Invalidity dossier

US 7818794

Data traffic filtering indicator

Current assignee: InterDigital CE Patent Holdings SAS

Added 9/26/2026, 4:18:28 PM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US 7,818,794 B2 — "Data traffic filtering indicator"

Sources consulted: Google Patents full text (https://patents.google.com/patent/US7818794/en), Justia/companyprofiles claim text, FreePatentsOnline family listing, USPTO PTAB exhibit file histories, CourtListener/IPWatchdog 2026 litigation reporting.


1. Bibliographic data (authoritative, from the patent text)

Field Value
Patent number US 7,818,794 B2
Title Data traffic filtering indicator
Inventor Brian Albert Wittman (sole inventor)
Original assignee Thomson Licensing S.A. / Thomson Licensing SAS
Current assignee (per Google Patents) InterDigital CE Patent Holdings SAS (reassignment recorded 2019‑12‑16; earlier change‑of‑name Thomson Licensing S.A. → Thomson Licensing)
Application no. US 10/517,574 (national stage of PCT/US03/18191)
Priority date 2002‑06‑12 (US provisional 60/388,082)
Filing date 2003‑06‑09 (PCT filed same day)
Pre‑grant publication US 2005/0169282 A1, 2005‑08‑04
Issue date 2010‑10‑19
Claims 18 total; independent claims 1 (apparatus), 7 (method), 13 (cable modem)
Legal status Expired – Fee Related; adjusted expiration listed as 2026‑04‑02
Key CPC classes H04L63/0227 (filtering policies), H04L63/1416 (attack signature detection), G06F21/554 (intrusion counter‑measures), H04L12/22, H04L67/75
Family EP1550259B1, WO2003107590A1, JP2005530398A, KR100986967B1, CN1659822B, AU2003248653A1, BR0305037A, MXPA04012519A, MY143801A, TWI244297B

2. Abstract (as issued)

"Disclosed are a method and bi-directional communication device, such as a cable modem, router, bridge, or other communication device adapted to communicate via a network and having a firewall, for identifying those packets associated with inappropriate activity. The communication device includes at least one user discernable indicator associated with the firewall. The at least one user discernable indicator contemporaneously indicates that a number of packets associated with the inappropriate activity has exceeded a threshold level."

3. What the patent covers (plain language)

The disclosure addresses the problem that conventional software firewalls only log filtered events to a log file, or pop up dialog windows that annoy users until they are disabled (Background, citing the log‑file/dialog‑box practice). The invention places a human‑perceptible indicator — visually/an audibly discernable — on or near the network device itself (e.g., an LED on the outer cover of a cable modem, or a highlighted/red icon in a Windows system‑tray) so an administrator or end user is notified contemporaneously, in real time, that traffic is being filtered. Rules are ranked into classes/priority levels; higher‑class (e.g., hacker/infiltration) violations can trigger immediately on a single packet, while lower‑class violations (e.g., blocked web domains, "Code‑Red" ARP noise) require a threshold count before an indicator fires. Multiple indicators can be used, e.g., a yellow LED for general filtering and a red LED for malevolent/high‑ranked violations. The specification works the concept through both a generic multi‑mode bi‑directional communications device (FIG. 1) and a DOCSIS cable modem with downstream/upstream processing circuitry and internal TCP/IP stack routing (FIG. 2), with the method flow in FIG. 3.

4. Independent claims — plain language

Claim 1 (apparatus). An apparatus that communicates over a network, with:

  • a firewall whose set of rules is divided into multiple classes, where the rules are prioritized so each class is a different priority level; and
  • an indicator device that provides several user‑discernable, visually discernable indicators, each tied to a different rule class, where the matching indicator fires when a rule in its class is violated.
  • Crucially, all but one of the indicators map to a class; the remaining "particular" indicator is a general status light meaning "filtering is being performed right now."
  • The general status indicator and the class‑specific indicator are triggered concurrently, and only when the number of violating packets exceeds a pre‑specified threshold (i.e., the "we are actively filtering" signal is gated on the threshold, together with the class indicator).

Claim 7 (method). Define a rule set to detect inappropriate communication activity; separate the rules into classes; associate each class with a different visually discernable indicator; examine data traffic for rule violations; and when a rule in a first class is violated, filter that traffic and notify the user by triggering the class's indicator. Rules are prioritized into levels; a particular indicator is dedicated to the affirmative status "filtering is being contemporaneously performed"; and when a rule of at least a first class is violated and the violating‑packet count exceeds a pre‑specified threshold, the system triggers the class indicator and the general "filtering in progress" indicator concurrently.

Claim 13 (cable modem). A cable modem with downstream processing circuitry, upstream processing circuitry, and a controller coupled to those circuits and to memory; a firewall program with class‑separated, prioritized rules resident in memory and executable by the controller to examine packets from the downstream and upstream circuitry and to filter violators; and multiple visually discernable user indicators, each mapped to a different rule class, plus the particular general‑status indicator that filtering is happening now, which is triggered concurrently with the class indicator only if a rule is violated, filtering is actually performed, and the violating‑packet count exceeds a pre‑specified threshold.

Dependent claims in brief: highlighted icon on a computing device (2, 15); filter violators regardless of count but trigger an indicator only above threshold (3, 10, 16); when the threshold is not exceeded, only the general "filtering" indicator fires and not the violation indicator (4, 11, 17); which indicator fires depends on the priority level involved (5, 12, 18); different, end‑user‑settable thresholds per class governing when filtering begins (6); threshold determination before filtering (8) and before triggering (9); and a two‑LED embodiment — one LED for a general filtering event, a second LED for packets deemed pernicious in the rule set (14).

5. Prior art and prosecution context (from the patent record)

  • References of record include US 6,052,788 (Network Engineering Software), US 6,119,236 (Shipley), US 6,327,338 and US 6,282,546 (intrusion detection), WO 99/59071 (Motorola, packet overload), WO 00/54458 (Psionic, IDS), US 6,219,786 (Surfcontrol), and non‑patent literature on ZoneAlarm Pro 3.0 (Nallawalla, May 2002; Grevstad; Geroski, May 23, 2002), plus Kondo, "A Study on Internal Security Management of Network" (IEICE Technical Report, Sept. 1995). The pending‑claims version of the patent was granted only after these were considered.
  • The patent is cited as prior art in later filings, e.g., it appears in the prosecution file history of Centripetal Networks' US 9,565,213 (PTAB IPR2018‑01512, Ex. 1002) and in a later Centripetal patent's citation list.

6. Litigation / CAFC 2026 check — and an important caveat

  • I found no CAFC 2026 docket, PTAB proceeding, or district‑court complaint naming US 7,818,794. Searches of the Federal Circuit 2026 opinion summaries and 2026 patent‑litigation reporting returned nothing for this number.
  • **Do not confuse this patent with the "'879 Patent" in Neonode Smartphone LLC v. Apple Inc., No. 3:21‑cv‑08872‑EMC (N.D. Cal.)**, which produced 2026 filings on written description for a negative limitation about "gliding" a representation on a touch screen (see the March 16, 2026 order and the joint letter at CourtListener). That is a different patent owned by Neonode — not US 7,818,794. I am flagging this because a bare "'879" search pulls up that case first.
  • The current assignee, InterDigital CE Patent Holdings SAS, is active in 2026 litigation — e.g., the UPC Düsseldorf decision in InterDigital CE Patent Holdings, SAS v. The Walt Disney Company (UPC_CFI_297/2025, Sept. 2, 2026) and InterDigital, Inc. v. The Walt Disney Company, No. 2:25‑cv‑00895‑WLH‑BFM (C.D. Cal.) — but the patents asserted there (e.g., US 8,085,297 and video‑coding patents) are not US 7,818,794, and the '794 patent is expired for fee reasons with a listed adjusted expiration of 2026‑04‑02, making fresh assertion unlikely.

Uncertainty statement: The bibliographic, claim, and abstract data above come from the authoritative full patent text and are high confidence. The negative litigation finding is based only on public/web searches I was able to run; it is not an exhaustive USPTO PatentCenter, PACER, or Federal Circuit docket query, so I cannot rule out an unindexed or very recent filing. If you need a certified docket‑level confirmation, that requires a direct PACER/PatentCenter/PTAB (PTActs) check.

Generated 9/27/2026, 7:34:27 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 7818794. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search the litigation databases for US 7,818,794.

The initial searches returned hits for unrelated patents with similar numbers. Let me narrow to the exact patent and check specific litigation databases.

Let me check a few more targeted sources.

Litigation search — US 7,818,794 ("Data traffic filtering indicator")

Bottom line: I found no litigation — no district court action, no ITC § 337 investigation, no PTAB proceeding, and no Federal Circuit appeal — in which US 7,818,794 is the asserted or challenged patent. Every apparent "794" hit that surfaced was a different patent with a similar number. I could not identify a single plaintiff, defendant, jurisdiction, or case number for this patent.


1. What I searched and what came back

Query type Result
"7818794" patent litigation No case. Only hits were unrelated patents and a Brazilian state registry list (JUCIS-RS) where "7818794" is a company registration number, not a patent — that is a pure numeric false positive.
"7,818,794" patent case / CourtListener No case.
"Data traffic filtering indicator" + Thomson/InterDigital + lawsuit No case. Only the Google Patents page and unrelated Centripetal/IPR material.
"7818794" in PTAB/IPR document text Appears only as a citation or a search-string entry, never as a challenged patent (see §3).
PTAB US 7,818,794 IPR petition No petition found.

2. False positives you should NOT attribute to this patent

To keep the record clean, the following surfaced under "'794" and are not US 7,818,794:

  • US 7,955,794 (Illumina) — the "794 patent" in Verinata Health, Inc. v. Ariosa Diagnostics, Inc., Fed. Cir. Nos. 2018‑2198 et al. (decided Apr. 24, 2020), on appeal from N.D. Cal. Nos. 3:12‑cv‑05501‑SI, 3:14‑cv‑01921‑SI, 3:15‑cv‑02216‑SI. DNA assay optimization, not firewalls.
  • Ivera Medical Corp. v. Hospira, Inc., 801 F.3d 1336 (Fed. Cir. 2015) — also refers to an unrelated "794 patent" (medical cleaning device).
  • Cellspin Soft, Inc. v. Fitbit LLC, N.D. Cal. 4:17‑cv‑05928 — Dkt. 39 Att. 3 is an exhibit of Cellspin's own "'794 patent," a different document.
  • Neonode Smartphone LLC v. Apple Inc., No. 3:21‑cv‑08872‑EMC (N.D. Cal.) and Neonode Smartphone LLC v. Samsung, W.D. Tex. 6:20‑cv‑00507‑ADA / 6:23‑cv‑00204 — these concern Neonode's '879 patent (glide/swipe UI), not '794. As flagged in the earlier section of this analysis, a bare "'879" search pulls these up first; a search for "794" pulls up a parallel set of equally irrelevant hits.
  • US 8,794,516 (Smartflash, CBM2015‑00121), US 8,776,794 and US 9,279,794 (Mallinckrodt nitric-oxide jury verdict), US 10,212,417 / Realtime Data line of cases — all unrelated.

3. Where US 7,818,794 actually appears in the public record

The only appearances of the literal string 7818794 I could retrieve were inside other parties' patent prosecution file histories submitted as IPR exhibits, where it functions as a cited prior-art reference or an examiner search-log entry, not as an asserted patent:

  • Centripetal Networks IPR2018‑01512 (Petitioner's Ex. 1002, file history of US 9,565,213) — "7818794" appears in a cited-references table.
  • Centripetal IPR2021‑01520 and IPR2021‑01521 (Petitioner Ex. 1002 file histories of US 6,686,193 / related) — "7818794" appears in examiner search strings (e.g., ("7478429" "7818794" "8935785").PN.).
  • A 2020 USPTO search-query exhibit (S702) lists "7814158" | "7814546" | "7818794".

This is consistent with the earlier finding in this analysis that '794 is cited as prior art in later Centripetal-related filings. Being cited as art is not litigation involving the patent.

4. Why the absence is credible here (contextual cross-check)

  • The patent is recorded on Google Patents as Expired – Fee Related, with an adjusted expiration of 2026‑04‑02. By the current date (April 26, 2026) the statutory term has run, which removes any practical incentive to file fresh infringement suits.
  • The only recorded assertion activity for the Thomson/Digital-video patent family (now InterDigital CE Patent Holdings SAS) in the 2026 period involves other patents — e.g., the UPC Düsseldorf matter InterDigital CE Patent Holdings, SAS v. The Walt Disney Company, UPC_CFI_297/2025, and InterDigital, Inc. v. The Walt Disney Company, No. 2:25‑cv‑00895‑WLH‑BFM (C.D. Cal.) — none of which names '794.

5. Caveats — please read before relying on this

  1. The instruction said "search sites that cover patent litigation, like portal.unifiedpatents.com/litigation/caselist." I was not able to complete a direct query of the Unified Patents litigation caselist or a PACER docket query — my tool calls were exhausted before those targeted lookups returned. My conclusion rests on general web searches and on indexed IPR/CourtListener/PTActs material.
  2. A negative finding from web search is not an exhaustive docket check. Patent suits that were filed, settled, or voluntarily dismissed pre‑2010 (before broad RECAP coverage), or that are sealed, may not be indexed. The 2003–2010 window is exactly when an assertion of this patent would have been most likely.
  3. No PTAB proceeding, and no Federal Circuit appeal, is a high-confidence negative for the AIA era (post‑Sept. 16, 2012), because those are comprehensively indexed in PTActs and the Fed. Cir. dockets.
  4. Note also a date inconsistency to be aware of: this task states the current date is April 26, 2026, while the operating header on this analysis states 2026‑09‑27. I have resolved searches as of the task date and flagged that a post‑April 2026 filing would not have been captured.

Recommended next step if you need a certified answer: run the exact patent number through (a) USPTO PatentCenter → "Patent Litigation" / assignment and ex parte reexam tabs, (b) PACER Case Locator (all district courts, plus the Federal Circuit), (c) PTAB PTActs for IPR/PGR/CBM/DER, and (d) Unified Patents' portal directly. I can draft the specific query strings for those four systems if you want them.


Status of this section: The earlier-generated litigation section of this analysis reached the same conclusion (no CAFC 2026 docket, PTAB proceeding, or district-court complaint naming US 7,818,794). Nothing in this new search contradicts it, and this pass adds the specific clarification that the recurring "7818794" hits in the Centripetal IPR exhibits are prior-art citations and examiner search strings, not evidence of litigation over the patent.

Generated 9/27/2026, 7:41:02 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

Total AIA trial proceedings on US 7,818,794: zero. The structured USPTO Open Data Portal block supplied for this patent returns no AIA trial proceedings (no IPR, no PGR, no CBM), and my independent web searches surfaced no PTAB proceeding in which US 7,818,794 is the subject patent as of 2026-09-27. The breakdown by status is therefore: active 0 / claims invalidated 0 / claims sustained 0 / settled 0 / institution denied 0.

Bottom-line defensive posture: the patent has never been tested at the PTAB — it is neither "hardened" by a survivor's record nor "gutted" by a cancellation. But that absence of PTAB activity is not because it is a battle-hardened, Teflon patent. It is because no one ever asserted it. The more consequential fact for a defendant today is on the bibliographic face of the patent: it is "Expired – Fee Related," adjusted expiration 2026-04-02 (per the Google Patents record in the prior sections). An expired patent cannot be infringed prospectively, and damages can reach back only six years under 35 U.S.C. § 286 — so the practical question is whether a fee-lapsed patent is even worth defending against at the PTAB. It generally is not.


Proceedings

None found. There is no proceeding to report. Rather than invent a proceeding number (which I am expressly instructed not to do), here is the negative evidence base:

Check run Result
Canonical PTAB proceeding list (USPTO ODP, per prompt) No AIA trials on US 7,818,794
Web search: "7,818,794" IPR PTAB Only other '794-numbered patents (e.g., US 8,605,794 in IPR2022-01086, US 8,605,794 in IPR2022-01086/Unified Patents; US 8,605,794 in the Cellspin v. Fitbit order) — none is US 7,818,794
Web search: ptacts.uspto.gov "7818794" No PTAB petition, institution decision, FWD, or appeal paper for this patent
Web search: "7818794" reexamination OR reissue No ex parte reexam or reissue certificate for this patent surfaced
Web search: patent title + "challenged / IPR / CBM / asserted" No results tying this patent to any validity challenge

Where the literal string "7818794" did appear — all false positives, all citations, not proceedings:

  • Exhibit 1002 (file history of US 9,565,213), IPR2018-01512 — the number appears inside a patentability search string in a third party's file history (Docket Alarm PDF). The subject patent there is Centripetal's US 9,565,213, owned by Centripetal Networks, not the '794 patent. (Docket Alarm, IPR2018-01512, Ex. 1002)
  • Exhibit 1002 in Palo Alto Networks v. Centripetal Networks, IPR2021-01520 / IPR2021-01521 — same phenomenon: ("7478429" "7818794" "8935785").PN. is a Westlaw/PatBase search string. Not an asserted patent.
  • File histories of US 9,917,856 (IPR2022-01151, Cisco; IPR2022-01199, Keysight) and US 8,205,205 (IPR2018-01444, Cisco) — US 7,818,794 appears on a PTO-1449 / IDS listing of "U.S. PATENTS" cited (Wittman, issued 2010-10-19), i.e., it was cited against or next to other inventors' applications. Being cited as art is the opposite of being a petitioner's target. (PTAB data, IPR2018-01444, Cisco Ex. 1002)

None of the above is a lawsuit, an AIA trial, or a validity challenge to US 7,818,794.


Strategic summary

Claim status: all 18 claims UNTESTED at the PTAB. There are no canceled claims, no claims sustained in a Final Written Decision, and no certificate of cancellation. Claims 1 (apparatus), 7 (method), and 13 (cable modem) stand exactly as issued on 2010-10-19, unamended and unchallenged. Do not let anyone tell you the '794 patent "survived IPRs" — it never faced one. Equally, do not assume the absence of IPRs implies non-obviousness; a defensive aggregator (Unified Patents) has challenged roughly a thousand patents, and the fact that it never touched this one most likely reflects that no operating company was ever sued on it.

Estoppel landscape: there is none to work with, and none to worry about. Section 315(e)(2) estoppel attaches only to a petitioner that reaches a final written decision; with zero proceedings there is no estopped party, no IPR-derived prior-art record, and no institution decision to cite. That means a defendant today faces no procedural bar to filing an IPR — no § 315(b) one-year service clock running (because there is no service), no General Plastic multiplicity problem, no Fintiv/discretionary-denial risk from parallel litigation. It also means a defendant has no free win — nothing is pre-canceled.

Pattern signals: none. No repeat petitioner; no patent-owner appeal activity (nothing to appeal); no defensive-aggregator chain. Ownership tells its own story: originally Thomson Licensing S.A., reassigned to InterDigital CE Patent Holdings on 2019-12-16 — and it lapsed for failure to pay maintenance fees with an adjusted expiration of 2026-04-02. Both Thomson and InterDigital are active enforcers overall, but this particular patent was allowed to die on the vine, which is inconsistent with it ever having been a revenue-bearing assertion asset.

Caveat consistent with the earlier sections: this negative finding rests on the ODP canonical list plus the web searches I was able to complete. It is not a certified PTAB E2E/PTActs docket query, and the last planned targeted query was cut off. A definitive negative requires running the literal string 7818794 in (1) PTAB E2E / PTActs, (2) USPTO Patent Center's "Patent Trial" tab, and (3) the Federal Circuit docket for any appeal from a decision that a document search might have missed.

Recommended next steps

  • If you are a defendant facing a demand letter citing US 7,818,794: the more powerful argument is not an IPR — it is that the patent expired 2026-04-02 for failure to pay maintenance fees. Check the USPTO maintenance-fee record directly to confirm the "Expired – Fee Related" status and identify the last-paid window; that caps any § 286 six-year lookback and, for post-expiration conduct, eliminates infringement entirely. An IPR would be slow, expensive, and would create the estoppel record you currently lack.
  • If you nonetheless want a PTAB record (e.g., to defeat a pre-expiration damages theory longer than the lookback): you have a clean runway — no § 315(b) bar, no § 325(d) same-art overlap concern from this patent's own prosecution beyond the references of record already listed, and no discretionary-denial anchor from a parallel case. Note the Magnolia Medical v. Kurin, IPR2026-00097 (PTAB 2026-05-14) (precedential) posture, however: the Director is denying institution where the challenge looks like a repeat or litigation-substitute rather than a genuine alternative — so a thin, timing-driven petition is a bad bet.
  • If you are looking for an invalidity theory rather than an IPR: the '794 patent issued 2010 on a 2003 PCT filing, and its own IDS cites the ZoneAlarm Pro 3.0 reviews (Nallawalla, May 2002; Geroski, May 23, 2002) plus US 6,052,788 and US 6,119,236. Those are the same references the examiner already considered, so a § 102/§ 103 attack would need materially new art — and it would have to be a patent or printed publication, since IPR excludes system art.
  • If no PTAB activity exists — say so plainly, as I have here. The absence is itself the signal: a fifteen-plus-year-old networking patent that was never asserted never attracted an IPR, and it has now lapsed for non-payment.

Generated 9/27/2026, 7:41:03 PM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2004-12-09 · Assignment

    Wittman, Brian AlbertTHOMSON LICENSING

  2. ? · recorded 2019-12-16 · Change of Name

    THOMSON LICENSINGTHOMSON LICENSING

    change of name only

  3. ? · recorded 2019-12-16 · Assignment

    THOMSON LICENSINGInterDigital CE Patent Holdings

    acquisition

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment chain for US 7,818,794, starting with ownership-relevant searches.

Let me try to pin down the specific reel/frame records and the parties involved.

Let me search for the specific assignment record pages and the recording correspondent.

Ownership & Assignment Reconstruction — US 7,818,794 B2 ("Data traffic filtering indicator")

Critical data limitation up front. I was not able to retrieve the reel/frame numbers, execution dates, or correspondents of record for this patent's assignments in this session. The USPTO Assignment Center / assignment.uspto.gov record pages did not surface in my searches (both the legacy assignment.uspto.gov interface and the newer assignmentcenter.uspto.gov are JS-driven and largely opaque to web indexing). What follows is built from the Google Patents legal-events table, which mirrors the Assignment Center's conveyance list (type + assignor + assignee + recording date) but does not expose reel/frame or correspondent. I have therefore left those fields explicitly unfilled rather than guess. Verify at: https://assignmentcenter.uspto.gov/ (search: Patent Number 7818794, or Application 10517574).


Inventors

Inventor Employer at filing (determinable) Notes
Brian Albert Wittman (sole inventor) Thomson Licensing S.A. — the PCT application PCT/US03/18191 was filed by the Thomson entity, and Wittman executed an assignment of his inventor rights to Thomson Licensing S.A. (recorded 2004‑12‑09 per Google Patents legal events). No co‑inventors.

Pattern flags on inventorship:

  • No mass-departure pattern detectable. With a single inventor and no co-inventor data, the "all inventors left the assignee within 12 months" tell is not applicable. There is nothing in the record suggesting the inventor departed or re-filed elsewhere.
  • Caution — a conflicting third-party attribution exists. A patent-analytics aggregator (patentleaderboard.com) lists "Brian Albert Wittman — 24 Patents at AT&T" and includes US 7,818,794 in that list. This conflicts with the authoritative patent front matter, which names Thomson Licensing S.A./SAS. Treat the AT&T attribution as an aggregator artifact (likely name disambiguation or a portfolio-mapping error) unless separately confirmed. Do not rely on it.

Original assignee

Thomson Licensing S.A. / Thomson Licensing SAS — the French intellectual-property holding and licensing arm of the Thomson (later Technicolor) group. (Note the literal discrepancy in the records: Google Patents lists the Original Assignee as "Thomson Licensing SAS" while the 2004 assignment event names "THOMSON LICENSING S.A." The two corporate forms are not auto-corrected here; a single French entity registration is the likely explanation, but the record as written is inconsistent and worth a corporate-registry check.)

  • Primary line of business: consumer electronics and, at group level, set-top boxes, cable/DSL modems, and consumer video hardware, plus outbound patent licensing. Thomson was a DOCSIS cable-modem and set-top-box vendor in the 2002–2010 era — the exact product category the patent's FIG. 2 cable modem embodiment targets.
  • Product embodying the claims: the specification's cable-modem embodiment (FIG. 2, downstream/upstream processing circuitry + firewall) fits Thomson's product line, but I could not verify a specific shipping Thomson/RCA cable modem that practiced the multi-class-indicator limitations of claim 1. Treat "shipped an embodying product" as plausible but unconfirmed.
  • Current status of the assignee: Thomson Licensing was renamed (change of name recorded 2019‑12‑16) and the former Thomson/Technicolor patent estate has since been consolidated into InterDigital holding entities. The Technicolor parent subsequently underwent material corporate restructuring (including divestitures and a later rebranding of residual businesses); I could not verify a specific Chapter 7/11 or French insolvency filing in this session, so I make no bankruptcy finding.

Assignment timeline

Recorded conveyances per the Google Patents legal-events table (which mirrors the Assignment Center conveyance list). Reel/frame and correspondent are NOT captured — I will not fabricate them.

  • 2003‑06‑09 (filing) / — — Reel not captured

    • Conveyance: Application filed (not an assignment; baseline event)
    • Assignor: n/a
    • Assignee: Thomson Licensing SAS
    • Correspondent: not captured
    • Context: PCT national-stage filing by the Thomson IP-holding entity.
  • 2004‑12‑09 — Reel not captured

    • Conveyance: Assignment of assignors interest (inventor → company)
    • Assignor: Wittman, Brian Albert
    • Assignee: Thomson Licensing S.A.
    • Correspondent: not captured
    • Context: Routine inventor-to-employer assignment perfecting title; recorded ~18 months after the 2003‑06‑09 PCT filing, consistent with national-stage housekeeping rather than any distress event.
  • 2010‑10‑19 — Reel n/a

    • Conveyance: Issue (not an assignment)
    • Assignee (patentee of record): Thomson Licensing
    • Context: Grant of the patent.
  • 2019‑12‑16 — Reel not captured

    • Conveyance: Change of Name
    • Assignor: Thomson Licensing S.A.
    • Assignee: Thomson Licensing
    • Correspondent: not captured
    • Context: Pure corporate rename — no change in beneficial ownership.
  • 2019‑12‑16 — Reel not captured

    • Conveyance: Assignment
    • Assignor: Thomson Licensing
    • Assignee: InterDigital CE Patent Holdings (current assignee, per Google Patents; the EPO/INPI registers render the name as InterDigital CE Patent Holdings, SAS, 3 rue du Colonel Moll, 75017 Paris, and InterDigital CE Patent Holdings, 4 Research Way, Princeton NJ for US correspondence)
    • Correspondent: not captured — candidate to verify: Patricia A. Verlangieri, InterDigital CE Patent Holdings, 4 Research Way, 3rd Floor, Princeton, NJ 08540. She appears as correspondent on a related Thomson→InterDigital CE recording (USPTO Assignment 49605/898, recorded 2019‑06‑27, covering US 7,199,396). This is a corroborating data point, not a confirmed correspondent for the '794 recording. If she (or the same Princeton/InterDigital correspondence address) also appears on the '794 reel, that is a repeat-correspondent finding; if the recording was handled by a different outside firm, it is not.
    • Context: Portfolio-level corporate transfer of the former Thomson/Technicolor patent estate into an InterDigital holding entity. The European parallel register records in the same estate show deeds of assignment dated 2018‑07‑23 (to InterDigital Madison Patent Holdings) and 2019‑07‑30 (to InterDigital CE Patent Holdings) — a strong indication the US execution date is in the same July‑2019 window, with the US recordation following on 2019‑12‑16. Flag: I could not retrieve the US execution date or the SEC 8-K / deal document, so the exact execution date is unconfirmed.
  • 2026‑04‑02 — Reel n/a

    • Conveyance: Lapse / fee-related expiration (per Google Patents "Adjusted expiration" and status "Expired – Fee Related")
    • Context: No maintenance-fee payment by the current assignee; the asset was permitted to lapse rather than be asserted or sold on.

Timeline diagram

timeline
    title Ownership of US 7818794
    2002 : Provisional application filed
    2003 : PCT application filed by Thomson
    2004 : Inventor assigns to Thomson Licensing SA
    2010 : Patent issued to Thomson Licensing
    2019 : Thomson change of name recorded
         : Assigned to InterDigital CE Patent Holdings
    2026 : Expired for failure to pay fees

NPE / troll-pattern signals

# Signal Call Basis
1 Shell-entity transfer Not present (in classic form) The patent does move from an operating parent to a "Holdings" licensing entity (InterDigital CE Patent Holdings, recorded 2019‑12‑16) — the "Holdings" suffix tell is literally present. But the other tells are absent: the transferee is a transparent subsidiary of a publicly traded company (InterDigital, Inc., NASDAQ: IDCC), with disclosed corporate addresses (3 rue du Colonel Moll, Paris; Wilmington DE; Princeton NJ), not a registered-agent service, not an anonymous single-member Delaware/Texas LLC. This is a group IP-holding consolidation, not an anonymous shell.
2 Known asserter in the chain Not present Neither the original assignee (Thomson Licensing) nor the current assignee (InterDigital CE Patent Holdings) appears on the enumerated rosters (Acacia, Marathon, IV, IPNav, Wi‑LAN, Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation, Spangenberg entities). InterDigital is a large, publicly traded licensing/R&D enterprise, categorically distinct from those troll rosters — though it is definitionally a non-practicing licensing entity for the CE patent estate.
3 Repeat correspondent across the chain Unclear — verify I could not retrieve the correspondent for any '794 recording. One adjacent data point: Patricia A. Verlangieri / InterDigital CE Patent Holdings, 4 Research Way, 3rd Floor, Princeton NJ appears as correspondent on a related Thomson→InterDigital CE recording (reel 49605/898, recorded 2019‑06‑27, US 7,199,396). If that same correspondent sits on the '794 reels, it is a genuine repeat-correspondent signal across the estate; a single related appearance is not a finding. Pull the PDFs from the reel/frame pages and confirm names + addresses.
4 Cascading transfers (<24 months through chained LLCs) Not present The 2019 events are two recordings on the same day (change of name + assignment, both 2019‑12‑16). That is a single-step corporate restructuring, not a chain of successive LLC transfers. No shared-correspondent chained-LLC sequence appears.
5 Pre-litigation transfer Not present Per the earlier litigation analysis, no infringement suit, DJ action, ITC investigation, or PTAB proceeding names US 7,818,794. There is therefore no suit for the 2019 assignment to precede — the "transfer to set venue / clean standing" pattern has nothing to attach to.
6 Bankruptcy fire-sale Unclear No evidence of a bankruptcy sale of this asset was found. The 2019 transfer to InterDigital predates the Technicolor group's later financial restructuring by roughly a year, and the EPO/INPI records frame it as a negotiated portfolio assignment (deed dated 2019‑07‑30), not a court-supervised sale. I could not verify the underlying commercial transaction or any insolvency filing; the signal is unresolved, not affirmative.
7 Privateering Unclear / not present The structure (operating parent → affiliated licensing holding company) resembles the privateering shape, but privateering requires evidence the operating company retains a stake or benefit and directs assertion against competitors. InterDigital appears to have acquired outright, and no suit was ever filed on this patent; there is no coverage (EFF/Patent Progress/SEC) linking Thomson to assertion of the '794 patent. No finding.
8 Defensive aggregator (anti-NPE) Not present The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. InterDigital CE Patent Holdings is an asserting-capable licensing entity, not a defensive aggregator. (The patent's 2026 fee lapse means it is now practically neutralized, but the ownership chain itself is not a defensive-aggregation termination.)

Note on the strongest counter-indicator: the patent expired for failure to pay maintenance fees, with an adjusted expiration of 2026‑04‑02, and was never asserted in any forum I could identify. A genuine NPE enforcement play does not normally let an asset lapse uncollected.


Verdict

NPE — moderate confidence.

Justification. The ownership chain terminates at a non-practicing patent holding/licensing entity — InterDigital CE Patent Holdings — pursuant to the assignment recorded 2019‑12‑16 from Thomson Licensing (preceded that same day by the Thomson Licensing S.A. change of name). Because the terminal assignee is a licensing company that does not manufacture the claimed cable modem, the chain is, by definition, an NPE chain — one strong signal under the task's taxonomy. That said, this is an institutional licensing NPE inside a publicly traded company (InterDigital, Inc.), not a troll pattern: signals 1, 4, 5, and 8 are all absent, and no correspondent recurrence has been established yet (signal 3 unresolved; reel/frame not captured). The two counter-indicators — no assertion ever filed against this patent and fee-based lapse (adjusted expiration 2026‑04‑02) — mean this asset looks like a long-tail portfolio member transferred for defensive/coverage value, not a litigation vehicle.

Confidence caveat: the call rests on the terminal-assignee identity and the 2019‑12‑16 recording dates, which I verified via the Google Patents legal-events table. It does not rest on reel/frame or correspondent evidence, which I could not obtain. If a reel/frame pull shows the 2019 InterDigital recording was made by a third-party NPE-focused firm (rather than InterDigital's own Princeton-based correspondent), signal 3 would upgrade and the verdict could move toward high confidence. Conversely, if InterDigital filed the recordation through its own in-house correspondent, the "institutional, non-troll" characterization is reinforced.

Verification links:

Generated 9/27/2026, 7:41:30 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll verify the patent identity and then work through its citation record. Let me start with targeted lookups.

Good — I now have strong material on the ZoneAlarm NPL and the two key firewall patents. Let me pull the remaining substantive references.

Prior-Art Analysis — US 7,818,794 B2 ("Data traffic filtering indicator")

0. Scope, method, and a flag

Patent confirmed: US 7,818,794 B2, Brian Albert Wittman, "Data traffic filtering indicator," original assignee Thomson Licensing S.A., app. 10/517,574 (PCT/US03/18191), priority 2002‑06‑12, issued 2010‑10‑19. This matches the authoritative full text supplied and the Justia/Google Patents records I re‑verified in this pass (Google Patents; Justia companyprofiles/7818794). No auto‑correction of the number was performed.

Method note (important for how much weight to give this): I did not execute a literal query inside USPTO Patent Public Search (ppubs) or the PTAB/PatentCenter back‑end. What I can verify is the patent's own USPTO "References Cited" record (44 printed citations + a parallel 48‑entry citation list, 3 family‑cited references, and 6 non‑patent citations) as mirrored on Google Patents, supplemented by targeted web verification of the most substantive references. My tool budget was exhausted before I could independently re‑verify WO 99/59071, WO 00/54458, and US 6,282,546, so descriptions of those three rest on the patent‑record titles plus prior knowledge — treat them as lower confidence.

Contradiction already flagged elsewhere, repeated here: the analysis header reads 2026‑09‑27, while this task specifies April 26, 2026. I proceed on the task date; a filing between the two dates would not be captured.

Statutory framework. Because the priority date is 2002‑06‑12, pre‑AIA 35 U.S.C. § 102 governs. A cited reference is § 102(a)/(b) art if it issued or published before 2002‑06‑12, and § 102(e) art if it was filed before that date but published/issued after. Anticipation under § 102 requires a single reference disclosing every limitation of the claim, arranged as claimed.


1. What a § 102 reference would have to disclose

Breaking the independent claims into limitations (this is the map I use against every reference):

ID Limitation Claim 1 Claim 7 Claim 13
L1 Networked apparatus / method for examining data traffic / cable modem ✓ ✓ ✓ (+ down/upstream circuitry, controller, memory)
L2 Firewall with rule set identifying inappropriate activity ✓ ✓ ✓
L3 Rules separated into a plurality of classes ✓ ✓ ✓
L4 Rules prioritized so each class = a different priority level ✓ ✓ ✓
L5 Plurality of user‑discernable, visually discernable indicators ✓ ✓ ✓
L6 Each indicator mapped to a different class (except one) ✓ ✓ ✓
L7 Matching indicator fires on rule violation in its class ✓ ✓ ✓
L8 A "particular" indicator = affirmative status that filtering is being contemporaneously performed ✓ ✓ ✓
L9 Particular indicator concurrently triggered with the class indicator ✓ ✓ ✓
L10 Only when the number of violating packets exceeds a pre‑specified threshold ✓ ✓ ✓

No cited reference contains L5–L10 together. That is the load‑bearing conclusion of this section; everything below explains why, reference by reference.


2. Tier A — the closest citations (firewall + a human‑perceptible alert)

A1. ZoneAlarm Pro 3.0 — Nallawalla, PC Update, May 2002 (NPL)

  • Citation: Ash Nallawalla, "ZoneAlarm Pro 3.0," PC Update (Melbourne PC User Group), May 2002, melbpc.org.au/pcupdate/2205/2205article5.htm.
  • Date: May 2002 — printed publication two weeks to one month before the 2002‑06‑12 priority date. § 102(a)/(b) art.
  • Description (verified this pass): ZoneAlarm Pro 3.0/3.1 presents a Windows system‑tray icon that changes appearance with firewall state (a red lock when Internet Lock/Stop is engaged, a yellow lock when locked by policy), red/green in‑bound/out‑bound traffic bars, and an Alerts panel whose "Blocked Intrusions" counter reports "how many times the ZoneAlarm Pro firewall … acted to protect you, and how many of the alerts were high‑rated," with a reset control and a per‑alert "high rating" flag. See the Zone Labs help/manual excerpts surfaced in this pass (download.zonelabs.com ZA31 help PDF; IPR2015‑01927 Ex. 1019, ZoneAlarm Pro User Manual, at 19 and the "Blocked Intrusions / Protection" panel) and the contemporaneous reviews (ZDNet; PCMag; Geroski, TechRepublic, 2002‑05‑23).
  • § 102 assessment: This is the most dangerous reference in the set, because it is (i) the closest in time to the priority date and (ii) the only cited art that actually shows a visually discernable, user‑facing firewall indicator on the user's machine together with a count of blocked events broken out by severity rating.
    • It maps cleanly onto L5, L7, L8 and plausibly onto L10 (a discrete count of blocked intrusions, with a "high‑rated" subset).
    • It maps weakly onto L3, L4, L6, L9 — ZoneAlarm's "rating" is a per‑alert quality attribute rather than a rule set formally separated into classes each mapped to its own distinct indicator, and nothing shows a second, dedicated "filtering‑in‑progress" indicator concurrently lit with a class indicator.
    • Potentially anticipates: the genus of claim 1's indicator element and, if liberally read, dependent claim 4 ("only the general filtering indicator fires below threshold") and claim 5 (which indicator fires depends on priority level). It does not anticipate independent claims 1, 7, or 13 as a whole.
  • Why the examiner cited it: the three ZoneAlarm reviews sit in the IDS precisely because ZoneAlarm is the archetype of a firewall that tells the user in real time, on‑screen, that it is blocking traffic — i.e., the disclosure's own stated problem ("Many users simply disable the dialog window, and only keep the logging to the log file enabled").

A2. ZoneAlarm Pro User Manual / pre‑3.0 help (NPL, corroborating)

  • Citation: Zone Labs ZoneAlarm Pro User Manual (v3.0.062), cited in IPR2015‑01927 Ex. 1019; ZoneAlarm Help ("How do I know the lock is on? … you'll see a red lock icon in the system tray … a yellow lock icon"). Date: 2001–2002.
  • Description / § 102: Same disclosure family as A1. Reinforces L5/L8. The red‑vs‑yellow lock distinguishes state of protection, not rule class — so it does not supply L3/L4/L6.

A3. Eric Grevstad, "ZoneAlarm 3.0 Review," Internet.com (NPL)

  • Date: unknown/undated per the record (Google Patents lists "Date Unknown"). Because the publication date is not established, this reference is procedurally weak as § 102 art unless a date is proven; I flag it rather than rely on it.
  • Substance: same product family as A1/A2.

A4. Ray Geroski, "Secure Client Machines with ZoneAlarm Pro 3.0," TechRepublic, 2002‑05‑23 (NPL)

  • Date: 2002‑05‑23 — three weeks pre‑priority. § 102(a)/(b).
  • Description / § 102: Same ZoneAlarm disclosure; independently dates the on‑screen alert/indicator behaviour before the priority date. Supports L5/L8 against claim 1 only in combination.

A5. US 6,052,788 (Wesinger et al., Network Engineering Software)

  • Citation: US 6,052,788 A — filed 1996‑10‑17 (continuation chain to US 5,898,830), issued 2000‑04‑18. § 102(a)/(b).
  • Description (verified): Firewall "envoys"/virtual‑host proxy firewall that "monitors and controls the flow of data between two networks"; administrator "establishes a set of rules that specify what types of packets … are to be allowed to pass and what types are to be blocked"; packet filtering "may occur in a router, in a bridge, or on an individual host computer."
  • § 102 assessment: Discloses L1, L2 richly and even the desirability of alerting: "it is of equal if not greater importance to be alerted to an attack so that measures may be taken to thwart the attack," and it discusses "Pager beep‑back … if a hacker attempts unauthorized access … the user will be alerted by the device unexpectedly receiving the access key" (relevant to the specification's audible‑indicator embodiment, ¶ "speaker to provide an audibly discernable sound (e.g., a 'beep')").
    • Potentially anticipates: nothing alone, because it discloses no L3–L7 indicator‑class mapping and no L10 threshold. Its value is as a § 103 primary reference for the firewall‑plus‑alerting substrate; the "beep‑back" teaches the audible alert on attack concept.
    • Note: this is a named inventor's own field predecessor, and the same family (US 5,898,830) was used as an IPR exhibit in Apple v. VirnetX, IPR2016‑01585 (Ex. 1044) — showing it is a well‑worn piece of firewall prior art.

A6. US 6,119,236 (Shipley, "Intelligent network security device and method")

  • Citation: US 6,119,236 A — filed 1998‑12‑10 (CIP of 1996‑10‑07), issued 2000‑09‑12. § 102(a)/(b).
  • Description (verified): An in‑LAN device (INSD) monitors all packets crossing the firewall, detects "code and patterns of behavior," assigns a value to a perceived attempted security breach, and "directs the firewall to take any of a prescribed plurality of actions, based upon such value." Blocking occurs "in several degrees, depending upon the assigned seriousness of a breach attempt." Claims 12/15/16/17 expressly recite classification of the breach, including a factor "relating to the number of attempts" and "relative sophistication."
  • § 102 assessment: This is the best single § 102 reference for L3/L4 (rule/severity classes with priority) and a strong reference for L10's threshold‑on‑count concept (breach severity keyed to the number of attempts).
    • Potentially anticipates: a method of classifying violations by severity and gating response on the number of attempts — i.e., the analytical core of claim 7 minus everything indicator‑related and minus the filtering‑class/indicator mapping.
    • Cannot anticipate claims 1/7/13: it contains no user‑discernable indicator of any kind (no LED, no icon, no beep). It is therefore the classic § 103 partner to A1/A5: Shipley supplies prioritised classes + count‑threshold; ZoneAlarm supplies the real‑time user‑discernable indicator.

A7. US 6,317,837 (Applianceware, "Internal network node with dedicated firewall")

  • Citation: US 6,317,837 B1 — filed 1998‑09‑01, issued 2001‑11‑13. § 102(a)/(b).
  • Description: A node on the internal network that itself hosts a dedicated firewall, so filtering happens at the protected host rather than only at the gateway — structurally analogous to the '794 disclosure's firewall resident in a cable modem's memory.
  • § 102: Bearson L1/L2 (firewall co‑located with the protected device). No indicator, no classes. Not anticipatory.

A8. US 6,219,786 (Surfcontrol, "Method and system for monitoring and controlling network access")

  • Citation: US 6,219,786 B1 — filed 1998‑09‑09, issued 2001‑04‑17. § 102(a)/(b).
  • Description: Server‑side/agent monitoring and control of network access, including blocking of Web destinations — the real‑world analogue of the '794 specification's third‑class rules ("blocking of particular data packet destination addresses of Internet domains and web sites").
  • § 102: Supplies L2/L3 content (a policy rule set with different categories of block) but with no user‑discernable indicator and no priority‑to‑indicator mapping. Relevant; not anticipatory.

3. Tier B — class / threshold / detection architecture

Citation Filed / Issued (published) § 102 basis Description Potential § 102 target / role
US 6,321,338 B1 (Porras & Valdes, SRI International, "Network surveillance") 1998‑11‑09 / 2001‑11‑20 § 102(a)/(b)/(e) Builds long‑ and short‑term statistical profiles of packet measures; a deviation "indicates suspicious network activity"; responds by altering packet analysis or severing the communication channel; expressly describes acting "after some threshold volume of traffic, directed at an unused port, has been exceeded," and forwarding event records to a monitor. Discloses threshold‑on‑volume (L10 concept) and automated response (L2 filtering). No user‑discernable indicator → not anticipatory of 1/7/13; strong § 103 art for the threshold limitation.
US 6,282,546 B1 (Cisco, "…real‑time insertion of data into a multi‑dimensional database for network intrusion detection and vulnerability assessment") 1998‑06‑30 / 2001‑08‑28 § 102(a)/(b) Real‑time insertion of intrusion‑detection and vulnerability data into a multi‑dimensional DB for correlation/response. Background art for rule/signature‑based detection and storage (L2/L3 substrate). Lower confidence — search not independently re‑run. Not anticipatory.
WO 00/54458 A1 (Psionic Software, "Intrusion detection system") 1999‑03‑12 / 2000‑09‑14 § 102(a)/(b) Commercial IDS (the Psionic/Entercept lineage) detecting and logging intrusions. Background art for IDS rules and logging. Lower confidence — search not independently re‑run. Not anticipatory; notable because the specification's own criticism is that firewalls "do not provide contemporaneous feedback."
WO 99/59071 A1 = US 6,189,035 B1 (Motorola, "Method for protecting a network from data packet overload"; also CN1308745A) 1998‑05‑08 / 1999‑11‑18 (WO); US 2001‑02‑13 § 102(a)/(b) Detects and protects against data‑packet overload (a count/rate phenomenon) at a network element. Directly relevant to the number‑of‑packets threshold (L10). Lower confidence on WO text — search not independently re‑run. Not anticipatory (no indicator).
US 6,510,509 B1 (PMC‑Sierra, "Method and apparatus for high‑speed network rule processing") 1999‑03‑29 / 2003‑01‑21 § 102(e) (filed pre‑priority) Hardware pipeline for evaluating packet rule sets at line rate. Supports L2/L3 (rule‑set evaluation engine). No indicator. Not anticipatory.
US 6,389,532 B1 (Sun Microsystems, "Method and apparatus for using digital signatures to filter packets in a network") 1998‑04‑20 / 2002‑05‑14 § 102(a)/(b) Cryptographic‑signature‑based packet filtering. L2 only. Not anticipatory.
US 6,266,9447 B1 (Raytheon, "Information security analysis system") 1998‑07‑21 / 2001‑07‑31 § 102(a)/(b) Security analysis/assessment platform for network information. Background. Not anticipatory.
US 6,243,815 B1 (Antur, "Method and apparatus for reconfiguring and managing firewalls and security devices") 1997‑04‑25 / 2001‑06‑05 § 102(a)/(b) Remotely reconfiguring/managing firewall rule sets and security devices. Supports the "rules established by an administrator / default rules" element and end‑user‑settable thresholds (claim 6 context). Not anticipatory.
US 6,327,338 / US 6,321,267 B1 (Escom, "Method and apparatus for filtering junk email") 1999‑11‑23 / 2001‑11‑20 § 102(a)/(b) Content filtering of e‑mail. L2/L3 analogue only. Not anticipatory.
US 2002/0133586 A1 (Carter Shanklin, "Method and device for monitoring data traffic and preventing unauthorized access to a network") 2001‑01‑16 / 2002‑09‑19 § 102(a)/(b)/(e) Monitors data traffic and takes protective action against unauthorised access. Touches L1/L2. Published after the priority date → only § 102(e) art. Not anticipatory.
US 2002/0178383 A1 (Michael Hrabik, "Method and apparatus for verifying the integrity and security of computer networks and implementing counter measures") 2001‑01‑25 / 2002‑11‑28 § 102(e) Integrity verification + counter‑measures. Background. Not anticipatory.
US 2002/0178365 A1 (Shingo Yamaguchi, "Method and system for controlling access to network resources based on connection security") 2001‑05‑24 / 2002‑11‑28 § 102(e) Access control keyed to connection security level — a de facto priority/class notion. Weak L3/L4 analogue. Not anticipatory.
US 2003/0051026 A1 (Carter Ernst B., "Network surveillance and security system") 2001‑01‑19 / 2003‑03‑13 § 102(e) Network surveillance/security system. Background. Not anticipatory.
US 2003/0084349 A1 (Oliver Friedrichs, Symantec, "Early warning system for network attacks") 2001‑10‑12 / 2003‑05‑01 § 102(e) Attack early‑warning / alerting system with severity‑graded notifications. Relevant to alerting on detection and severity grading; still not an on‑device/on‑screen filtering indicator mapped to rule classes. Not anticipatory.
US 2003/015485 A1 (Milliken, "Hash‑based systems and methods for detecting, preventing, and tracing network worms and viruses") 2001‑12‑14 / 2003‑06‑19 § 102(e) Hash‑based worm/virus detection and prevention. Relevant to the "worm" and "Code Red" subject matter the specification discusses; not to the indicator architecture. Not anticipatory.
US 7,010,807 B1 (Sonicwall, "System and method for network virus protection") 2001‑04‑13 / 2006‑03‑07 § 102(e) Gateway‑level virus protection per rule set. L2 analogue. Not anticipatory.
US 7,224,359 B2 and US 7,340,770 B2 (Check Point Software) 2001‑07‑27 / 2007‑05‑22; and 2002‑05‑15 / 2008‑03‑04 § 102(e) (both filed pre‑priority) (i) Automatic local‑network discovery + firewall reconfiguration for mobile devices; (ii) community‑based security policies. Policy‑management background. Not anticipatory.
US 7,574,740 B1 (IBM, "Method and system for intrusion detection in a computer network") 2000‑04‑28 / 2009‑08‑11 § 102(e) Intrusion detection in a network. Background. Not anticipatory.
US 2002/0083168 A1 (Sweeney, "Integrated monitoring system") 2000‑12‑22 / 2002‑06‑27 § 102(e) Integrated network monitoring. Background. Not anticipatory.
US 2004/0103021 A1 (Richard Scarfe, "System and method of detecting events") 2000‑08‑11 / 2004‑05‑27 § 102(e) Event detection with graded/queued event notification. Plausibly relevant to event notification with threshold/aggregation; not to class‑mapped indicators. Not anticipatory.
US 2006/0253903 A1 (Krumel, "Real time firewall/data protection systems and methods") 2000‑07‑07 / 2006‑11‑09 § 102(e) Real‑time firewall/data‑protection. Directly on‑point to the "contemporaneous feedback" theme; cited precisely for that. Not anticipatory on the indicator mapping.
WO 02/045380 A2 (Lancope, "Flow‑based detection of network intrusions") 2000‑11‑30 / 2002‑06‑06 § 102(a)/(b)/(e) Flow‑based (not per‑packet) intrusion detection. Relevant to the specification's "or a group of packets considered as a whole" filtering trigger. Not anticipatory.
WO 01/88731 A1 (Niksun, "Security camera for a network") 2000‑05‑12 / 2001‑11‑22 § 102(a)/(b) Passive network monitoring/recording appliance. Background. Not anticipatory.
US 2001/0044886 A1 (Cassagnol, "Method and apparatus for controlling access to confidential data by analyzing property inherent in data") 1997‑09‑26 / 2001‑11‑22 § 102(a)/(b) Content‑property‑based access control. L2/L3 analogue. Not anticipatory.

4. Tier C — cable‑modem / gateway hardware (relevant to claim 13 only)

Citation Filed / Issued § 102 basis Description Potential § 102 target
US 5,802,952 A (Intel, "Cable modem interface unit for capturing and processing incoming packets from a cable modem") 1996‑12‑13 / 1998‑09‑15 § 102(a)/(b) Cable‑modem interface unit capturing/processing incoming packets. Claim 13's structural half: downstream/upstream packet handling in a cable modem. Silent on indicators/rules. Not anticipatory of claim 13 as a whole.
US 6,185,624 B1 (3Com, "Method and system for cable modem management of a data‑over‑cable system") 1998‑02‑04 / 2001‑02‑06 § 102(a)/(b) DOCSIS‑era cable‑modem management. Claim 13's cable‑modem/DOCSIS context. Not anticipatory.
US 2003/0106067 A1 (Hoskins, "Integrated internet protocol (IP) gateway services in an RF cable network") 2001‑11‑30 / 2003‑06‑05 § 102(e) Cable‑network IP gateway (routing, NAT, policy) integrated in the RF plant. Close to the FIG. 2 architecture (routing functions 221/222/223 between an internal TCP/IP stack and the RF path). Not anticipatory.
US 2002/0062450 A1 (Brian Carlson, "Methods, modems, and systems for blocking data transfers unless including predefined communications to provide access to a network") 1999‑05‑07 / 2002‑05‑23 § 102(a)/(b)/(e) Modem‑resident blocking of data transfers against predefined conditions. Structurally the nearest "filtering inside the modem" citation — relevant to claims 1/13's "firewall… resident in said memory." Still no class‑mapped user indicator. Not anticipatory.

5. Remaining cited references (background / peripheral; none anticipatory)

Citation Filed / Pub. § 102 basis Description Note
US 4,707,738 A (Thomson Grand Public) 1984‑12‑21 / 1987‑11‑17 § 102(a)/(b) Adaptive picture coding/decoding by transform. Not relevant to any claim. Almost certainly a Thomson portfolio artifact in the IDS. Flagging so no one infers technical relevance.
US 2002/0062450 / US 2002/0080784 / US 2002/0080771 (802 Systems) 2000‑12‑21 / 2002‑06‑27 § 102(e) PLD/FPGA‑based network communication protocols. Hardware rule implementation — marginal.
JP 2002063084 A = US 7,116,675 B2 (Toshiba, "Packet transfer device, packet transfer method…") 2000‑08‑21 / 2003‑04‑22 (JP); US 2006‑10‑03 § 102(a)/(b)/(e) Packet transfer device that prevents illicit access. Rule‑based packet gating. Not anticipatory.
JP 2002124996 A (Baba, "Fast packet acquiring engine/security") 2000‑10‑13 / 2002‑04‑26 § 102(a)/(b) High‑speed packet acquisition engine for security. Background.
US 6,581,092 B1 (Ricoh, "Method and system for remote diagnostic, control and information collection… sending messages to users") 1999‑09‑29 / 2003‑06‑17 § 102(e) Remote diagnostic/control sending messages to users. Tangential to "notify the administrator/end‑user." Not anticipatory.
US 6,799,877 B1 (Juniper, "Filtering and route lookup in a switching device") 2000‑04‑17 / 2004‑09‑28 § 102(e) Combined filtering + route lookup in hardware. L2 engine. Not anticipatory.
US 2005/0235360 A1 = US 6,990,591 B1 (Secureworks, "Method and system for remotely configuring and monitoring a communication device") 1999‑11‑18 / 2005‑10‑20 (US 2006‑01‑24) § 102(e) Remote configuration and monitoring of a security device, incl. alert delivery. Relevant to remote alerting; not to on‑device indicators.
US 2003/015485 see Tier B
US 2002/0178383 see Tier B
US 2007/0053513-lineage references (Hoffberg) — — Not a direct citation of '794; appears only in third‑party cross‑citation tables. Ignore.

6. ⚠️ References on the IDS list that are NOT § 102 prior art on their face

Two entries in the cited‑references block post‑date the 2002‑06‑12 priority date and therefore cannot be § 102 art against this patent unless they carry an earlier (unshown) effective filing date. I flag these because a reader would otherwise wrongly assume the examiner had pre‑priority art of this quality:

  • US 7,698,550 B2 (Netgear, "Peripheral device with visual indicators"), priority/listed 2005‑06‑30, issued 2010‑04‑13. This is exactly the kind of reference one would want (visual indicators on a peripheral box), but it post‑dates the priority date by three years. On the face of the record it is not § 102(a)/(b)/(e) art. If it appears in the file, it was likely added post‑issuance or is an artifact of Google Patents' citation merge.
  • US 2004/0117834 A1 (Jeyhan Karaoguz, Broadcom, "Server architecture supporting a personal media exchange network"), filed 2002‑12‑11 — six months after the priority date. Not § 102 art absent an earlier benefit claim.

Please treat these two as citation‑record noise, not prior art. This is the kind of thing I was warned about in the operating rules: the number and the listing are literal, but a listing's presence in an IDS does not make the reference prior art.


7. Family‑cited references (cited against the EP/JP/KR siblings)

These three were cited against family members (not necessarily against the US case), so they are also candidate art of record:

  • KR 1998‑0022833 A (Choi Seung‑ryul, "Apparatus and method for tracking information leakage"), 1996‑09‑24 / 1998‑07‑06. § 102(a)/(b). Data‑leak tracking. Peripheral.
  • JP 2003‑505934 A (Sun Microsystems, "Secure network switch"), 1999‑07‑15 / 2003‑02‑12. § 102(a)/(b). A switch that performs security filtering — relevant to the "router, bridge … or any other networked communication device" claim scope, but silent on indicators.
  • KR 100334128 B1 (Jeon Chang‑oh, "Security policy system"), 2000‑03‑24 / 2002‑04‑26. § 102(a)/(b). Policy‑based security — a rule‑set/class analogue with no indicator.

8. Bottom line under § 102

No cited reference anticipates independent claim 1, 7, or 13. Every candidate fails at least the following combination:

  1. L3 + L4 + L6 — a rule set formally separated into classes and prioritised, with each class mapped to its own distinct visually‑discernable indicator. The references split cleanly into two camps that never meet:
    • Class/priority/threshold camp: US 6,119,236 (severity‑graded classification keyed to the number of attempts), US 6,321,338 (statistical‑profile threshold), US 6,219,786 (categorised URL/HTTP blocking), WO 99/59071 / US 6,189,035 (packet‑overload count threshold) — none of which has any user‑discernable indicator.
    • Indicator camp: ZoneAlarm Pro 3.0 NPL (system‑tray icon, red/yellow lock states, "Blocked Intrusions … how many were high‑rated") and US 6,052,788 (firewall + alerting, "pager beep‑back") — neither of which maps distinct indicators to a formal prioritised rule‑class taxonomy.
  2. L8 + L9 + L10 — a distinct "particular" indicator meaning "filtering is being performed right now," concurrently lit with the class indicator, and only when the violating‑packet count crosses a pre‑specified threshold. Nothing in the cited set shows a dedicated general‑status indicator that is gated on a count threshold and conditioned on the class indicator also firing.

The residual novelty of the patent therefore lives almost entirely in the indicator‑architecture claims, not in the firewall/classification/threshold substrate. That is consistent with the disclosure's own framing: the Background concedes firewalls, rules, logging and class‑based policies are old; the stated advance is the contemporaneous, user‑discernable filtering indicator.

Anticipation map by claim (most‑to‑least exposed)

Claim Best § 102 candidate Verdict
4 / 11 / 17 ("only the general indicator fires below threshold") ZoneAlarm Pro 3.0 NPL Closest call. ZoneAlarm shows a persistent tray state indicator while individual blocked‑connection alerts are separately surfaced; a liberal reading of "general status indicator on, violation indicator off" is arguable. Still a coin‑flip, and better run as § 103.
5 / 12 / 18 (which indicator fires depends on priority level) US 6,119,236 + ZoneAlarm Not anticipatory alone; strong § 103 combination (severity classification + severity‑graded icon).
14 (two LEDs: general vs pernicious) — No § 102 reference. Specification's own "yellow LED / red LED" is the invention; nothing cited has a two‑LED firewall indicator.
6 (per‑class, end‑user‑settable thresholds governing when filtering begins) US 6,243,815 (administrator‑managed rule sets) + US 6,119,236 (severity‑scaled response) § 103 only.
1 / 7 / 13 (independents) ZoneAlarm Pro 3.0 (nearest) Not anticipated. Missing L3/L4/L6/L9.
2 / 15 (highlighted icon on a computing device) ZoneAlarm Pro 3.0 NPL (tray icon) Highest § 102 exposure of any claim. A highlighted system‑tray icon is ZoneAlarm's disclosure. If claim 2/15 were ever tested alone, the May‑2002 ZoneAlarm literature is a serious § 102(b) problem.
3 / 10 / 16 (filter always, trigger only above threshold) ZoneAlarm Pro 3.0 Arguable § 102 on the "count of blocked intrusions" model; more safely § 103.
8 / 9 (threshold before filtering / before triggering) US 6,321,338; WO 99/59071 / US 6,189,035 § 103 only.
13 (cable modem structure) US 5,802,952; US 6,185,624; US 2002/0062450 § 103 only; structure anticipated, indicator not.

The strategic takeaway for an invalidity theory: the '794 patent is not vulnerable on a clean single‑reference § 102 attack against its independents. It is vulnerable — and this is where the cited art does its work — on a § 103 combination: ZoneAlarm Pro 3.0 (pre‑priority NPL) for the user‑discernable, visually discernable on‑screen firewall indicator and its blocked‑event counter, in view of US 6,119,236 for severity‑classified breaches with responses scaled to the number of attempts, and in view of US 6,052,788 for a firewall that both filters and alerts the user to an attack. The dependency claims 2/15 (highlighted icon) and 4/11/17 (general‑only indicator below threshold) are the weakest links.


9. Caveats you should carry forward

  1. Not an exhaustive database query. I relied on the patent's own USPTO references‑cited record plus targeted verification. A certified § 102 search would require running the claim limitations through Patent Public Search (ppubs), Espacenet, and Google Patents' "similar documents" and generating a proper IDS‑grade search report; I did not do that here.
  2. Three references under‑verified. WO 99/59071 (Motorola), WO 00/54458 (Psionic), and US 6,282,546 (Cisco) were in my final, truncated search batch — I could not complete independent verification of their text. Their descriptions above rest on the citation‑record titles and background knowledge; confidence: medium.
  3. Two references flagged as non‑art. US 7,698,550 (Netgear, 2005) and US 2004/0117834 (Karaoguz, filed 2002‑12‑11) post‑date the priority date and cannot be § 102 art on their face (see § 6). Do not cite them against this patent without an earlier‑priority proof.
  4. ZoneAlarm's dates matter and cut both ways. ZDNet places the free ZoneAlarm 3.0 release in April 2002 and PCMag/ZDNet reviewed ZoneAlarm Pro 3.0 in May 2002 — i.e., weeks before the 2002‑06‑12 priority date. That is enough for § 102(b) on the on‑screen indicator disclosure, but it is narrow: any feature shown only in ZoneAlarm builds released after early June 2002 is not § 102(b) art. ZoneAlarm Pro's "high‑rated" alert count and the red/yellow lock icons are documented in the 3.0/3.1 help and manual, which is where the § 102(b) argument has to be anchored.
  5. The litigations/PTAB posture is unchanged and still relevant to motive: per the earlier sections of this analysis, US 7,818,794 is expired for failure to pay maintenance fees (listed adjusted expiration 2026‑04‑02) and has never been asserted or challenged at the PTAB. An invalidity analysis on this patent is therefore academic unless someone is asserting pre‑expiration damages within the § 286 six‑year lookback — and if the priority‑date references above were never actually relied on by the examiner in a rejection, they remain available for a § 282 defense regardless of any IPR estoppel (there is none).

One-line answer to the task: The closest § 102 art for US 7,818,794 is the ZoneAlarm Pro 3.0 literature (Nallawalla, PC Update, May 2002; Geroski, TechRepublic, 2002‑05‑23; Zone Labs v3.0 manual) for claims 2/4/5/15 (the on‑screen firewall indicator), and US 6,119,236 (Shipley) for the "prioritised, severity‑classified rules gated on a count of attempts" elements — but no cited reference anticipates independent claims 1, 7, or 13, all of which require the combination of class‑mapped distinct indicators and a dedicated contemporaneously‑filtering indicator concurrently triggered only above a pre‑specified packet‑count threshold, which appears nowhere in the record.

Generated 9/27/2026, 7:42:24 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll verify a few key prior-art references from the patent's own citation record before building the § 103 combinations.

The random searches confirmed several key reference disclosures. Let me verify two more firewall references from the record.

Obviousness analysis — US 7,818,794 B2 under 35 U.S.C. § 103

Scope note / orientation. This is a retrospective, defensive-style validity analysis of a patent that the earlier sections of this review establish is "Expired – Fee Related," adjusted expiration 2026‑04‑02, with no litigation and no PTAB proceeding ever filed on it. A § 103 attack therefore has practical value only for (a) an IPR/§ 282 defense reaching pre‑expiration conduct inside the § 286 six-year lookback, or (b) a defensive validity opinion. Additionally, note an internal date inconsistency already flagged in this analysis: the task header says 2026‑04‑26 while the document header says 2026‑09‑27; nothing in this section turns on the difference. Finally, the statutory framework is pre‑AIA § 103(a) (priority 2002‑06‑12; PCT filed 2003‑06‑09), so Graham v. John Deere Co., 383 U.S. 1 (1966), and KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), supply the controlling test.

Everything below is drawn from the patent's own record — the "Citations (44)" / "Patent Citations (48)" lists, the "Cited By" list, and the six items of non‑patent literature — except where I explicitly say I verified a reference's text on the open web.


1. Person of ordinary skill in the art (POSITA)

A POSITA as of June 2002 would have: a bachelor's degree in EE/CS (or equivalent) plus ~2–4 years in data networking and network security; working familiarity with (i) packet‑filtering firewall rule configuration, (ii) stateful/statistical intrusion‑detection concepts then commercialized by SRI (US 6,327,338), Psionic (WO 00/54458) and Cisco/NetRanger (US 6,282,546), (iii) DOCSIS cable‑modem architecture (US 5,809,252; US 6,185,624), and (iv) consumer/enterprise network hardware front‑panel conventions — power/link/activity LEDs, and the colored‑lock and system‑tray indicators already shipping in ZoneAlarm.

2. Claim element decomposition (as issued, no reexamination certificate)

The claims were granted unamended on 2010‑10‑19 and never tested. Element IDs used below:

ID Claim 1 (apparatus) Claim 7 (method) Claim 13 (cable modem)
A apparatus adapted to communicate via a network — downstream + upstream processing circuitry; controller + memory
B firewall with a set of rules identifying packets of inappropriate activity defining such a rule set firewall program resident in memory, executable by controller
C rules separated into a plurality of classes separating rules into classes rules separated into classes
D rules prioritized so each class = a different priority level same same
E indicator device giving multiple, visually discernable indicators associating each class with a different visually discernable indicator multiple visually discernable indicators
F each indicator mapped to a different class same same
G the class indicator fires when a rule in its class is violated examining traffic; filtering; triggering the class indicator same
H all but a particular indicator map to a class same same
I the particular indicator = affirmative status "filtering is being contemporaneously performed" same same
J particular and class indicator concurrently triggered, only when the violating‑packet count exceeds a pre‑specified threshold same same, plus "filtering is performed by the firewall program" as an express condition

Drafting tension worth exploiting: claim 1 element J says the pair fires "only when" the count exceeds the threshold, yet dependent claim 4 (and 11, 17) says only the particular indicator fires when filtering is performed and the count does not exceed the threshold. That is only coherent if J's "only when" modifies the concurrent firing of the pair rather than the individual firing of the general indicator. A petitioner should pin the patentee to one construction; under either reading the prior‑art combinations below supply the structure.


3. Prior‑art inventory (all from the record of the patent, all pre‑2002‑06‑12)

Group I — Firewall with contemporaneous user notification (the "indicator" element)

I‑1. ZoneAlarm Pro 3.0 — ZA Pro 3.0 User's Manual (© 2002 Zone Labs, Inc.), plus its review‑of‑record articles: Nallawalla, PC Update (May 2002); Geroski, TechRepublic (May 23, 2002); Grevstad, Internet.com. Verified full text of the 3.0 manual and a contemporaneous ZDNet review. Key disclosure I confirmed:

  • Rating field / class hierarchy: "Each alert is high‑rated or medium‑rated. High‑rated alerts are those likely to have been caused by hacker activity. Medium‑rated alerts are likely to have been caused by unwanted but harmless network traffic." → two classes keyed to severity/priority (elements C, D, and the ability to trigger indicators class‑by‑class).
  • System Tray Alert tab — a user‑configurable visual indicator in the OS tray tied to the firewall's blocking activity (element E, I).
  • Alert Events tab — "In the event that traffic is blocked, an alert can be generated and logged. From the list of events below, check the events for which you wish to generate alerts and log entries" → end‑user‑settable, per‑class/per‑type triggering (elements G, and claim 6's settable‑threshold concept).
  • Count field — "the number of times an alert of the same type, with the same source, destination, and protocol, occurred during a single session," plus a dashboard counter ("19 Intrusions have been blocked since install / 0 of those have been high‑rated") → packet/event counting and aggregation, the raw material for element J.
  • Multi‑state color indicators: the tray icon renders red bars for outbound / green for inbound traffic, and displays a red lock icon vs. a yellow lock icon for different lock states; "ZA" on a red‑and‑yellow background when idle. → plurality of visually discernable, distinguishable indicators keyed to different statuses.
  • Action Taken field ("How the traffic was handled by ZoneAlarm Pro") → filtering.
  • Contemporaneity is not incidental: the ZDNet review‑of‑record framing ties the product to "always‑on DSL and cable connections."

I‑2. US 6,052,788 (Wesinger et al., Network Engineering Software; family member US 5,898,830). Title: "Firewall providing enhanced network security and user transparency." Verified text of the family specification states the motivation in terms useful to a petitioner: "it is of equal if not greater importance to be alerted to an attack so that measures may be taken to thwart the attack or render it harmless… Hence a firewall, in addition to security, should provide timely information that enables attacks to be detected."

I‑3. US 6,219,786 (Surfcontrol) — "Method and system for monitoring and controlling network access": the corporate‑policy blocking of sites/domains that maps to the patent's own "third class" (blocked Internet domains/web sites). Title/record‑level characterization; I did not verify column text.

Group II — Classified/prioritized rule sets with graded, count‑sensitive response

II‑1. US 6,119,236 (Shipley) — "Intelligent network security device and method." Verified abstract and specification text. The INSD assigns a value to perceived breach attempts and "directs the firewall to take any of a prescribed plurality of actions, based upon such value"; "Blocking will occur in several degrees, depending upon the assigned seriousness of a breach attempt"; it provides "an adaptable response appropriate to both the type of breach attempt and the source and quantity of such breach attempts"; and it expressly "looks at patterns of activity over time … more than one packet." → elements B, C, D, G, and a quantity/count basis for J. (Continuation US 6,304,975 carries the same disclosure.)

II‑2. US 6,327,338 (Porras & Valdes, SRI International) — "Network surveillance." Verified abstract. Statistical comparison of short‑term vs. long‑term profiles built from packet counts/volumes/connection measures → detection of suspicious activity when a count‑based short‑term deviation appears, with a response and event records pushed to hierarchical monitors. → an alternative primary for C/D and a strong teaching of count‑threshold detection over time, which is elemental to J.

II‑3. US 6,282,546 (Cisco) — real‑time insertion of intrusion data into a database for intrusion detection/vulnerability assessment; US 7,014,807 (SonicWall, filed 2001‑04‑13) — "System and method for network virus protection," available as § 102(e) art as of its 2001 filing date; US 7,577,474 (IBM, filed 2000‑04‑28) — intrusion detection in a computer network. These give the grader/priority‑tiered virus/intrusion rule engine. Title/record‑level characterization.

Group III — Count‑threshold gating of protective action

III‑1. US 6,189,035 (Lockhart & Reardon, Motorola) — "Method for protecting a network from data packet overload" (WO 99/59071; CN 1308745; CN 1210653C). Verified specification text and pending‑claim text. For each packet: identify source; increment that source's "recent packet count"; "a determination is made as to whether the recent packet count … exceeds a predetermined threshold. If the answer is affirmative … the data packet is discarded"; separately, "if that total count exceeds a predetermined upper limit, then data packets from all non‑trusted sources are rejected." Its claim 1 recites "d) if the packet count exceeds a threshold then discard the packet; e) if the packet count is below the threshold then transmit the packet to the internal network." → two independent, pre‑set counts (per‑source and aggregate), i.e., the threshold architecture of element J and of claim 6.

Group IV — Cable‑modem / gateway platform for claim 13

US 5,809,252 (Intel) "Cable modem interface unit for capturing and processing incoming packets from a cable modem"; US 6,185,624 (3Com) "Method and system for cable modem management of a data‑over‑cable system" (DHCP/management, mirroring the '794 spec's DHCP paragraph); US 6,317,837 (Applianceware) "Internal network node with dedicated firewall"; US 2002/0062450 A1 (Carlson) "Methods, modems, and systems for blocking data transfers…"; US 2003/0106067 A1 (Hoskins) "Integrated internet protocol (IP) gateway services in an RF cable network." Title/record‑level characterization for all five.

Group V — Multi‑indicator hardware and management/configurability

Two‑LED "general vs. pernicious" signaling is the ordinary front‑panel convention for consumer network hardware and is also literally present in ZA Pro's yellow‑lock/red‑lock and red/green‑bar iconography. User‑settable policy parameters are taught by US 6,243,815 (Antur), "Method and apparatus for reconfiguring and managing firewalls and security devices," and by ZA Pro's own sliders and checkboxes (claim 6).

Important negative flag: the record's own citation list includes US 7,697,550 (Netgear), "Peripheral device with visual indicators," filed 2005‑06‑30 — that is a forward citation to the '794 patent, not prior art against it (post‑dates the June 2002 priority date). Do not use it in a § 103 ground. The same trap applies to the Centripetal "Cited By" family.


4. Ground 1 — Claims 1 and 7: ZA Pro 3.0 in view of Shipley (US 6,119,236), further in view of Lockhart (US 6,189,035)

Element Supplied by
A ZA Pro 3.0 (network‑attached firewall apparatus); US 6,052,788 (firewall between Internet/Intranet)
B ZA Pro 3.0 (blocked‑traffic events; "traffic is blocked… an alert can be generated and logged"); US 6,052,788
C ZA Pro 3.0 ("high‑rated" = hacker activity vs. "medium‑rated" = unwanted but harmless traffic); Shipley ("degrees … depending upon the assigned seriousness")
D ZA Pro 3.0 (two‑tier rating); Shipley ("value" assigned to breach attempts; graded blocking)
E ZA Pro 3.0 (System Tray Alert tab; red/green bars; red vs. yellow lock icon)
F, G ZA Pro 3.0 (per‑event/per‑rating alert generation, user‑selected by blocked‑traffic type)
H, I ZA Pro 3.0 dashboard status ("All Systems Active"), "Action Taken," blocked‑intrusion counter — a status indication that blocking is occurring
J ZA Pro 3.0 "Count" field (repeats of same‑type alert per session) + Lockhart (recent‑packet‑count > pre‑set threshold; total‑count > second pre‑set threshold) + Shipley ("quantity of such breach attempts")

Motivation to combine (articulated, KSR‑compliant):

  1. Explicit problem in the art and in the patent's own admission. The '794 Background concedes that firewalls already log filtering events and already raise dialog windows, and concedes the resulting user behavior (users disable the dialogs). Under KSR, the patentee's own statement of the problem is powerful evidence of what a POSITA was motivated to solve. US 6,052,788 supplies the express goal: "a firewall, in addition to security, should provide timely information that enables attacks to be detected" — i.e., a POSITA seeking "timely," non‑intrusive notification is directly motivated to move notification out of a modal dialog and into an always‑visible status indicator of the kind ZoneAlarm already shipped in its system tray.
  2. Same field, same problem, overlapping inventors' art. All four references address unauthorized/inappropriate network traffic at a gateway. Under In re Merck & Co., 800 F.2d 1091 (Fed. Cir. 1986), and In re Keller, 642 F.2d 413 (CCPA 1981), the references need only be reasonably pertinent, not bodily incorporable.
  3. Alarm‑fatigue / false‑positive suppression. Both ZA Pro (High/Medium alert display setting; alert ratings) and Shipley (graded response by seriousness) are expressly engineered around not treating harmless traffic like a hacker attack. A POSITA reading the '794 spec's own example — "Code Red" ARP noise (class 3) versus systematic port probing (class 1) — would recognize a known technique (severity classification + repeat counting) applied to a known device (a firewall's user indicator) to yield the predictable result of distinguishing nuisance from attack. That is the KSR "known technique to improve a similar device in the same way" rationale, and it is also the In re Fulton, 391 F.3d 1195 (Fed. Cir. 2004), "design choice / arrangement of known elements" rationale.
  4. Thresholding a notification is a routine engineering variable. Lockhart already teaches two pre‑set count thresholds governing protective action, and expressly teaches that below threshold the packet is passed and above threshold it is dropped. Applying the same count‑and‑threshold construct to the notification decision (rather than to the drop decision) is a mere rearrangement of Lockhart's own two‑branch logic — exactly the kind of "improvement in one reference's system in the same way, per the other reference's teaching" that KSR holds obvious.

Why this is the strongest ground: ZA Pro supplies elements E–I verbatim (a visually discernable, multi‑state, contemporaneous indicator of firewall blocking activity), and Shipley plus Lockhart supply the two things ZA Pro lacks (an explicit priority‑class rule model and a pre‑set count threshold). Nothing in the combination requires a mechanism not already present in one of the references.


5. Ground 2 — Claim 13: Ground 1 applied to a cable‑modem platform, additionally in view of US 5,809,252 and US 6,185,624 (and optionally US 6,317,837)

Claim 13 adds only: downstream processing circuitry, upstream processing circuitry, a controller with memory, the firewall resident in memory, and "positioned proximate the cable modem."

  • US 5,809,252 (Intel) discloses a cable modem interface unit that captures and processes incoming packets from a cable modem — i.e., the packet‑capture machinery needed to feed a firewall.
  • US 6,185,624 (3Com) discloses cable‑modem management of a data‑over‑cable system, including the provisioning/DHCP functions the '794 specification itself recites for its FIG. 2 embodiment.
  • US 6,317,837 (Applianceware) discloses a network node with a dedicated firewall, i.e., the firewall‑in‑the‑appliance architecture.

Motivation: (i) the same ZDNet/ZA‑Pro framing of record — the rise of "always‑on DSL and cable connections" — is itself the reason a POSITA would relocate firewall inspection and its indicator to the subscriber's broadband gateway, which is the sole always‑on, always‑powered node in the home; (ii) the cable modem is the natural "choke point" for all traffic to/from the LAN, which is precisely the architectural justification US 6,052,788 gives for firewalls ("All communications … must pass through the firewall"); (iii) placing a status lamp on the outer cover of a consumer appliance is not a new mechanism but the application of the ordinary front‑panel convention for consumer networking gear to the newly integrated firewall — In re Fulton.


6. Ground 3 (alternative primary) — Porras US 6,327,338 + Cisco US 6,282,546 + ZA Pro 3.0 (+ Shanklin US 2002/0133586)

For a petitioner who wants to avoid over‑relying on NPL, this substitutes a patent primary: Porras teaches count/volume‑based statistical detection of suspicious activity over long‑ and short‑term windows (element J's "number of packets" concept, and C/D by extension via its signature/statistics engines and event records), and Cisco US 6,282,546 teaches real‑time event insertion and reporting for intrusion detection. ZA Pro 3.0 then supplies the user‑discernable indicator. Shanklin US 2002/0133586 ("monitoring data traffic and preventing unauthorized access to a network") supplies the monolithic monitor‑and‑block apparatus. The motivation is identical to Ground 1, rationale (1)–(3).


7. Dependent‑claim grounds

Claim Additional limitation Primary art / rationale
2, 15 indicator = highlighted icon on a computing device ZA Pro 3.0 System Tray Alert + dashboard (literal); design choice
3, 10, 16 filter all violators, but trigger indicator only above threshold Lockhart's threshold logic decoupled from the drop decision; ZA Pro logs/counts regardless; predictable result
4, 11, 17 below threshold, only the general indicator fires Direct consequence of the two‑indicator architecture of Ground 1 using ZA Pro's always‑on status area plus per‑event alert
5, 12, 18 which indicator fires depends on the priority level ZA Pro high‑rated vs. medium‑rated; Shipley graded seriousness; Surfcontrol policy classes
6 per‑class thresholds, end‑user settable, governing when filtering begins ZA Pro Alert Events checkboxes + High/Medium display control + Zone security sliders; Lockhart's two pre‑set thresholds; US 6,243,815 (reconfiguring/managing firewalls)
8, 9 threshold check before filtering / before triggering Lockhart step 64 vs. step 70 (two separate pre‑action tests)
14 two LEDs: general event + pernicious packets ZA Pro red‑lock vs. yellow‑lock icon states and red/green traffic bars; conventional multi‑LED front panels; Shipley's seriousness gradation. Not US 7,697,550 (post‑dates priority)

8. Weaknesses a petitioner must confront (and how the patentee will attack)

  1. The examiner already had this art. The ZoneAlarm Pro 3.0 reviews, Shipley, the SRI/Cisco intrusion‑detection patents and Motorola's WO 99/59071 are all in the IDS/record (verified in the "Non‑Patent Citations (6)" and citation lists above). Claim 1 nevertheless issued in 2010. The patentee will argue the examiner considered this exact combination. A petitioner must therefore win on the specific conjunctive limitation J — the concurrent firing of (i) a general "filtering is in progress" indicator and (ii) the class indicator, gated on a count threshold. That precise coupling appears to be the actual point of novelty, and none of the references individually frames indication and thresholding in that coupled way; that is the "arrangement of old elements" / In re O'Farrell, 853 F.2d 894 (Fed. Cir. 1988) tension in the case. The counter is the functional benefit itself (distinguishing ordinary filtering noise from an attack in progress), which the references collectively suggest but do not state.
  2. Teaching away (weak but arguable). ZA Pro's own UI pushes users toward suppressing display and toward logging ("Alert Events Shown" reduced to Medium; "This control does not affect logging"), which the patentee may spin as teaching away from more visible indicators. Under O'Farrell this is a hard sell: ZA Pro does not criticize or discredit a hardware/always‑visible indicator; it merely offers a different convenience trade‑off.
  3. § 102(a) dating of the NPL is the biggest factual exposure. The ZoneAlarm Pro 3.0 reviews of record are dated May 2002 and the manual is © 2002; the '794 priority date is 2002‑06‑12. That is a gap of only weeks. ZA Pro 3.0 is § 102(a) art only if it predates the applicant's actual invention date. A well‑advised patentee will attempt to swear behind the NPL under 37 C.F.R. § 1.131 (a showing is not available against § 102(b)‑qualified art, but these May‑2002 items are not § 102(b) art). A petitioner should therefore anchor the ground on the patents (Shipley 2000; Porras 2001; Lockhart 2001; US 7,014,807 as of its 2001‑04‑13 § 102(e) date) and use ZoneAlarm as a secondary teaching, or else develop a pre‑2002 edition of the ZoneAlarm documentation as the primary indicator reference.
  4. Claim construction fight on "only when." As noted in § 2, claim 1 element J and claim 4 pull in opposite directions. The Board applies Phillips to an expired claim. A petitioner should offer the construction that preserves claim validity (the "only when" governs concurrent, paired triggering) and then show both references' teachings meet it; otherwise the patentee may retreat to the broader reading and moot part of the ground.
  5. Secondary considerations are essentially unclaimed. No record evidence of commercial success with nexus, licensing, copying, or industry praise for this feature appears in the material available; the patent was never asserted and lapsed for non‑payment. If the patentee asserts long‑felt need, the answer is that the ZA Pro NPL of record dates the "need" and the solution to 2002 (and Code Red, July 2001 CERT advisories, dates the specific ARP‑noise problem the spec discusses).

9. Bottom line

  • Ground 1 (strongest): ZoneAlarm Pro 3.0 + US 6,119,236 (Shipley) + US 6,189,035 (Lockhart) — expressly motivated by (a) the patent's own admitted dialog‑box/log‑file problem, (b) US 6,052,788's express statement that a firewall "should provide timely information that enables attacks to be detected," and (c) KSR's known‑technique/known‑element rationales — renders claims 1 and 7 prima facie obvious.
  • Ground 2: Ground 1 + US 5,809,252 + US 6,185,624 (+ US 6,317,837) renders claim 13 obvious, the motivation being the always‑on broadband gateway as the natural inspection point (and the record's own "always‑on cable connection" framing).
  • Ground 3 (alternative primary, avoids NPL dating risk): US 6,327,338 (Porras) + US 6,282,546 (Cisco) + ZoneAlarm Pro 3.0.
  • Dependent claims 2–6 and 8–18 fall with routine design‑choice and threshold‑setting rationales as charted in § 7.
  • The hard part is element J — the concurrent, threshold‑gated pairing of a general "filtering in progress" indicator with a class indicator. That is where a petition lives or dies, because the examiner had every other element in front of him in 2002–2010 and still allowed the claims.

Confidence: The disclosed content of ZoneAlarm Pro 3.0, US 6,119,236, US 6,327,338 and US 6,189,035 was verified against full text/manual excerpts this session (high confidence). The characterizations of US 6,052,788, US 6,282,546, US 6,219,786, US 6,243,815, US 6,317,837, US 5,809,252, US 6,185,624, US 2002/0062450 and US 2002/0133586 are title/record‑level only — I did not verify their column or paragraph text, and any IPR pleading should confirm those passages against the documents themselves. The § 102(a) dating vulnerability for the ZoneAlarm NPL is a legal‑factual risk, not a verified date conflict.

Generated 9/27/2026, 7:42:40 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →