Invalidity dossier

US 6845448

Online repository for personal information

Current assignee: Web 2.0 Technologies, LLC, Pennar Software Corp.

Added 9/27/2026, 4:47:46 AM

At a glanceNo PTAB challenges16 lawsuits on fileasserted by Web 2.0 Technologies, LLC +1Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll verify current status with searches before summarizing, since you've asked specifically about USPTO/CAFC docket activity.

Let me check specifically for any Federal Circuit appeal activity in 2026 involving this patent.

US 6,845,448 — Verification and Summary

Scope note on method: I ran targeted searches for the literal string 6845448 across Google Patents/Espacenet, the Stanford NPE Litigation Database, Unified Patents litigation & Patroll records, UniCourt/Casetext dockets, and 2026 Federal Circuit reporting. I could not directly query USPTO PatentCenter or PACER, so docket statements below rest on third-party aggregators. Where sources conflict with the patent text you supplied, I flag it rather than reconcile it.


1. Bibliographic data

Field Value
Patent number US 6,845,448 B1 (interpreted literally; note below re: a source that calls it "B2")
Title "Online repository for personal information"
Application no. US 09/478,796
Filing date 2000-01-07
Issue/publication date 2005-01-18
Inventors Naren Chaganti; Sitapathi Rao Chaganti; Damayanti Chaganti
Original assignee Pennar Software Corp
Current assignees (per Google Patents) PENNER SOFTWARE Corp; Web 20 Technologies LLC
Claim count 3 (claims 1 and 3 independent; claim 2 dependent on claim 1)
Legal status Expired – Lifetime; anticipated expiration 2020-01-07
Family ID 33563780

Ownership chain, as recorded and taken literally:

  • 2000-01-31 — assignment recorded to "PENNER SOFTWARE CORPORATION" (assignor: Chaganti, Naren). Note the spelling difference from the original assignee "Pennar Software Corp" appearing elsewhere in the same record; I have not resolved which spelling is correct and am not auto-correcting either.
  • 2023-05-08 — assigned to WEB 2.0 TECHNOLOGIES, LLC (assignor: Pennar Software Corporation).

Sources: Google Patents US6845448B1, Espacenet bibliographic record


2. Abstract (verbatim)

"Method and system for gathering, storing personal information on a server computer and releasing such information to authorized requesters. Several types of information are stored for release to different entities with appropriate authorization. Any modifications or updates are automatically notified to any authorized requesters. The requester optionally provides information about to whom and where to notify changes or updates. Such change or update notification is made by sending a notification to an electronic mailbox. A frequent unauthorized requester of information is tagged as 'junk' requester, to whom no further information will be released."


3. Plain-language overview of the independent claims

Claim 1 — server-side selective disbursement with audit of unauthorized requesters. A service provider runs a server with a database. First, an account is set up for a "first party" (the data subject) and an identifier assigned. The first party enters personal information as "information objects," and — critically — the first party itself assigns one of several security levels to each object "at any granularity", which the claim states enables access to "individually selected portions" of that person's information by individual receiving parties. The identifier, object, and security level are stored. On receiving a request containing the first party's identifier, the system selects a first portion of the objects that could be transmitted, retrieves it, and securely transmits it to a "second party." It then obtains a second-party identifier; if the second party is not authorized, the system records that identifier and rejects the request. Note that the claim mixes an authorized-transmission path and an unauthorized-rejection path without expressly conditioning one on the other — worth flagging if you are claim-charting.

Claim 2 — "junk requester" designation (dependent on claim 1). Adds two steps: designating the second party as a "junk" requester once it presents a predetermined number of unauthorized requests, and generating an alarm indication.

Claim 3 — authorization keys with encoded usage criteria. Recites the same core sequence as claim 1, then adds: generating an authorization key, providing it to the second party, and encoding the key with at least one of a plurality of criteria, where the criteria include a limit on the number of times the key can be used to obtain access. Caveat: as reproduced in the authoritative text, claim 3's closing recites "generating an authorization key; providing the authorization key to the second party" twice before the wherein clause. I am reporting that literally — it appears to be a drafting duplication in the granted claim, not a transcription artifact I should silently fix.

The specification otherwise discloses (but does not claim) change/update notification to designated recipients, secure e-mail delivery of notifications, a reference-monitor-style database interface module 130, a trusted computing base/secure kernel, numerical security-level scoring for requesters, networks, and even networks/requesters' computers, and audit trails written once and read-only thereafter.

Practice note: the "assigning, by the first party, ... at any granularity" language in claims 1 and 3 is the point most heavily attacked on eligibility grounds (see §4), because it is the limitation most plausibly pointing to a specific implementation rather than a generic "store and authorize access" idea.


4. Litigation / docket status as of April 2026

2023 assertion campaign. Web 2.0 Technologies, LLC (with Pennar Software Corporation as co-plaintiff, Devlin Law Firm representing) filed a large wave of §101-challenged infringement suits asserting the '448 patent alongside US 8,117,644 B2, across D. Del., S.D.N.Y., N.D. Ill., and C.D. Cal. — e.g., 1:23-cv-00001 (Accelo), 1:23-cv-00002 (Hive Technology), 1:23-cv-00042 (TaskWorld), 1:23-cv-00343 (ProofHub), 1:23-cv-00230 (37signals d/b/a Basecamp). See Stanford NPE Litigation Database.

Key merits ruling. In Web 2.0 Techs. v. 37signals LLC, No. 1:23-cv-00230 (N.D. Ill.), Judge John Robert Blakey granted the defendant's Rule 12(b)(6) motion on March 25, 2024, holding the asserted subject matter "remains ineligible" under §101 — the opinion records the defendant's argument that the '448 patent claims "steps for storing personal information and determining whether users are authorized to access said personal information" over generic components. That dismissal was without prejudice with leave to amend. The case was then stipulated dismissed with prejudice on June 28, 2024. Sources: Casetext opinion text, UniCourt docket, PatSnap case analysis.

Other dispositions. With-prejudice stipulations/voluntary dismissals also reported in the Hive Technology (1:23-cv-00002) and ProofHub (1:23-cv-00343) matters; these bind only those defendants and produced no validity holding.

IPR / prior-art challenge. Unified Patents ran a Patroll prior-art contest targeting at least claim 1 of this patent (Jan 20 – Mar 31, 2023), prize $2,000, expressly describing the owner as an NPE. See Unified Patents Patroll contest. Note: that page refers to the patent as "US-6845448-B2"; the authoritative granted designation is B1, and I am not adopting the "B2" label.

No 2026 Federal Circuit docket found. My searches of 2026 Federal Circuit reporting (including Patterson Sheridan weekly summaries, WilmerHale's Federal Circuit Patent Watch, Gibson Dunn's June 2026 update, fedcircuitblog.com petitions, and govinfo slip opinions) returned no appeal involving US 6,845,448 or Web 2.0 Technologies. The 2026 §101 appeals surfacing in those searches (e.g., Oasis Tooling v. Siemens, Nos. 2024-2085/2086, decided Feb. 26, 2026; Q Technologies v. Walmart, No. 24-1667, decided Feb. 5, 2026; Constellation Designs v. LG, No. 24-1822, decided Apr. 28, 2026; AGI SureTrack v. Farmers Edge, Nos. 24-1730/1830, decided June 2, 2026) involve different patents and parties. I cannot rule out a docket I did not surface, but I found no positive evidence of a CAFC 2026 appeal on this patent.


5. Explicit uncertainties

  • Direct USPTO/CAFC query not performed. I did not access PatentCenter, PACER, or the Federal Circuit's own docket system directly; all litigation statements are from aggregators (Stanford NPE DB, Unified Patents, UniCourt, Casetext, PatSnap) and could be incomplete or stale.
  • Assignee spelling. "Pennar" vs. "Penner" SOFTWARE CORPORATION appear in the same record; unresolved.
  • "B2" designation appears in one third-party source for this patent number; the authoritative filing text and Google Patents both show B1.
  • Claim 3 duplication in the printed claim text is reported as-is rather than corrected.
  • Family scope. Continuations/continuations-in-part with the same 2000-01-07 priority claim include US 2005/0065950 A1 (abandoned), US 8,117,644 B2, US 9,519,940 B1, US 8,589,440 B1, US 8,978,147 B2, US 8,739,301 B1, US 9,465,913 B1, US 9,015,803 B1, US 9,349,021 B1, US 9,864,877 B1, and US 9,886,594 B1. These are separate patents with their own claims; do not treat them as coextensive with the '448 patent.
  • Expiration. Legal status is "Expired – Lifetime" with an anticipated expiry of 2020-01-07, which is consistent with the 2000-01-07 filing date and a 20-year term. The 2023 suits were therefore filed on an already-expired patent asserting past damages — I state this as an observation from the record, not as a verified legal conclusion.

Generated 9/27/2026, 5:53:18 PM

Cases on file (16)

Group view →

Specific litigation cases in our database that name US patent 6845448. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US 6,845,448. Let me run several searches in parallel.

Let me gather more details on the specific cases, including the New York, California, and Illinois dockets.

Bottom line

Yes — US 6,845,448 ("Online repository for personal information," Chaganti et al., original assignee Pennar Software Corp., now Web 2.0 Technologies, LLC) has an extensive known litigation history. Nearly all of it is a single 2023 patent‑assertion campaign waged by Web 2.0 Technologies, LLC (and in at least one case joined by Pennar Software Corporation). The patent itself is now Expired – Lifetime (anticipated expiration 2000‑01‑07 + 20 years = 2020‑01‑07), and the Google Patents page carries a "Family has litigation" flag.

Two important caveats before the table:

  1. The case inventory below is anchored to the litigation entries listed on the patent record itself (Google Patents → Unified Patents / Darts‑ip data, https://patents.google.com/patent/US6845448/en) plus PACER‑derived dockets (CourtListener, Justia, UniCourt, Dockets.Justia). Party names for some docket numbers could not be confirmed within my research limits and are marked accordingly.
  2. Identifiers are reproduced literally as found, including any apparent inconsistencies (e.g., "Web 2.0 Technologies, Inc." vs. "LLC," and Unified Patents' reference to "US‑6845448‑B2").

Litigation on the patent record (from the US6845448 patent page)

The patent page lists these suits (all filed 2023):

Jurisdiction Case numbers
D. Del. 1:23‑cv‑00001; 00002; 00003; 00004; 00042; 00045; 00047; 00049; 00104; 00105; 00107; 00108; 00340; 00341; 00342; 00343; 00344; 00345
S.D.N.Y. 1:23‑cv‑00339; 1:23‑cv‑02589
N.D. Ill. 1:23‑cv‑00230
C.D. Cal. 2:23‑cv‑02246

There is also a Darts‑ip "first worldwide family litigation filed" link for family ID 33563780.
Source: https://patents.google.com/patent/US6845448/en


Cases with confirmed parties, dates, and status

District of Delaware (Judge Maryellen Noreika, who was assigned the January 2023 cluster)

Case No. Plaintiff(s) Defendant(s) Filed Status/Outcome
1:23‑cv‑00108 Web 2.0 Technologies, LLC Freshworks, Inc. 2023‑01‑27 Open as of the last docket update retrieved (2023‑03‑28); asserted U.S. 6,845,448 B1 and U.S. 8,117,644 B2
1:23‑cv‑00107 Web 2.0 Technologies, LLC Mango Technologies, Inc. d/b/a ClickUp 2023‑01‑27 Complaint + summons; Judge Noreika
1:23‑cv‑00105 Web 2.0 Technologies, LLC Zendesk, Inc. 2023‑01‑27 Complaint filed with jury demand; Judge Noreika
1:23‑cv‑00104 Web 2.0 Technologies, LLC (defendant not confirmed in retrieved sources) 2023‑01‑27 (docket cluster) Part of the same four‑case January 27 cluster (‑104, ‑105, ‑107, ‑108)
1:23‑cv‑00001 Web 2.0 Technologies, LLC Accelo, Inc. 2023 Listed in Stanford NPE Litigation Database
1:23‑cv‑00042 Web 2.0 Technologies, LLC TaskWorld Inc. 2023 Listed in Stanford NPE Litigation Database
1:23‑cv‑00340 Web 2.0 Technologies, LLC Google LLC 2023 (March wave) Complaint asserted the '448 patent and '644 patent; status not confirmed
1:23‑cv‑00343 Web 2.0 Technologies, LLC ProofHub, LLC 2023‑03‑27 Served 2023‑03‑29; defendant moved to dismiss under Rule 12(b)(6) / joined § 101 motions; Judge Noreika
1:23‑cv‑00345 Web 2.0 Technologies, LLC / Pennar Software Corporation (maker of the Workzone project‑management app; name not confirmed) 2023 First Amended Complaint (D.I. 25) filed 2023‑11‑06, alleging infringement via Workzone access‑level/permission features
C.A. No. not confirmed Web 2.0 Technologies, LLC Createch Group Inc. 2023‑01‑13 (complaint) Defendant never appeared; Clerk's Entry of Default 2023‑10‑20; Plaintiff's motion for default judgment GRANTED — but the court noted the request for a cease‑and‑desist/permanent injunction was effectively an injunction motion and treated it separately

Sources: dockets.justia.com (D. Del. 1:2023cv00105, 1:2023cv00107); courtlistener.com dockets; unicourt.com records for 1:23‑cv‑00108 and 1:23‑cv‑00343; https://insight.rpxcorp.com/litigation_documents/15439405 (D. Del. 1:23‑cv‑00345‑MN, Doc. 25); https://www.courtlistener.com/opinion/[10300593](/patent/10300593)/web-20-technologies-llc-v-createch-group-inc/; https://npe.law.stanford.edu/patent/6845448

Northern District of Illinois (Judge John Robert Blakey)

Case No. Plaintiff(s) Defendant(s) Status/Outcome
1:23‑cv‑00230 Web 2.0 Technologies, LLC and Pennar Software Corporation 37signals LLC d/b/a Basecamp Decided. Order dated/entered March 25, 2024: motion to dismiss granted; both the '448 and '644 patents held directed to patent‑ineligible abstract ideas under 35 U.S.C. § 101 (Alice step one and step two). Dismissal without prejudice, with leave to amend.

Key holding language: the '448 patent "recites a method for automatically disbursing personal information saved on a computer to an approved requester," but the claims "use generic computer hardware and software components to automate the conventional manual process," i.e., "a simple automation of a conventional (manual) process." The court treated claim 1 as representative (claim 2 depends from it; claim 3 adds an authorization key).
Sources: https://law.justia.com/cases/federal/district-courts/illinois/ilndce/1:2023cv00230/[425327](/patent/425327)/43/; https://www.courtlistener.com/opinion/[9683624](/patent/9683624)/; https://news.bloomberglaw.com/ip-law/case-patents-eligibility-n-d-ill-4; https://www.vitallaw.com/news/patent-n-d-ill-two-computer-related-patents-found-to-cover-ineligible-subject-matter/ipm012395dc55b9f6480795901e113ef425ac

Southern District of New York

Case No. Plaintiff(s) Defendant(s) Filed Status
1:23‑cv‑00339 "Web 2.0 Technologies, Inc." (as docketed) Nulab Inc. 2023‑01‑13 Pending – Other Pending as of the last retrieved update (2023‑03‑14); Judge Paul A. Engelmayer; cause of action 35 U.S.C. § 271
1:23‑cv‑02589 Web 2.0 Technologies (per patent record) Not confirmed 2023 Not confirmed — I was unable to retrieve this docket within my search limits

Source: https://unicourt.com/case/pc-db5-web-20-technologies-inc-v-nulab-inc-[1379532](/patent/1379532); https://dockets.justia.com/browse/circuit-2/state-new_york/noscat-10/nos-830

Central District of California

Case No. Parties Status
2:23‑cv‑02246 Not confirmed Listed as a "US case filed in California Central District Court" on the patent record; I could not retrieve party names within my search limits

Related non‑litigation proceeding

  • Unified Patents "Patroll" prior‑art contest for US‑6845448 (styled on the contest page as "US‑6845448‑B2," reproduced literally): Unified Patents sought prior art on "at least claim 1," cross‑referencing the Unified litigation portal listing for patent 6845448. This is a crowd‑sourced invalidity effort, not an AIA trial, and I found no IPR/PGR/CBM number for the patent in my retrieved results.
    Source: https://patroll.unifiedpatents.com/contests/FFCfbQioWc8jvocjE

Ownership / enforcement context

  • Original assignee: Pennar Software Corporation; assignment recorded 2000‑01‑31 (assignor Naren Chaganti).
  • Current assignee per the record: Web 2.0 Technologies, LLC, via assignment recorded 2023‑05‑08 from Pennar Software Corporation.
  • Inventors: Naren Chaganti, Sitapathi Rao Chaganti, Damayanti Chaganti.
  • The '448 patent is the parent of a large family (e.g., US 8,117,644; US 8,589,440; US 8,978,147; US 8,739,301; US 9,465,913; US 9,015,803; US 9,349,021; US 9,864,877; US 9,886,594), and the 2023 campaign typically asserted the '448 patent alongside US 8,117,644. The 37signals decision addressed both.

What I could not confirm (stated explicitly rather than guessed)

  • Defendant identities for D. Del. 1:23‑cv‑00002, ‑00003, ‑00004, ‑00045, ‑00047, ‑00049, ‑00104, ‑00341, ‑00342, ‑00344; the defendant in 1:23‑cv‑00345 (only that the accused product is Workzone); the full case number for the Createch Group Inc. default‑judgment case; the parties in S.D.N.Y. 1:23‑cv‑02589 and C.D. Cal. 2:23‑cv‑02246.
  • Terminal outcomes for most of the Delaware 2023 filings. The D. Del. docket descriptors retrieved were current only to early‑mid 2023 (many show "Open"/"Pending – Other Pending" as of the last crawl), so any later dismissal, transfer, stay, or settlement is not reflected here. PACER would be the authoritative source for current status, and the Unified Patents case list (https://portal.unifiedpatents.com/litigation/caselist?patents=6845448&sort=-filed_date) is the best consolidated tracker.
  • No Federal Circuit appeal of the N.D. Ill. § 101 dismissal appeared in my results; the dismissal was without prejudice with leave to amend by April 15, 2024 (the Justia PDF contains an apparent typo reading "April 15, 2015"), so the operative post‑dismissal posture is unverified.

If you want, I can do a follow‑up pass targeting PACER/Unified for the specific unconfirmed docket numbers above.

Generated 9/27/2026, 5:53:36 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Web 2.0 Technologies, LLC, Pennar Software Corp.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

PTAB / AIA Trial Landscape — US 6,845,448 B1 ("Online repository for personal information")

Prepared: 2026-09-27 · Patent: US 6,845,448 B1 · App. No. 09/478,796 · Filed/Priority: 2000-01-07 · Granted: 2005-01-18 · Original assignee: Pennar Software Corporation · Current assignee of record (per Google Patents): PENNER SOFTWARE Corp / Web 20 Technologies LLC (assignment recorded 2023-05-08 to WEB 2.0 TECHNOLOGIES, LLC) · Status: Expired – Lifetime, anticipated expiration 2020-01-07.

Sourcing note. The canonical proceedings list comes from the structured "PTAB proceedings on file" block, which is sourced from the USPTO Open Data Portal and returns no AIA trial proceedings. I attempted to corroborate and find unindexed proceedings via web search (PTAB petition documents, PTAB E2E/PTACTs, Docket Alarm, litigation databases). My searches did not surface any IPR, PGR, or CBM bearing this patent number. I was not able to query PTAB E2E or the ODP API directly in this session, so treat "zero proceedings" as high confidence but independently reverifiable — see verification steps at the end. I found no proceeding numbers to report, so I have not invented any.


Proceedings overview

Total AIA trial proceedings on US 6,845,448: 0. Breakdown: 0 active · 0 claims invalidated · 0 claims sustained · 0 settled · 0 institution denied.

The bottom line for a defendant: the patent has never been tested at the PTAB at all, so there is no IPR-driven claim cancellation to lean on and no § 315(e)(2) estoppel against anyone. That cuts both ways. On the plus side, the entire prior-art universe (including art that "reasonably could have been raised" in an IPR) remains available to you and no petitioner has burned it. On the minus side, you get no free claim-construction findings, no narrowed claim set, and no FWD to point at. Your realistic defenses are (a) § 101 — a district court has already found these claims directed to an abstract idea at the Rule 12(b)(6) stage, and (b) damages math — the patent expired 2020-01-07, so any recovery is limited to the § 286 six-year lookback window (approximately 2014-01-07 through 2020-01-07, further bounded by the limitations period). A defendant facing a 2023-era demand should not expect an IPR to be the dispositive weapon here; note also that under the Office's current discretionary-denial posture toward older patents ("settled expectations"), a petition against a patent that expired in 2020 is a genuinely harder sell on § 314(a).


AIA trial proceedings

None to report. There is no IPR, PGR, or CBM on file for US 6,845,448 in the structured data, and I found no evidence of one in public sources. Accordingly there is no institution decision, no Final Written Decision, no judge panel, no settlement, and no Federal Circuit appeal to describe — and I will not manufacture any.

Adjacent activity that is not an AIA trial (do not confuse these)


Strategic summary

Claim status: claims 1, 2, and 3 are all UNTESTED. The patent has three claims. Claim 1 is the independent method claim (account establishment; assigning a first-party identifier; entering information objects; the first party assigning one of a plurality of security levels "at any granularity"; storing; receiving a request; selecting a first portion of objects that could be transmitted; retrieving; securely transmitting; obtaining a second-party identifier; recording an unauthorized second-party identifier; and rejecting the request). Claim 2 depends from claim 1 and adds designation of a "junk requester" upon a predetermined number of unauthorized requests plus generation of an alarm. Claim 3 is a separate independent claim that largely parallels claim 1 and adds generating/providing an authorization key encoded with criteria, expressly including "the number of times the authorization key can be used by the second party to obtain access." Because no claim has ever been construed or adjudicated by the Board, there is no canceled claim to point to and no sustained claim to work around — every claim is fair game for challenge. As a practical drafting matter, note that claim 3 as printed contains visibly garbled repeated text (the "generating an authorization key; providing the authorization key …" sequence appears twice, embedded mid-limitation); that is a § 112 indefiniteness talking point and a claim-construction headache for the patent owner, but it is not a PTAB holding and I am not characterizing it as one.

Estoppel landscape: clean. Because no IPR, PGR, or CBM was ever instituted and no FWD ever issued against this patent, § 315(e)(2) estoppel has never attached to anyone. No petitioner, privy, or real party in interest is barred from raising any § 102/§ 103 ground in district court. For a defendant being asserted today, that means the full prior-art record — including the 1990s personal-information-management, access-control, and selective-dissemination references already on the face of the patent (e.g., US 5,276,901; US 5,428,778; US 5,527,703 / 5,555,303 / 5,646,998 / 5,793,302 / 5,936,541 / 5,974,148 (Stambler); US 5,644,711; US 5,626,727; US 6,006,939; US 6,073,106 (Rozen, "Method of managing and controlling access to personal information"); US 6,148,342 (Ho)) plus the sizeable NPL set — remains available, subject only to the normal district-court estoppel and IPR-timing rules. Conversely, if you file an IPR and lose, you hand the patent owner an estoppel shield for future defendants; with the patent already expired and a favorable § 101 ruling on the books, the cost/benefit on an IPR is unfavorable.

Pattern signals. (1) No repeat-petitioner pattern exists — there is no petitioner at all. (2) No PTAB appeal track record — the patent owner (Chaganti/Pennar → Web 2.0 Technologies) has not pursued any PTAB appeal on this patent, because there has been no PTAB proceeding. (3) Defensive aggregator presence is real but stopped short of the Board. Unified Patents ran the Patroll contest on this asset in Q1 2023 and the patent shows up in Unified's litigation/patent portals, but there is no Unified-filed IPR on US 6,845,448 that I could find. If any IPR does exist, Unified Patents is the single most likely petitioner. (4) Enforcement posture: the 2023 campaign was broad and short-lived — many parallel Delaware/Illinois/New York/California complaints, at least one § 101 dismissal, and at least one walk-away dismissal with prejudice.


Recommended next steps

  1. Independently verify the "zero proceedings" finding before you rely on it in a brief or a budget. Check PTAB E2E / PTACTs (https://ptacts.uspto.gov/ptacts/) by patent number, the USPTO ODP API proceeding records, and Docket Alarm's PTAB coverage for "6,845,448" and for the patent owner names (Pennar Software Corporation; Web 2.0 Technologies, LLC; Web 2.0 Technologies, LLC as successor to Pennar). Verify also the family members' status — US 8,117,644, US 8,589,440, US 8,739,301, US 9,019,803, US 9,465,913, US 9,515,940, US 9,349,021, US 9,864,877, US 9,886,594 — since an NPE asserting the expired '448 is often really asserting a later-issued continuation, and any IPR on a sibling could matter to your case even if the '448 itself is untouched. I found no such IPR, but I did not exhaustively check the siblings.
  2. Lead with § 101 and damages, not with the PTAB. Cite Web 2.0 Technologies LLC v. 37signals LLC, No. 1:23-cv-00230 (N.D. Ill. 2024-03-25) and the underlying motion record at https://storage.courtlistener.com/recap/gov.uscourts.ilnd.425327/gov.uscourts.ilnd.425327.43.0.pdf for the abstract-idea holding on this exact patent. Because that dismissal was without prejudice, the patent owner was given leave to replead — check the current docket (PACER, or CourtListener/recap at https://www.courtlistener.com) to confirm whether an amended complaint was filed and how the court ruled on any renewed motion.
  3. Run the expiration math now. Anticipated expiration 2020-01-07 (status "Expired – Lifetime"). Any infringement theory can only reach past conduct; build the damages model around the 35 U.S.C. § 286 six-year window and check whether the entity you represent was on notice of the patent before the relevant date. Pre-suit notice (§ 287) and laches-adjacent arguments deserve a look given the patent's age and the 2023 timing.
  4. If your client insists on an IPR, the practical posture is unfavorable: the patent is expired, discretionary denial under § 314(a) is being applied aggressively to old patents under the Office's "settled expectations" line of decisions, and there is an existing, cheaper § 101 path. If you do file, note that § 315(b) runs one year from service of the complaint — calendar that date immediately — and that an expired patent remains IPR-eligible but leaves you with estoppel risk and no injunctive upside.
  5. Watch for a Unified Patents filing. Unified's Q1-2023 Patroll contest on this asset (closed 2023-03-31) is the clearest signal that a defensive aggregator took an interest. If a petition materializes, § 315(e)(2) estoppel would run only to Unified and its privies/RPIs — not to you — so your prior-art positions stay open unless you join or coordinate in a way that creates a significant relationship.

Caveats. I could not confirm or deny the existence of any ex parte reexamination request on this patent; Unified Patents does file reexam requests as an alternative to IPRs, and one such Unified request appeared in my search results for an unrelated patent (US 10,601,780). Treat reexam status as unverified and check the file history via USPTO Patent Center before relying on it. Where my web searches returned documents bearing the string "684," "6845," or "6845448" for entirely different patents (e.g., an optical-filter patent, a battery-case patent, a Brazilian corporate-registry notice), I disregarded them; none of those results relate to US 6,845,448.

Generated 9/27/2026, 5:53:47 PM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2000-01-31 · Assignment

    CHAGANTI, NARENPENNER SOFTWARE CORPORATION

  2. 2023-05-08 · Assignment

    PENNAR SOFTWARE CORPORATIONWEB 2.0 TECHNOLOGIES, LLC

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll attempt to verify the assignment record against live sources before writing, since reel/frame and correspondent data are not in the authoritative text.

Let me dig specifically for the recorded assignment metadata (reel/frame, execution date, correspondent) and the ownership/naming anomaly surfaced in the Delaware dockets.

Assignment-Chain Reconstruction — US 6,845,448 B1

Sourcing limitation, stated up front. I could not directly query the USPTO Assignment Center (https://assignmentcenter.uspto.gov/) or the legacy AOTW interface (https://assignment.uspto.gov/patent/index.html) in this session. Those systems are not meaningfully indexed by the search tools available to me, and no mirror reproduced the reel/frame, execution date, or correspondent-of-record fields for this patent. Everything below is therefore built from (a) the authoritative Google Patents legal-events block in the supplied text — which does surface two post-filing assignment events — and (b) secondary sources (state corporate registry mirrors, court dockets, Unified Patents, Stanford NPE DB). I have not fabricated any reel/frame numbers or correspondents. The precise fields the task asks for are marked not retrieved where they are genuinely unavailable. A direct Assignment Center query by patent number remains the step that would close these gaps.

⚠️ Cross-reference flag / contradiction. The earlier-generated summary states the 2023-delivered suits were filed "on an already-expired patent asserting past damages." The Google Patents legal events corroborate expiry (anticipated expiration 2020-01-07), and the January 2023 filings post-date it. Separately, a 2023-10-02 oral order by Judge Noreika (D. Del.) records that Pennar Software Corporation is "purportedly the owner by assignment of 100% interest in the Asserted Patents" — yet the same authoritative record shows a 2023-05-08 assignment of the patent to Web 2.0 Technologies, LLC. Those two propositions cannot both be literally true of the same undivided interest. I flag the inconsistency rather than resolve it.


Inventors

Inventor Address as it appears across the family Employer at filing (inferred)
Naren Chaganti Town & Country, MO (family patents); Palo Alto / Sunnyvale, CA (later) Pennar Software Corp — he is listed as PRES/SEC of the Virginia entity; also pro se appellant in the Fortune 500 Systems appeals
Sitapathi Rao Chaganti Nellore, India (US 9,465,913); Palo Alto, CA (US 8,739,301) Pennar Software Corp (co-inventor on the family continuations through 2018 grants)
Damayanti Chaganti Nellore, India (US 9,465,913); Palo Alto, CA (US 8,739,301) Pennar Software Corp

Sources: Google Patents legal events (supplied text); family-patent front pages US 9,465,913, US 8,739,301, US 9,015,803; City-Data VA registry mirror, entity 04213898.

Unusual patterns — findings:

  1. Same-surname family group. All three inventors share the surname Chaganti. Combined with Naren Chaganti's role as Pennar's President/Secretary, this is a family-controlled inventorship group, not an arm's-length engineering team. That is a governance/ownership fact worth noting for chain-of-title diligence.
  2. The 2000-01-31 recorded assignment names only Naren Chaganti as assignor. The Google Patents legal-event recites: "Assignors: CHAGANTI, NAREN." Neither Sitapathi Rao nor Damayanti Chaganti is listed on that record as reproduced. I cannot confirm from available sources whether separate recorded assignments exist from the other two inventors — this is a potential recordation gap / chain-of-title question that a direct Assignment Center assignor-name search would settle. Do not treat the absence as proof of a defect; treat it as an unresolved item.
  3. No inventor-departure signal. Contrary to the "all inventors depart within 12 months" heuristic, the three inventors persisted together on the same family through grants in 2015–2018 (e.g., US 9,465,913, US 9,015,803, US 9,349,021). There was no fire-sale-triggering inventorship exodus; the portfolio stayed in-family for ~15 years.
  4. Prosecution of record was handled by an inventor. FreePatentsOnline lists the attorney/agent of record as NAREN CHAGANTI — i.e., the inventor was his own prosecution correspondent. (FPO record) This is why a "recording correspondent" search may surface the same individual name on early filings, and it is a real distinguishing fact versus a commercially prosecuted portfolio.

Original assignee

Pennar Software Corporation (also appearing in one USPTO recording as "PENNER SOFTWARE CORPORATION" — spelling reproduced literally, unresolved).

  • Entity type / status: Virginia Stock Corporation, entity ID 04213898, registered 1994-01-20; registry mirror shows status "Active — Active and In Good Standing" (status date 2001-04-30). Not dissolved, not in bankruptcy on the record I found. (City-Data registry mirror)
  • Addresses of record: 4445 Corporation Lane, Ste 264, Virginia Beach, VA 23462 (registry); Alexandria, VA and Town and Country, MO appear as assignee addresses on the family patents. Multiple addresses over time.
  • Principals: Naren Chaganti — PRES/SEC; a Surendra Chaganti also listed as director (consistent with the family-controlled picture).
  • Primary line of business: software / patent holding. The specification describes a service-provider model ("Personal Information Repository Service Provider"), but I found no evidence Pennar ever commercialized a PIRSP product embodying the claims — no product pages, no 10-K, no marketing. Treat "no product evidence found" as the accurate statement, not "proven no product."
  • Litigation posture (relevant to "operating" characterization): Pennar has an assertion history predating the '448 campaign — Pennar Software Corp. v. Fortune 500 Systems, Ltd. (M.D. Pa.; 3d Cir. appeals dismissed/affirmed 2008-03-05), where Naren Chaganti appeared pro se and the district court imposed sanctions, culminating in involuntary dismissal under Rule 41(b). (3d Cir. order) Pennar is still a named co-plaintiff in the 2025 Texas filings (e.g., Web 2.0 Technologies, LLC et al v. Baylor Scott & White Medical Center Hillcrest, 6:25-cv-00071, W.D. Tex.). (Justia docket)
  • SEC / RPX cross-reference: neither Pennar Software Corporation nor Web 2.0 Technologies, LLC appears in SEC filings as a public registrant; I found no 10-K/8-K entry for either. No RPX directory entry surfaced.

Assignment timeline

Recorded events, as they appear on the authoritative Google Patents legal-events block (which does not publish reel/frame or correspondent):

2000-01-31 (execution/recording date as shown) — Reel/Frame: not retrieved

  • Conveyance: Assignment of Assignors' Interest ("SEE DOCUMENT FOR DETAILS")
  • Assignor: CHAGANTI, NAREN (only)
  • Assignee: PENNER SOFTWARE CORPORATION (spelling as recorded)
  • Correspondent: not retrieved — requires direct Assignment Center query. Note the prosecution agent of record is NAREN CHAGANTI himself; if the recording correspondent is also Chaganti, that would be an inventor-as-correspondent pattern, not a repeat-player-NPE-attorney pattern.
  • Context: inventor-to-company assignment, recorded ~3 weeks after the 2000-01-07 filing. The timing (assignment follows filing) is routine for a family-held startup and is not an obligation-to-assign signature.

2023-05-08 (execution/recording date as shown) — Reel/Frame: not retrieved

  • Conveyance: Assignment
  • Assignor: PENNAR SOFTWARE CORPORATION
  • Assignee: WEB 2.0 TECHNOLOGIES, LLC
  • Correspondent: not retrieved. I cannot confirm or deny the repeat-correspondent signal for this recording.
  • Context: transfer to a licensing/asserting entity. Sequencing caveat, per the authoritative record: the delivered suits were docketed January 2023 (e.g., Web 2.0 Technologies, LLC v. Accelo, 1:23-cv-00001; v. TaskWorld, 1:23-cv-00042; v. 37signals, 1:23-cv-00230 filed 2023-01-13) — i.e., the January 2023 filing wave precedes the 2023-05-08 recorded transfer. This is the inverse of the usual "transfer then sue" sequence and is the natural source of the ownership confusion Judge Noreika flagged.

No other recorded assignments found. Two transfers only. Notably absent: any recorded Security Agreement, Release, Merger, Change of Name, or Correction — and, importantly, no defensive-aggregator entity anywhere in the chain.

Recurring litigation counsel (distinct from recording correspondents — do not conflate):

  • Devlin Law Firm LLC — Timothy Devlin; Jason Michael Wejnert; Neil A. Benchell — repeat plaintiff-side counsel across the 2023 campaign (37signals, ProofHub, Workfront, Zendesk, Mango, LiquidPlanner, Nulab). (UniCourt 37signals; Patexia Workfront docket; PatSnap ProofHub)
  • Robert Kiddie (Hayden Corrales) — repeat counsel for the 2025 Texas hospital/health-system campaign (Judge Albright, W.D. Tex.).

The recurrence is real at the litigation layer; whether it recurs at the recording-correspondent layer is unverified.


Timeline diagram

timeline
    title Ownership and assertion of US 6845448
    1994 : Pennar Software Corp registered in Virginia
    2000 : Application filed 07 Jan
         : Naren Chaganti assigns to Pennar
    2005 : Patent issues as US 6845448 B1
    2006 : Pennar sues Fortune 500 Systems
    2020 : Patent term expires 07 Jan
    2023 : Assigned to Web 2.0 Technologies LLC
         : Infringement campaign launched
    2024 : Claims held ineligible under 101
    2025 : Hospital defendants sued in Texas

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT (moderate support, registration evidence missing).
The 2023-05-08 recording moves the patent from a 1994-registered Virginia operating stock corporation to an LLC that has no product footprint and asserts the patent. Supporting: Unified Patents describes owner Web 2.0 Technologies as "a NPE." (Unified Patents Patroll) Counter-evidence against a pure shell reading: the original assignee (Pennar) remains a co-plaintiff and is pleaded as the 100%-interest owner — a hybrid arrangement, not a clean hand-off. The specific tells — registered-agent address, single-member DE/LLC status, "no products" proof — were not verified.

2. Known asserter in the chain — PRESENT. Web 2.0 Technologies, LLC is not on the enumerated legacy list (Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). It qualifies instead via the high-frequency-plaintiff route: 31 total cases, 9 active (ExParte party page); Stanford NPE Litigation Database classifies the asserts under "Acquired patents" (Stanford NPE DB — patent 6845448); and Unified Patents ran a $2,000 Patroll prior-art contest against claim 1 on 2023-01-20 → 2023-03-31, expressly describing the owner as an NPE.

3. Repeat correspondent across the chain — UNCLEAR (data not retrieved). No recording correspondent obtained for either the 2000-01-31 or the 2023-05-08 recording. Do not score this as present. What is documented is a repeating litigation firm (Devlin Law Firm) and a repeating 2025 Texas counsel (Kiddie) — different field, weaker inference.

4. Cascading transfers — NOT PRESENT. Only one post-issuance transfer. There is no chain of chained LLCs. The apparent multi-entity appearance comes from Pennar remaining a co-plaintiff, not from successive assignments.

5. Pre-litigation transfer — NOT PRESENT (indeed, inverted). The recorded transfer (2023-05-08) post-dates the first suits (docketed January 2023). The usual "assign within 6 months before suing to clean up standing/venue" tell does not hold; if anything the record shows suits on a patent whose recorded title still named Pennar. This sequencing, not naming, is what drove Judge Noreika's 2023-10-02 order demanding plaintiffs explain the discrepancy in plaintiffs among the Web 2.0 cases.

6. Bankruptcy fire-sale — NOT PRESENT. Pennar shows as an active, in-good-standing Virginia corporation in the registry mirror; no Chapter 7/11 proceeding surfaced. (Family patents continued to issue to Pennar in 2015–2018, inconsistent with a bankruptcy liquidation of the portfolio.)

7. Privateering — UNCLEAR. The 2025 Texas campaign names both Pennar (original assignee/owner-of-100%-interest pleader) and Web 2.0 Technologies as co-plaintiffs — a joint-assertion posture rather than the classic operating-co → NPE hand-off. No SEC disclosure or Patent Progress/EFF coverage found. Insufficient to call privateering.

8. Defensive aggregator — NOT PRESENT. The chain does not terminate at RPX, AST, LOT, Unified Patents, or OIN. The patent is live as an assertion tool, not neutralized — it was re-asserted in 2025 against a large set of health-system defendants.

9. (Additional, unlisted) Litigation outcome risk signal — PRESENT. In Web 2.0 Techs. v. 37signals, No. 1:23-cv-00230 (N.D. Ill.), Judge Blakey held on 2024-03-25 that the patented subject matter "remains ineligible" under §101, then the case was stipulated dismissed with prejudice on 2024-06-28. Corroborated independently by a Bloomberg/VitalLaw write-up. (Justia opinion text; Casetext; PatSnap) This is a §101-driven early-exit pattern, not an ownership signal, but it materially changes the enforcement value of any chain analysis.


Verdict

NPE — high confidence.

Basis: Two independent strong signals. First, signal 2 (known asserter): the current assignee, Web 2.0 Technologies, LLC, was designated an NPE by Unified Patents (Patroll contest opened 2023-01-20, closed 2023-03-31), is catalogued in the Stanford NPE Litigation Database under acquired patents for this specific patent, and is a 31-case high-frequency plaintiff. Second, signal 1 (shell-entity transfer): the 2023-05-08 recorded assignment moved the patent from a 1994-registered Virginia operating corporation to that licensing LLC while the original assignee remained a co-plaintiff — a hybrid assignee/asserter structure rather than a product-shipping owner. The post-filing rather than pre-filing timing of the transfer (suits docketed January 2023, transfer recorded 2023-05-08) is an inverted sequencing that further supports an assertion-driven arrangement. I am not scoring signals 3, 4, 7, or 8 as present.

Confidence caveat, for the record: this verdict rests on docket and third-party-source evidence, not on reel/frame-level USPTO assignment data, which I could not retrieve. If reel/frame-level proof is required, the chain would be downgraded to moderate confidence pending a direct query.

Verify directly at: https://assignmentcenter.uspto.gov/ (search patent number 6845448), and https://assignment.uspto.gov/patent/index.html — query both by patent number and by assignor name "CHAGANTI" to resolve whether Sitapathi Rao and Damayanti Chaganti executed separate assignments, and capture the reel/frame + correspondent for the two records identified above.

Generated 9/27/2026, 5:54:11 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll search for the specific prior-art citations associated with US 6,845,448 and verify against the authoritative record you supplied.

Let me retrieve the complete front-page reference list for the '448 patent.

Let me verify the details of the most anticipation-relevant cited references.

Prior-Art Analysis — US 6,845,448 B1 ("Online repository for personal information")

0. Scope, method, and a caveat you should read first

Search scope. I searched for the literal number 6845448 and recovered the reference list printed on the face of the '448 patent as reproduced by FreePatentsOnline, SumoBrain, Google Patents, and Justia. I did not directly query USPTO PatentCenter or the USPTO full-text search API — the prior-art list below is taken from the patent's own front-page "(56) References Cited" section as republished by those aggregators, cross-checked against the authoritative text you supplied. Where a third-party aggregator's listing could be incomplete or mis-dated, I flag it rather than assert it.

Statutory framework. The '448 patent has a filing/priority date of 2000-01-07 and issued 2005-01-18, so it is governed by pre-AIA 35 U.S.C. § 102. Applicability thresholds for the analysis below:

  • § 102(a)/(b) — references patented or described in a printed publication before 2000-01-07 (and, for (b), more than one year before, i.e., before 1999-01-07).
  • § 102(e) — U.S. patents granted on applications filed before 2000-01-07, even if they issued later. This is why several references that issued after the '448 filing date (e.g., Rozen, Ho, Jerger) are properly citable.

Important structural note (carried forward from the prior section, not repeated): the '448 patent has only 3 claims — claim 1 (independent), claim 2 (dependent on claim 1, "junk" requester + alarm), claim 3 (independent, authorization key). Anticipation analysis therefore turns almost entirely on claim 1's core sequence.


1. Verification of the target patent

Field Value (literal)
Patent no. US 6,845,448 B1
Title Online repository for personal information
Application US 09/478,796
Filed 2000-01-07
Issued 2005-01-18
Inventors Naren Chaganti; Sitapathi Rao Chaganti; Damayanti Chaganti
Claims 3
Status Expired – Lifetime (anticipated expiration 2020-01-07)

Source: Google Patents US6845448B1; FreePatentsOnline.


2. The prior art cited on the face of the '448 patent

2a. U.S. Patent Documents (23 identified)

No. Date Inventor Title (as listed) Filing vs. '448
RE31,302 E 1983-07-05 Stambler Validation systems for credit card or the like pre-102(b)
4,491,725 A 1985-01-01* Pritchard (title not recovered) pre-102(b)
4,956,769 A 1990-09-11 Smith Occurrence and value based security system for computer databases pre-102(b)
5,144,557 A 1992-09-01 Wang et al. Method and system for document distribution by reference to a first group and particular document to a second group of users pre-102(b)
5,204,897 A 1993-04-13* Wyman (title not recovered) pre-102(b)
5,241,466 A 1993-08-31 Perry et al. System for administering a central depository for living wills and other associated information pre-102(b)
5,247,672 A 1993-09-21 Mohan Transaction processing system (IBM) pre-102(b)
5,267,314 A 1993-11-30 Stambler Secure transaction system and method utilized therein pre-102(b)
5,276,901 A 1994-01-04 Howell et al. System for controlling group access to objects using group access control folder and group identification as individual user pre-102(b)
5,428,778 A 1995-06-27 Brookes Selective dissemination of information pre-102(b)
5,524,073 A 1996-06-04 Stambler Secure transaction system and method utilized therein pre-102(b)
5,555,303 A 1996-09-10 Stambler Secure transaction system and method utilized therein pre-102(b)
5,621,727 A 1997-04-15 Vaudreuil System and method for private addressing plans using community addressing pre-102(b)
5,644,711 A 1997-07-01 Murphy Multi-privileged level directory access on the AT&T WorldWorx(SM) personal conferencing service pre-102(b)
5,646,998 A 1997-07-08 Stambler Secure transaction system and method utilized therein pre-102(b)
5,710,578 A 1998-01-20 Beauregard et al. Computer program product for utilizing fast polygon fill routines in a graphics display system pre-102(b)
5,793,302 A 1998-08-11 Stambler Method for securing information relevant to a transaction pre-102(b)
5,936,541 A 1999-08-10 Stambler Method for securing information relevant to a transaction § 102(a)
5,974,148 A 1999-10-26 Stambler Method for securing information relevant to a transaction § 102(a)
6,005,939 A 1999-12-21 Fortenberry et al. Method and apparatus for storing an internet user's identity and access rights to world wide web resources § 102(a)/(e)
6,073,106 A 2000-06-06 Rozen et al. Method of managing and controlling access to personal information § 102(e) (filed 1998-10-30; prov. 1997-10-30)
6,148,342 A 2000-11-14 Ho Secure database management system for confidential records using separately encrypted identifier and access request § 102(e)
6,321,334 B1 2001-11-20 Jerger et al. Administering permissions associated with a security zone in a computer system security model § 102(e)

* Dates shown as recovered from aggregator listings; I could not independently re-confirm the exact issue day for 4,491,725 and 5,204,897 within this session and have not auto-corrected them. Treat those two as approximate.

Count discrepancy flagged: FreePatentsOnline/SumoBrain reproduce 23 U.S. references. I could not confirm that any foreign patent documents appear on the '448 front page, and I could not fully enumerate the list because the aggregator pages truncate. If you need an exact, certified count, pull the PDF front page directly.

2b. Other Publications (NPL) as listed

  • Moozakis, Chuck, "Internet Printing Takes Hold," Sep. 29, 1998 (retrieved Aug. 10, 2000, internetwk.com) — citable under § 102(b).
  • Kelso, "Final Report on the National Integration Resource Center Task Force—The Lisle Report," Apr. 19, 1999 — citable under § 102(a).
  • J. Michael Murphy, "Privacy Protection—A New Beginning?" 21st Int'l Conference on Privacy and Personal Data Protection, Sep. 13–14, 1999 — citable under § 102(a).
  • Gardner, "Office of Justice Programs, Integrated Justice Privacy Initiative," Apr. 12, 2000 — after the '448 filing date; not prior art (§ 102(a)/(b) fail).
  • Cavoukian et al., "Privacy Design Principles for an Integrated Justice System," Apr. 5, 2000 — not prior art.
  • Kendall et al., "Privacy Impact Assessment for Justice Information Systems," draft, Jul. 5, 2000 — not prior art.
  • Rolf Blom, Mats Näslund & Göran Selander, "Object Security and Personal Information Management," Apr. 27, 2001 — not prior art.

⚠️ Flag: three of the four "privacy" NPL items (Gardner, Cavoukian, Kendall) and the Blom paper post-date the '448 filing date, so they cannot anticipate or render obvious under § 102. They appear to have been cited for background/general-principle purposes only. If anyone later argues these as art, that argument fails on its face as to the '448 patent's 2000-01-07 priority date.


3. Reference-by-reference anticipation assessment (against the 3 claims)

The claims at issue, distilled: claim 1 = account + identifier + entry of personal-info "information objects" + first-party-assigned security level per object "at any granularity" + storage + receipt of a request bearing the first-party identifier + selection/retrieval of a transmittable portion + secure transmission + obtain second-party identifier + record if unauthorized + reject. Claim 2 = "junk" requester after a predetermined number of unauthorized requests + alarm. Claim 3 = authorization key encoded with criteria including a usage-count limit.

Tier 1 — Closest to claim 1

US 6,073,106 A — Rozen, Doherty & Chesko (NEHDC, Inc.)

  • Citation: U.S. Patent 6,073,106; filed Oct. 30, 1998; benefit of provisional 60/064,332 filed Oct. 30, 1997; issued June 6, 2000.
  • Description: A service provider manages a participant's personal (chiefly medical) information. The participant supplies a constant identifier + password and populates multiple categories of information, each category gated by a different PIN (PIN-1, PIN-2). A "requester" (including emergency medical facilities) presents the identifier and the relevant PIN and receives only that category of the participant's data, delivered over the internet/web site or by fax/e-mail.
  • Potentially anticipates: claim 1 (strong). It discloses nearly element-for-element: account/identifier, entry of information objects, per-category security gating set by the data subject, storage, receipt of a request bearing the identifier, selection of an authorized portion, retrieval, and disclosure. It is also § 102(e) art (filed 1998).
  • Weakness for anticipation: the disclosure is telephone/fax-centric and the "granularity" is category-level rather than the claim's broader "any granularity"; a patentee would press the claim's "by the first party … at any granularity" language to distinguish. Also, Rozen's disclosure is arguably closer to emergency override than to general-purpose "individually selected portions by individual receiving parties."
  • Claim 3: The PINs function as access keys, but the claim's specific "criterion to indicate the number of times the authorization key can be used" is not disclosed → not anticipated on this record.
  • Claim 2: Not disclosed.

US 5,428,778 A — Brookes, "Selective dissemination of information"

  • Citation: issued June 27, 1995 (§ 102(b)).
  • Description: Profile-based selective dissemination of information to subscribers — i.e., selecting a sub-portion of stored information and distributing it to a requesting/subscribing party according to pre-set criteria.
  • Potentially anticipates: the "selecting a first portion … that could be transmitted" step of claim 1, and by itself the subscription/dissemination concept. As a standalone reference for the whole of claim 1 it is thinner (no clear personal-information-repository with first-party-assigned per-object security levels), but it is the strongest cited reference on the "selective release" concept.

US 6,005,939 A — Fortenberry, Kalt & Loe (MCI)

  • Citation: issued Dec. 21, 1999 (§ 102(a)/(e) candidate).
  • Description: Storing an internet user's identity and access rights to World Wide Web resources — i.e., a central record of who a user is and which resources they may access.
  • Potentially anticipates: the identifier + stored access-rights/storage steps of claim 1. Does not reach first-party granularity assignment or disbursement-to-requester.

US 5,276,901 A — Howell et al.

  • Citation: issued Jan. 4, 1994 (§ 102(b)).
  • Description: Controlling group access to objects via a group access-control folder and group identification.
  • Potentially anticipates: the access-control-by-security-classification mechanism underlying claim 1 (and the alternative "access control lists for each level of a multi-level security system" the '448 spec itself acknowledges). Not the personal-information-repository framing.

US 4,956,769 A — Smith

  • Citation: issued Sep. 11, 1990 (§ 102(b)).
  • Description: Occurrence- and value-based security system for computer databases.
  • Potentially anticipates: the data-level (per-tuple/per-field) security-classification limitation of claim 1 — this is the reference most directly on the "security classification assigned to each information object" concept.

US 5,241,466 A — Perry et al.

  • Citation: issued Aug. 31, 1993 (§ 102(b)).
  • Description: A central depository for living wills and associated personal information, administered so that designated parties may access it.
  • Potentially anticipates: the "central repository of personal information + controlled access by designated parties" concept of claim 1; a common examiner citation for the repository framing.

US 5,144,557 A — Wang et al.

  • Citation: issued Sep. 1, 1992 (§ 102(b)).
  • Description: Document distribution by reference to a first group and a particular document to a second group of users.
  • Potentially anticipates: the group-based distribution-to-authorized-party step of claim 1.

Tier 2 — Secure-transaction / encryption / transaction-processing infrastructure

Stambler family — RE31,302 E; 5,267,314; 5,524,073; 5,555,303; 5,646,998; 5,793,302; 5,936,541; 5,974,148 (issued 1983–1999).

  • Description: A long series of "secure transaction system" / "validation" / "securing information relevant to a transaction" patents (cards, terminals, validation of a party's authority to complete a protected transaction).
  • Potentially anticipates: the "obtain a second party identifier / verify authorization before releasing" and secure-transmission aspects of claim 1, and the key/authorization concept underlying claim 3. Individually, none discloses a personal-information repository with first-party per-object security levels; they are more likely to be combined or cited for the verification-of-requester concept.

US 5,621,727 A — Vaudreuil (Oct. 15, 1997) — private addressing plans using community addressing; relevant to the secure message routing/notification aspects, not to the core claim 1 sequence.

US 5,644,711 A — Murphy (Jul. 1, 1997) — multi-privileged-level directory access; relevant to multi-level security as recited in claim 1's security-level scheme.

US 5,247,672 A — Mohan (IBM, Sep. 21, 1993) — transaction-processing system with reduced locking; cited for database infrastructure, not substantive anticipation.

US 5,204,897 A and US 5,710,578 A (Beauregard) — data-processing/database utility references; background.

US 4,491,725 A — Pritchard (1985) and RE31,302 E — Stambler (1983) — forerunner validation/systems art; background.

Tier 3 — Post-1998 issued references cited under § 102(e)

US 6,148,342 A — Ho (issued Nov. 14, 2000)

  • Description: Secure database management for confidential records using a separately encrypted identifier and access request.
  • Potentially anticipates: the secure-transmission and reference-monitor/access-mediation aspects of claim 1 (the '448 spec's own database interface module 130 "reference monitor" language maps to this). § 102(e) applicability depends on its filing date being before 2000-01-07 — I could not confirm that filing date in this session; verify before relying on it.

US 6,321,334 B1 — Jerger et al. (issued Nov. 20, 2001)

  • Description: Administering permissions associated with a security zone in a computer system security model.
  • Potentially anticipates: the permissions/security-level administration of claim 1. Again, confirm its filing date before treating it as § 102(e) art.

4. Bottom line on anticipation

Claim Best cited anticipatory reference(s) Confidence
Claim 1 US 6,073,106 (Rozen) — closest overall; then US 5,428,778 (Brookes) for the selective-disbursement core; US 4,956,769 (Smith) and US 5,276,901 (Howell) for per-object/group security classification; US 5,241,466 (Perry) for the central personal-information depository Moderate. No single cited reference cleanly discloses all elements, and the "by the first party … at any granularity" limitation is the distinguishing hook.
Claim 2 None of the cited references discloses "junk" requester designation after a predetermined number of unauthorized requests, or the alarm indication. Low — claim 2 appears not anticipated by the cited art.
Claim 3 Authorization-key concepts appear in the Stambler family and (functionally) in Rozen's PINs, but the specific "number of times the authorization key can be used" criterion was not located in any cited reference. Low — claim 3 appears not anticipated on the cited record.

Note connecting to your earlier section: the 37signals dismissal turned on § 101 eligibility, not § 102. Nothing in that ruling resolves anticipation. And because the patent is Expired – Lifetime (exp. 2020-01-07), any current assertion can only target past damages — a fact that, as the prior section noted, is an observation from the record, not a verified legal conclusion.


5. Explicit uncertainties (do not treat these as resolved)

  1. Direct USPTO/PatentCenter query not performed. The reference list is from the patent's printed front page as republished by third-party aggregators; a certified list should be pulled from the grant PDF or PatentCenter.
  2. Truncation risk. FreePatentsOnline/SumoBrain truncated the list; I identified 23 U.S. references but cannot rule out additional U.S. or foreign patent documents on the front page.
  3. Two dates approximate (US 4,491,725; US 5,204,897) — not independently re-verified and not auto-corrected.
  4. § 102(e) filing dates unconfirmed for US 6,148,342 (Ho) and US 6,321,334 (Jerger). If either was filed on/after 2000-01-07, it drops out as § 102(e) art for the '448 patent.
  5. § 102(g) / public-use art not searched. No search was run for prior public use, on-sale, or non-cited 102(g) art; my analysis is limited to the references actually cited on the face of the '448 patent, as you instructed.
  6. NPL dates after filing. Gardner (Apr. 12, 2000), Cavoukian (Apr. 5, 2000), Kendall (Jul. 5, 2000), and Blom (Apr. 27, 2001) all post-date 2000-01-07 and are not § 102 art for this patent.

Generated 9/27/2026, 5:54:09 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll first try to surface the actual Prior Art / "References Cited" section for this patent, since the text supplied to me contains the "Prior art keywords" and "Prior art date" fields but not the enumerated cited references.

I have the actual "References Cited" list now. Let me pull the fuller cited-reference list and the key references' content.

Step 0 — Source-availability note (read first)

The task says "use the results from the Prior Art section of this page," but the authoritative text supplied in the user message contains only the "Prior art keywords" field (party / information / user / personal information / database) and "Prior art date 2000-01-07" — no enumerated References Cited list. An unsupplied list is not an empty list, so rather than treat the field as disclosing nothing, I retrieved the actual cited-art lists from FreePatentsOnline, Justia (family-member cross-lists), and the Unified Patents portal page for this patent. Everything below is grounded in those retrievals and flagged where they are incomplete. This does not contradict the previously generated §1–§5 sections; it fills the gap they left open.


Obviousness analysis — US 6,845,448 B1 under 35 U.S.C. § 103

I. Governing framework and scope

Statute. The '448 patent's filing date is 2000-01-07, so pre-AIA § 103(a) applies. The controlling obviousness test is Graham v. John Deere as refined by KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007) — a POSITA may combine references where the combination is "the product not of innovation but of ordinary skill and common sense."

Statutory-date buckets (all keyed to 2000-01-07):

  • § 102(b) — printed publication/public patent issued on or before 1999-01-07.
  • § 102(e) — U.S. patents granted on applications filed before the applicant's invention; for a reference that issued after 1999-01-07, this is the applicable hook.
  • Watch item: several NPL items of record are dated after 2000-01-07 (Gardner, Apr. 12, 2000; Cavoukian, Apr. 5, 2000; Kendall, Jul. 5, 2000; Blom/Näslund/Selander, Apr. 27, 2001). These cannot be prior art to the '448 itself and were almost certainly cited via the Aug. 5, 2000 continuation-in-part or a later family member. Do not chart them against the '448.

Level of ordinary skill. Bachelor's degree in computer science or electrical engineering (or equivalent experience) plus roughly two years developing networked database/web applications or information-security software, as of January 2000. That person knew relational DBMS access control, SSL, HTTP/CGI, and role/group-based permission models as routine tools.

Claim-construction caveats carried forward from the prior sections (do not repeat): claim 3 recites the "generating an authorization key / providing the authorization key" step twice as printed; claim 1 mixes an authorized-transmission path with an unauthorized-rejection path without expressly conditioning one on the other. For § 103 the claims should be given their broadest reasonable scope consistent with the specification — which makes the analysis below more favorable to the challenger, not less.


II. The prior art actually cited on the face of the '448 (and closely linked family art)

Ref Date(s) Subject Statutory basis Relevance to '448
US 5,241,466 (Perry) 1991-06-25 Central depository for living wills "and other associated information" § 102(b) Repository where a person deposits info and designates who may retrieve it
US 5,428,778 (Brookes, Oracle) 1992-02-12 / 1995-06-27 "Selective dissemination of information" § 102(b) Server-side selection of a subset of stored documents for delivery
US 5,276,901 (Howell) 1991-12-15 / 1994-01-04 Group access to objects via access control folder + group ID as individual user § 102(b) Per-object, per-identity access levels; enforcement
US 5,146,557 (Wang, IBM) 1990-08-12 / 1992-09-01 Document distribution by reference to a first group and a particular document to a second group § 102(b) Controlled release of a record to a designated recipient
US 4,956,769 (Smith) 1988-05-15 / 1990-09-11 Occurrence- and value-based security for computer databases § 102(b) Counting/repeat-triggered security response; logging
US 5,267,314 / 5,554,? / 5,524,073 / 5,646,998 / US RE31,302 (Stambler) 1972–1997 Validation/secure-transaction systems (incl. credit-card validation) § 102(b) Authenticating a requesting party; limited-use/validation codes
US 5,621,727 (Vaudreuil) 1994-09-15 / 1997-04-15 Private addressing plans / community addressing § 102(b) Messaging/notification infrastructure
US 5,644,711 (Murphy) 1995-05-25 / 1997-07-01 Multi-privileged-level directory access § 102(b) Layered privilege levels
US 6,073,106 (Rozen et al., WellMed/NEHDC) filed 1998-10-29; issued 2000-06-06 "Method of managing and controlling access to personal information" § 102(e) Closest single reference — see below
US 6,005,939 (Fortenberry) filed 1996-12-05; issued 1999-12-21 Storing an Internet user's identity and access rights to WWW resources § 102(e) Identifier + stored access-rights list + secure transmission
US 6,148,342 (Ho) filed 1998-01-26; issued 2000-11-14 Secure DB for confidential records using separately encrypted identifier and access request § 102(e) Secure transmission/access mediation
US 6,321,334 (Jerger, Microsoft) filed 1998-07-14; issued 2001-11-20 Administering permissions in a security-zone model § 102(e) Multi-level permission administration

Rozen (US 6,073,106) is the linchpin. Its claims and description (retrieved via SumoBrain/uspto.report) recite: enrolling a participant with a service provider; collecting personal information; sorting it into a first category (emergency-disclosable) and a second category (sensitive, requiring a second PIN); storing a per-item instruction to disclose or not disclose; providing an Internet communications site (claim 12) for the method; a requester presenting the identifier and a PIN; and faxing or e-mailing the information on presentation of the correct PIN. It also expressly contemplates participant alteration of the stored information. That is elements (a)–(e), (f), (h), (i), (j) and much of (d) of claim 1 — including per-item disclosure control, which is the limitation the earlier section correctly identified as the crux.

Not-of-record but § 102(b) NPL that a POSITA would have known: the Netscape/Microsoft/Firefly Open Profiling Standard (OPS, 1997) and the W3C P3P work (1998) taught exactly the "user stores a personal profile once and selectively authorizes a site to read named fields" model; Sixdegrees.com's April 1998 "About Privacy" page (actually cited of record) disclosed user-registered profiles with user-controlled visibility; and the 21st International Conference on Privacy and Personal Data Protection papers (Hong Kong, Sept. 13–14, 1999 — of record) taught notice, choice, purpose limitation and limiting disclosure to authorized recipients. I flag OPS/P3P as my own identification, not of-record art — treat their citation as requiring independent verification.


III. Obviousness grounds

Ground 1 (claim 1) — Rozen in view of Howell and Brookes

  • Rozen → account establishment, identifier, personal-information collection, category- and item-level disclosure instructions, storage, request carrying the participant identifier, retrieval, and transmission to the requester.
  • Howell → supplies the "plurality of security levels" assigned "at any granularity": access control folders per object with group identification as the individual user (i.e., a per-object access-control entry resolved per requesting identity).
  • Brookes → supplies the server-side "selecting a first portion of the information objects that could be transmitted" (SDI profile-matching against a stored user profile).
  • Ho and/or Fortenberry → supply the "securely transmitting" element (separately encrypted identifier/access request; identity-plus-access-rights carried on the request).

Motivation: Rozen already sorts the same data into disclosure tiers; Howell's per-object ACL is the recognized, off-the-shelf mechanism for making such tiers arbitrary and identity-specific rather than two fixed buckets. Applying a known access-control technique to a known tiered-disclosure repository to yield a finer, predictable granularity is precisely the KSR "known technique to improve similar devices in the same way" rationale. The step from Rozen's two categories to "any granularity" is a matter of degree, not of kind, and the record's own privacy literature (Cranor's "Agents of Choice," Cavoukian, the Hong Kong conference papers) supplies the expressed design goal of user-controlled selective disclosure.

Ground 2 (claim 1) — Perry in view of Wang, Howell and Stambler (US RE31,302)

An alternative, older-art-only ground: Perry teaches a central depository of a person's "associated information" retrievable by authorized parties; Wang teaches distributing a particular document to a second designated group by reference to a first group; Howell supplies per-object multi-level access control; Stambler (RE31,302 / 5,267,314) supplies requester validation before release. This ground has the advantage of resting entirely on § 102(b) art (all printed/issued well before 1999-01-07) and therefore does not depend on a § 102(e) date fight over Rozen or Fortenberry.

Motivation: each reference addresses the same underlying problem — controlled release of a record to an identified, verified recipient — and the combination is a mere aggregation of known database-access functions with predictable results.

Ground 3 (claim 1) — Fortenberry in view of Rozen

Fortenberry (stored Internet-user identity plus access rights to named resources) + Rozen (personal-information categories and release instructions) reaches every element, with Fortenberry supplying identifier/access-rights storage and the secure request path, and Rozen supplying the personal-information repository and per-item disclosure control.

Ground 4 (claim 2) — any of Grounds 1–3 in view of Smith (US 4,956,769)

Claim 2 adds (i) designating the party a "junk" requester after a predetermined number of unauthorized requests and (ii) generating an alarm indication. Smith's "occurrence and value based security system for computer databases" is squarely on point: it monitors the occurrence of database accesses and takes a security action based on accumulated occurrence. A POSITA would apply Smith's occurrence counter to the rejection path of Ground 1 to add lock-out after N failures.

Motivation: lock-out after a fixed number of failed authentication attempts was, by 2000, a routine, near-universal security practice (UNIX login lockout; ATM/smart-card PIN retry limits — cf. the cited Stambler validation patents and Jain's secure information retrieval service, US 5,559,888). The "alarm" half is met by Vaudreuil's messaging/notification infrastructure or by any of the audit-log teachings in Howell/Smith. Result: predictable, no new mechanism.

Ground 5 (claim 3) — Ground 1 or 2 in view of Stambler (RE31,302 / 5,267,314) or US 5,559,885

Claim 3 adds an authorization key provided to the second party and encoded with criteria including a limit on the number of uses. This is the weakest limitation to defend:

  • The '448 specification itself admits that "There could be a number of types of authorization keys obtainable by the user: a one-time-use-only authorization key, a multiple-use authorization key, a qualified authorization key, and others." That is applicant-admitted prior art.
  • Stambler's validation systems for credit cards/transaction cards, and US 5,559,885 ("Two stage read-write method for transaction cards," with its retry/attempt accounting), disclose issue-limited, count-delimited validation credentials.
  • One-time and N-use credentials were general knowledge (e.g., RFC 2289's one-time password system, Feb. 1989 — I flag that this specific document surfaced in a different IPR exhibit list and is not of record in the '448).

Motivation: encoding a use-count into a credential is the canonical, well-known way to bound the authority conveyed by that credential; the '448 expressly frames it as a selectable attribute. No unexpected result is asserted.


IV. Why a POSITA would have combined these (consolidated KSR rationales)

  1. Same field, same problem. Every reference above operates on the "store a record → receive a request naming the record's owner → verify the requester → release or refuse" pipeline. Rozen, Perry and Wang each identify the same problem the '448 identifies (that authorizing release of personal information to many different entities is burdensome and error-prone).
  2. Known technique improving a known system. Applying Howell's per-object ACLs (or Jerger's permission administration) to Rozen's tiered personal-information file yields finer, identity-specific authorization with predictable results — the KSR "improve similar devices in the same way" rationale.
  3. Answering a recognized design need, not guessing. The privacy literature of record (the Hong Kong conference papers, Cranor's "Agents of Choice," Blom et al. on personal-information management) expressly frames user-controlled, purpose-limited disclosure as the desired end state — a documented problem-side motivation existing before January 2000.
  4. Automation of established manual practice with generic tools. Both the '448 specification and the district court in Web 2.0 Techs. v. 37signals characterize the claims as automating a conventional manual process using generic computer hardware (SSL, CGI, a relational DBMS). For § 103, automating a known manual workflow with off-the-shelf components is ordinarily obvious; note that the same reasoning that supported the § 101 dismissal (previously reported) cuts against nonobviousness here.
  5. Finite, predictable design space. The disclosed options for the key criteria (uses, expiration, scope, requester trustworthiness) are a small, enumerated set — the KSR "finite number of identified, predictable solutions" factor.

V. Where the obviousness case is weakest (candid assessment)

  • "assigning, by the first party, … at any granularity." The only plausible nonobviousness anchor is not granularity per se but who sets the levels. If the claims are read to require the data subject to be the classifier, Rozen's participant-supplied per-item "instruction to disclose or not disclose" (claims 2–3, 9) and Perry's depositor instructions anticipate that reading — but the mapping needs an element-by-element chart, not a title-level argument. If instead "by the first party" is read merely as "at the direction of," the limitation collapses into Ground 1.
  • Claim 3's duplicated "generating/providing the authorization key" language creates indefiniteness exposure that can moot parts of the § 103 chart.
  • Claim 1's unlinked authorized and unauthorized paths means a challenger must supply the rejection/logging path from a second reference even though the transmission path is fully met by one — the Smith/Vaudreuil joinder is doing real work.
  • Mapping confidence. I retrieved titles, abstracts and partial claim text for Rozen only, and titles/dates for the others. No ground above should be filed or relied on without full-text charts. Where I relied on OPS, P3P or RFC 2289, I have expressly flagged them as not of record.

VI. Secondary considerations

No evidence of nexus was surfaced. The record shows the patent expired for lifetime on 2020-01-07, was asserted only in 2023 (i.e., on an already-expired patent seeking past damages), drew no instituted IPR, and was held § 101-ineligible at the pleading stage in Web 2.0 Technologies v. 37signals (N.D. Ill., Mar. 25, 2024, Blakey, J.). None of that establishes objective indicia of nonobviousness; the long 2000→2005 pendency is prosecution duration, not commercial success. Note that the family members that continued to issue (US 9,465,913; 9,864,877; 9,886,594, etc.) contain different claims and are not evidence about the '448's claims.


VII. Verification steps still required

  1. Pull the complete References Cited list from USPTO PatentCenter for 09/478,796 — the FreePatentsOnline list I retrieved appears truncated (it begins mid-alphabet at US 5,710,578) and there are likely additional cited patents.
  2. Full-text retrieve and chart Rozen (US 6,073,106), Perry (US 5,241,466), Howell (US 5,276,901), Brookes (US 5,428,778), Fortenberry (US 6,005,939), Ho (US 6,148,342) and Smith (US 4,956,769) against claims 1–3.
  3. Independently corroborate OPS (1997) and P3P (1998) as publicly available § 102(b) printed publications with archived-dated copies.
  4. Confirm whether any of the post-2000-dated NPL of record was cited via the Aug. 5, 2000 CIP rather than against the '448's own 2000-01-07 date, and exclude it accordingly.

Persisting flag from the prior sections: Unified Patents' Patroll page styles this patent "US-6845448-B2." The authoritative granted designation is B1. I am not adopting "B2," and nothing in this § 103 analysis turns on that label.

Generated 9/27/2026, 5:54:35 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Log in to generate
Not generated yet. Log in to request this analysis.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Log in to generate
Not generated yet. Log in to request this analysis.

Keep exploring

More patents asserted by Web 2.0 Technologies, LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (16)

16 tracked lawsuits name US 6845448.