Invalidity dossier

US 7290288

Method and system for controlling access, by an authentication server, to protected computer resources provided via an internet protocol network

Current assignee: Prism Technologies LLC

Added 9/24/2026, 3:27:17 AM

At a glanceNo PTAB challenges8 lawsuits on fileasserted by Prism Technologies LLCSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll verify this patent against live sources, then summarize.

Let me check for any 2026 appellate activity and the post-reexamination claim set.

Let me check the reexamination outcome and any recent/2026 activity.

US 7,290,288 B2 — Verification Summary

Scope note / search caveat: I searched for the patent on the open web (Google Patents, Justia, patentimages/USPTO PDFs, Casetext, CourtListener, Unified Patents litigation data mirrored on Google Patents). I could not access the USPTO PatentCenter or CAFC docket systems directly, and I found no CAFC 2026 docket activity for this patent (or for any matching Prism Technologies appeal). Absence of a hit is not proof of absence — I am flagging this explicitly rather than asserting the docket is clean. Everything below is limited to what the supplied full patent text and the retrievable secondary sources support.


1. Bibliographic data (as issued)

Field Value
Patent number US 7,290,288 B2 (literal; also cited as "'288 patent")
Title Method and system for controlling access, by an authentication server, to protected computer resources provided via an internet protocol network
Inventors Richard L. Gregg (Omaha, NE); Sandeep Giri (Omaha, NE); Timothy C. Goeke (Elkhorn, NE)
Assignee (original / current per Google Patents) Prism Technologies, L.L.C. (also written "Prism Technologies LLC"), Omaha, NE
Assignment chain Prism Resources (2002‑10‑25, assignor Gregg) → Prism Technologies, L.L.C. (2004‑07‑22, from Prism Resources) → further assignment 2006‑03‑03 (assignors Giri, Goeke)
Application no. 10/230,638
Filing date August 29, 2002
Priority June 11, 1997 — continuation‑in‑part of 08/872,710, now US 6,516,416 ("Subscription Access System for Use with an Untrusted Network")
Issue date October 30, 2007
Pre‑grant publication US 2003/0046589 A1 (published 2003‑03‑06)
Legal status Expired – Fee Related; Google Patents lists an adjusted expiration of 2022‑10‑12 (consistent with a 20‑year term from the 2002‑08‑29 filing plus adjustment). Treat this as an assumption, not a legal conclusion.
Main classifications H04L63/10, H04L63/08, H04L63/0823, H04L63/083, H04L63/0853; G06F21/31, G06F21/33, G06F21/335, G06F21/44

Reexamination history (important for any claim reading):

  • Ex Parte Reexamination 90/010,565, requested June 4, 2009; Ex Parte Reexamination Certificate US 7,290,288 C1 issued August 3, 2010 (7660th certificate). A Certificate of Correction issued earlier, Sept. 8, 2009.
  • A second reexamination, 90/010,948, was filed April 8, 2010 and was still pending when the C1 certificate issued. The C1 certificate expressly warns: "the claim content of the patent may be subsequently revised in the reexamination proceeding." I could not verify the final outcome of 90/010,948 — flag this as an open uncertainty.
  • The 2009–2010 reexamination was filed in parallel with the RIM ITC dispute and was the vehicle by which Prism secured the 1997 priority claim (removing most RIM prior art as unavailable). Source discussion: https://blog.whda.com/2010/07/patentee-establishes-priority-by-reexamination/

2. Abstract

The abstract of record (as it appears on the C1 reexamination certificate and in Google Patents) reads:

"A method and system for controlling access, by an authentication server, to protected computer resources provided via an Internet Protocol network that includes storing (i) a digital identification associated with at least one client computer device, and (ii) data associated with the protected computer resources in at least one database associated with the authentication server; authenticating, by the authentication server, the digital identification forwarded by at least one access server; authorizing, by the authentication server, the at least one client computer device to receive at least a portion of the protected computer resources requested by the at least one client computer device, based on the stored data associated with the requested protected computer resources; and permitting access, by the authentication server, to the at least the portion of the protected computer resources upon successfully authenticating the digital identification and upon successfully authorizing the at least one client computer device."

Source: https://patentimages.storage.googleapis.com/a6/12/25/d5311fbe7546ff/US7290288.pdf

Note the terminology shift: the specification's summary of invention still speaks in the original "clearinghouse means ... hardware key" language (the '416 lineage), while the claims/abstract of record were rewritten in the "authentication server / access server / protected computer resources" vocabulary. That is the vocabulary the courts later construed.


3. Plain-language overview of the claims

Confidence caveat: the full patent text supplied to me is truncated before the claims section, and the claims were amended in reexamination. I am therefore not quoting verified claim language for every independent claim, and I am not asserting specific independent-claim numbers. The following is grounded in three authoritative sources:

  1. The C1 reexamination certificate abstract (quoted above), which mirrors the operative independent-claim structure.
  2. The D. Nebraska claim-construction orders in Prism Techs., LLC v. Adobe Sys., Inc., 8:10CV220 (Feb. 14, 2012), which state that "Each of the asserted claims of the '288 patent requires either a 'hardware key' or an 'access key.'"
  3. The Federal Circuit's quotation of the parallel, identical-disclosure claim 1 in Prism Techs. LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. 2017).

The asserted independent claims fall into two functional families:

(A) Method/system claims for controlling access via an authentication server (the post-reexam core).
Steps, in plain terms:

  1. Store at the authentication server (a) a digital identification tied to a client computer device and (b) data describing the protected computer resources;
  2. Receive/forward the digital identification via an access server (the server that actually hosts the resources);
  3. Authenticate, at the authentication server, that forwarded digital identification;
  4. Authorize the client device to receive the requested resources, based on the stored resource data; and
  5. Permit access only if both authentication and authorization succeed.
    → The inventive hook is the separation of the authentication function from the resource-holding access server, on an untrusted Internet Protocol network. The asserted independent claims require user/device authentication to be performed by an entity independent of the server hosting the resources.

(B) Hardware-key / access-key claims.
These claim the same access-control method/system but require a hardware key (or "access key") from which a digital identification is generated or read — e.g., a hardware token, magnetic-stripe card, smart card, biometric reader, or a secure CPU/TPM. The two-factor variants pair "something known" (username/password/PIN) with "something held" (the physical key). The specification describes these concretely at FIGS. 21–25 (Rainbow Technologies iKey 1000 USB Smart Token, magnetic card readers, smart cards, biometric readers, TPM-based secure CPU).

Key constructions that define claim scope (D. Neb., Feb. 14, 2012, 8:10CV220):

  • "authentication server" = server software independent of the access server, capable of storing data and controlling access to the access server's protected resources
  • "access server" = server software that makes available information or other resources
  • "digital identification" = digital data whose value is known in advance or calculated at the moment
  • "hardware key" = an external hardware device or object from which the predetermined digital identification can be read
  • "untrusted network" = a public network with no controlling organization, with the path to access the network being undefined and the user being anonymous
  • "Internet Protocol network" = a network using any protocol of the Internet Protocol Suite including at least one of IP, TCP/IP, UDP/IP, and HTTP
  • Preambles of the asserted claims are limiting (jointly stipulated).

Sources: http://g.casetext.com/case/prism-techs-llc-v-adobe-sys-3 · https://www.studicata.com/summaries/united-states-district-court-district-of-nebraska/prism-technologies-v-adobe-systems-2011-eqnjwj/


4. Litigation / validity posture (relevant to any 2026 analysis)

Proceeding Identifier Outcome / relevance
ITC 337‑TA‑697 Prism v. RIM; asserted the '288 patent; terminated after settlement.
D. Neb. 8:08‑cv‑00537 Prism v. Research in Motion; '288 only.
D. Neb. 8:10‑cv‑00220 Prism v. Adobe, Autodesk, McAfee, National Instruments, Sage, Symantec, Trend Micro; '288 only; two Markman orders (2011 "hardware key", 2012 additional terms).
CAFC 13‑1135 Appeal from the Adobe case.
CAFC 16‑2031 / 16‑2049 → 696 F. App'x 1014 (June 23, 2017) Prism v. T‑Mobile. Claims held patent‑ineligible under 35 U.S.C. § 101 (Alice) — directed to the abstract idea of "providing restricted access to resources," with generic computer components supplying no inventive concept. The opinion quoted claim 1 of the '345 patent (the direct continuation of the '288 application), which recites receiving/authenticating identity data / authorizing / permitting access by "at least one authentication server."
CAFC 18‑1108 → 757 F. App'x 983 (2019) Prism v. Sprint; collateral-estoppel / mandate-rule dispute over whether the § 101 ruling reached the "Sprint-only" claims.
Supreme Court Cert petitions 17‑430, 17‑716, 18‑1397 All sought review of the § 101 / preclusion rulings. Source: https://www.supremecourt.gov/DocketPDF/18/18-1397/98180/20190501124836955_Prism%20Technologies%20Petition.pdf

Practical bottom line: the '288 patent family was judicially invalidated under § 101 through the 2017 Federal Circuit decision on the closely related continuation claims, with the § 101 reasoning later applied across the family (e.g., Prism Techs. cited as controlling § 101 authority in D. Del. 17‑585 and elsewhere). The '288 patent itself also lapsed for failure to pay maintenance fees with an adjusted expiration of 2022‑10‑12. I found no indication of any live 2026 CAFC appeal involving US 7,290,288.


5. Family members (direct continuations all claiming priority to 10/230,638)

US 8,127,345 B2 (filed 2007‑10‑30, 92 claims) · US 8,387,155 B2 · US 8,898,746 B2 · US 9,369,469 B2 · US 9,413,768 B1 · US 9,544,314 B2. All are listed on Google Patents at https://patents.google.com/patent/US7290288/en


6. Explicit uncertainties

  1. Operative claim set. Because of reexaminations 90/010,565 and 90/010,948 and the Sept. 8, 2009 Certificate of Correction, the issued 2007 claim text is not necessarily the operative claim text. I could not verify whether claims were cancelled or amended by 90/010,948.
  2. Independent claim numbering. I did not verify which claim numbers are independent in the '288 patent, nor the exact count of claims. Do not attribute a claim count to 7,290,288 without checking the C1/C2 certificate.
  3. CAFC 2026 dockets. No results found; the query returned an empty set. This should be verified directly against the CAFC CM/ECF docket and USPTO PatentCenter rather than inferred.
  4. Expiration date. The 2022‑10‑12 adjusted expiration comes from Google Patents' automated legal-status field and is expressly characterized by Google as an assumption.
  5. Assignee spelling. "Prism Technologies, L.L.C." and "Prism Technologies LLC" both appear; the parent is Prism Technologies Group, Inc. (NASDAQ-listed per the 2017 CAFC certificate of interest).

Generated 10/1/2026, 3:53:51 PM

Cases on file (8)

Group view →

Specific litigation cases in our database that name US patent 7290288. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2008: 1 case'08'092010: 1 case'10'112012: 3 cases3'12
Cases asserting US 7290288, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research this systematically, starting with the litigation data attached to the patent record and then verifying/expanding via litigation databases.

Good initial results. Let me now pin down the individual cases, appeals, ITC investigation, and Supreme Court dockets.

Now let me verify the Federal Circuit appeals and Supreme Court dockets listed on the patent record, and get the full case list.

Litigation involving U.S. Patent No. 7,290,288 ("'288 patent")

Method and system for controlling access, by an authentication server, to protected computer resources provided via an internet protocol network — Prism Technologies LLC (Omaha, NE); priority 1997‑06‑11 (CIP of the application that issued as 6,516,416), filed 2002‑08‑29, issued 2007‑10‑30. Status per Google Patents: Expired – Fee Related; adjusted expiration 2022‑10‑12.

Important caveat up front: I could not verify every item in the litigation listing on the Google Patents page, because the tool budget ran out mid‑research. Below I separate (A) cases where I could confirm the '288 patent itself was asserted from primary/secondary sources, (B) proceedings on the patent record I could not fully verify, and (C) related Prism litigation that does not involve the '288 patent (a common source of error, because Google Patents' "Family has litigation" list is patent‑family‑level).


A. Confirmed '288 cases

# Plaintiff Defendant(s) Jurisdiction Case No. Filed Outcome / Status
1 Prism Technologies LLC Research in Motion, Ltd.; Research in Motion Corp.; [Microsoft Corp.](/litigations/by-plaintiff/Microsoft%20Corp.) D. Neb. (District Court) 8:08‑cv‑00537‑LES‑TDT 2008‑12‑29 Complaint asserted the '288 patent only. Settled before Markman; no claim construction order issued.
2 Prism Technologies LLC (Complainant) Research in Motion, Ltd. (Ontario, Canada); Research in Motion Corp. (Irving, TX) U.S. International Trade Commission Inv. No. 337‑TA‑697, Certain Authentication Systems, Including Software and Handheld Electronic Devices Complaint 2009‑12‑02; supplement 2009‑12‑18; instituted 2010‑01‑05 Terminated on settlement. ALJ Order No. 13 granting joint motion to terminate based on a settlement agreement; Commission determined not to review (notice issued 2010‑06‑21, published 75 FR 36678, 2010‑06‑28). No exclusion/cease‑and‑desist order issued.
3 Prism Technologies LLC Adobe Systems Inc.; Autodesk, Inc.; McAfee, Inc.; National Instruments Corp.; Nuance Communications, Inc.; Quark, Inc.; Sage Software, Inc.; Symantec Corp.; The Mathworks, Inc.; The Sage Group plc; Trend Micro Inc. D. Neb. 8:10‑cv‑00220‑LES‑TDT 2010‑06‑08 '288 patent only. Two Markman rounds (2011 on "hardware key"/"access key"; 2012 on remaining terms). Mathworks dismissed with prejudice 2012‑01‑04. Final Order and Judgment 2012‑12‑10: summary judgment of non‑infringement for McAfee, Symantec and Trend Micro (accused "hardware keys" were product CDs; serial numbers were not "read from" the key); declaratory judgment of non‑infringement for each; invalidity counterclaims dismissed for lack of an actual controversy; costs taxed against Prism. Subsequent 2013‑02‑13 opinion denied defendants' § 285 exceptional‑case/fee motion.
4 Prism Technologies LLC AT&T Mobility LLC D. Neb. 8:12‑cv‑00122‑LES‑TDT Complaint 2012‑04‑04 (amended 2012‑09‑21, 2013‑03‑01) '288 patent was one of three patents originally asserted; Prism withdrew the '288 claims in March 2014 "to further streamline the issues," leaving the '345 and '155 patents. Case settled on the last day of trial (Oct. 2014, before closing arguments); claims dismissed (Order 2014‑12‑29). The AT&T settlement became key evidence in the Sprint case (see #5).
5 Prism Technologies LLC Sprint Spectrum L.P. d/b/a Sprint PCS D. Neb. 8:12‑cv‑00123‑LES‑TDT 2012 (same day as #4) '288 withdrawn March 2014. June 2015 jury verdict on '345/'155: infringement + $30 million reasonable royalty. Fed. Cir. affirmed (settlement‑agreement admissibility, damages evidence, ongoing royalty), Prism Techs. LLC v. Sprint Spectrum L.P., 849 F.3d 1360 (Fed. Cir. Mar. 6, 2017) (Nos. 2016‑1456, 2016‑1457). Later reversed on § 101: Prism Techs. LLC v. Sprint Spectrum L.P., 757 F. App'x 980 (Fed. Cir. 2019) (holding the T‑Mobile eligibility decision invalidated all claims at issue); cert. denied June 10, 2019.
6 Prism Technologies LLC T‑Mobile USA, Inc. D. Neb. 8:12‑cv‑00124‑LES‑TDT 2012 '288 withdrawn March 2014. Jury found non‑infringement of the asserted '345/'155 claims; post‑trial motions denied 2016‑04‑06; T‑Mobile cross‑appealed 2016‑05‑10. Fed. Cir. reversed the district court's § 101 patent‑eligibility ruling and held the claims ineligible; affirmed denial of T‑Mobile's § 285 motion; Prism's appeal dismissed as moot (No. 2016‑2560, 696 F. App'x 1014, Aug. 25, 2017).
7 Prism Technologies LLC United States Cellular Corporation D. Neb. 8:12‑cv‑00125‑LES‑TDT 2012 '288 withdrawn March 2014. Action stayed pending the Sprint and T‑Mobile appeals; after those decisions the court issued a show‑cause order (2019‑06‑25) indicating the appeals were dispositive and that the case should likely be dismissed.
8 Prism Technologies LLC [Cellco Partnership d/b/a Verizon Wireless](/litigations/by-plaintiff/Cellco%20Partnership%20d%2Fb%2Fa%20Verizon%20Wireless) D. Neb. 8:12‑cv‑00126‑LES‑TDT 2012 '288 withdrawn March 2014; case consolidated for pretrial purposes with the other carrier actions (Nos. 122–125).

Sources: RIM complaint (insight.rpxcorp.com/litigation_documents/3915389); ITC institution and termination notices (govinfo.gov FR‑2010‑01‑05/E9‑31246; FR‑2010‑06‑28/2010‑15665); Adobe judgment (cases.justia.com …/8:2010cv00220/52647/1135/0.pdf); D. Neb. Markman order (cases.justia.com …/8:2012cv00122/58574/132/0.pdf); Sprint opinion (courtlistener.com/opinion/4373125); 2019 show‑cause order (cases.justia.com …/8:2012cv00125/58577/365/0.pdf); Stanford NPE Litigation Database (npe.law.stanford.edu/patent/7290288).


B. Proceedings on the patent record that I could not independently verify

  • Federal Circuit docket numbers listed on the Google Patents page for this patent: 13‑1135, 16‑1456, 16‑1457, 16‑2031, 16‑2049, 18‑1108. I confirmed that 2016‑1456/1457 is the Sprint appeal (No. 5 above) and that 18‑1108 is consistent with the 2019 nonprecedential Sprint decision at 757 F. App'x 980 that produced the June 10, 2019 cert denial. The appeal number 13‑1135 most plausibly corresponds to the appeal from the Adobe‑case judgment (No. 3), and 16‑2031/16‑2049 plausibly correspond to appeals/notices of appeal filed in the 2016 carrier cases — but I could not confirm the parties or dispositions for 13‑1135, 16‑2031 or 16‑2049. Do not rely on those three without checking PACER/CM‑ECF.
  • U.S. Supreme Court dockets listed for this patent: 17‑430, 17‑716, and 18‑1397 (portal.unifiedpatents.com, "US case filed in U.S. Supreme Court"). I could not verify the petitioner/respondent or disposition of any of the three. They are chronologically consistent with cert petitions arising from the 2017 Sprint and T‑Mobile Federal Circuit decisions and the 2019 Sprint decision, but that is inference, not confirmation. I am flagging these as unverified rather than guessing.
  • USPTO proceedings: the record shows a Request for Ex Parte Reexamination of U.S. Pat. No. 7,290,288 dated June 4, 2009 (cited in later Prism patents' IDS), and an expert‑declaration index in the PTAB materials references IPR2017‑00590 alongside "Prism v Sprint, Prism v T‑Mobile, Prism v US Cellular." These are not litigation, and I could not confirm which patent or parties the IPR targeted — do not attribute IPR2017‑00590 to the '288 patent without verification.

C. Related Prism litigation that does not involve the '288 patent (avoid confusion)

  • Prism Technologies LLC v. VeriSign, Inc., et al., No. 1:05‑cv‑00214‑JJF (D. Del.) — filed 2005‑04‑11 against VeriSign, RSA Security, Netegrity, Computer Associates and Johnson & Johnson Services. This case asserted U.S. Patent 6,516,416 (the '288 parent), not the '288 patent. Markman order 2007‑04‑02 construed key terms against Prism; Prism stipulated to non‑infringement; final judgment of non‑infringement 2007‑04‑23; affirmed, 263 F. App'x 878 (Fed. Cir. 2008) (appeal No. 2007‑1315); fee motion denied, 579 F. Supp. 2d 625 (D. Del. 2008). Claim constructions from this case were later disclosed to the PTO and reused in Prism's '288 litigation.
  • The Fed. Cir. 2019 invalidation of the claims Prism actually won on (in the Sprint case) rested on § 101 against the '345 and '155 patents — descendant patents, not the '288 patent — although the '288 patent shares the same specification lineage and was asserted early in those same suits.

Practical summary

The '288 patent was asserted against (i) RIM/Microsoft (D. Neb. 8:08‑cv‑00537, settled), (ii) RIM at the ITC (337‑TA‑697, settled and terminated in 2010), (iii) eleven software/consumer‑software companies led by Adobe (D. Neb. 8:10‑cv‑00220 — Prism lost on summary judgment of non‑infringement in December 2012), and (iv) initially against the five U.S. wireless carriers (AT&T, Sprint, T‑Mobile, U.S. Cellular, Verizon Wireless — D. Neb. Nos. 8:12‑cv‑122 through ‑126), from which Prism voluntarily withdrew the '288 claims in March 2014. No case is known in which the '288 patent was ultimately held valid and infringed, and no damages award or injunction appears to have been entered on this patent.

Recommended verification before relying on this list: PACER/CM‑ECF for D. Neb. 8:08‑cv‑00537, 8:10‑cv‑00220, and 8:12‑cv‑122/123/124/125/126; the ITC EDIS record for 337‑TA‑697; Supreme Court dockets 17‑430, 17‑716 and 18‑1397; and Federal Circuit dockets 13‑1135, 16‑2031 and 16‑2049.

Generated 10/1/2026, 3:53:58 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Prism Technologies LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll verify the structured ODP result against public sources before reporting.

Let me run more targeted searches on PTAB activity and the related litigation history.

Let me confirm whether any AIA trial names the '288 patent, including via PTAB dockets and family patents.

PTAB / AIA Trial Landscape — US 7,290,288 (Gregg et al., "Method and system for controlling access, by an authentication server, to protected computer resources provided via an Internet Protocol network")

Verification basis. The structured "PTAB proceedings on file" block for this patent (USPTO Open Data Portal) reports no AIA trial proceedings. I independently searched for IPRs, PGRs, and CBMs naming the '288 patent (by patent number and by patent owner / family), including petitioner-side petitions and Prism Technologies family dockets, and surfaced none. I am reporting zero AIA trials, not a low count. Where the record is thin I say so rather than fill it in.


Proceedings overview

Total AIA trial proceedings on US 7,290,288: 0. Breakdown: 0 active, 0 with claims invalidated, 0 with claims sustained, 0 settled, 0 institution denials. The defensive posture this creates is unusual and worth stating precisely: there is no claim-cancellation history to hand a defendant, and equally no IPR estoppel (§ 315(e)(2)) constraining anyone's invalidity case — the '288 patent has never been tested at the PTAB, so the usual "the patent survived two IPRs and is hardened" narrative simply does not exist here. A defendant's real leverage comes from a different direction entirely: the patent expired on 2022-10-12 (listed status: "Expired – Fee Related"), and the Federal Circuit held substantially similar claims in its direct continuations under 35 U.S.C. § 101 in a 2017 nonprecedential decision.

Because no AIA proceedings exist, I substitute, below, the closest analogues in the post-grant and adversarial record — two ex parte reexaminations and the § 101 Federal Circuit ruling — clearly labeled as not AIA trials, since mislabeling a reexam as an IPR is exactly the kind of error that gets a defendant sanctioned or embarrassed.


No AIA proceedings — but here is the equivalent post-grant and appellate record

EX PARTE REEXAMINATION 90/010,565 — (third-party requester) v. Prism Technologies, L.L.C.

  • Type: Ex parte reexamination (NOT an AIA trial; no PTAB panel, no FWD, no § 315(e) estoppel)
  • Filed: 2009-06-04 (reexamination request)
  • Status: Concluded — Ex Parte Reexamination Certificate US 7,290,288 C1 issued 2010-08-03
  • Judge panel: N/A (examiner corps; Primary Examiner Matthew Heneghan on the certificate)
  • Grounds: § 102 / § 103 over prior art cited in the request; the central contested issue was whether the '288 claims are entitled to the 1997-06-11 filing date of application 08/872,710 (now US 6,516,416), because a priority entitlement loss would have exposed the claims to a much larger art field
  • Outcome at claim level: Certificate issued 2010-08-03. The certificate front page reflects claim text changes (e.g., a correction changing "Vard" to "Card"). I cannot state with high confidence from the sources I reviewed which specific claims were confirmed as written versus amended, or how many of the 187 claims were substantively touched — a defendant should pull the C1 certificate itself before relying on any claim-level characterization.
  • Settlement / termination: N/A
  • Appeal: None identified
  • Defensive value: Modest. The reexam shored up the 1997 priority date, which removes a large body of post-1997 art (this is the opposite of helpful to a defendant relying on late-1990s art). Link: US 7,290,288 file including C1 certificate

EX PARTE REEXAMINATION 90/010,948 — (Research in Motion / third party) v. Prism Technologies, L.L.C.

  • Type: Ex parte reexamination (NOT an AIA trial)
  • Filed: 2010-04-08
  • Status: Was pending as of the 2010-08-03 C1 certificate date. I could not confirm the terminal claim-level disposition of this second reexam from the sources I reviewed.
  • Grounds: § 102 / § 103 prior-art challenge; per contemporaneous reporting, the PTO granted the request as to one combination that raised a substantial new question of patentability, while holding the remaining cited references were not available as prior art because Prism was entitled to the earlier application's benefit (WHDA, "Patentee Establishes Priority by Reexamination," 2010-07-16)
  • Context: This ran parallel to ITC Investigation No. 337-TA-697, Certain Authentication Systems (RIM's motion for summary determination that the asserted '288 claims are invalid), which was terminated following a Prism–RIM settlement (district court case 8:08-cv-00537 also settled), so the ITC never reached the merits of RIM's invalidity theory.
  • Defensive value: Neutral-to-unfavorable. The requester's art was largely knocked out on priority grounds, not on the merits.

CAFC 16-2031 — Prism Technologies LLC v. T-Mobile USA, Inc. (Fed. Cir. 2017-06-23, nonprecedential)

  • Type: Federal Circuit appeal from district court (NOT a PTAB appeal, and NOT on the '288 patent itself)
  • Patents at issue: US 8,127,345 and US 8,387,155 — direct continuations of the '288 patent and, per Prism's own representations, sharing the same specification/inventive disclosure
  • Holding: The asserted claims are directed to the abstract idea of "providing restricted access to resources" and, at Alice step two, recite "merely a host of elements that are indisputably generic computer components." The Federal Circuit reversed the district court's finding of § 101 eligibility. Prism's new-trial and JMOL requests were denied; the jury's non-infringement verdict stood.
  • Appeal: This is the appellate disposition. Opinion: CourtListener PDF
  • Defensive value: This is the single most valuable defensive asset against the '288 patent. The '288 specification and claim architecture are the same family tree, so a § 101 motion built on Prism v. T-Mobile has a strong template — while being candid that the holding is nonprecedential and addressed different claims, so it is persuasive authority, not a claim-preclusive judgment about '288's claims.

Strategic summary

Claim status: no claims CANCELED by the PTAB; no claims SUSTAINED by the PTAB; effectively all claims UNTESTED at the PTAB. US 7,290,288 issued with a large claim set (the Adobe litigation discussed asserted claims numbered at least into the 180s, e.g., claims 186 and 187). The only Office-side narrowing of record is the C1 reexamination certificate of 2010-08-03 plus a 2009-09-08 certificate of correction. I did not find a claim-by-claim invalidation of any '288 claim anywhere — the patent was instead narrowed by claim construction in district court (N.D. Neb.) and avoided by defendants' products on non-infringement, and it was voluntarily dropped by Prism from the 2012 carrier campaign (8:12-cv-00122 through -126). If you are being asserted against today, assume the asserted claims are still legally alive (subject to expiration) until you prove otherwise.

Estoppel landscape: clean. Because there has been no IPR/PGR/CBM that reached a final written decision, 35 U.S.C. § 315(e)(2) estoppel does not apply to anyone. No petitioner or privy is barred from raising § 102 or § 103 grounds in a district court or ITC. Nor does ex parte reexamination generate IPR-style estoppel. Practically, this means: (a) every prior-art ground is available to you; (b) your exposure to patent-owner prosecution-history estoppel is real, because Prism amended claims during reexamination and prosecution — that cuts against Prism's doctrine-of-equivalents case; and (c) if you do file an IPR and it reaches FWD, you will then be estopped as to grounds you raised or reasonably could have raised — so file the IPR with your full § 103 case, not a toe-in-the-water petition.

Pattern signals. No defensive aggregator (Unified Patents, RPX, etc.) appears anywhere in the '288 record I reviewed — no CBM filings in the 2012–2019 window when this patent would have been a prime CBM target, despite it being a "controlling access to resources" claim set that is textually exposed to § 101 and covered-business-method attack. The reason appears commercial, not legal: Prism settled its campaigns (RIM/Microsoft 2008–2010; the Adobe/software-defendant case; the carriers), so defendants bought peace rather than filing post-grant challenges, and by the time the Federal Circuit invalidated the continuation claims in 2017 the '288 patent had little remaining life. Note also the family-level activity on the Google Patents record: Nebraska cases 8:08-cv-00537, 8:10-cv-00220, 8:12-cv-00122–126; ITC 337-TA-697; CAFC dockets 13-1135, 16-1456, 16-1457, 16-2031 (verified = Prism v. T-Mobile, 2017-06-23), 16-2049, 18-1108; and Supreme Court dockets 17-430, 17-716, 18-1397. I verified only 16-2031; I did not confirm what the other five CAFC dockets and three cert dockets concerned and would not guess.

Expiration — the biggest fact in the file. The patent's listed status is "Expired – Fee Related," with an adjusted expiration of 2022-10-12 (the '288 patent is a CIP of the 1997-06-11 application, so it is long past its statutory term regardless). Consequences: no injunction; no ongoing royalties; and, applying the § 286 six-year damages bar to today's date (2026-10-01), recoverable damages are confined to infringement accruing on or after 2020-10-01 and on or before 2022-10-12 — a roughly 24-month accrual window. Any demand letter asserting open-ended or future damages is facially overreaching.


Recommended next steps

  1. If you are a defendant today, lead with expiration + § 101, not with IPR. There are no canceled claims to point to, so do not plan around a PTAB kill shot. Get the demand letter's cited claims identified, then:
    • Quote Prism Techs. LLC v. T-Mobile USA, Inc., No. 16-2031 (Fed. Cir. 2017-06-23) (nonprecedential) — "the asserted claims are directed to the abstract idea of 'providing restricted access to resources'" — and move for § 101 dismissal/ineligibility on the '288 claims, framing it as a same-specification, same-family extension of that holding, while acknowledging the decision addressed the '345/'155 claims.
    • Pair it with the § 286 damages cap (pre-2020-10-01 conduct is not recoverable at all) and the absence of injunction.
  2. Mine the existing claim-construction record rather than re-inventing it. N.D. Neb. construed the key '288 terms: "hardware key"/"access key" = "an external hardware device or object from which the predetermined digital identification can be read"; "digital identification" = "digital data whose value is known in advance or calculated at the moment"; "identity data"; "clearinghouse"; "authentication server." The Adobe-case summary judgment found the accused software-distribution CDs could not be hardware keys, disposing of literal infringement and much of the DOE case for those products. If your accused product authenticates a user rather than a device — the exact ground on which the carriers won a jury verdict — that construction is your non-infringement argument. Cite the construction orders (Casetext summary of the 2012 Adobe order).
  3. A defensive IPR remains legally available but is probably not worth it — and if you file, file it once and file it complete. The patent is expired, so there is no amendment risk and no forward-looking value; and there is no § 315(e)(2) estoppel to gain by not filing. If you do file, watch the § 315(b) one-year clock from service of the complaint, and note that for an expired patent the PTAB still permits review. Budget for a full § 103 case; a partial petition buys you estoppel without buying you a cancellation.
  4. Do not cite any "'288 IPR FWD" — there isn't one. If opposing counsel, a broker, or a prior art vendor hands you an IPR number supposedly on the '288 patent, treat it as a family-patent or unrelated-patent mix-up and demand the proceeding number be run through PTAB E2E before you rely on it. The public family record that does exist is ex parte reexamination 90/010,565 (C1 certificate 2010-08-03) and 90/010,948 (filed 2010-04-08), plus the ITC investigation 337-TA-697 that ended in settlement — none of which is an AIA trial and none of which carries § 315(e) estoppel.

Confidence and gaps. I am confident in the zero-AIA-trial count (ODP structured data, plus independent searching). I am confident about: patent dates and identity, the two reexamination numbers and the C1 certificate date, the RIM ITC motion and settlement, the N.D. Neb. "hardware key" construction, the Adobe non-infringement ruling, and the CAFC 16-2031 § 101 holding. I am not able to confirm from available sources: the claim-by-claim disposition of reexamination 90/010,948; whether the C1 certificate narrowed or merely confirmed any particular claim; and the subject matter of CAFC dockets 13-1135, 16-1456, 16-1457, 16-2049, 18-1108 and Supreme Court dockets 17-430, 17-716, 18-1397. Pull the certificate and those dockets directly before relying on them.

Generated 10/1/2026, 3:54:15 PM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2002-10-25 · Assignment

    Richard L. GreggPrism Resources

    title-perfection

  2. ? · recorded 2004-07-22 · Assignment

    Prism ResourcesPrism Technologies, L.L.C.

    internal reorg

  3. ? · recorded 2006-03-03 · Assignment

    Sandeep Giri; Timothy C. GoekePrism Technologies, L.L.C.

    title cleanup

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research this patent's assignment record and litigation history before writing the analysis.

Let me dig into the assignment records, corporate parent, and any security interests.

Assignment & Ownership Reconstruction — US 7,290,288 B2

Patent: US 7,290,288 B2 — Method and system for controlling access, by an authentication server, to protected computer resources provided via an internet protocol network
App. No.: 10/230,638 · filed 2002-08-29 · issued 2007-10-30
Earliest priority: 1997-06-11 (via US 08/872,710, which issued as US 6,516,416 B2)
Current assignee of record (per patent front page): Prism Technologies LLC
Post-issuance family: US 8,127,345; 8,387,155; 8,898,746; 9,369,469; 9,413,768; 9,544,314 — all still held by Prism Technologies LLC


⚠️ Data-availability caveat (read before the timeline)

I could not retrieve reel/frame numbers or assignment-correspondent data for this patent in this session. The Assignment Center records were not reachable through the tools available to me, and no reel/frame numbers for US 7,290,288 appear in the Google Patents legal-events data, the litigation record, or the SEC filings I retrieved. Every assignment entry below is reported with the recording date and the parties, taken from Google Patents legal events (https://patents.google.com/patent/US7290288/en#legal-events). Recording dates are not execution dates — Google Patents surfaces the record date only. I have not invented reel/frame numbers or attorney names where the record is silent. Two of the rubric's signals (repeat correspondent, and precise pre-litigation timing) cannot be scored rigorously without that data, and I have marked them accordingly.


Inventors

Inventor Residence of record Employer at filing (inferred)
Richard L. Gregg Omaha, Nebraska Prism Resources, Omaha NE
Sandeep Giri Omaha, Nebraska Prism Resources, Omaha NE
Timothy C. Goeke Elkhorn, Nebraska Prism Resources, Omaha NE

The employer inference is not speculative naming: the 1997 parent application (08/872,710 → US 6,516,416) issued with Prism Resources (Omaha, NE) as assignee, and the earliest recorded assignment on the '288 chain (2002-10-25) is Gregg → Prism Resources. All three inventors are Omaha-metro residents, matching Prism Resources' and later Prism Technologies LLC's Omaha headquarters.

Unusual patterns worth noting:

  • The three inventors did not assign to the same entity. Gregg assigned to Prism Resources (recorded 2002-10-25); Giri and Goeke assigned directly to Prism Technologies, L.L.C. (recorded 2006-03-03). That is a two-tier, non-uniform chain that needed a bridging assignment (Prism Resources → Prism Technologies, 2004-07-22) to be complete. It looks like title was assembled piecemeal rather than papered at filing.
  • The Giri/Goeke assignment was recorded roughly 20 months before issuance and ~3.5 years after the 2002-08-29 filing — consistent with a pre-issuance title cure.
  • No inventor departure / fire-sale pattern is evidenced. The same three inventors continued to be named on the continuation filings through at least 2016 (e.g., US 9,544,314, filed 2016-05-26), so the inventors stayed attached to the family rather than exiting early. I found no evidence of inventor departure.

Original assignee

The patent's front page names Prism Technologies LLC as original assignee, but the earliest recorded assignment is to Prism Resources — I interpret both literally and present them separately.

Prism Resources (Omaha, NE) — the entity that took the 1997 priority application and the 2002 Gregg assignment. Primary line of business: not established by any document I retrieved; it appears to be the invention-stage vehicle behind a 1990s "subscription access system" concept (hardware key + clearinghouse authentication over an untrusted network). I found no evidence that Prism Resources shipped a commercial product embodying the claims. Current status: superseded on this chain by Prism Technologies, L.L.C. as of the 2004-07-22 assignment; no dissolution, bankruptcy, or acquisition record surfaced.

Prism Technologies, L.L.C. / Prism Technologies LLC (Omaha, NE) — the entity that has owned the patent (and its entire continuation family) through issuance and every assertion campaign. Per its parent's SEC Form 10-K, Prism is a Nebraska LLC, Omaha-headquartered, whose business is patent licensing and enforcement. Parent status:

  • 2015-03-26: Prism Technologies, LLC was acquired by Internet Patents Corporation (formerly InsWeb Corporation, a Nasdaq-listed online insurance marketplace that had sold its operating business in 2012 and renamed itself Internet Patents Corporation). Merger consideration to Prism's former members: $16.5M cash + 3.5M shares + up to ~$49.5M revenue share — i.e., the patent portfolio was the acquired asset.
  • 2015-09: parent renamed Prism Technologies Group, Inc. (ticker PRZM).
  • FY2016 10-K (filed 2017-03-31): auditor Ernst & Young issued a going-concern doubt; the company recorded a $23.4M impairment of its patent portfolio "as a result of significantly lower than anticipated revenues."
  • 2022-10-12: the '288 patent expired for failure to pay maintenance fees ("Expired – Fee Related" per Google Patents legal status).

So: at no point in its post-2004 life was this patent held by an entity that made or sold a product. The holding entity is, by its own SEC disclosure, a licensing-and-enforcement-only subsidiary of a public patent-assertion company.


Assignment timeline

Three recorded assignments appear in the legal-events data. Chronological, with reel/frame reported honestly as unavailable:

1. 2002-10-25 (recorded) — Reel not retrieved

  • Conveyance: Assignment of assignors' interest
  • Assignor: Richard L. Gregg
  • Assignee: Prism Resources (Omaha, NE)
  • Correspondent: not retrievable from sources available to me
  • Context: Inventor-to-company assignment perfecting title at the time of the 2002-08-29 continuation filing.

2. 2004-07-22 (recorded) — Reel not retrieved

  • Conveyance: Assignment
  • Assignor: Prism Resources
  • Assignee: Prism Technologies, L.L.C.
  • Correspondent: not retrievable
  • Context: Internal reorg — transfer of the patent out of the original invention vehicle and into the licensing/enforcement entity, ~4 years before the first infringement suit on this patent and ~3 years before issuance.

3. 2006-03-03 (recorded) — Reel not retrieved

  • Conveyance: Assignment
  • Assignor: Sandeep Giri; Timothy C. Goeke
  • Assignee: Prism Technologies, L.L.C.
  • Correspondent: not retrievable
  • Context: Title cleanup — the two co-inventors cured their chain of title directly into Prism Technologies, L.L.C. ~20 months before the 2007-10-30 issuance.

Post-2007: no further recorded assignment on the patent itself. The 2015 merger (Prism Technologies, LLC into Internet Patents Corporation / Prism Technologies Group) does not appear as a recorded patent assignment, because the LLC survived as a wholly owned subsidiary and bare title did not move. No security agreement, license, release, or merger conveyance is recorded against this patent in the data I retrieved. No assignment to any third-party NPE, aggregator, or defensive entity appears.

Note on the corporate shell at the top: Internet Patents Corporation / Prism Technologies Group did not record a separate assignment, but the corporate chain above the patent is documented in SEC filings (InsWeb Corp → Internet Patents Corp, 2012 disposition + rename; → Prism Technologies Group, 2015 merger + rename).


Timeline diagram

timeline
    title Ownership and Assertion of US 7290288
    1997 : Priority app filed by Prism Resources
    2002 : Continuation application filed
         : Gregg assigns his rights to Prism Resources
    2004 : Prism Resources transfers to Prism Technologies
    2006 : Giri and Goeke assign to Prism Technologies
    2007 : Patent 7290288 issues
    2008 : First suit filed against RIM
    2009 : Ex parte reexamination requested
    2010 : Suits filed against security software vendors
    2012 : Suits filed against five US wireless carriers
    2015 : Prism acquired by Internet Patents Corp
         : Parent renamed Prism Technologies Group
    2017 : Federal Circuit finds claims ineligible
    2019 : Sprint judgment vacated and cert denied
    2022 : Patent expires for unpaid maintenance fees

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT.
The patent moved from the invention-stage entity Prism Resources to Prism Technologies, L.L.C. by the recorded 2004-07-22 assignment. Prism Technologies' own SEC-described business (via parent Prism Technologies Group's 10-K) is "licensing and enforcing a portfolio of patents"; the parent's portfolio table shows a $23.4M impairment in FY2016 after "significantly lower than anticipated revenues." The 2017 certificate of interest in Prism Techs. LLC v. T-Mobile lists Prism's address as 750 Old Hickory Blvd., Ste. 150, Brentwood, TN 37027 — a suburban office-suite address, and states Prism "is a wholly owned subsidiary of Prism Technologies Group, Inc., a public company listed on the NASDAQ." That is a licensing-only subsidiary, not an operating company.

2. Known asserter in the chain — PRESENT.
The patent's owner, Prism Technologies LLC, appears as the asserter in the Stanford NPE Litigation Database entry for patent 7,290,288 (https://npe.law.stanford.edu/patent/7290288), with the asserter category "Acquired patents." Prism is also a repeat plaintiff — a partial docket pull shows cases against AT&T, Verizon/Cellco, Sprint, T-Mobile, U.S. Cellular (all 2012-04-04), Nintendo and a dozen retailers (2013-01-18), display-adapter and accessory vendors (2013-04-22), and financial-services firms including T. Rowe Price (2013-10-16) and Texas Capital Bancshares. The parent's own 10-K describes the company as "engaged in the business of licensing and enforcing a portfolio of patents." Prism is not on the classic enumerated list (Acacia, Marathon, IV, Wi-LAN, etc.), but it is a high-frequency plaintiff surfaced as such by the Stanford NPE database.

3. Repeat correspondent across the chain — UNCLEAR.
No assignment correspondent is available in any source I retrieved, for any of the three recorded assignments. I cannot confirm or refute a repeat attorney-of-record. The only counsel names I can ground are litigation counsel, not recording counsel: André J. Bahou (identified in the T-Mobile appeal certificate of interest as counsel for Prism Technologies LLC), Kramer Levin Naftalis & Frankel LLP and Koley Jessen P.C., L.L.O. These are merits counsel and are not evidence of assignment-recording behavior — I flag them only so the absence is not mistaken for a clean bill.

4. Cascading transfers — NOT PRESENT.
The three recorded assignments are spread across 2002-10-25, 2004-07-22 and 2006-03-03 — roughly 41 months end-to-end, not sub-24-month chaining — and all three stay inside the same corporate family. There is no chain of unrelated LLCs, no shared registered-agent address pattern evidenced, and no transfer after 2006.

5. Pre-litigation transfer — NOT PRESENT.
The last recorded assignment (2006-03-03) predates the first '288 suit — Prism Technologies v. Research in Motion, D. Neb. 8:08-cv-00537, filed 2008 — by roughly two years, and predates the wireless-carrier campaign (2012-04-04) by six years. The chain was not re-arranged within six months of filing suit. (No recorded assignment appears anywhere near 2008 or 2012.)

6. Bankruptcy fire-sale — NOT PRESENT.
No Chapter 7/11 or asset-sale proceeding, and no creditor assignment, appears in the records I retrieved. The nearest pressure indicator is the FY2016 going-concern qualification by Ernst & Young (10-K filed 2017-03-31) after the $23.4M portfolio write-down — distress, but not a bankruptcy sale of this patent.

7. Privateering — NOT PRESENT.
The chain has no operating-company grantor passing patents to an NPE to assert against that company's competitors. The grantors are the inventors themselves and their invention-stage LLC. No SEC filing or third-party coverage I found documents an operating company funding or directing the assertion.

8. Defensive aggregator — NOT PRESENT.
The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. The patent instead expired 2022-10-12 for non-payment of maintenance fees while still titled to Prism Technologies LLC. Note that Unified Patents-adjacent pressure exists on the family — an ex parte reexamination of US 7,290,288 was requested 2009-06-04 with ~148 pages of prior art, and the Federal Circuit invalidated the asserted claims of the related '345/'155 patents under §101 — but that is validity attrition, not defensive ownership.


Verdict

NPE — high confidence

Reasoning: The patent was moved out of its invention-stage vehicle into Prism Technologies, L.L.C. by the recorded 2004-07-22 assignment, and that entity's own corporate parent describes its business as patent licensing and enforcement (Prism Technologies Group 10-K; $23.4M patent-portfolio impairment in FY2016). Prism Technologies LLC then asserted the '288 family against at least four distinct defendant classes — RIM (8:08-cv-00537), the McAfee/Symantec/Trend Micro security vendors (8:10-cv-00220), five U.S. wireless carriers (2012-04-04), Nintendo and big-box retailers (2013-01-18), and financial-services firms including T. Rowe Price (2013-10-16) — while the Stanford NPE Litigation Database classifies the asserter as "Acquired patents." There is no evidence the patent owner ever made or sold a product, no defensive-aggregator termination, and the patent was finally permitted to lapse for unpaid maintenance fees on 2022-10-12 after the Federal Circuit invalidated the asserted continuation claims under §101.

Two signals (repeat assignment correspondent, and precisely dated pre-suit transfer) could not be scored because reel/frame and correspondent fields were not retrievable here; the "high confidence" call rests on signals 1, 2, and the litigation record, all of which are independently grounded in dated sources.

Verify at:

Generated 10/1/2026, 3:54:28 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research US patent 7290288 and its cited prior art references.

Let me get the specific "References Cited" / prior art section for this patent.

I found the prior art list on Unified Patents. Let me get the full citation list from multiple sources.

US 7,290,288 — Identification and Prior-Art Analysis

Important limitation up front: In this session I was able to retrieve the patent's bibliographic data and a prior-art list associated with its pre‑grant publication, but I was not able to pull the literal USPTO Form PTO‑1449 / "References Cited (56)" list as it appears on the face of the printed patent. The reference list below is drawn from the Unified Patents "Patent Art" record for US 2003/0046589 A1 (the pre‑grant publication of this application) and matching bibliographic data. I could not verify the exact examiner‑cited set, so treat the "which claims it anticipates" mapping as a screening analysis, not a legal conclusion. I flag each uncertainty rather than asserting certainty I don't have.


1. The patent (confirmed identifiers — interpreted literally)

Field Value
Patent number US 7,290,288 B2
Title Method and system for controlling access, by an authentication server, to protected computer resources provided via an internet protocol network
Application no. US 10/230,638
Filing date 2002‑08‑29
Priority date 1997‑06‑11
Earliest priority application US 08/872,710 (which issued as US 6,516,416 B2)
Inventors Richard L. Gregg; Sandeep Giri; Timothy C. Goeke
Assignee Prism Technologies LLC
Pre‑grant pub. US 2003/0046589 A1 (2003‑03‑06)
Grant date 2007‑10‑30
Classification H04L 63/10; G06F 21/33; H04L 63/0853, etc.
Status Expired – Fee Related (adjusted expiration 2022‑10‑12)

Claim scope (as recited in the specification's own summary): a system with clearinghouse means storing identity data of both the server and client; server‑side and client‑side software that forward identity data to the clearinghouse at the start of a session; a hardware key at the client that generates a digital ID; server software that periodically requests the client to re‑forward the ID to confirm the hardware key is still connected; and the clearinghouse authenticating both the client's and the server's identity and granting access only on mutual successful authentication. This "bidirectional/clearinghouse‑mediated authentication + hardware token + re‑polling" combination is the inventive core and is what the prior art below must be measured against.


2. Prior art references (patent citations)

The list below reflects the art associated with US 2003/0046589 A1 / US 7,290,288. Assignee names and priority dates are as returned by the source and are reproduced as‑is.

A. Most relevant — potentially anticipatory under § 102

Ref. Publication / Priority Brief description Claims potentially affected
US 5,848,970 A — Authentication Method for Networks (Identity Verification Solutions LLC) prio. 1995‑09‑07 Network authentication methodology; establishing verified identities of parties communicating over a network. Directly on point for the "authenticate client and server identity" concept. Independent system claim + its authentication‑step dependents — a strong §102 candidate if it discloses authenticating both parties.
US 5,708,780 A — Internet Server Access Control and Monitoring Systems (Open Market Inc / Soverain IP LLC) prio. 1995‑06‑06 Internet/web‑server access control and monitoring; session identifiers, access‑control to protected resources over a network. Classic reference in this space. Independent claim (controlling access to protected resources over an IP network; session‑based granting) — key §102/§103 reference.
US 5,721,781 A — Authentication System and Method for Smart Card Transactions (Microsoft Technology Licensing) prio. 1995‑09‑12 Authentication using a smart card as a hardware token. Bears on the "hardware key generating a digital ID" limitation. Hardware‑key/digital‑ID dependent claims; combinable with a clearinghouse reference.
US 5,483,596 A — Apparatus and Method for Controlling Access to and Interconnection of Computer System Resources (Paralon Tech Inc) prio. 1994‑01‑23 Central apparatus controlling access to and interconnection of computing resources. Independent claim's "clearinghouse authorizing access to resources" element.
US 5,592,553 A — Authentication System Using One‑time Passwords prio. 1993‑07‑29 One‑time‑password authentication. Authentication‑method dependents; less likely to touch the hardware‑key element alone.
US 5,416,842 A — Method and Apparatus for Key‑management Scheme for Use with Internet Protocols at Site Firewalls prio. 1994‑06‑09 Key management across firewalls for Internet protocols; relevant to the firewall/LAN architecture in Fig. 1. Dependent claims on secure server↔clearinghouse communication.
US 4,885,789 A — Remote Trusted Path Mechanism for Telnet 1988‑01‑31 Establishing a trusted path to a remote host — relevant to "authenticating the server before the client accepts commands." Server‑authentication dependents.
US 5,499,297 A — System and Method for Trusted Path Communications (McAfee LLC) prio. 1992‑04‑16 Trusted‑path communication between parties. Server‑authentication dependents.
US 5,546,463 A — Pocket Encrypting and Authenticating Communications Device (Thales DIS CPL USA) prio. 1994‑07‑11 Portable/token cryptographic device — bears on hardware‑token authentication. Hardware‑key dependents.
US 4,916,738 A — Remote Access Terminal Security 1986‑11‑04 Remote terminal access security. Background to access‑control independent claim.
US 5,659,616 A — Method for Securely Using Digital Signatures in a Commercial Cryptographic System (Certco LLC) prio. 1994‑07‑18 Digital‑signature use in commercial cryptography. Digital‑ID/signature dependents.
US 5,774,552 A — Method and Apparatus for Retrieving X.509 Certificates from an X.500 Directory prio. 1995‑12‑12 Certificate retrieval/validation — bears on server & client identity verification. Identity‑data dependents.
US 5,371,794 A — Method and Apparatus for Privacy and Authentication in Wireless Networks (Oracle America) prio. 1993‑11‑01 Privacy/authentication scheme. Authentication dependents.

B. Secondary / background references

Ref. Date Brief description Notes
US 5,229,764 A — Continuous Biometric Authentication Matrix 1991‑06‑19 Repeated/continuous biometric authentication — conceptually analogous to the patent's periodic re‑authentication/polling for continued presence of the token. Potentially relevant to re‑authentication dependents (§103).
US 5,357,573 A — Memory Card (Intelligent Solution Services GMBH) 1991‑08‑11 Portable memory card. Hardware media background.
US 5,032,979 A — Distributed Security Auditing Subsystem (IBM) 1990‑06‑21 Distributed auditing — relates to transaction/session logging. Session‑tracking dependents (§103).
US 5,754,864 A — Software Piracy Detection System (Charles E. Hill & Assoc.) prio. 1992‑04‑09 Detects unauthorized software use. Background.
US 4,864,494 A — Software Usage Authorization System with Key… 1986‑03‑20 Key‑based software usage authorization. Background.
US 5,081,676 A — Method and Apparatus for Protecting Multiple Copies of Computer Software… (Software Security Inc) 1990‑10‑03 Software copy protection. Background.
US 5,502,831 A — Method for Detecting Unauthorized Modification of a Communication or Broadcast Unit (Motorola Solutions) — Tamper/unauthorized‑modification detection. Background.
US 5,379,343 A — Detection of Unauthorized Use of Software Applications in Communication Units (Motorola Mobility) prio. 1993‑02‑25 Unauthorized‑use detection. Background.
US 5,485,409 A — Automated Penetration Analysis System and Method prio. 1992‑04‑29 Security‑vulnerability analysis. Background.
US 5,629,980 A — System for Controlling the Distribution and Use of Digital Works (ContentGuard) prio. 1994‑11‑22 Rights management for digital content. Background.
US 5,497,421 A — Method and Apparatus for Protecting the Confidentiality of Passwords in a Distributed Data Processing System (HP) prio. 1992‑04‑27 Password confidentiality in distributed systems. Password‑handling dependents.
US 6,047,376 A — Client‑server System, Server Access Authentication Method… (Toshiba Information Systems Japan) prio. 1996‑10‑17 Client‑server access authentication with issuance device. Notably later priority (1996) — still before the 1997‑06‑11 priority date; relevant to client/server authentication dependents.

3. Analytical notes for a § 102 assessment

  1. No single reference above appears to disclose all elements of the broad independent claim — specifically the combination of (a) a clearinghouse separate from the server, (b) authenticating both server and client through it, and (c) a hardware key whose continued connection is periodically re‑polled mid‑session. Anticipation under § 102 would most plausibly be argued against the narrower/dependent claims (hardware token, digital ID, server authentication), while the independent claim would more likely be attacked as obvious under § 103 over a clearinghouse/access‑control reference (e.g., US 5,708,780 or US 5,848,970) in view of a token reference (US 5,721,781 or US 5,546,463).

  2. US 5,229,764 (Continuous Biometric Authentication Matrix) deserves special attention: it is the closest conceptual analogue to the patent's periodic re‑authentication limitation and would be the natural § 103 secondary reference on that feature.

  3. Prosecution history caveat: Because this patent's family was heavily litigated (Prism Technologies v. Research In Motion, D. Neb. 8:08‑cv‑00537 and numerous follow‑ons cited on the Google Patents record), the operative anticipation/obviousness positions were actually tested in the district court and IPR context, not just at examination. If you need the authoritative examiner‑cited set, it must be pulled from USPTO PatentCenter / the file wrapper (IFW) for US 10/230,638 and the printed PTO‑1449 on the face of US 7,290,288 — which I could not retrieve here.


4. Verification status / what I could not obtain

  • ✅ Confirmed: patent number, title, inventors, assignee, app. no., filing/priority/grant dates, pre‑grant publication number, the invention's stated claim scope, and the litigation record.
  • ⚠️ Not independently confirmed: the exact examiner‑signed "References Cited" list on the printed patent. The reference set presented here is derived from the pre‑grant publication's prior‑art record (Unified Patents) and bibliographic matches; some entries may be references cited by this patent (i.e., prior art the applicant/examiner overcame) versus references cited against it elsewhere (e.g., the Russian FIPS document listed US 7,290,288 B2 itself as prior art in a third‑party search report — a forward citation, not backward).
  • I did not guess at any patent number, date, or assignee; each is reproduced as returned by the sources. Where a field was not returned (e.g., some priority dates in the background group), it is left blank rather than estimated.

If you want the certain, primary‑source citation list, the next step is to open USPTO PatentCenter for application 10/230,638 and read the PTO‑1449 / "References Cited" block on the granted patent — I can then reconcile it entry‑by‑entry against the list above.

Generated 10/1/2026, 3:54:19 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll retrieve the prior-art references associated with this patent before analyzing obviousness.

Let me pull the actual cited prior-art list and the ITC invalidity contentions for this patent.

Let me identify the specific references RIM and Microsoft relied on, and the exam's cited art.

Obviousness Analysis — U.S. Patent No. 7,290,288 B2

35 U.S.C. § 103 (pre‑AIA), in view of the prior art of record


A. Scope, sources, and an explicit gap flag

Flag — contradiction/gap with the earlier section: the task instructs me to "use the results from the Prior Art section of this page." The full patent text supplied to me is truncated before the claims and before the front‑page "References Cited" block, so that section was not in my input. The only "prior art" content actually present in the supplied text is the Google Patents metadata line (Prior art keywords: server; client computer; computer device; access; resources; Prior art date: 1997‑06‑11). I therefore reconstructed the prior‑art record from live sources and say so explicitly below. This is a departure from the instruction, and I am marking it rather than papering over it.

Sources actually used for the prior art:

  1. The Ex Parte Reexamination Certificate US 7,290,288 C1 (Aug. 3, 2010) front page — the References Cited list as it stands in the reexamined patent — https://patentimages.storage.googleapis.com/a6/12/25/d5311fbe7546ff/US7290288.pdf
  2. Defendant Research in Motion, Ltd.'s Amended Invalidity Contentions (Sep. 18, 2009), chart index, and Second Amended Invalidity Contentions (Apr. 23, 2010) — reproduced in the '345/'469/'155 patent file wrappers: https://www.freepatentsonline.com/[8387155](/patent/8387155).html and https://patentimages.storage.googleapis.com/1d/0f/62/0311679e62d798/[US9369469](/patent/US9369469).pdf
  3. Microsoft Corporation's Preliminary Invalidity Contentions (Jul. 24, 2009).
  4. Request for Ex Parte Reexamination 90/010,948 (Apr. 8, 2010), 288 pp. + Exs. L–T.
  5. Claim construction orders in Prism Techs., LLC v. Adobe Sys., Inc., 8:10CV220 (D. Neb. Feb. 14, 2012) — supplying the constructions that verbatim govern any § 103 element mapping: http://g.casetext.com/case/prism-techs-llc-v-adobe-sys-3

Confidence labels used throughout: ★★★ = high confidence (reference identity and teaching verified or well‑established in the art); ★★ = moderate; ★ = low / not verifiable from retrievable material. I do not invent teachings for references I could not verify.


B. The § 103 framework actually applicable here

Under Graham v. John Deere Co., 383 U.S. 1 (1966), and KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007):

  1. Scope and content of the prior art — determined by the field of the inventor's endeavor and the problem to be solved (network authentication / access control). The references below are all in the same field of endeavor, and several are from the same problem space (web access management, enterprise SSO, password abuse).
  2. Differences between the prior art and the claims — mapped element‑by‑element below.
  3. Level of ordinary skill — see § E.
  4. Motivation to combine — the KSR rationales relied on: (a) combination of known elements each performing its known function yielding predictable results; (b) known technique ready for improvement; (c) market/design incentives; (d) interchangeable known elements; (e) "obvious to try" in a finite, identified solution space.

Critical threshold point — the effective filing date. The '288 application was filed Aug. 29, 2002, as a continuation‑in‑part of 08/872,710 (filed June 11, 1997, now US 6,516,416). The claims asserted by Prism — particularly claims 117–187, added by an amendment filed March 2, 2007 which substituted "access server"/"authentication server" vocabulary for "server computer"/"clearinghouse" (see the Adobe order) — are only entitled to June 11, 1997 if the 2002 CIP added no new matter with respect to those terms. That is exactly the issue RIM raised in its Motion for Summary Determination of Invalidity in ITC Inv. No. 337‑TA‑697 (Mar. 29, 2010), and that Prism defeated in reexamination 90/010,565.

This bifurcates the § 103 analysis:

Priority outcome Art available as § 102/§ 103 prior art
June 11, 1997 (as the examiner found in 90/010,565) Only art published or filed before 1997‑06‑11: Kerberos V5 (RFC 1510, 1993), OSF DCE (1991–93), Weiss '614 (1993), Krajewski '199 (1996), Handbook of Applied Cryptography (Oct. 1996), Barlow '961 (1993), Wang '844 (1995), existing SiteMinder product documentation predating 6/97, plus 1996‑filed U.S. applications later issuing as Akiyama '464 / Teper '665 under pre‑AIA § 102(e). Excluded: Ketcham '860 (2000), Tabuki '970 (1998) and '232 (1999), Grawrock '376 (2006), SAML 1.0 (2002), and — depending on its exact publication date — SET 1.0 (May 31, 1997).
Aug. 29, 2002 (if the CIP terms are new matter) The entire 1997–2002 corpus becomes available, including Ketcham, Tabuki, Akiyama, Teper, Grawrock, the Rainbow Sentinel SuperPro documentation, and SET 1.0.

The § 103 case is materially stronger on the 2002 date. On the 1997 date it must rest on Kerberos/DCE/SiteMinder/Krajewski/HAC. I flag this as the single most decision‑relevant variable in the analysis, and note the earlier section's uncertainty about 90/010,948 is unresolved — but the claim‑number uncertainty flagged earlier is now partly resolved: the ITC institution notice asserts claims 31–35, 38, 41, 51, 54, 56, 58, 59, 61, 87–92, 95, 98, 109–113, 115, 117, 119–126, 129–132, 143–145, 149, 150, 152–159, 164–167, 178–180, and 184–187 — establishing the patent has at least 187 claims, with 117–187 added in 2007.


C. The claim families being tested

Per the C1 certificate abstract (which mirrors the operative independent‑claim structure) and the D. Neb. constructions:

Family (A) — Authentication‑server claims (e.g., claim 1 / claims 117+):

  • (a1) storing at the authentication server (i) a digital identification associated with a client computer device and (ii) data associated with the protected computer resources;
  • (a2) authenticating, by the authentication server, the digital identification forwarded by at least one access server;
  • (a3) authorizing, by the authentication server, the client device to receive at least a portion of the requested resources based on the stored resource data;
  • (a4) permitting access, by the authentication server, upon successful authentication and successful authorization.

Family (B) — Hardware‑key / access‑key claims (e.g., claims 186, 187; and claim 87 which requires reading the digital identification from a hardware key): Family (A) plus an external hardware device or object from which a predetermined digital identification can be read, and (in dependent claims) session establishment, periodic re‑authentication, and transaction logging.

Governing constructions (Adobe, Feb. 14, 2012) — these control every mapping below:

  • "authentication server" = server software independent of the access server and capable of storing data and controlling access to protected computer resources of the access server
  • "access server" = server software that makes available information or other resources
  • "digital identification" = digital data whose value is known in advance or calculated at the moment
  • "hardware key"/"access key" = an external hardware device or external object from which the predetermined digital identification can be read
  • "[said/the] client computer device to forward" = choosing to require that the client computer device transmit certain information
  • "authorizing" = determining whether to grant access to
  • Preambles are limiting.

D. Prior art of record

D.1 References on the face of the reexamined patent (US 7,290,288 C1)

Ref. Identity Date Relevance to '288 Conf.
US 5,590,199 Krajewski, Jr. et al. (IBM) issued Dec. 31, 1996 Network authentication / trusted‑party credential handling; charted by RIM (127 pp.) ★★ (identity/date); ★ (precise teaching)
US 5,237,614 Weiss Aug. 17, 1993 Networked computer system access control; charted by RIM (46 pp.) ★★
US 5,204,961 Barlow Apr. 20, 1993 Distributed data processing / access control ★★
US 5,414,844 Wang May 9, 1995 Computer system resource access ★★
US 4,933,054 Chou et al. Jun. 5, 1990 Distributed authentication ★★★ (identity)
US 4,907,268 Bosen et al. Mar. 6, 1990 Cryptographic key/credential management ★★★ (identity)
US 4,916,738 / 4,864,494 / 4,885,789 / 4,691,355 / 4,694,492 Chandra; Kobus; Burger; Wirstrom (×2) 1987–1990 Foundational remote‑access / credential verification art ★★
US 5,784,464 Akiyama et al. issued July 21, 1998 RIM chart (65 pp.); pre‑AIA § 102(e) candidate if filed pre‑6/97 ★★
US 5,815,665 Teper et al. (V‑ONE‑lineage security‑server art) issued Sep. 29, 1998 Security server mediating client↔resource server over an untrusted network; RIM chart (54 pp.) ★★
US 5,841,970 / 5,987,232 Tabuki 1998 / 1999 Network access control; RIM charts (52 pp.) ★★
US 6,075,860 Ketcham issued June 13, 2000 RIM chart (74 pp.) — post‑1997 art ★★
US 7,117,376 B2 Grawrock (Intel) issued Oct. 3, 2006 Trusted Platform Module / platform trust — the FIG. 25 "secure CPU" embodiment; post‑1997 art ★★★
EP 94111581.8 EPO Feb. 1995 European counterpart art ★★
Non‑patent Andrews, Whit, "Content Sites Vexed By Password Abuse," Web Week, vol. 3, iss. 4, Feb. 17, 1997 Feb. 1997 The problem statement — shared/abused passwords on content sites. Directly supplies motivation. ★★★

D.2 Litigation‑charted references (RIM Amended / Second Amended Invalidity Contentions, 2009–2010)

Reference Type Relevance Conf.
Kerberos V5 (RFC 1510, Sept. 1993; MIT Athena) Standard Authentication Server + Ticket‑Granting Server independent of application/resource servers; KDC principal database; ticket/authenticator forwarding; authorization privileges ★★★
OSF DCE Security Service (DCE 1.0/1.1, 1991–93; Kerberos‑V5‑based KDC + Registry + Privilege Service + ACLs; DCE smart‑card login) Standard/product Registry stores identity; security server independent of resource servers; ACLs authorize; documented smart‑card login ★★★
Netegrity SiteMinder (1996–97 product) Product Centralized policy/authentication server independent of the web server; web agents forward identity; policy store holds resource data; cookie‑based sessions ★★★
DTN Cookie‑Authentication System Product Session/cookie authentication — maps to the "session ID in HTTP headers" and session‑renewal limitations ★★
Secure‑ftp / "Encrypted File Transfer System Without Key Management" Product Server‑mediated encrypted session establishment ★
Gifford Patent/paper Cryptographic‑envelope credential distribution ★
Handbook of Applied Cryptography (Menezes, van Oorschot, Vanstone, CRC Press, Oct. 1996) Treatise Password authentication, challenge‑response, one‑time passwords, certificates, Kerberos/Needham‑Schroeder — supplies § 103 motivation and the obviousness of credential variants ★★★
Rainbow Sentinel SuperPro Hardware dongle/product The hardware key — external device from which a predetermined digital ID is read ★★★
SET Secure Electronic Transaction Specification v1.0 (May 31, 1997) Standard Certificate hierarchy, cardholder/merchant authentication, signed digital IDs ★★
SAML v1.0 (2002) Standard Post‑dates 1997 priority; available only on a 2002 date ★★
"Study of an Authentication Protocol in a Distributed System Environment" Paper Distributed authentication protocol ★
Charts Akiyama, Yu, Tabuki, Teper, Grawrock, Crane, Murphy, He, Ketcham, Krajewski, DCE, SiteMinder mixed Chart index is verified; the underlying Yu / Crane / Murphy / He references I could not identify from retrievable sources ★ (for Yu/Crane/Murphy/He)

E. Level of ordinary skill in the art

No court construction of the POSITA for the '288 patent is retrievable. Based on the field and the Federal Circuit's treatment of the family, the defensible definition is: a bachelor's degree in computer science, computer engineering, or electrical engineering, or equivalent, plus 2–3 years' experience designing or administering networked authentication/access‑control systems (including directory services, KDC/SSO deployments, or web access‑management products), or equivalent practical experience. This is a moderate level of skill — not a visionary — which matters because KSR holds that the "obvious to try" standard is applied generously where the solution space is finite and the field is one of predictable engineering.


F. Element‑by‑element analysis of representative independent claims

F.1 Family (A) — authentication‑server claims (representative claim 1)

Claim element (construed) Kerberos V5 + SiteMinder/DCE Conf.
Storing a digital identification of a client device in a database associated with the authentication server Kerberos KDC principal database / DCE Registry store each principal's long‑term key and identity record; the KDC is the authentication server, independent of the file/print/application servers ★★★
Storing data associated with the protected computer resources SiteMinder policy store holds resource/URL policies; DCE ACL manager stores per‑object access‑control lists in the privilege service database ★★★
Authenticating, by the authentication server, the digital identification forwarded by at least one access server Kerberos: the client's authenticator + ticket is presented through and forwarded by the target *application/resource server (the "verifier") to validate against the KDC; the access server does not itself authenticate ★★★
Authorizing ... based on the stored data associated with the requested protected resources SiteMinder: policy server evaluates the requested resource against stored policy → grant/deny; DCE: privilege service issues PACs and evaluates the object's ACL ★★★
Permitting access upon successful authentication and authorization Both: access to the resource server is conditioned on the KDC/policy‑server response; the resource server enforces the decision ★★★

Result: every element of the Family (A) claims is disclosed, in a single reference (DCE) or in a two‑reference combination (Kerberos V5 + SiteMinder). The only genuine gap is the vocabulary, not the function — which is itself a point Prism's opponents made repeatedly (the 2007 amendment simply substituted "access server" for "server computer" and "authentication server" for "clearinghouse").

F.2 Family (B) — hardware‑key claims (representative claims 87, 186, 187)

Additional element Reference Conf.
External hardware device/object from which a predetermined digital ID can be read Rainbow Sentinel SuperPro hardware dongle (product); Ketcham '860 (charted hardware‑token authentication); DCE smart‑card login; ISO 7816 smart‑card art ★★★ (dongle); ★★ (Ketcham)
Something held + something known (two‑factor) Handbook of Applied Cryptography § 10 / § 12 (POS‑based and token‑augmented password authentication); DCE smart‑card login ★★★
Session establishment / session ID in headers SiteMinder cookies; DTN cookie‑authentication system; Kerberos TGT/session key lifetime ★★★
Periodic re‑authentication while the key remains attached NIST/DoD "trusted path" guidance; Microsoft smart‑card logon desktop policy; DCE login policy; Kerberos ticket re‑validation ★★
Transaction logging to a clearinghouse DCE audit service; Kerberos KDC audit logs; SiteMinder smaccess/audit log ★★
Secure CPU / TPM (FIG. 25) Grawrock '376 (Intel TPM: secure memory, cryptographic sign/verify, immutable key pair, platform integrity metrics) — but see date problem ★★★

G. The obviousness grounds

Ground 1 — Kerberos V5 (RFC 1510) in view of SiteMinder (D.1/D.2)

Covers Family (A) essentially in full; forms the base for Families (B) via Ground 2.

  • Disclosure: Kerberos discloses an authentication server logically and physically independent of the resource server — the Architectural Overview of RFC 1510 § 1 frames the KDC as exactly that. SiteMinder discloses the same architecture applied to HTTP/IP web resources, including the storage of resource policies at the central server.
  • KSR motivation: (i) same field, same problem — RFC 1510 and SiteMinder both solve "how do I challenge and prove identity before granting access to network‑reachable resources"; (ii) predictable results — combining a KDC with a web policy server is "a combination of familiar elements according to known methods [yielding] predictable results"; (iii) market force — the Feb. 1997 Web Week article (Andrews, on the face of the patent) documents the pressing commercial need to stop password abuse on content sites, which is the precise problem both references address; (iv) known technique ready for improvement — applying an enterprise SSO authentication server to Internet‑reachable servers was the recognized next step.
  • Anticipated rebuttal: Prism would argue Kerberos tickets are not "digital identification ... forwarded by an access server" under the court's construction. Weak — the ticket+authenticator is both "known in advance" (the ticket) and "calculated at the moment" (the authenticator timestamp/keyed hash), satisfying the disjunctive construction.

Ground 2 — Ground 1 (or DCE alone) in view of Rainbow Sentinel SuperPro and/or Ketcham '860

Adds the hardware‑key limitation of Family (B).

  • Disclosure: The Sentinel SuperPro is literally "an external hardware device from which a predetermined digital identification can be read." Ketcham '860 was charted (74 pp.) by RIM against the hardware‑key claims. DCE's documented smart‑card login embeds the token into the DCE registry/KDC authentication chain.
  • KSR motivation: (i) interchangeable, known elements — Handbook of Applied Cryptography treats password, token, and biometric factors as an enumerated, combinatorially interchangeable set; the '288 specification itself states the same ("Biometric identification can be also combined with smart cards or magnetic cards in the preferred embodiment"); (ii) known technique ready for improvement — hardening weak password authentication with a physical token was the standard remedial technique of the period and the explicit recommendation of the Web Week problem literature; (iii) finite solution space — magnetic stripe, smart card, USB token, biometric, TPM were the known options, making the combination "obvious to try."
  • Anticipated rebuttal: The Adobe court's summary judgment held that software CDs bearing a printed serial number are not hardware keys because the digital ID must be read from the external object. A dongle or smart card is read from, so this rebuttal does not defeat Ground 2.

Ground 3 — OSF DCE Security Service, alone or in view of Grawrock '376

The most likely single‑reference § 102/§ 103 challenge (RIM's 192‑page DCE chart is the largest in the production).

  • Disclosure: DCE supplies, in one system: an independent security server (Registry + KDC + Privilege Service), storage of both principal identity and resource ACLs, authentication of the client's credentials, and authorization via PACs/ACLs — the complete Family (A) architecture — plus documented smart‑card login for Family (B).
  • Motivation (if combined): DCE is the reference platform for enterprise distributed authentication; combining it with a hardware token is a natural extension the DCE documentation itself contemplates.

Ground 4 — Teper '665 in view of SiteMinder and a hardware token

Only viable on a 2002 effective date, or if the reference is verified to predate 1997‑06‑11 by more than its issue date suggests.

  • Disclosure: a security/authentication server architecturally distinct from the resource server, mediating client sessions over untrusted networks — the '288 patent's core inventive hook.
  • KSR motivation: same field, same problem; both references are directed to securing access to protected resources on a public network, and the combination yields no more than the expected sum of their parts.

Ground 5 — Krajewski '199 in view of Kerberos V5 + Ketcham '860 / Rainbow Sentinel SuperPro

The IBM trusted‑third‑party line of art, combined with the token art.

  • Motivation: Krajewski's assigned‑to‑IBM credential handling addresses the cryptographic problem; Kerberos supplies the architecture (independent authentication authority); the token supplies the second factor. Each does what it was known to do.

Ground 6 — Handbook of Applied Cryptography in view of Gifford and SET 1.0

Directed at the certificate / signed‑digital‑ID dependent claims.

  • Motivation: HAC (Oct. 1996) is the canonical teaching that authentication is achieved via challenge‑response and certified public keys; SET 1.0's certificate hierarchy is the concrete, standardized application of that teaching; combining a treatise with a standard in the same field is the paradigm KSR combination.

Ground 7 — Weiss '614 in view of Grawrock '376 (TPM)

Directed at the FIG. 25 secure‑CPU embodiment.

  • Motivation: Weiss discloses networked access control via a host‑resident trusted component; Grawrock '376 (Intel TPM) supplies the measured‑boot digest and immutable key pair the specification itself describes. The inventors incorporated the TPM concept into the patent, which is powerful evidence that it was known art, not an invention. Date caveat: Grawrock issued 2006 and is presumptively post‑1997.

Grounds I could not fully reconstruct

RIM's chart index names Yu (72 pp.), Crane (37 pp.), Murphy (38 pp.), and He (45 pp.), and the second amended contentions add Secure‑ftp, Gifford, a "Study of an Authentication Protocol in a Distributed System Environment," and SAML v1.0. I could not identify the specific underlying documents for Yu, Crane, Murphy, or He from retrievable sources, and I therefore do not assert what they teach. They should be verified against the actual contention exhibits before being relied on.


H. What Prism would argue in rebuttal (and how it fares)

  1. Teaching away. Prism argued that the pre‑1997 art was committed to weak password protection and that the industry believed secure access required private networks (see Prism's "Background of the Patented Technology" as quoted in Prism Techs. v. AT&T Mobility). Under KSR, however, evidence that the art simply did not yet apply known SSO architecture to the public Internet is not "teaching away" — it is a gap in implementation, and the Web Week article (on the face of the patent) shows the art was actively addressing that exact gap in February 1997, four months before the priority date.
  2. Hindsight / unexpected results. No unexpected‑results evidence is in the record I could retrieve. The system-level benefits (single sign‑on, transaction tracking, geographic distribution) are the expected consequences of centralizing authentication, not an unpredictable result.
  3. Long‑felt need. Available as an argument, but undercuts Prism: the need was felt and documented in the Web Week piece of Feb. 17, 1997, and addressed by DCE/Kerberos/SiteMinder before the priority date.
  4. § 101 overlay. Note that the Federal Circuit in Prism Techs. LLC v. T‑Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. 2017) held the closely related continuation claims (the '345 patent, the direct continuation of the '288 application) ineligible under § 101 as directed to the abstract idea of "providing restricted access to resources" implemented with generic computer components. That reasoning is not § 103, but it is mutually reinforcing: it means the claims add nothing over the generic combination of known computing elements that Grounds 1–3 supply.

I. Bottom line

Most probable outcome on the merits: the Family (A) "authentication server / access server" claims would be rendered obvious by Kerberos V5 in view of Netegrity SiteMinder (Ground 1), and even more cleanly by OSF DCE Security Service alone or in view of Kerberos V5 (Ground 3), because each reference element performs precisely the function the claim assigns to it and the field was one of predictable engineering. The Family (B) hardware‑key claims would be rendered obvious by the addition of Rainbow Sentinel SuperPro and/or Ketcham '860 (Ground 2), with the motivation supplied by Handbook of Applied Cryptography, the DCE smart‑card login feature, and the documented password‑abuse problem.

The decisive caveat is temporal, not technical. If the operative claims receive the June 11, 1997 priority date that the examiner confirmed in reexamination 90/010,565, then Ketcham '860, Tabuki '970/'232, Grawrock '376, SAML 1.0, and possibly SET 1.0 drop out, and the case must be carried by Kerberos V5, DCE, SiteMinder, Krajewski '199, Weiss '614, and HAC — all of which predate the priority date. If the "access server / authentication server" vocabulary added in the 2002 CIP and the 2007 amendment is instead held to be new matter, the full 1997–2002 corpus is available and the § 103 case becomes substantially stronger. RIM staked its ITC invalidity motion on the new‑matter theory; that motion was never adjudicated (Inv. No. 337‑TA‑697 terminated on settlement, June 21, 2010), so it remains an open question rather than a decided one.

Practical significance: the '288 patent expired on 2022‑10‑12 (Google Patents adjusted‑expiration field, expressly an assumption) and the family was judicially invalidated under § 101 through the 2017 Federal Circuit decision. A § 103 analysis today is therefore of historical, defensive, or portfolio‑due‑diligence value only.


J. Confidence flags and unresolved items

  1. The "Prior Art section of this page" was not in my input. The prior art above was reconstructed from the C1 reexamination certificate and the RIM/Microsoft contention indices. Contradiction with the task instruction — flagged, not resolved.
  2. Exact claim text of the operative independent claims is not verified. My element mapping uses the C1 certificate abstract plus the court constructions. Claim numbers for "claim 1" in the post‑2007 claim set are not verified.
  3. Effective filing date is the controlling variable and is contested. Verify whether reexam 90/010,948 (filed Apr. 8, 2010) reached a final determination, and whether any claims were cancelled or further amended. The earlier section flagged this as unresolved; it remains unresolved here.
  4. Krajewski '199, Ketcham '860, Tabuki '970/'232, Akiyama '464, Teper '665, Weiss '614, Gifford, and the Yu/Crane/Murphy/He charts: I could not verify the precise title, assignee, filing date, or teaching of each from retrievable sources. The analysis treats them generically by their date and by the RIM chart titles. Do not rely on any specific teaching I attributed to them without checking the primary documents.
  5. "Brown Hill" on the C1 front page is apparently a garbled OCR rendering (US 5,740,361 A, Apr. 1998, "Brown") and I have not treated it as a distinct reference.
  6. No 2026 CAFC activity involving US 7,290,288 was found. Absence of a search hit is not proof of absence.

Generated 10/1/2026, 3:55:10 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Prism Technologies LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (8)

8 tracked lawsuits name US 7290288.