. Because there is no proceeding, there is no status breakdown to give: active = 0, claims invalidated = 0, claims sustained = 0, settled = 0, institution denied = 0. The defensive posture is therefore not "hardened by surviving IPRs" — it is "untested at the PTAB, but expired," which for a 2026 defendant is the more important fact (see Strategic summary). What is on file is meaningful adjacent activity against family members — an IPR that killed all challenged claims of US 8,892,600 (a continuation of the '837) and a Unified Patents PATROLL bounty on US 7,739,302. Those are flagged below, clearly labeled as not proceedings on the '837.
Flagged adjacent activity (NOT proceedings on US 6,317,837)
IPR2020-00471 — Unified Patents, LLC v. Firenet Technologies, LLC
Challenged patent: US 8,892,600 — not the '837.
- Type: Inter Partes Review
- Filed: 2020-03-13
- Patent challenged: US 8,892,600 ("Security for a Network Attached Device" — a continuation in the same family as the '837; all four family members share priority date 1998-09-01)
- Status (from sources located): Trial instituted 2020-09-01 on all challenged claims; Final Written Decision 2021-03-18 holding all challenged claims unpatentable. Public source: Unified Patents, "FireNet Technologies patent held unpatentable" (2021-03-18); docket documents at Patexia case record for IPR2020-00471.
- Judge panel: not confirmed in the sources I could reach — verify on PTAB E2E (ptab.uspto.gov) before relying on it.
- Petition grounds (as summarized by a third-party docket summary; verify against the FWD itself):
- Ground 1 — § 103 over Coley (US 5,826,014) in view of Coss (US 6,098,172) for claims 1–14, 16, 17, 19–22.
- Ground 2 — § 103 over Coley + Coss + Shand (US 6,147,976) for claims 15 and 23 (adding the "logging rejected packets" limitation).
- Ground 3 — § 103 over Coss in view of Gelb (US 5,550,984) for claims 1–14, 16, 17, 19–22.
- Institution decision: instituted on all challenged claims, 2020-09-01 (Unified Patents, "FireNet Technologies patent determined to be likely invalid").
- Final Written Decision: 2021-03-18 — all challenged claims (reported as claims 1–17 and 19–23) held unpatentable. Note: as reported, claim 18 was not part of the disposition — do not assume it was canceled. Also note the reported time from institution (2020-09-01) to FWD (2021-03-18) is well under the statutory 12-month window; that is unusual and worth verifying against the decision document.
- Settlement / termination: none reported — case went to a merits FWD.
- Appeal: not confirmed in the sources I could reach. I did not find a Federal Circuit appeal of this FWD.
- Why it matters for the '837: discloses Unified's reference set (Coley/Coss/Shand/Gelb) and the Board's willingness to accept that combination against this family's "first computing device = firewall protecting a second device with an attached peripheral" architecture. It creates no estoppel against the '837 — § 315(e)(2) estoppel attaches only to the patent that was the subject of the IPR.
- Defensive value for a '837 defendant: indirect but real. The '837 and '600 share a priority date and largely overlapping disclosure, so the Coley/Coss/Gelb/Sand art is a productive starting point for a fresh invalidity analysis of '837 claims 1, 37, 58, and 79–84 — subject to an independent pre-1998-09-01 (or pre-1997-09-01 for § 102(b)) reference-date check on each reference.
Notable: the '837 was itself used as an exhibit in that IPR
Petitioner's Exhibit 1013 in IPR2020-00471 was "U.S. Patent 6,317,837 (Kenworthy '837)" (alongside Exhibit 1012, US 7,739,302). This appears to be for the family/priority chain rather than as attacking prior art — the '837 has the same 1998-09-01 priority date as the '600 and cannot be prior art to it. Sources: Patexia docket, IPR2020-00471.
PATROLL contest — US 7,739,302 (another family member, not the '837)
On 2020-09-29 Unified Patents opened a $2,500 crowdsourced prior-art contest on at least claim 1 of US 7,739,302 (a '837 family member), asserted against KEMP, Fortinet, Citrix, A10 Networks, and Fujitsu; a $1,250 award was paid 2021-05-11. Sources: PATROLL contest page, Unified announcement. This signals that Unified was actively hunting invalidity art across the FireNet family in 2020–2021 but never filed a petition against the '837 itself — a notable absence rather than an oversight, given the family was otherwise targeted.
Strategic summary
Claim status on the '837: everything is UNTESTED at the PTAB. No claim of US 6,317,837 has been canceled, confirmed, or even subjected to an institution decision by the Board. Claims 1, 37, 58, and 79–84 therefore remain in force as issued — but "in force" overstates the practical threat, because the patent expired on 2018-09-01 (20 years from the 1998-09-01 filing; Google Patents records "Anticipated expiration 2018-09-01" and status "Expired – Lifetime"). An expired patent cannot support prospective injunctive relief; damages reach only past infringement, and § 286 caps recovery at six years before suit. Given the assertion campaign ran in 2018–2019 (S.D.N.Y. 1:18-cv-05564 against KEMP; E.D. Tex. 2:18-cv-00270 against Fujitsu; N.D. Cal. 3:18-cv-06502 and 3:19-cv-00798; N.D. Ga. 1:19-cv-03199), the § 286 window on the '837 has almost certainly closed as of 2026. That — not PTAB history — is the strongest fact in a defendant's favor.
Estoppel landscape: essentially clean, in both directions. Because no IPR was ever instituted on the '837, no petitioner is barred under § 315(e)(2) from raising any ground against it. Conversely, the patent owner obtained no validity wins to hide behind. Unified's FWD on the '600 generates estoppel only as to the '600. If a current defendant wants PTAB invalidation of the '837, the path is technically open (the Board does institute on expired patents, though a patent owner cannot amend and the Board may question whether a live controversy remains), and the practical value is limited — the far cheaper play is a § 286 limitations analysis plus the Coley/Coss/Gelb/Shand art noted above if validity ever matters again (e.g., for an indemnity or a damages apportionment dispute over pre-expiration sales).
Pattern signals. The owner chain shows a classic NPE monetization cascade: Realm/Applianceware → Optifacio/Opticaute → Robust Networks → Mineral Lassen → Intellectual Ventures Assets 57 → IQ Holdings → FireNet Technologies, LLC (recorded 2018-04-13), asserted against KEMP, Fortinet, Citrix, A10, and Fujitsu in 2018–2019. FireNet is an IPinvestments Group entity. A defensive aggregator — Unified Patents — was clearly in the chain, with in-house counsel David Seastrunk and Roshan Mansinghani handling IPR2020-00471. Unified hit the '600 (petition 2020-03-13, FWD 2021-03-18 killing the challenged claims) and ran a PATROLL bounty on the '302, but did not petition against the '837 or, so far as my searches show, against the '302. Also relevant: the '837 and its three family continuations are all now expired; the '600, '302, and '094 records show "Expired – Fee Related" / "Expired – Lifetime," meaning the family's assertion value has largely run out.
Recommended next steps
- Do not build a defense on imagined PTAB history. There is none. State this plainly in any invalidity/PTAB risk memo: no AIA trial proceeding has ever been filed or instituted on US 6,317,837 (per USPTO ODP; independently confirmed by search). If opposing counsel or a demand letter implies the patent was "upheld by the PTAB," that is false — it was never tested there.
- Lead with expiration and § 286. The '837 expired 2018-09-01. Map any accused conduct against the six-year lookback from the date of any complaint and confirm no actionable past-acts window remains. Verify the expiration date against the USPTO Patent Center file wrapper for any PTA/PTE that could shift it.
- If a validity fight is needed, start from the family-member IPR record: pull the IPR2020-00471 Final Written Decision (2021-03-18) from PTAB E2E and the petition's grounds, then re-run the Coley (US 5,826,014) / Coss (US 6,098,172) / Shand (US 6,147,976) / Gelb (US 5,550,984) combination against '837 claims 1, 37, 58, and 79–84 — with an independent pre-1998-09-01 reference-date check on each reference, since the '837's claims differ from the '600's and a reference that qualifies against one family member may not qualify against the other.
- Track litigation closure rather than PTAB. The five 2018–2019 district court cases (listed in the structured block) are the live-or-concluded events that determine exposure. Confirm dismissal/settlement status in S.D.N.Y. 1:18-cv-05564, E.D. Tex. 2:18-cv-00270, N.D. Cal. 3:18-cv-06502 and 3:19-cv-00798, and N.D. Ga. 1:19-cv-03199.
- Verify before filing anything. I could not confirm the APJ panel, the exact claim-by-claim disposition beyond "claims 1–17 and 19–23," the status of claim 18, or whether the '600 FWD was appealed to the Federal Circuit. Confirm each on PTAB E2E and the Federal Circuit docket / CourtListener before relying on them. If you find a newly-filed or recently-indexed petition against the '837 that the ODP ingest missed, that would change this analysis — but as of today, the record is zero.
Generated 9/12/2026, 12:45:53 AM
Ownership chain (16)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
1998-09-01 · reel 009446/0291 · Assignment
Stacy KenworthyRealm Information Technologies, LLC
founder-to-operating-company assignment
? · recorded 2000-06-30 · Merger and Name Change
Realm Information Technologies, LLCApplianceware, Inc.
internal reorg
? · recorded 2001-03-29 · Change of Name
Realm Holding CorporationApplianceware, Inc.
change of name only
? · recorded 2002-01-31 · Assignment
Applianceware, Inc.OptiFacio, Inc.
divestiture
? · recorded 2004-07-23 · Assignment
OptiFacio, Inc.Opticaute, Inc.
secondary transfer
? · recorded 2004-07-23 · Assignment
Stacy KenworthyOpticaute, Inc.
residual-rights cleanup
? · recorded 2006-12-04 · Assignment of Additional Rights
Stacy KenworthyOpticaute, Inc.
residual-rights cleanup
? · recorded 2007-02-15 · Assignment
Opticaute, Inc.Robust Networks, LLC
transfer-to-asserter
? · recorded 2011-06-17 · Correction
Stacy KenworthyRealm Information Technologies, LLC
administrative cleanup
? · recorded 2011-06-17 · Correction
Applianceware, Inc.Applianceware, Inc.
administrative cleanup
? · recorded 2011-06-17 · Correction
Realm Information Technologies, LLCApplianceware, Inc.
change of name only
? · recorded 2015-11-18 · Merger
Robust Networks, LLCMineral Lassen LLC
transfer-to-asserter
? · recorded 2017-09-26 · Assignment
Mineral Lassen LLCIntellectual Ventures Assets 57 LLC
transfer-to-asserter
? · recorded 2018-01-19 · reel 044669/0326 · Assignment
Intellectual Ventures Assets 57 LLCIQ Holdings, LLC
transfer-to-asserter
? · recorded 2018-04-13 · Assignment
IQ Holdings, LLCFireNet Technologies, LLC
pre-assertion transfer
? · recorded 2019-04-05 · Security Agreement
KEMP Technologies Inc.Brightwood Loan Services LLC, as collateral agent
security interest
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll verify the ownership chain against live sources before writing up the record.
Rich results. Let me pin down the corporate history, the intermediate transfers, and any litigated-sibling reel/frame data.
US 6,317,837 — Ownership & Assignment Reconstruction
Patent: US 6,317,837 B1 — "Internal network node with dedicated firewall"
App. No.: 09/144,954 · Filed: 1998-09-01 · Issued: 2001-11-13 · Status: Expired – Lifetime (anticipated expiration 2018-09-01)
Family: US 7,739,302 · US 8,306,994 · US 8,892,600 (all sharing the 1998-09-01 priority)
Sourcing caveat up front. Google Patents' legal-events tab exposes party names, dates and conveyance types but not the reel/frame or the recording correspondent. The assignment-record correspondent field — the single most probative datum you asked for — is not published on Google Patents, PEDS/ODP, RPX, or Unified Patents' public pages, and I was unable to retrieve the Assignment Center record pages directly in this session. I am therefore not supplying correspondent names or reel/frame numbers for most links. Fabricating them would be worse than the gap. Where I can corroborate a reel/frame from a primary document, I say so and mark its evidentiary weight.
Inventors
| Inventor | Employer at filing | Basis |
|---|---|---|
| Stacy Kenworthy (sole inventor) | Realm Information Technologies, Inc. — Atlanta, later San Jose, CA; developer of the ApplianceWare Linux server-appliance/NAS software platform | Kenworthy assigned his rights to Realm Information Technologies by instrument executed 1998-09-01, recorded at Reel 009446 / Frame 0291 (reel/frame recited verbatim in the 2011 corrective assignment text carried on Google Patents' legal-events tab) |
Unusual pattern — flag. This is a single-inventor patent, so there is no "all inventors depart within 12 months" pattern. The anomaly is different and more interesting: Kenworthy reappears as an assignOR after the operating company had divested the patent. The 2004-07-23 assignment to Opticaute, Inc. lists assignors both OptiFacio, Inc. and Kenworthy, and a further 2006-12-04 record to Opticaute is captioned "ASSIGNMENT OF ADDITIONAL RIGHTS" with Kenworthy as assignor. A solo inventor executing an "additional rights" assignment to a downstream IP holding company two years after the patent left the operating company is consistent with a founder retaining a personal residual interest (or a carried-inventor participation) in a monetization vehicle — not with an ordinary corporate chain of title.
Original assignee
Realm Information Technologies, Inc. (assignee of record at filing, 1998-09-01), which became Applianceware, Inc. by merger (2000-06-30) and then Applianceware, LLC by change of name (2001-03-29). The patent issued 2001-11-13 naming Applianceware, LLC as assignee; Google Patents accordingly lists "Original Assignee: Applianceware LLC."
- Primary line of business: Linux server-appliance software — an OEM software platform sold to appliance manufacturers, administered over the Web or via Java, running on Intel/Alpha under Linux. Realm was explicitly building for the network-attached storage (NAS) appliance market at the time of filing — i.e., the commercial embodiment is directly on point for the patent's claimed subject matter.
- Did they ship a product embodying the claims? Yes, at least in part. CNET reported Realm's ApplianceWare as a shipping software product capable of connecting storage devices (disk drives, CD-ROMs) to networks running Unix, Windows or Novell — precisely the "NAD server with dedicated firewall" architecture claimed here. This matters: the chain starts at a genuine operating company with a real product.
- Funding / corporate trajectory: ~$5M private funding from inception (1996) plus a $3M investment from SoundView Technology Group; HQ relocated Atlanta → San Jose. The company was capitalized and East-to-West migrating during the filing window.
- Current status: Not determinable from the sources available to me. Realm/Applianceware does not appear as a live operating entity in the material I could retrieve, and the patent was divested to OptiFacio, Inc. by 2002 — an unusually fast post-issuance exit. I will not characterize it as dissolved, bankrupt, or acquired; I simply could not confirm which. If you have a public-records subscription, the Georgia and Delaware secretary-of-state registries plus SEC EDGAR full-text for 2000–2003 are the obvious next checks.
Assignment timeline
All entries below are drawn from Google Patents legal events for US 6,317,837. Google's legal-events dates are not segregated into execution date vs. recording date, so each date below should be read as "recorded/effective as listed." Where the underlying instrument's reel/frame is recoverable, it is shown in bold.
1998-09-01 — Reel 009446 / 0291
- Conveyance: Assignment
- Assignor: Stacy Kenworthy
- Assignee: Realm Information Technologies, Inc.
- Correspondent: Not retrievable (see sourcing caveat).
- Context: Founder-to-operating-company assignment of the sole inventor's rights at filing — standard clean-chain origination.
2000-06-30
- Conveyance: Merger and Name Change
- Assignor: Realm Information Technologies, LLC
- Assignee: Applianceware, Inc.
- Correspondent: Not retrievable.
- Context: Internal reorg — operating company renamed/mergered; no new consideration, no third party.
2001-03-29
- Conveyance: Change of Name
- Assignor: Realm Holding Corporation
- Assignee: Applianceware, LLC
- Correspondent: Not retrievable.
- Context: Internal reorg, name-change only — the entity named on the face of the issued patent.
2002-01-31
- Conveyance: Assignment
- Assignor: Applianceware, Inc.
- Assignee: OptiFacio, Inc.
- Correspondent: Not retrievable. (Flag: the OptiFacio/Ap…) — see note below.
- Context: First outbound transfer — the operating company exits the chain ~10 weeks after issuance. Consistent with a divestiture/sale of the patent out of the operating business rather than a licensing program run by Applianceware.
2004-07-23 (two records, same date)
- Conveyance: Assignment
- Assignors: OptiFacio, Inc. and Stacy Kenworthy
- Assignee: Opticaute, Inc.
- Correspondent: Not retrievable.
- Context: Secondary transfer plus inventor's residual-rights cleanup — the "additional rights" pattern noted under Inventors.
2006-12-04
- Conveyance: Assignment of Additional Rights
- Assignor: Stacy Kenworthy
- Assignee: Opticaute, Inc.
- Correspondent: Not retrievable.
- Context: Cleanup of inventor residual rights, again — the same holding company is still perfecting its title 8 years post-filing.
2007-02-15
- Conveyance: Assignment
- Assignor: Opticaute, Inc.
- Assignee: Robust Networks, LLC
- Correspondent: Not retrievable.
- Context: Transfer into an entity whose name carries no operating-business signal — the first link in the chain whose only discernible function is holding/monetizing the asset.
2011-06-17 (three corrective records, same date)
- Conveyance: Correction (to recordation cover sheets)
- Assignors/Assignees: Kenworthy → Realm Information Technologies, LLC; Applianceware, LLC → Applianceware, Inc. (merger); Realm Information Technologies, LLC → Applianceware, LLC (corrective; "conveyance type is name change only")
- Correspondent: Not retrievable.
- Context: Administrative cleanup of the 1998–2001 reorg records only. No new party, no new consideration. This is not an ownership event and should be excluded from any chain-of-title count. Notably, the 2011 correction to the 1998 record is the only place in the entire public file where an actual reel/frame is recited.
2015-11-18
- Conveyance: Merger
- Assignor: Robust Networks, LLC
- Assignee: Mineral Lassen LLC
- Correspondent: Not retrievable.
- Context: Merger into an entity using the characteristic Intellectual Ventures "invention-investment" shell-naming convention — the point at which the asset plausibly enters the IV ecosystem.
2017-09-26
- Conveyance: Assignment
- Assignor: Mineral Lassen LLC
- Assignee: Intellectual Ventures Assets 57 LLC
- Correspondent: Not retrievable.
- Context: Transfer-to-asserter pipeline — consolidation into an IV asset-holding vehicle.
2018-01-19 — Reel 044669 / Frame 0326 (probable, not confirmed for '837)
- Conveyance: Assignment
- Assignor: Intellectual Ventures Assets 57 LLC
- Assignee: IQ Holdings, LLC
- Correspondent: Not retrievable.
- Context: IV divestiture to an assertion vehicle. The reel/frame above is recited in Unified Patents Exhibit 1029 ("Patent Assignment Sheet, 504737617, Reel 044669, Frame 0326 (Jan. 19, 2018)") filed in Unified Patents v. Firenet Technologies, IPR2020-00471. Caveat: that exhibit is directed to sibling patent US 8,892,600, so the identical date and identical counterparties make it strongly consistent with — but not documentary proof of — the '837 record. Treat as corroborative, not dispositive.
2018-04-13
- Conveyance: Assignment
- Assignor: IQ Holdings, LLC
- Assignee: FireNet Technologies, LLC
- Correspondent: Not retrievable.
- Context: Pre-assertion transfer. FireNet is the entity that actually filed the campaign — this is the last link before litigation.
2019-04-05 — anomalous record on the chain
- Conveyance: Intellectual Property Security Agreement (assignor listed as KEMP Technologies Inc.; assignee Brightwood Loan Services LLC, as collateral agent), released 2022-01-24.
- Correspondent: Not retrievable.
- Context: Not an ownership link in the chain. KEMP is the defendant in FireNet v. KEMP, and this is a security interest granted by KEMP over its own IP estate that Google's event feed surfaces alongside this patent. I flag it because it recurs on the record and can be misread as a chain link; on the evidence available it is a collateral encumbrance by a defendant, possibly a data-association artifact. Unclear — do not count as a transfer.
Related but distinct (litigation counsel, not assignment correspondents): the S.D.N.Y. docket in FireNet Technologies, LLC v. KEMP Technologies Inc., 1:18-cv-05564, lists plaintiff's counsel of record as Andrey Belenky, Hanna Glomska Cohen, and Dmitry A. Kheyfits (firms not verifiable from the docket text I retrieved). These are assertion-side counsel, not the USPTO recording correspondents you asked about — but they are the right names to run against the recording records, since a monetization operation frequently uses the same counsel family for both.
Timeline diagram
timeline
title Ownership of US 6317837
1998 : Filed by Realm Information Technologies
: Kenworthy assigns to Realm
2000 : Realm becomes Applianceware Inc
2001 : Name change to Applianceware LLC
: Patent issues on 2001-11-13
2002 : Sold to OptiFacio Inc
2004 : Transferred to Opticaute Inc
2006 : Kenworthy assigns additional rights
2007 : Sold to Robust Networks LLC
2015 : Merged into Mineral Lassen LLC
2017 : Sold to IV Assets 57 LLC
2018 : Sold to IQ Holdings LLC
: Sold to FireNet Technologies LLC
: Suits filed vs KEMP Fujitsu A10
2019 : Suits vs Fortinet and Citrix
2022 : KEMP security interest released
NPE / troll-pattern signals
1. Shell-entity transfer — PRESENT.
The asset travels Realm/Applianceware (product company) → OptiFacio → Opticaute → Robust Networks, LLC → Mineral Lassen LLC → IV Assets 57 LLC → IQ Holdings, LLC → FireNet Technologies, LLC (2018-04-13). This is not a finding based on naming: RPX describes FireNet Technologies, LLC as "an affiliate of Georgia-based IP Investments Group LLC (d/b/a IPinvestments Group), a monetization firm controlled by Michael W. McLaughlin," and Unified Patents states flatly that FireNet is "an NPE and entity of IPinvestments Group." RPX similarly identifies IQ Holdings, LLC as controlled by Michael W. McLaughlin. No products in commerce attributed to any post-2002 assignee in any source retrieved.
2. Known asserter in the chain — PRESENT.
Intellectual Ventures is squarely in the chain via INTELLECTUAL VENTURES ASSETS 57 LLC (recorded transfer 2017-09-26, recorded out 2018-01-19). RPX is explicit that the FireNet campaign is one "in which Intellectual Ventures LLC (IV) retains an interest." RPX further documents the identical playbook for the same principals: IV → IQ Holdings → Accelerated Memory Tech, LLC / Visible Connections, LLC, with IQ Holdings and IPinvestments Group "controlled by Michael W. McLaughlin." FireNet also appears on Unified Patents' PATROLL prior-art-contest list ("$2,500 for FireNet Technologies prior art," 2020-09-16) as a campaign target — the standard signature of a high-frequency plaintiff.
3. Repeat correspondent across the chain — UNKNOWN.
No correspondent data is available to me, and I will not infer one. The recurrence test cannot be run from public web sources; the recording correspondents for Reel 009446/0291 (1998) and the 2002–2018 links must be read off the Assignment Center record pages or the underlying assignment instruments (Unified's Ex. 1029 is a copy of one such sheet and is the template to request for the others). This is the single highest-value open item in this reconstruction.
4. Cascading transfers — PRESENT (strong).
Three hops in under seven months: Mineral Lassen → IV Assets 57 (2017-09-26) → IQ Holdings (2018-01-19) → FireNet Technologies (2018-04-13). That the last two are separated by less than 90 days, that both counterparties trace to the same principals per RPX (McLaughlin-controlled IQ Holdings; IPinvestments-affiliated FireNet), and that the intermediate Reel 044669/0326 sheet was produced as an IPR exhibit all point to a deliberately staged hand-off rather than independent commercial transactions.
5. Pre-litigation transfer — PRESENT (strong).
FireNet took title 2018-04-13; FireNet Technologies, LLC v. KEMP Technologies Inc. was filed 2018-06-20 in S.D.N.Y. (1:18-cv-05564) — approximately two months later, well inside your 6-month window. Venue is consistent with deliberate placement (S.D.N.Y., later E.D. Tex. for the Fujitsu case, 2:18-cv-00270). Direct confirmation that this patent was in the campaign: the S.D.N.Y. complaint excerpt alleges "KEMP has infringed at least claim 37 of the '837 Patent" — claim 37 being this patent's independent method claim. Suits followed against Fujitsu (2:18-cv-00270), A10 Networks (N.D. Cal. 2018), Fortinet (N.D. Cal., Feb. 2019), and Citrix (N.D. Ga., July 2019). The four asserted patents are the four members of this family ('837/'302/'994/'600) — the whole family was transferred and asserted as a unit.
6. Bankruptcy fire-sale — NOT PRESENT (no evidence).
I found no bankruptcy, receivership, or Chapter 11/7 record for Realm, Applianceware, OptiFacio, or Opticaute. The exit to OptiFacio on 2002-01-31 reads as an ordinary divestiture or a wind-down sale, not a court-supervised asset sale. Marked on absence of evidence, not on affirmative evidence of solvency.
7. Privateering — NOT PRESENT in the classic sense.
Classic privateering requires an operating company transferring to an NPE to assert against its competitors. Here the transferor of record (IV Assets 57) is itself a non-practicing entity. The adjacent observation — IV retaining a financial interest in the FireNet campaign per RPX — is a revenue-share/back-end-interest structure, i.e. monetization, not competitive privateering.
8. Defensive aggregator (anti-NPE) — NOT PRESENT in the chain; note the counter-offensive.
The chain terminates at FireNet Technologies, LLC — an asserter, not RPX/AST/LOT/Unified/OIN. The inverse event is worth recording, however: Unified Patents successfully invalidated sibling US 8,892,600 (final written decision, 2021-03-18, Unified Patents, LLC v. Firenet Technologies, LLC, IPR2020-00471 — all of claims 1–17 and 19–23 unpatentable), and ran a PATROLL contest on US 7,739,302. Meanwhile this patent ('837) reached its 2018-09-01 anticipated expiration, so the post-2019 suits reach only backward-looking damages. The family's assertion value was substantially neutralized by expiration plus Unified's IPR — but that is a defensive response, not a defensive acquisition.
Verdict
NPE — high confidence.
Four independent strong signals converge on the same conclusion, each grounded in a dated record rather than a suggestive name. (i) Known asserter in the chain: Intellectual Ventures Assets 57 LLC is the recorded assignor-out on 2018-01-19 (Reel 044669/0326, probable), with RPX reporting that IV "retains an interest" in the resulting campaign. (ii) Cascading transfers: three hops in ~7 months — Mineral Lassen → IV Assets 57 (2017-09-26) → IQ Holdings (2018-01-19) → FireNet Technologies (2018-04-13) — where RPX identifies both IQ Holdings and FireNet as entities of the same McLaughlin/IPinvestments control group. (iii) Pre-litigation transfer: title moved 2018-04-13 and FireNet v. KEMP was filed 2018-06-20, roughly two months later, with the complaint expressly charting claim 37 of the '837 patent. (iv) Shell-entity transfer: the chain departs a genuine product company (Realm/Applianceware, whose shipping ApplianceWare NAS platform embodied the subject matter) by 2002-01-31 — ten weeks after issuance — and thereafter passes exclusively through non-practicing holding vehicles, terminating at a monetization vehicle affirmatively labelled an NPE by both RPX and Unified Patents. The one signal I could not evaluate is the repeat-correspondent test, because the Assignment Center's correspondent field is not exposed on any source I could reach; that is a gap in my evidence, not a negative finding, and it is the first thing to close.
Verify at: USPTO Assignment Center · Assignment Search (legacy index) — search patent 6,317,837. Cross-references: Google Patents legal events · RPX Empower — FireNet v. KEMP, 1:18-cv-05564 · Unified Patents — FireNet '600 held unpatentable · Unified PATROLL — FireNet '302.
Two items I could not establish and did not guess: (a) the recording correspondent of record for every link, and (b) the current status of Realm Information Technologies / Applianceware (operating, acquired, or dissolved). Item (a) is retrievable today from the Assignment Center record pages and from Unified's Ex. 1029 assignment sheet; item (b) requires state registries and EDGAR.
Generated 9/12/2026, 12:46:16 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research US 6317837 and its cited prior art. Let me run several searches.
Let me research the remaining cited prior-art references to describe them accurately.
Prior-Art Analysis — US 6,317,837 B1
"Internal network node with dedicated firewall"
Inventor: Stacy Kenworthy · Assignee (as granted): Applianceware, LLC · Appl. No. 09/144,954 · Filed/Priority: 1998‑09‑01 · Granted: 2001‑11‑13 · Status: Expired – Lifetime (anticipated expiration 2018‑09‑01)
Sources consulted: the full patent text and front page (Google Patents, https://patents.google.com/patent/US6317837/en), the USPTO-derived front-page citation list (https://uspto.report/patent/grant/[6317837](/patent/6317837)), and Patexia (https://patexia.com/us/patent/06317837).
1. Scope note and caveats
- The patent's front page lists 15 cited references: 13 U.S. patents and 2 PCT/WO publications. These are the references reproduced in the "Citations (15)" table and on the uspto.report front page. All of them pre-date the 1998‑09‑01 filing date either by publication (WO/earlier patents) or by U.S. filing date (for the later-published patents, which are available as §102(e) art).
- Strict-rule compliance: all patent/publication numbers below are reproduced exactly as they appear in the record (including the erroneous-looking
US6105027Aform used in the source table, which is the granted number for the Schneider reference). No identifiers have been auto-corrected. - Authority of descriptions: Dates, assignees and inventors are taken from the patent front page. Descriptions marked (confirmed) are supported by text I retrieved from the reference itself (or its full-text record); descriptions marked (title-based) are inferred solely from the reference's title/assignee as listed on the face of US 6,317,837, because I was unable to retrieve the reference's full text within the research budget. Where a §102 mapping depends on a title-based description, I say so.
- Legal standard applied: For anticipation under 35 U.S.C. §102, a single reference must disclose each and every limitation of the claim, arranged as in the claim. For the dependent claims I therefore ask whether the reference discloses the added limitation, not whether it discloses the invention as a whole. Nothing below is a legal opinion.
2. What must be shown to anticipate
The asserted independent claims are claims 1, 37, 58, and 79–84. Claim 1 (representative apparatus claim) requires, in combination:
- a first group of nodes = internal network; a second group = external network;
- an intermediate node with a bastion firewall connecting the two;
- within the internal network, (a) a NAD and (b) a NAD node at which every request for network access to the NAD must be received;
- the NAD node performing (i) receipt, (ii) authorization determination, (iii) provide access if authorized, (iv) deny if not;
- the NAD protected by a dedicated NAD firewall at the NAD node against requests originating at intermediate, internal and external nodes.
Claim 37 is the method counterpart; claim 58 is the "internal node with NAD + dedicated firewall" apparatus; claims 79–84 are device-specific apparatus claims (CD-ROM server, network storage server, audio device, video device, facsimile machine, printer).
Key takeaway: For §102 purposes, the novel concept is a firewall dedicated to and physically/architecturally wrapped around a NAD or storage/print/AV node positioned inside the LAN, behind the bastion firewall, such that the NAD is reachable only through that node. No cited reference, on its face, discloses this complete combination. Most cited art is directed at perimeter firewalls, host security interfaces, or session/authentication mechanisms, and is therefore more useful as §103 (obviousness) art against dependent limitations than as §102 anticipation of the independent claims.
3. Reference-by-reference analysis
A. References most relevant to the independent claims (1, 37, 58, 79–84)
1. US 5,577,209 A — Boyle et al. (ITT Corporation)
- Full citation: U.S. Patent 5,577,209, "Apparatus and method for providing multi-level security for communication among computers and terminals on a network," Boyle, Maiwald & Snow, appl. 08/270,398 (continuation of 07/728,633, filed 1991‑07‑11).
- Dates: priority/filing 1991‑07‑11; granted 1996‑11‑19.
- Description (confirmed — I retrieved the full record): A Secure Network Interface Unit (SNIU) is coupled between each host/user computer and the network, operating at the session layer. The SNIU identifies the user, verifies authorization for network access, controls the data path, and only then establishes a session; a Security Manager architecture administers policy. A global security perimeter is created when an SNIU sits at each node. The SNIU intercepts IP datagrams and decides whether each datagram is releasable to the network and whether/how to encrypt it.
- Potential §102 mapping: Relevant to claim 1 elements (b)(i)–(iv) (a node that must receive traffic and determine authorization) and to claim 58's "internal node … determining whether each request for network access is authorized." Also relevant to claims 18–19 and 72–73 (data-packet/header-based decisions). It does not disclose a NAD or a firewall dedicated to a NAD, so it does not anticipate claims 1, 37, 58 or 79–84 outright; it is best characterized as §103 art against the authorization-node limitations.
2. US 6,088,796 A — Cianfrocca, Francis (and Sohn, Adam H.)
- Full citation: U.S. Patent 6,088,796, "Secure middleware and server control system for querying through a network firewall," appl. 09/129,800; provisional 60/054,876 filed 1997‑08‑06.
- Dates: priority 1997‑08‑06; U.S. filing 1998‑08‑06 (three weeks before the 1998‑09‑01 filing of US 6,317,837); granted 2000‑07‑11.
- Description (confirmed — I retrieved the full record): A secure access query system with a communication server, an application/server resource behind a network firewall, and a middleware/messenger system. The application server inside the firewall opens an outbound secure pathway to the middleware; the firewall blocks any inbound connection and only the authorized resource path is permitted. Claim 21 is expressly an "access control system" in which a resource inside the firewall is "protected against any access from outside the firewall except through the middleware system," including database/application-server resources, load balancing across multiple back-end servers, and port restriction per server.
- Potential §102 mapping: Highly relevant to claims 1, 4 ("NAD is accessible only through said NAD node"), 9/71 ("firewall component … wraps the dedicated firewall exclusively around … the NAD" + data-management component), 14 (proxy server for a second server), and 58. It discloses a protected resource behind a firewall plus a controlled access path and anti-inbound-connection firewall, but it does not disclose a NAD/storage/printer/AV device, nor a firewall dedicated at a NAD node inside the LAN. Because it was filed only ~3 weeks before the target's filing date and published only in 2000, its practical weight is as §102(e) art against the "protected resource inside the firewall" concept. It does not, alone, anticipate the independent claims.
3. US 6,005,475 A — Shrader (International Business Machines Corp.)
- Full citation: U.S. Patent 6,009,475, "Filter rule validation and administration for firewalls," Theodore Jack London Shrader, appl. 08/773,543 (related to 08/773,542, now US 5,864,666).
- Dates: filed 1996‑12‑23; granted 1999‑12‑28.
- Description (confirmed — I retrieved the full record): A user interface for validating test packets against firewall filter rules between a secure and nonsecure network. Test packets are defined by attributes "selected from a set of attributes of normal packets" (source/destination address and mask, etc.); the system validates the packet against the filter rules, identifies the rule that denied it, and indicates whether the action/information was logged to a syslog file.
- Potential §102 mapping: Directly relevant to the header-attribute filtering and logging limitations — claims 19–24, 39–44 and 73–78 (filtering based on IP addresses and other header information; determining completeness; valid source/destination; proper port) and to the specification's logging-on-discard feature. It is a firewall administration/validation tool on a perimeter firewall, so it does not disclose a NAD-node firewall. Best as §103 art against the filtering/logging dependent claims.
4. WO 98/31124 A1 — Hanson, Gordon L.
- Full citation: PCT publication WO 1998031124 A1, "Reverse proxy server," Hanson, Gordon L.; priority 1997‑01‑10; published 1998‑07‑16.
- Description (title-based): A reverse-proxy server architecture. As listed on the front page of US 6,317,837 it appears under "Foreign Patent Documents."
- Potential §102 mapping: Relevant to the proxy-server limitations of claims 14, 24, 44, 78 and to the specification's proxy capacity (§FIG. 5 discussion; the data-management component generating "a new data packet" for a second NAD server). A reverse proxy does not, on its face, disclose a dedicated NAD firewall; useful as §103 art against the proxy-related dependent claims.
5. US 5,655,077 A — Jones et al. (Microsoft Corporation)
- Full citation: U.S. Patent 5,655,077, "Method and system for authenticating access to heterogeneous computing services," appl. filed 1994‑12‑13; granted 1997‑08‑05.
- Description (title-based; a Microsoft authentication patent of that era): A method/system for authenticating user access to heterogeneous computing services.
- Potential §102 mapping: Relevant to claim 5 (and the corresponding disclosure) reciting "a plurality of network protocol programs for accepting requests for network access from multiple heterogeneous network nodes," and to the heterogeneous-client discussion (Mac/PC/UNIX: AppleTalk/Netware/TCP-IP). Not a NAD firewall; §103 art for claim 5.
B. References relevant to specific device / media limitations
6. US 5,642,337 A — Oskay et al. (Sony Corporation)
- Full citation: U.S. Patent 5,642,337, "Network with optical mass storage devices," priority/filing 1995‑03‑14; granted 1997‑06‑24.
- Description (title-based): A network employing optical mass-storage devices (i.e., CD/optical media served across a network).
- Potential §102 mapping: Relevant to the storage-device limitations — claims 25–32, 45–52, 59–66 and especially claim 79 (CD-ROM server apparatus serving "requests for network access to a CD"). It shows networked optical storage but no dedicated per-device firewall, so claim 79's "determining whether each request … is authorized" and "dedicated firewall of the apparatus" elements are not shown. §103 art.
7. US 5,719,786 A — Nelson et al. (Novell, Inc.)
- Full citation: U.S. Patent 5,719,786, "Digital media data stream network management system," priority/filing 1993‑02‑03; granted 1998‑02‑17.
- Description (title-based): Network management of digital media data streams (audio/video).
- Potential §102 mapping: Relevant to the audio/video device limitations — claims 34, 35, 54, 55, 57, 68, 69, 81, 82 ("audio device"/"video device"/"audio-visual device"). No dedicated device firewall is shown. §103 art.
C. References relevant to security architecture and access control (perimeter/host)
8. US 5,416,842 A — Aziz (Sun Microsystems, Inc.)
- Full citation: U.S. Patent 5,416,842, "Method and apparatus for key-management scheme for use with internet protocols at site firewalls," priority/filing 1994‑06‑10; granted 1995‑05‑16.
- Description (title-based): Key management for Internet protocols at site firewalls.
- Potential §102 mapping: Bears on the bastion/site-firewall context of claims 1 and 37 (the intermediate node with a bastion firewall), but discloses cryptographic key management, not NAD access authorization. Not anticipatory; background/§103 art.
9. US 5,548,721 A — Denslow (Harris Corporation)
- Full citation: U.S. Patent 5,548,721, "Method of conducting secure operations on an uncontrolled network," priority/filing 1994‑04‑28; granted 1996‑08‑20.
- Description (title-based): Conducting secure operations over an untrusted ("uncontrolled") network.
- Potential §102 mapping: General background on securing operations over untrusted networks; relevant conceptually to the "second layer of security"/protected-resource rationale but not to the specific NAD-node claim elements. §103/background art.
10. US 5,692,124 A — Holden et al. (ITT Industries)
- Full citation: U.S. Patent 5,692,124, "Support of limited write downs through trustworthy predictions in multilevel security of computer network communications," priority/filing 1996‑08‑30; granted 1997‑11‑25.
- Description (title-based; related to the Boyle/ITT SNIU family discussed above): Multilevel-security flow control using predictions to validate "write down" releases.
- Potential §102 mapping: Relevant to the security-node/flow-control limitations (claims 1/37/58) as a family companion to US 5,577,209; no NAD or per-device firewall. §103 art.
D. References relevant to NAD access management / session and QoS management
11. US 5,247,670 A — Matsunaga (Fuji Xerox Co., Ltd.)
- Full citation: U.S. Patent 5,247,670, "Network server," priority 1988‑03‑16; granted 1993‑09‑21.
- Description (title-based): A network server (early networked-peripheral/resource server context).
- Potential §102 mapping: Pertinent background to the "NAD server" concept (claims 3, 10–15) — a node that permits network nodes to access attached resources. No firewall/authorization layer is indicated by the title; not anticipatory. Background art.
12. US 5,652,908 A — Douglas et al. (International Business Machines Corp.)
- Full citation: U.S. Patent 5,652,908, "Method and apparatus for establishing communications sessions in a remote resource control environment," priority/filing 1991‑10‑02; granted 1997‑07‑29.
- Description (title-based): Establishing communication sessions to control remote resources.
- Potential §102 mapping: Bears on the "NAD node" / remote-resource-access concept (claims 1(b), 6, 58(a)) but not on firewall authorization. Background/§103 art.
13. US 6,047,322 A — Vaid et al. (Ukiah Software, Inc.)
- Full citation: U.S. Patent 6,047,322, "Method and apparatus for quality of service management," priority/filing 1997‑05‑27; granted 2000‑04‑04.
- Description (title-based): Quality-of-service management (the patent family includes firewall/QoS-related work such as US 6,119,235 and US 6,047,322).
- Potential §102 mapping: Peripheral to the claims; relevant only as context for packet classification/management. Not anticipatory.
14. US 6,105,027 A — Schneider et al. (Internet Dynamics, Inc.)
- Full citation: U.S. Patent 6,105,027, "Techniques for eliminating redundant access checking by access filters," priority/filing 1997‑03‑10; granted 2000‑08‑15. (Note: the citation table renders this as
US6105027A; that is the same granted document number.) - Description (title-based): Access-filter (firewall/access-control) techniques that avoid redundant access checking.
- Potential §102 mapping: Relevant to the filtering/authorization limitations (claims 1(b)(ii), 19–24, 37(a), 73–78) and to the "series of filtering tests" disclosure. It is an access-control/filter optimization patent, not a NAD firewall. §103 art against the authorization/filtering claims.
15. WO 98/32077 A1 — Cornett, Bruce
- Full citation: PCT publication WO 1998032077 A1, "Method for connecting multiple heterogeneous computers to public networks using a single physical connection," Cornett, Bruce; priority 1997‑01‑16; published 1998‑07‑23.
- Description (title-based): Connecting heterogeneous computers to public networks over a single physical connection.
- Potential §102 mapping: Relevant to claim 5/heterogeneous-client support and to the internal-network/external-network bridging context. Not a NAD firewall; §103 art.
4. Summary table
| # | Reference | Date (prio → pub) | Assignee | Relevance to 6,317,837 | Most relevant claims |
|---|---|---|---|---|---|
| 1 | US 5,577,209 A | 1991‑07‑11 → 1996‑11‑19 | ITT Corp. | Session-layer secure network interface; authorization node | 1(b)(ii)–(iv), 58, 18–19, 72–73 |
| 2 | US 6,088,796 A | 1997‑08‑06 → 2000‑07‑11 | Cianfrocca/Sohn | Resource behind firewall; access control system; no inbound connections | 1, 4, 9, 14, 58, 71 |
| 3 | US 6,009,475 A | 1996‑12‑23 → 1999‑12‑28 | IBM | Firewall filter-rule validation; packet-attribute matching; syslog | 19–24, 39–44, 73–78 |
| 4 | WO 98/31124 A1 | 1997‑01‑10 → 1998‑07‑16 | Hanson | Reverse proxy server | 14, 24, 44, 78 |
| 5 | US 5,655,077 A | 1994‑12‑13 → 1997‑08‑05 | Microsoft | Authenticating heterogeneous services | 5 |
| 6 | US 5,642,337 A | 1995‑03‑14 → 1997‑06‑24 | Sony | Networked optical mass storage | 25–32, 45–52, 59–66, 79 |
| 7 | US 5,719,786 A | 1993‑02‑03 → 1998‑02‑17 | Novell | Digital media stream network management | 34, 35, 57, 68, 69, 81, 82 |
| 8 | US 5,416,842 A | 1994‑06‑10 → 1995‑05‑16 | Sun Microsystems | Key management at site firewalls | 1, 37 (bastion context) |
| 9 | US 5,548,721 A | 1994‑04‑28 → 1996‑08‑20 | Harris Corp. | Secure ops on uncontrolled network | background |
| 10 | US 5,692,124 A | 1996‑08‑30 → 1997‑11‑25 | ITT Industries | Multilevel-security predictions | 1, 37, 58 |
| 11 | US 5,247,670 A | 1988‑03‑16 → 1993‑09‑21 | Fuji Xerox | Network server | 3, 10–15 (background) |
| 12 | US 5,652,908 A | 1991‑10‑02 → 1997‑07‑29 | IBM | Remote resource session establishment | 1(b), 6, 58(a) |
| 13 | US 6,047,322 A | 1997‑05‑27 → 2000‑04‑04 | Ukiah Software | Quality-of-service management | peripheral |
| 14 | US 6,105,027 A | 1997‑03‑10 → 2000‑08‑15 | Internet Dynamics | Non-redundant access-filter checking | 1(b)(ii), 19–24, 73–78 |
| 15 | WO 98/32077 A1 | 1997‑01‑16 → 1998‑07‑23 | Cornett | Heterogeneous computers to public networks | 5 |
5. Conclusion — most relevant prior art
US 5,577,209 A (Boyle et al., ITT) and its family companion US 5,692,124 A (Holden et al., ITT) are the most structurally analogous references: they place an authorization-decision node between a client and the network at the session layer. They are the strongest §103 combination candidates against the "NAD node determines authorization / provides or denies access" limitations of claims 1, 37 and 58 — but they do not disclose a NAD or a per-device dedicated firewall, so they do not anticipate.
US 6,088,796 A (Cianfrocca) is the most relevant reference to the "resource protected behind a firewall, reachable only via a controlled access path" concept that underlies claims 1, 4, 9, 14 and 58 — and it is temporally close (filed 1998‑08‑06). It remains non-anticipatory because it lacks the NAD and NAD-node architecture.
US 6,009,475 A (Shrader, IBM) and US 6,105,027 A (Schneider, Internet Dynamics) are the most relevant to the header-based filtering, rule-testing and logging dependent limitations (claims 19–24, 39–44, 73–78).
US 5,642,337 A (Sony) and US 5,719,786 A (Novell) are the most relevant to the device-specific independent claims 79–84 (optical/CD-ROM storage; audio/video media), and US 5,655,077 A (Microsoft) / WO 98/32077 A1 (Cornett) to the heterogeneous-protocol limitation of claim 5. WO 98/31124 A1 (Hanson) is the most relevant to the proxy limitations.
No reference cited on the face of US 6,317,837 appears to anticipate any of independent claims 1, 37, 58 or 79–84 under 35 U.S.C. §102 on its own, because none discloses the claimed combination of (i) a bastion-firewall-protected internal network, (ii) a NAD, and (iii) a NAD node inside the LAN serving as the exclusive, dedicated firewall for that NAD. The cited art is best deployed under §103, in combinations, against the narrower dependent claims.
6. Confidence and limitations
- High confidence: the identity, dates, assignees, inventor, claim set, and the 15-item citation list of US 6,317,837; the full claim-recitation mapping for claims 1, 37, 58 and 79–84; the detailed descriptions of US 5,577,209, US 6,009,475 and US 6,088,796.
- Moderate confidence: descriptions of US 5,416,842, US 5,548,721, US 5,247,670, US 5,642,337, US 5,652,908, US 5,655,077, US 5,692,124, US 5,719,786, US 6,047,322, US 6,105,027, WO 98/31124 and WO 98/32077, which are largely title-based for this report (I could not retrieve their full texts within the research budget). Any §102 conclusion as to those references should be re-verified against each reference's complete specification and claims before being relied upon.
- I was unable to retrieve the full text of several references (searches for US 5,416,842, US 5,719,786, WO 98/31124, US 6,105,027 and US 5,652,908 did not return usable full-text records). Corresponding descriptions and claim mappings are therefore provisional.
- This is an analytical summary, not legal advice; a formal invalidity or infringement opinion would require the full texts of, at minimum, US 5,577,209, US 6,088,796, US 6,009,475 and US 6,105,027, plus consideration of any art cited during prosecution but not listed on the front page.
Generated 9/12/2026, 12:45:59 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll research the key prior-art references cited on this page to ground the obviousness analysis.
Let me research a few more of the cited references to ground combination arguments.
Obviousness Analysis — U.S. Patent 6,317,837 B1
"Internal network node with dedicated firewall" · Inventor: Stacy Kenworthy · Appl. No. 09/144,954 · Filed & priority: 1998-09-01 · Granted: 2001-11-13 · Status: Expired – Lifetime (anticipated expiration 1998-09-01 + 20 yrs)
1. Scope, governing standard, and claim framework
The § 103 inquiry is the Graham v. John Deere / KSR Int'l v. Teleflex framework: scope and content of the prior art, differences between the prior art and the claims, level of ordinary skill, and secondary considerations. For an invention with a 1998-09-01 filing/priority date, pre-AIA § 102/§ 103 govern. Critically, several of the strongest references issued after 1998-09-01 but were filed before it, making them prior art only under pre-AIA § 102(e) — which is nonetheless fully available as § 103 art.
The 90 claims reduce to a small number of independent concepts (independent claims 1, 37, 58, 79, 80, 81, 82, 83, 84), plus a large dependent tail that largely recites (a) packet-header filtering sub-steps, (b) a catalogue of known network-attached devices ("NADs"), and (c) direct-connect/interface hardware arrangements.
The asserted point of novelty, per the specification, is:
"NAD servers are not equipped with a second layer of security because it is generally accepted that such a second layer of security is redundant of the bastion firewall." … "the present invention introduces another firewall that is dedicated exclusively to the protection of the data stored on a NAD."
So the inventive contribution reduces to placement + dedication: put a firewall into/at the resource-serving internal node, wrap it exclusively around the NAD, and require that every request — internal, external, or from the intermediate (bastion) node — pass through it, filtering on packet-header content.
2. Prior-art inventory (as cited on the page, with effective dates)
| Reference | Title | Effective prior-art date | § 102 basis | Relevance |
|---|---|---|---|---|
| US 5,623,601 A (Vu, Milkway Networks) | Apparatus and method for providing a secure gateway for communication and data exchanges between networks | granted 1997-04-22 | § 102(b) | Application-level proxy gateway; rule-base checks on source/destination address and port; drops denied packets; listens on all ports; authenticates sources |
| US 5,826,014 A (Coley/Wesinger, Network Engineering Software) | Firewall system for protecting network elements connected to a public network | filed 1996-02-06, granted 1998-10-20 | § 102(e) | Stand-alone "firewall box" dedicated to the firewall application; all access to protected network element must pass through it; proxy agents assigned by port; source/destination/user/time verification; transaction log; explicitly extensible to "any scenario requiring the protection of network elements" |
| US 5,968,176 A (Nessett/Sherer, 3Com) | Multilayer firewall system | filed 1997-05-29, granted 1999-10-19 (WO 98/54644 publ. 1998-12-03) | § 102(e) | Distributed firewall at internal nodes/end systems; expressly motivated by insider threat; "border firewalls are completely unsuitable to address insider threats" |
| US 5,655,077 A (Jones et al., Microsoft) | Method and system for authenticating access to heterogeneous computing services | granted 1997-08-05 | § 102(b) | Heterogeneous multi-protocol authentication/access |
| US 6,008,796 A (Cianfrocca/Sohn) | Secure middleware and server control system for querying through a network firewall | prov. 1997-08-06, filed 1998-08-06, granted 2000-07-11 | § 102(e) | Resource inside the firewall reachable only through a controlled intermediary; firewall blocks inbound connections |
| US 6,009,475 A (IBM) | Filter rule validation and administration for firewalls | filed 1996-12-23, granted 1999-12-28 | § 102(e) | Filter-rule validation/administration |
| US 5,647,743? / US 5,647,724? — see note | — | — | — | (identifier check below) |
| WO 98/31124 A1 (Hanson) | Reverse proxy server | publ. 1998-07-16 | § 102(a) | Reverse-proxy / second-server proxying |
| US 5,247,670 A (Fuji Xerox) | Network server | granted 1993-09-21 | § 102(b) | Dedicated network server providing access to network resources |
| US 5,642,337 A (Sony) | Network with optical mass storage devices | granted 1997-06-24 | § 102(b) | Network-attached optical/CD mass storage |
| US 5,987,547 A (Texas Instruments) | Network computer with interchangeable hard drive and data transceiver | filed 1997-03-31, granted 1999-11-16 | § 102(e) | Computer with directly-attached/interchangeable storage |
| US 5,600,668 A (Shwed, Check Point) | System for securing inbound and outbound data packet flow in a computer network | granted 1997-02-25 | § 102(b) | Bidirectional packet-flow security |
| US 5,550,984 A (Gelb, Matsushita) | Security system for preventing unauthorized communications between networks… | granted 1996-08-27 | § 102(b) | Address/routing-information removal at a network boundary |
| US 6,003,084 A (Green et al., Secure Computing) | Secure network proxy for connecting entities | filed 1996-09-13, granted 1999-12-14 | § 102(e) | Secure network proxy |
| US 5,944,823 A (IBM) | Outside access to computer resources through a firewall | filed 1996-10-21, granted 1999-08-31 | § 102(e) | Controlled outside access to protected resources |
| US 5,778,174 A (U S West) | Method and system for providing secured access to a server connected to a private computer network | granted 1998-07-07 | § 102(b) | Secured access to a server on a private network |
| US 5,544,721 A (Denslow, Harris) | Method of conducting secure operations on an uncontrolled network | granted 1996-08-20 | § 102(b) | Secure operation over untrusted network |
| US 5,577,209 A (Boyle, ITT); US 5,692,124 A (ITT) | Multi-level security for communication among computers/terminals | 1996-11-19 / 1997-11-25 | § 102(b) | Graded/multi-level authorization for network resources |
| US 5,716,978 A (Novell) | Digital media data stream network management system | granted 1998-02-17 | § 102(b) | Network management of media devices |
Identifier caveats (interpreted literally, not auto-corrected):
- The page's Citations list includes
US6047322A(1997-05-27, Ukiah Software — "Method and apparatus for quality of service management"); I have applied the identifier as written. - Two entries on the page read "US5247670A — Fuji Xerox, 1988-03-16/1993-09-21" and "US5642337A — Sony, 1995-03-14/1997-06-24." I use them as written.
- I could not independently re-verify
US6009475A,US5642337A, andWO1998031124A1contents in this session (search budget exhausted); my descriptions of them rest on the titles/dates on the source page and should be re-confirmed against the reference documents before any filing.
3. Independent claim 1 — primary combination
Claim 1 requires, in substance:
- Internal network (first group of nodes) + external network (second group), joined by an intermediate node including a bastion firewall;
- An internal NAD;
- A NAD node through which every request for access to the NAD "initially originated at any other node" must pass;
- Instructions that (i) receive, (ii) determine authorization, (iii) grant if authorized, (iv) deny if not;
- Result: NAD protected by a dedicated NAD firewall at the NAD node, defeating requests from the intermediate, internal, and external nodes.
Combination 1a: US 5,826,014 (Coley) in view of US 5,623,601 (Vu) and US 5,247,670 (Fuji Xerox) / US 5,642,337 (Sony)
- US 5,826,014 discloses a "firewall box … a stand alone computing platform dedicated to supporting a firewall application," connected to the protected network element by a single connection, such that "any and all access … to the protected network elements must go through the firewall." Its proxy agents verify authority by port/protocol match, source address, destination address, user/password, and time-of-day, discard failing packets, and log access-request information. This supplies elements 3–5 essentially verbatim, including the dedication and exclusivity language the 837 patent treats as its point of novelty.
- US 5,623,601 (Vu) supplies the rule-base packet filtering on source address/source port → destination address/destination port with packet drop, and confirms the gateway model can serve nodes on either side of the boundary — i.e., it is not inherently limited to screening external traffic.
- US 5,247,670 (Fuji Xerox, "Network server") and US 5,642,337 (Sony, "Network with optical mass storage devices") supply the NAD/NAD-server architecture: dedicated nodes that mediate access to attached resources (including mass-storage/optical devices).
Motivation to combine (explicit, not hindsight): Coley's own specification states the firewall "can be applied in any scenario requiring the protection of network elements that are attached to a publicly accessible medium," and teaches that a firewall must be dedicated — that is, that sharing the firewall platform with other applications "merely compromises the integrity of the firewall." A person of ordinary skill (POSITA) implementing access to a Sony-style network optical-storage server (US 5,642,337) or any Fuji-Xerox-style network server would be directly led to interpose Coley's dedicated firewall box, because Coley tells him the box is specifically designed to sit immediately in front of a protected element. The result is claim 1.
Combination 1b: Add US 5,968,176 (3Com) to supply the internal-threat limitation expressly
Claim 1's distinctive flourish is that the dedicated firewall must defeat requests originating "at said intermediate and internal and external nodes." The 837 patent's own framing asserts this was counter-intuitive ("it is generally accepted that such a second layer of security is redundant of the bastion firewall"). The prior art removes that premise:
- US 5,968,176 (3Com) states: "Between 50% and 85% of losses by corporations are the result of insider attacks … a major security requirement of corporation intranets is protection against internal attacks," and: "Border firewalls are completely unsuitable to address insider threats. They are meant to keep external intruders from attacking the corporation intranet, but have no ability to prevent insiders from doing so."
- 3Com further teaches placing firewall function at the internal node/end system itself: "A network interface card enforces that part of the policy that is pertinent to the system or device to which it is connected," and describes distributing filtering to NICs, switches, repeaters, routers and remote-access equipment so that "particular devices enforce that part of the policy pertinent to their part of the network."
Combine 3Com + Coley + Vu: 3Com supplies the why (insider/internal attack is the dominant risk and border firewalls cannot address it) and the where (enforce at the internal node/end system). Coley supplies the how (a dedicated, standalone firewall box through which all access must pass, with header-based proxy verification). Vu supplies the filtering mechanics (rule-base address/port checks with packet drop). The combination meets every element of claim 1 with a clear, articulated motivation and a reasonable expectation of success.
Timing note: US 5,968,176 issued 1999-10-19, after the 837 filing, but its application was filed 1997-05-29 and its PCT counterpart WO 98/54644 published 1998-12-03. It is therefore available as pre-AIA § 102(e) art and, being analogous art directed to the same field of network security, is properly combinable under § 103.
4. Independent claims 37, 58, 79–84
- Claim 37 (method): Identical steps to claim 1, method-form. Coley's FIGS. 4A/4B flow diagram ("receiving an incoming access request; … verifying the authority …; forming a connection … if the authority … is verified") discloses the claimed method steps. Vu's method claims 10–18 disclose source/destination/port rule-base testing and packet dropping as method steps.
- Claim 58 (apparatus = internal node comprising a NAD + a computer with instructions): This is the closest overlap with US 5,826,014, whose firewall box is "a general purpose computer" (claim 8) with a microprocessor and memory containing instructions that "initializ[e] a plurality of proxy agents … verifying that incoming connection requests are formatted in accordance with said corresponding protocol … logging … and processing received packets …" (US 6,061,798, its continuation, claim 1). Combine with US 5,987,547 (TI) for the "network computer with interchangeable hard drive and data transceiver," i.e., a computer with a directly-attached NAD.
- Claims 79–84 (apparatus where the internal node is a CD-ROM server, network storage server, audio device, video device, facsimile machine, or printer): These differ from claim 58 only in the identity of the peripheral. US 5,642,337 (Sony) discloses the CD-ROM/optical network server; US 5,987,547 (TI) discloses network storage. Printers, facsimile machines, audio and video devices were, as the 837 patent's own Background admits, well-known "network attached devices" whose network-mediated access was routine. Under KSR, substituting one known network-peripheral for another in an otherwise-identical architecture is a predictable variation and "obvious to try" — the 837 specification itself concedes that "a NAD may be any type of hardware device that is attached to a computer network." There is no asserted difference in operation, and the specification provides no evidence of unexpected results.
5. Dependent-claim mapping
| Claim(s) | Limitation | Anticipated/disclosed by |
|---|---|---|
| 2, 3, 16, 17 | NAD communicates with NAD node directly, not over the internal network | US 5,826,014 (firewall box connected to protected element by "a single connection"; protected elements "connected to the backside of the firewall"); US 5,987,547 (directly-attached drive) |
| 4 | NAD accessible only through NAD node | US 5,826,014: "any and all access … must go through the firewall box" |
| 5 | Plural network protocol programs for heterogeneous nodes | US 5,655,077 (Microsoft, authenticating access to heterogeneous computing services/multiple heterogeneous networks); WO 98/32077 (Cornett, connecting multiple heterogeneous computers) |
| 6 | NAD interface mechanism | SCSI/Fibre Channel interfaces; conventional in the field (837 spec itself lists "ODE. SCSO. EODE, Fiber Channel") |
| 7 | NAD node comprises the NAD | US 6,008,796 (resource inside the firewall reachable only via controlled intermediary); US 5,968,176 (device-local enforcement) |
| 8 | Distributed program modules | US 5,968,176 (distributed firewall functions across nodes/end systems) |
| 9, 71 | Firewall component wrapping the firewall exclusively around NAD + data management component | US 5,826,014 (dedicated firewall box; proxy agent both verifies and completes the connection to the protected element on the requester's behalf) |
| 10–13 | CPU + motherboard; NAD connected directly to a motherboard port or to an interface plugged into the motherboard; not through a network interface | US 5,987,547 (TI) |
| 14 | NAD server is a proxy for a second NAD server | US 5,623,601 (proxy initiates a second session with the destination and transparently passes data); WO 98/31124 (reverse proxy server); US 5,826,014 (proxy agents) |
| 15 | Plural NADs | US 5,247,670 / US 5,642,337 (network servers serving multiple attached devices) |
| 18–19, 38–39, 72–73, 85–86 | Request in a data packet; filtering on IP addresses and other header information | US 5,623,601 (rule base keyed to source/destination address and port); US 5,600,668 (Shwed); US 5,550,984 (Gelb); US 6,009,475 (filter-rule validation) |
| 20–24, 40–44, 74–78, 87–90 | Header completeness; arrived via authorized network interface; valid source address; valid destination address; proper port + "network protocol program and an interface mechanism" | US 5,826,014 expressly checks protocol vs. port match, source address, destination address, user/password, time; US 5,623,601 checks source address/port vs. destination address/port; the "authorized network interface" test corresponds to US 5,623,601's acceptance of packets "encapsulated with a hardware destination address that matches the device address of the gateway" and to US 5,968,176's per-device/per-interface policy enforcement |
| 25–32, 45–52, 59–66 | NAD = storage drive (ZIP, JAZ, CD-ROM, DVD, optical, tape, hard drive) | US 5,642,337 (optical/CD mass storage); US 5,987,547 (hard drive); rest are predictable variations of known drives (KSR) |
| 33–36, 53–57, 67–70 | NAD = printer, audio device, video device, facsimile machine | Admitted NAD types in the 837 Background; KSR predictable variation |
6. Motivation to combine — the articulated rationales
- Express teaching in Coley (US 5,826,014): a firewall must be dedicated to the firewall application and must be the sole path to the protected element — this is the very "dedicated firewall … wrapped exclusively around" concept claim 9 recites. Coley also states its firewall applies to "any scenario requiring the protection of network elements."
- Express teaching in 3Com (US 5,968,176): border firewalls cannot stop insiders; the dominant corporate loss vector (50–85%) is internal; therefore distribute enforcement to internal nodes and end systems. This supplies the motivation to relocate firewall function from the perimeter to an internal NAD node — precisely what the Examiner would need for claim 1's "intermediate and internal and external nodes" language.
- Express teaching in Vu (US 5,623,601): rule-base filtering on addresses/ports with packet drop, plus generic-proxy listening on all ports, plus authentication — the claimed filtering mechanics.
- Express teaching in Microsoft (US 5,655,077): heterogeneous protocol support on a single authenticating node — the claimed "plurality of network protocol programs."
- Common sense / design need (KSR): Once the internal node is the enforcement point, placing the firewall in that node (rather than in a separate box) is a predictable, efficiency-driven implementation choice — fewer hops, no separate chassis, direct interface to the NAD (claim 2/3/13).
There is a reasonable expectation of success: every element is individually known and the combination is a straightforward architectural re-arrangement with no unpredictable interaction. None of the combination produces a new mode of operation; the elements perform their own known functions.
7. Rebutting the likely patentee arguments
- "Teaching away." The 837 specification asserts the art believed "a second layer of security [was] redundant of the bastion firewall." The patentee will call this teaching away. It is not: 3Com expressly contradicts that belief in print ("Border firewalls are completely unsuitable to address insider threats"), and Coley expressly criticizes co-locating firewalls on shared platforms and advocates a dedicated box immediately in front of the protected element. The art pointed toward, not away from, the claimed arrangement. In re Fulton-style "teaching away" requires a reference that criticizes, discredits, or otherwise discourages the claimed combination; none does.
- "Hindsight." Not applicable if the motivation is drawn from the references themselves — which it is (Coley's "any scenario" statement; 3Com's insider-threat rationale; Vu's rule-base filtering).
- "The prior art firewall box is external, not an internal node." Coley's firewall box sits directly between a public network and the protected element; 3Com teaches enforcement at internal nodes and end systems. The combination squarely places the dedicated firewall at an internal node. Additionally, the 837 claims themselves are agnostic about whether the NAD node is a separate box (claim 2/3) or contains the NAD (claim 7).
- "Separate independent apparatus claims (79–84) are patentably distinct." They differ only in the identity of the attached peripheral, a difference the 837 specification itself characterizes as immaterial ("a NAD may be any type of hardware device"). KSR forecloses this argument.
8. Secondary considerations and honest caveats
- No secondary-consideration record is presented on this page. There is no evidence of unexpected results, licensing nexus, copying, or long-felt need. The page does show substantial litigation (N.D. Cal. 3:19-cv-00798 and 3:18-cv-06502; N.D. Ga. 1:19-cv-03199; E.D. Tex. 2:18-cv-00270; S.D.N.Y. 1:18-cv-05564) and a long chain of assignees ending at FIRENET TECHNOLOGIES, LLC / KEMP Technologies Inc. Litigation and acquisition activity are not probative secondary considerations absent a nexus to a specific claim, and validity was not necessarily adjudicated in those cases.
- Note a limitation on this analysis: several of the most probative references (US 5,826,014, US 6,008,796, US 5,968,176, US 6,009,475, US 5,987,547) are § 102(e)-only art because they issued after 1998-09-01. Their availability depends on their filing (or provisional) dates preceding the 837 invention date, which must be established in the record. US 6,008,796 is the tightest case (non-provisional filed 1998-08-06), and its reliance on provisional Ser. No. 60/054,876 (filed 1997-08-06) should be verified.
- References I could not re-verify online in this session (search budget exhausted):
US6009475A,US5642337A,WO1998031124A1,US5875176,US5247670A. Their descriptions above rely on the titles and dates on the source page and on my general knowledge; they should be confirmed against the documents themselves before being relied upon in a filing. - I have interpreted all identifiers literally as printed on the page and have not auto-corrected any of them.
9. Bottom line
Independent claims 1, 37, 58, and 79–84 would have been obvious over, at minimum, the following combinations:
- (A) US 5,826,014 (Coley) + US 5,623,601 (Vu) + US 5,247,670 (Fuji Xerox) / US 5,642,337 (Sony) — dedicated firewall box through which all access to a protected element must pass, with address/port rule-base filtering, applied to a network server providing access to attached mass-storage devices;
- (B) US 5,968,176 (3Com) + US 5,826,014 (Coley) + US 5,623,601 (Vu) — the same, with 3Com supplying the express motivation to enforce at internal nodes because border firewalls cannot address insider attacks;
- (C) US 5,826,014 + US 6,008,796 (Cianfrocca) + US 6,009,475 (IBM) for the internal-node apparatus claims, where the protected resource lives inside the firewall and is reachable only through a controlled intermediary.
Dependent claims fall with additions as charted in § 5 — most notably US 5,655,077 (heterogeneous protocols), US 5,987,547 (directly-attached/interchangeable storage), US 5,623,601 and WO 98/31124 (proxying to a second server), and US 5,642,337 (optical/CD network storage) — with the remaining peripheral-identity claims (25–36, 45–57, 59–70) obvious as predictable variations under KSR.
Strongest defensible positions for the patentee are (i) any claim requiring the NAD-node to contain the NAD with a direct, non-network-interface connection (claims 7, 11–13, 58 as applied to an integrated appliance), and (ii) any claim requiring a specific header-field test not squarely disclosed (e.g., the completeness test of claims 20/40/74 if the art is read narrowly). Neither appears sufficient to save the independent claims as a whole.
Generated 9/12/2026, 12:46:19 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by FireNet Technologies, LLC
Other patents in Software Technology & Computing Systems (T)
- US 7512707I'll run targeted searches for the exact patent number and for any CAFC 2026 activity. No CAFC hit for the exact number. Let me probe further for any litigation, PTAB, or Federal Circuit activity tied to this exact patent. US Patent…
- US 7512702I'll search for this patent across the sources you specified. Let me dig deeper on the claims text and check for any 2026 CAFC activity. Search results summary I ran targeted searches against Google Patents, uspto.report…
- US 10841398I'll research this patent across several sources. Let me run independent searches. Let me verify the granted claims and check litigation/appellate dockets specifically referencing this patent. US Patent 10,841,398 — Research Summary Scope…
- US 6718277I'll verify the patent details against live sources, including the USPTO record and any 2026 CAFC activity. Let me check for any Federal Circuit 2026 activity and the PTAB proceeding referenced in the record. Let me do one more targeted…
- US 6854287I'll search for authoritative information on US 6854287 and check for any 2026 CAFC docket activity. The CAFC search returned nothing. Let me try a couple more targeted searches to confirm whether any 2026 Federal Circuit docket activity…
- US 6314409I'll research this patent number across the sources you specified. Let me check for recent litigation/docket activity and verify the claim set. US Patent 6,314,409 — Summary Identifier interpretation: The number "6314409" as given…
- US 6715084I have the authoritative patent text in front of me. Let me verify current status, especially for any 2026 Federal Circuit activity, via search. Both searches returned no results. Let me try a few alternate queries to confirm. Let me check…
- US 5745574I'll search for information on US patent 5745574, including USPTO records and any 2026 CAFC docket activity. The CAFC 2026 search returned nothing. Let me dig deeper on litigation/docket history and the claim set. Let me check for any 2026…
This patent in court (5)
5 tracked lawsuits name US 6317837.