Invalidity dossier
US 8127345
Method and system for managing access to protected computer resources provided via an internet protocol network
Current assignee: Prism Technologies LLC
Added 10/1/2026, 3:55:12 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll verify the patent against live sources before summarizing.
Now let me pull the actual claim language and check for any 2026 activity.
Let me obtain the actual claim text rather than paraphrase from memory.
US Patent 8,127,345 B2 — Verified Summary
Sources consulted: Google Patents (authoritative full text supplied), the granted-PDF OCR at patentimages.storage.googleapis.com/.../US8127345.pdf, the Federal Circuit's Prism Techs. LLC v. T-Mobile USA, Inc. opinion (696 F. App'x 1014), Prism Techs. LLC v. Sprint Spectrum L.P. (849 F.3d 1360), and Justia's claim listing for the '345 patent. Litigation data from the Google Patents "Family has litigation" panel and Unified Patents.
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 8,127,345 B2 |
| Title | Method and system for managing access to protected computer resources provided via an internet protocol network |
| Inventors | Richard L. Gregg (Elkhorn, NE); Sandeep Giri (Omaha, NE); Timothy C. Goeke (Elkhorn, NE) |
| Assignee | Prism Technologies LLC (Omaha, NE) — assignments recorded from Prism Resources Inc. |
| Appl. No. | 11/978,919 |
| Filed | October 30, 2007 |
| Issued | February 28, 2012 |
| Earliest priority claimed | June 11, 1997 (from US 08/872,710, which issued as US 6,516,416) |
| Claims / drawings | 92 claims, 27 drawing sheets |
| Other publication | US 2008/0066168 A1 (published March 13, 2008) |
| PTA | 585 days under 35 U.S.C. § 154(b); patent subject to a terminal disclaimer |
| Status | Expired – Fee Related; adjusted expiration 2019-01-17 |
| Primary CPC | H04L63/10, H04L63/08 & subclasses; G06F21/31, 21/33, 21/335, 21/44; G06F2221/2129 (authenticate client device independently of the user), 2221/2135 (metering), 2221/2141 (access rights) |
Two cautions on identifiers: the granted-PDF OCR renders the second inventor as "Sandeep Girl," where the Google Patents metadata (and Federal Circuit opinions) give "Sandeep Giri" — I report both rather than silently correcting. Also, the abstract as printed contains the phrase "the at least once client computer device"; that is the literal printed text, not a transcription slip on my part.
Abstract (verbatim)
"A method and system for controlling access, by an authentication server, to protected computer resources provided via an Internet Protocol network that includes storing (i) a digital identification associated with at least one client computer device, and (ii) data associated with the protected computer resources in at least one database associated with the authentication server; authenticating, by the authentication server, the digital identification forwarded by at least one access server; authorizing, by the authentication server, the at least one client computer device to receive at least a portion of the protected computer resources requested by the at least one client computer device, based on the stored data associated with the requested protected computer resources; and permitting access, by the authentication server, to the at least the portion of the protected computer resources upon successfully authenticating the digital identification and upon successfully authorizing the at least once client computer device."
Note: the text of the abstract supplied to me in the Google Patents HTML dump was truncated mid-word ("...client computer de"); the complete text above comes from the granted PDF.
Independent claims — partial, with stated uncertainty
⚠️ Important limitation. The Google Patents text dump I was given ends at the abstract and does not include the claims section. I therefore do not have a verbatim claim set from an authoritative source. What follows is what I can ground in quoted court documents and the Justia claim listing, and I flag every gap rather than paraphrasing from memory.
Claim 1 (independent method claim) — quoted by the Federal Circuit from '345 patent col. 34 ll. 17–42, in Prism Techs. LLC v. T-Mobile USA, Inc. (696 F. App'x at 1015). The opinion's reproduction is OCR-fragmented; ellipses below mark where the excerpt itself is incomplete:
"A method for controlling access, by at least one authentication server, to protected computer resources provided via an Internet Protocol network, the method comprising:
receiving, at the at least one authentication server … client computer device with a request from the at least one client computer device for the protected computer resources;
authenticating, by the at least one authentication server … least one access server, the identity data being stored in the at least one authentication server;
… server, the at least one client computer device … associated with the requested protected comput[er resources] … associated with the at least one authentication server; and
permitting access, by the at least one authentication server … protected computer resources upon successful[ly] … successfully authorizing the at least one client computer device."
Plain-language reading of claim 1: A central authentication server sits in front of protected resources on an IP network. It holds (a) identity data for client devices and (b) data describing the protected resources. A client's request reaches the authentication server; identity data forwarded by an "access server" is checked against the stored identity data; the server decides whether that client is entitled to the requested resource; and only if both authentication and authorization succeed does the authentication server let the client through. The recited actor is the authentication server itself, and the elements are the authentication server, access server, IP network, client computer device, and database.
The "identity data" gloss. The Federal Circuit characterized the invention as "systems and methods that control access to protected computer resources by authenticating identity data, i.e., unique identifying information of computer components," and pointed to claim 5's recitation of identity data of "hardware components" ('345 col. 2 ll. 1–24; col. 34 ll. 49–51).
Other independent claims — cannot confirm. Claim 49 is clearly the parent of a second claim family (claims 50–92 each read "The method of claim 49…"), which strongly implies claim 49 is the other independent claim. I could not retrieve claim 49's own text. Claim 33's text likewise was not retrieved; I know only that it was asserted alongside claim 1 against Sprint. Claims 77 and 87, though asserted against T-Mobile, are dependent claims (Justia shows "87. The method of claim 49, further comprising assigning one of a plurality of authorization levels…"). So of the four claim families litigated, I can give verbatim-independent language only for claim 1. I would treat the independent-claim inventory (1, 49) as an inference from dependency structure, not as confirmed fact.
Representative dependent-claim themes (from the Justia listing, all depending from claim 49) — useful for characterizing scope, though these are not independent claims: number of transactions (29); authorization levels assigned to resources and to identity data (39, 87); prompting for identity data plus username/password (90); querying the client device to generate identity data (91); encrypting protected resources (78); placing the authentication server on the same machine as, or a machine separate from, the access server (79, 80); distributing authentication/authorization/permission functions across multiple servers (81, 84–86); authenticating multiple client devices and multiple access servers (82, 83); providing resources to the client upon permission (88); requiring the client to forward its identity data (89); and changing identity data at the access server and forwarding it to the authentication server (92).
Disclosure context (from the specification)
The patent describes a "secure transaction system" with four components: a transaction clearinghouse 30 (SQL database, authentication daemon userauthd, transaction daemon transactiond), account holder administration software 32, a secure transaction server 34 (session manager sessiond, web-server shared object sts.so, login/re-authentication/application/activation CGI programs), and account holder (client) software 36. "Untrusted network" is defined in the specification as "a public network with no controlling organization, with the path to access the network being undefined and the user being anonymous." FIGS. 21–25 cover access devices: hardware token, magnetic card reader, smart card reader, biometric reader, and a TPM-based secure CPU. FIGS. 26–27 cover many-to-many server/clearinghouse topologies and single sign-on across geographically distributed sites.
Litigation and legal status (relevant to any 2026 inquiry)
- Asserted claims: claim 1 (+ claim 33) of the '345 in Prism v. Sprint; claims 1, 77, 87 of the '345 in Prism v. T-Mobile (Nos. 2016-2031, 2016-2049).
- June 2015: D. Neb. jury found Sprint infringed claims 1 and 33 of the '345 and claims 7 and 37 of the '155; $30M reasonable royalty.
- March 2017: CAFC affirmed the $30M award, Prism Techs. LLC v. Sprint Spectrum L.P., 849 F.3d 1360.
- June 23, 2017: CAFC held the asserted claims of the '345 and '155 ineligible under 35 U.S.C. § 101, finding them directed to the abstract idea of controlling access to resources and lacking an inventive concept because they "merely recite a host of elements that are indisputably generic computer components." En banc rehearing was sought (petition at
patentlyo.com/media/2017/08/PrismBrief.pdf) and denied. - August 8, 2017: D. Neb. memorandum opinion applied the invalidity holding to the Sprint case, undoing the $30M verdict.
- Supreme Court cert dockets listed by Google Patents: 17-430, 17-716, 18-1397.
- Termination of rights: adjusted expiration 2019-01-17, status "Expired – Fee Related."
On the 2026 CAFC docket search — negative result
I ran targeted searches for CAFC 2026 docket activity involving US 8,127,345 and found none. The only 2026 Federal Circuit material my searches surfaced was an unrelated matter — Headwater Research LLC v. [Cellco Partnership d/b/a Verizon Wireless](/litigations/by-plaintiff/Cellco%20Partnership%20d%2Fb%2Fa%20Verizon%20Wireless) (E.D. Tex. No. 2:23-cv-00352-JRG-RSP; CAFC No. 26-1884), which concerns different patents and parties and does not involve the '345 patent.
Two honest caveats: (1) I searched via general web search, not a direct query of the Federal Circuit's PACER/CM-ECF or the USPTO Patent Trial and Appeal Board docket systems, so this is a negative search result rather than a certified absence of 2026 proceedings; and (2) given that the '345 patent expired in January 2019 and its asserted claims were held ineligible in 2017, live 2026 appellate activity on this specific patent would be unexpected.
Bottom line: US 8,127,345 is a Prism Technologies patent with a 1997 priority date, issued 2012 on a 2007 continuation application, expired in 2019, whose asserted claims were invalidated under § 101 in 2017 after having supported a $30M verdict. I have high confidence in the bibliographic data, abstract, and litigation history; I have low confidence in any verbatim independent-claim text beyond claim 1, because the claims section was absent from my source text.
Generated 10/1/2026, 4:01:16 PM
Cases on file (7)
Group view →Specific litigation cases in our database that name US patent 8127345. The free-form analysis below may also discuss cases beyond this list.
- Prism Technologies LLC v. AT&T Mobility LLCfiled Apr 4, 20128:12-cv-00122-LES-TDTUnited States District Court for the District of Nebraskaterminated Dec 29, 2014settled
Defendants: AT&T Mobility LLC
- Prism Technologies LLC v. Sprint Spectrum L.P. d/b/a Sprint PCSfiled Apr 4, 20128:12-cv-00123-LES-TDTUnited States District Court for the District of Nebraskajudgment; reversed on § 101; cert denied
Defendants: Sprint Spectrum L.P. d/b/a Sprint PCS
- 8:12-cv-00125U.S. District Court for the District of Nebraska (Omaha)terminated Jul 18, 2019dismissed with prejudice
Defendants: United States Cellular Corporation d/b/a U.S. Cellular
- 8:12-cv-00124-LES-TDTUnited States District Court for the District of Nebraskajudgment; claims held ineligible
Defendants: T-Mobile USA, Inc.
- 8:12-cv-00125-LES-TDTUnited States District Court for the District of Nebraskastayed
Defendants: United States Cellular Corporation
- 8:12-cv-00126-LES-TDTUnited States District Court for the District of Nebraskaconsolidated; '288 withdrawn
Defendants: Cellco Partnership d/b/a Verizon Wireless
- U.S. Court of Appeals for the Federal Circuitaffirmed; rehearing denied; later affirmed vacatur
Defendants: Sprint Spectrum L.P.
Other patents asserted: 8387155
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US patent 8127345 by searching multiple litigation-focused sources.
Let me gather more specifics on the individual cases, outcomes, and any additional litigation.
Let me check for any additional cases, appeals details, and administrative proceedings involving this patent.
Litigation Involving U.S. Patent No. 8,127,345
Patent identified literally as requested: U.S. Patent No. 8,127,345 B2 — "Method and system for managing access to protected computer resources provided via an internet protocol network." Filed Oct. 30, 2007; granted Feb. 28, 2012; priority claimed from US 08/872,710 (June 11, 1997). Owner/assignee: Prism Technologies LLC (Omaha, NE; subsidiary of Prism Technologies Group, Inc.). (Source: https://patents.google.com/patent/[US8127345](/patent/US8127345)/en)
All litigation I could identify in which the '345 patent was actually asserted consists of five parallel complaints filed the same day, April 4, 2012, by Prism Technologies LLC in the U.S. District Court for the District of Nebraska (Omaha), plus their resulting appeals. In every case, Prism was the plaintiff/patentee.
District Court Cases (D. Neb., all filed April 4, 2012)
1. Prism Technologies LLC v. AT&T Mobility LLC (and AT&T Mobility, Inc.)
- Case No. 8:12-cv-00122-LES-TDT (a/k/a 8:12CV122)
- Patents asserted against AT&T: '345, '155, and originally '288
- Status/outcome: Motion to dismiss granted in part with leave to amend (Sept. 6, 2012). Case proceeded to trial (Oct./Nov. 2014); on the last day of trial, just before closing arguments, Prism and AT&T settled, and the court dismissed the claims (Order, Dec. 29, 2014, ECF No. 498). Press reports describe a settlement "on favorable terms" in November 2014.
- Sources: https://caselaw.findlaw.com/court/us-federal-circuit/[1851451](/patent/1851451).html ; https://www.courtlistener.com/opinion/[4373125](/patent/4373125)/prism-technologies-llc-v-sprint-spectrum-lp/ ; https://getfilings.com/sec-filings/[170307](/patent/170307)/Prism-Technologies-Group-Inc_8-K/ex99-1.htm
2. Prism Technologies LLC v. Sprint Spectrum L.P. d/b/a Sprint PCS
- Case No. 8:12-cv-00123-LES-TDT
- Patents asserted: '345, '288 (dropped March 2014); '155 added by amended complaint March 2013
- Status/outcome: Jury verdict for Prism on June 23, 2015 — infringement of claims 1 and 33 of the '345 patent and claims 7 and 37 of the '155 patent; $30 million reasonable royalty, plus $2,001,923 prejudgment interest. Post-trial motions (JMOL/new trial) denied. Federal Circuit affirmed (Mar. 6, 2017). After the T-Mobile invalidity ruling, the district court granted Sprint's Fed. R. Civ. P. 60(b) motion and set aside the $30 million judgment (Aug. 8, 2017); Federal Circuit affirmed (2019). Case closed June 25, 2019.
- Sources: https://www.courtlistener.com/opinion/4373125/prism-technologies-llc-v-sprint-spectrum-lp/ ; https://www.vitallaw.com/news/patent-d-neb-sprint-relieved-of-30m-judgment-after-security-systems-patents-invalidated/ipm011d06cb407ccc10008ff290b11c2ac4f106 ; https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/
3. Prism Technologies LLC v. T-Mobile USA, Inc.
- Case No. 8:12-cv-00124-LES-TDT
- Patents asserted: '345 and '155
- Status/outcome: District court denied T-Mobile's § 101 summary-judgment motion and granted Prism's cross-motion for eligibility (Sept. 22, 2015). Jury returned a verdict of non-infringement (Oct. 2015). On appeal, the Federal Circuit held the asserted claims invalid under 35 U.S.C. § 101 (Alice) — June 23, 2017, 696 F. App'x 1014; cert. denied 138 S. Ct. 689 (2018). This is the decision that invalidated the claims and effectively terminated the other Prism cases.
- Sources: https://cases.justia.com/federal/appellate-courts/cafc/16-2031/16-2031-2017-06-23.pdf ; https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/
4. Prism Technologies LLC v. United States Cellular Corporation
- Case No. 8:12-cv-00125-LES-SMB
- Patents asserted: '345, '155 (and originally '288)
- Status/outcome: Stayed pending the Sprint and T-Mobile appeals. After those appeals were resolved against Prism, the court issued a show-cause order (June 25, 2019) and then dismissed the action with prejudice (July 18, 2019, Judge Bataillon).
- Source: https://docs.justia.com/cases/federal/district-courts/nebraska/nedce/8:2012cv00125/[58577/369](https://assignmentcenter.uspto.gov/search/patent/reelFrameDetail?reelFrame=58577-0369)
5. Prism Technologies LLC v. [Cellco Partnership d/b/a Verizon Wireless](/litigations/by-plaintiff/Cellco%20Partnership%20d%2Fb%2Fa%20Verizon%20Wireless) (and Verizon Communications, Inc.)
- Case No. 8:12-cv-00126-LES-SMB
- Patents asserted: '345, '155 (and originally '288)
- Status/outcome: Motion to dismiss granted in part with leave to amend (Sept. 6, 2012). Defendant Verizon Communications, Inc. voluntarily dismissed without prejudice (June 26, 2012). Case stayed pending Sprint/T-Mobile appeals; dismissed with prejudice (July 18, 2019).
- Sources: https://docs.justia.com/cases/federal/district-courts/nebraska/nedce/8:2012cv00126/58578/34 ; https://docs.justia.com/cases/federal/district-courts/nebraska/nedce/8:2012cv00125/[58577/369](https://assignmentcenter.uspto.gov/search/patent/reelFrameDetail?reelFrame=58577-0369)
Appellate Proceedings
| Court / No. | Case | Result |
|---|---|---|
| Fed. Cir. 16-1456 (lead) & 16-1457 (cross-appeal) | Prism v. Sprint | Affirmed Mar. 6, 2017, 849 F.3d 1360 (Taranto, Linn, Chen, JJ.); rehearing denied May 2017 |
| Fed. Cir. 16-2031 & 16-2049 | Prism v. T-Mobile | Claims invalid under § 101 (Alice), June 23, 2017, 696 F. App'x 1014 |
| Fed. Cir. 18-1108 | Prism v. Sprint (appeal from Rule 60(b) relief) | Affirmed 2019, 757 F. App'x 980 |
| U.S. Supreme Court (cert. denied) | 138 S. Ct. 429 (Nov. 6, 2017) — Sprint matter; 138 S. Ct. 689 (2018) — T-Mobile matter; cert. denied June 10, 2019 — '18-1397 (Prism's petition re: retroactive invalidation) | Review denied |
The Google Patents litigation panel also lists associated docket identifiers 17-430, 17-716, 18-1397 (Supreme Court) and 16-1456, 16-1457, 16-2031, 16-2049, 18-1108 (Federal Circuit). I can confirm from the primary sources that 18-1397 is Prism's 2019 cert. petition and that cert. was denied in the Sprint and T-Mobile matters; I cannot confirm with high confidence from the search results exactly which party filed each of 17-430 and 17-716, so those are reported as docket identifiers only. (Source: https://patents.google.com/patent/US8127345/en ; https://www.supremecourt.gov/DocketPDF/18/18-1397/98180/20190501124836955_Prism%20Technologies%20Petition.pdf)
Important Practice Note
The '345 patent (together with U.S. 8,387,155) was held invalid as patent-ineligible under 35 U.S.C. § 101 in Prism Technologies, LLC v. T-Mobile USA, Inc. (Fed. Cir. June 23, 2017). That ruling was applied preclusively to vacate the Sprint judgment and drove the dismissal (with prejudice) of the U.S. Cellular and Verizon cases. Any analysis of the '345 patent's enforceability must account for this.
Caveats / Limitations
- No PTAB (IPR/PGR/CBM) proceedings involving the '345 patent were identified in the sources reviewed. My dedicated search on that point returned no results before I had to stop; I therefore cannot confirm the absence of such proceedings with high confidence, and that point should be verified.
- I found no other district-court litigation (in any other jurisdiction) in which U.S. 8,127,345 was asserted beyond the five Nebraska actions above. This is stated as "none identified," not as a definitive negative.
- Case numbers, dates, and outcomes above are drawn from the Federal Circuit opinions, district-court orders, and party statements cited. For a definitive docket check, PACER (D. Neb.) and the Unified Patents litigation portal (https://portal.unifiedpatents.com/litigation/caselist) should be consulted, as the litigation data on the Google Patents page is expressly described as an assumption and not a legal conclusion.
Generated 10/1/2026, 4:01:11 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Prism Technologies LLC
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll start by verifying the canonical structured list against live sources, then search for any PTAB activity involving this patent.
The first search surfaced an unrelated patent (7,035,345) — not our patent. Let me run targeted searches on PTAB proceedings for the '345 patent specifically.
Let me run a few more targeted searches to confirm the absence of AIA trials and check for any reexamination or later filings.
PTAB / AIA Trial Analysis — U.S. Patent No. 8,127,345
Note on source hierarchy. I worked from the structured "PTAB proceedings on file" block supplied in the prompt, which is the canonical USPTO Open Data Portal (ODP) list, and attempted to corroborate it with live search. The structured block states affirmatively that ODP returns no AIA trial proceedings for this patent. My targeted searches (PTAB docket strings, petitioner names, patent number, patent-owner portfolio) surfaced no IPR, PGR, or CBM against 8,127,345 and nothing to contradict the ODP result. I therefore report zero AIA trials and flag two "near-miss" hits that a careless researcher would wrongly attribute to this patent.
Proceedings overview
Total AIA trial proceedings on file for US 8,127,345: 0 — no IPRs, no PGRs, no CBMs, no derivation proceedings; the breakdown by status (active / invalidated / sustained / settled / denied) is therefore not applicable, and the defensive posture a defendant inherits is not "hardened by two IPRs" but the opposite: the patent was never stress-tested at the PTAB at all, and its asserted claims were instead held *invalid as patent-ineligible under 35 U.S.C. § 101 by the Federal Circuit in Prism Technologies LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. 2017-06-23)* — a court, not the Board, killed this patent. (Sources: structured ODP block in prompt; https://patents.google.com/patent/US8127345/en ; https://cases.justia.com/federal/appellate-courts/cafc/16-2031/16-2031-2017-06-23.pdf)
No proceedings to enumerate
There is no FWD, no institution decision, no panel, no settlement, and no PTAB appeal for this patent, because no petition was ever filed. For the record, the claim-level outcome that a defendant actually needs came from Article III:
- Adjudicated-invalid claims: claims 1, 77, and 87 of the '345 patent (the claims Prism identified as "the Asserted Claims … the only claims addressed by the Panel's decision"). Claim 1 was treated as representative. (Source: Prism en banc petition, 16-2031, https://patentlyo.com/media/2017/08/PrismBrief.pdf)
- Claims the jury found infringed (Sprint), later vacated: claims 1 and 33 of the '345 patent. (Source: https://www.courtlistener.com/opinion/[4373125](/patent/4373125)/prism-technologies-llc-v-sprint-spectrum-lp/)
- Statutory basis: § 101 (Alice/Mayo), not §§ 102/103/112. The court held the claims directed to the abstract idea of "controlling access to resources" with no inventive concept beyond generic computer components.
Near-miss #1 — must NOT be attributed to this patent
CBM2014-00100 (consol. CBM2015-00009) and IPR2014-00475 — these challenged U.S. Patent No. 7,631,191 B2 (the "Glazer" patent), owned by Secure Axcess, LLC, a different Prism Technologies Group subsidiary. The PTAB invalidated the '191 claims, but on 2017-02-21 the Federal Circuit vacated the CBM ruling (the '191 patent was not a "covered business method") and affirmed only the IPR. Prism's own SEC filing describes these — a different patent, different family, different owner-of-record. These are not proceedings on the '345 patent. (Source: https://www.getfilings.com/sec-filings/[170224](/patent/170224)/Prism-Technologies-Group-Inc_8-K/)
Near-miss #2 — a patent-number transposition trap
A live search hit returned IPR2025-00727, a pending petition referencing a "345 Patent." On inspection the caption is U.S. Patent No. 7,035,345 (Smart RF / Booth v. Leyendecker, amplifier linearization), filed by unrelated parties. It is not U.S. 8,127,345 and must not be cited as a proceeding against Prism's patent. (Source: https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1557522](/patent/1557522)/download-documents)
Near-miss #3 — "Unified Patents" is a data vendor here, not a petitioner
The Google Patents page carries a "Unified Patents Litigation Data" link (https://portal.unifiedpatents.com/litigation/Nebraska%20District%20Court/case/8%3A12-cv-00123). That is attribution of a litigation database feed, not evidence that Unified Patents filed an IPR. There is no defensive aggregator in the chain on this patent.
Strategic summary
Claim status. Of the claims ever asserted, 1, 77, and 87 of the '345 patent are invalidated under § 101 by the Federal Circuit's 2017-06-23 decision. Claim 33 was adjudged infringed by a jury in Prism v. Sprint but that judgment was set aside on Sprint's Rule 60(b) motion after the T-Mobile invalidity ruling and the vacatur was affirmed (Fed. Cir. 18-1108, 757 F. App'x 980). Untested claims: the '345 patent has 87 claims, the large majority of which were never construed, never litigated, and never adjudicated. Prism expressly argued on rehearing that the panel "overgeneralized" and did not consider the dependent claims' extra limitations (e.g., dependent claim 77's billing-tracking and the server-provides-resources limitations). That is the patent owner's own roadmap to arguing that unadjudicated dependent claims are not collaterally estopped — but it cannot revive claims 1, 77, or 87, which were named and decided.
Estoppel landscape. Because no IPR/PGR/CBM was ever instituted, there is no 35 U.S.C. § 315(e)(2) statutory estoppel — a defendant today faces no PTAB-based bar on any prior-art ground. The binding constraint is different and harsher for the patent owner: issue preclusion (collateral estoppel) from the T-Mobile judgment on claims 1/77/87, which requires identity of the patent owner (Prism) — a requirement satisfied in any future Prism assertion. Two practical caveats: (i) the T-Mobile decision is nonprecedential (Rule 36-adjacent, 696 F. App'x 1014), so it binds only as preclusion between the parties, not as circuit precedent; and (ii) it decided § 101 only — it says nothing about §§ 102/103/112, so those grounds remain fully open against any claim, including the unadjudicated dependent claims.
Pattern signals. No repeated-petitioner pattern, no PTAB appeal history, no aggregator — because there was never a single petition. The one-year § 315(b) windows opened when the five April 2012 Nebraska complaints were served, and five sophisticated telecom defendants (AT&T, Sprint, T-Mobile, U.S. Cellular, Verizon) collectively chose litigation over the PTAB. That is the single most notable signal here: on a patent that a jury later valued at $30 million, the absence of even one IPR is unusual and suggests the defendants preferred § 101 at the district court or had already priced in the art.
The dispositive practical fact. Per Google Patents, the '345 patent carries a status of "Expired – Fee Related," adjusted expiration 2019-01-17. (Source: https://patents.google.com/patent/US8127345/en) An expired, court-invalidated patent supports neither injunctive relief nor a live validity contest.
Recommended next steps
- If you have received a demand letter or been sued on the '345 patent, say so and I will research the specific assertion — the Google Patents litigation panel shows no new district-court cases beyond the five 2012 Nebraska actions, and no PTAB activity, but that is "none identified," not a certified negative.
- Link the kill shot directly. The Federal Circuit disposition is at 16-2031 / 16-2049, https://cases.justia.com/federal/appellate-courts/cafc/16-2031/16-2031-2017-06-23.pdf and mirrored at https://www.courtlistener.com/opinion/[4403153](/patent/4403153)/prism-technologies-llc-v-t-mobile-usa-inc/. The operative holding is that the asserted claims (including claim 1) are ineligible under § 101; a demand letter citing claims 1, 77, or 87 is citing claims that a Federal Circuit panel (Prost, C.J., Lourie and Schall, JJ.) has already held invalid.
- Do not plan an IPR as your primary defense. The patent expired 2019-01-17, so (a) there is no prospective injunctive exposure, (b) the § 315(b) one-year clock is long past for the original defendants, and (c) the Board is unlikely to spend resources on an expired patent whose key claims are already judicially invalidated. If a new plaintiff asserted the unadjudicated dependent claims, the realistic posture is a § 101 motion plus §§ 102/103 invalidity — and your prior-art grounds are unconstrained by any IPR estoppel.
- If you want the absence verified to a legal standard, run the patent number through PTAB E2E at https://ptab.uspto.gov (search by patent number) and the USPTO Patent Center "Post-Grant" tab for 8,127,345; also check for ex parte reexamination, which is not an AIA trial and would not appear in the ODP AIA-trial block.
Confidence and limitations. High confidence that no IPR/PGR/CBM was filed on 8,127,345, based on the canonical ODP block plus corroborating searches. I could not complete a full PTAB E2E docket pull (search budget exhausted), and I did not independently verify whether an ex parte reexamination was ever requested — that is the one residual gap worth a manual check. No proceeding numbers have been invented; the two numbers I do cite are affirmatively identified as belonging to other patents.
Generated 10/1/2026, 4:01:45 PM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2011-01-31 · Assignment
Richard L. GreggPrism Resources
internal reorg
? · recorded 2011-02-08 · Assignment
Prism ResourcesPRISM TECHNOLOGIES LLC
internal reorg
? · recorded 2011-03-01 · Assignment
Sandeep Giri; Timothy C. GoekePrism Technologies, L.L.C.
internal reorg
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment chain for this patent before writing anything. Let me run several targeted searches.
Good — significant findings on litigation funding and the 2015 acquisition. Now let me chase the actual recorded assignments and correspondents.
Source note up front: I could reach the USPTO Assignment Center data only indirectly — through the Google Patents legal-events ("reassignment") panel that mirrors USPTO assignment records. That panel reports assignor/assignee/date but not reel/frame and not correspondent. I therefore reconstruct the chain below from assignor/assignee/date evidence plus SEC filings, and I flag the reel/frame + correspondent fields as not retrieved. No reel/frame or correspondent value below is fabricated or reconstructed by pattern.
Inventors
| Inventor | Residence of record | Employer at time of filing |
|---|---|---|
| Richard L. Gregg | Elkhorn, Nebraska | Not established from available records. The recorded 2011 assignment from Gregg to Prism Resources Inc. indicates the invention was made for, or the rights were transferred to, Prism Resources. |
| Sandeep Giri | Omaha, Nebraska | Not established; assigned his rights to Prism Technologies, L.L.C. in the 2011-03-01 recording. |
| Timothy C. Goeke | Elkhorn, Nebraska | Same as Giri — assigned to Prism Technologies, L.L.C. in the 2011-03-01 recording. |
Notes on pattern:
- Inventor names are not in dispute but the OCR is. Check the printed front page against the Google Patents metadata: the OCR renders the second inventor as "Sandeep Girl"; the metadata and Federal Circuit opinions give "Sandeep Giri." Report the OCR faithfully; do not silently correct.
- Split assignment chain among co-inventors — this is the one genuinely unusual feature here. Gregg's rights went to Prism Resources Inc. while Giri's and Goeke's went to Prism Technologies, L.L.C. — different assignees, recorded 29 days apart in 2011. A patent whose co-inventors assigned to two differently named entities requires a written chain-of-title (
47) unless a later link joins them. - The "inventors departed within 12 months of filing" tell is not shown. Prism Resources is reported to have operated roughly 1991–2001; Prism Technologies LLC was formed in August 2003 (per Gregory J. Duman's SEC-referenced bio: "President, Chief Financial Officer and a director of Prism since its inception in August 2003"). That is a multi-year gap, not a 12-month departure. I could not retrieve any employment-termination evidence, so mark this signal not established rather than absent.
Original assignee
Prism Technologies LLC, Omaha, Nebraska (per Google Patents: "Original Assignee — Prism Technologies LLC"; complaint address of record 14707 California Street, Omaha, NE 68154). Two cautions:
- Prism Technologies LLC is not the entity named on the underlying 1997 priority filing. The 1997 application (US 08/872,710, which issued as US 6,516,416) is attributed to Prism Resources in FreePatentsOnline's assignee listing, and a 2005 District of Delaware AO-120 form in Prism Technologies LLC v. Verisign, RSA Security, Netegrity, Computer Associates and Johnson & Johnson (1:05-cv-00214-JJF, filed 04/12/2005) lists the Holder of '416 as "Prism Resources" — i.e., the licensor entity was still Prism Resources while the litigant was Prism Technologies LLC. That gap is exactly what the 2011 recordings close.
Primary line of business at grant (2012): patent licensing and enforcement only. Ars Technica's contemporaneous coverage, relayed by RB.ru, describes Prism Technologies as "founded as a successor to Prism Resources (which existed 1991 to 2001)… currently focused exclusively on licensing and litigation," owning 30+ patents. Prism Technologies Group's own 10-K confirms: "In 2015, we generated $700,000 in revenues from our patent licensing and enforcement business; in 2014, we did not generate any revenues."
Did it ship a product embodying the claims? No evidence of a commercial product. The only commercialization-adjacent fact in the record runs the other way — T-Mobile's on-sale-bar argument at trial relied on testimony that "Prism made a proposal in March of 1996 to a company called DTN to help fund the development of the invention" (D. Neb. 8:12-cv-00124, Order at 6). That is an offer to fund development, and Prism's position was that it was not offering to sell technology. Register this as an absence of product evidence, not as proof of one.
Current status: Not operating. Chain of control:
- Prism Resources Inc. (approx. 1991–2001) — developer-era entity.
- Prism Technologies LLC (formed Aug. 2003) — pure licensing/enforcement vehicle. Wholly owned subsidiary of Internet Patents Corporation (Nasdaq: IPCI) after a reverse triangular merger completed March 26, 2015, in which Strategic Concepts Acquisition Corp. (a Delaware sub of IPC) merged into Prism. Consideration: $16.5M cash + 3.5M shares, plus contingent revenue share up to ~$49.5M. Duman became a Prism officer/director and an IPC director. (SEC Form 8-K, event date 2015-03-26, filed 2015-03-30: https://getfilings.com/sec-filings/[150330](/patent/150330)/Internet-Patents-Corp_8-K/)
- Internet Patents Corporation (SEC CIK 1077370) — the former InsWeb Corporation, an online insurance lead-generation business that exited operations around December 21, 2011 and re-purposed as a patent licensing company; renamed Prism Technologies Group, Inc. Subsidiaries included Secure Axcess, LLC and Millenium Biologix, LLC.
- Financial condition: impaired, not healthy. A $23.4M write-down of the acquired Prism patent portfolio was booked because revenues were "significantly lower than anticipated" (2015 10-K). The Q3 2017 10-Q discloses that "the installment payments due on December 31, 2015, June 30, 2016 and December 2016 have not been paid." I found no bankruptcy filing document for Prism Technologies LLC or Prism Technologies Group, so I do not assert Chapter 7/11.
Assignment timeline
Data-gap disclosure — read before relying on this section. The USPTO Assignment Center record set for this patent (reel/frame, conveyance type as recorded, correspondent of record) was not retrievable in this session; searches against the Assignment Center and its mirrors returned no reel/frame or correspondent values, and the second and third search batches were cut off by a tool limit. What follows is the assignor/assignee/date chain as reported by the Google Patents legal-events panel, which is a mirror of USPTO reassignment data. Reel/frame and correspondent are stated as not retrieved — they are the single highest-value thing left to pull, and I will not guess them.
2011-01-31 (as reported; execution vs. recording date not distinguished in this source) — Reel not retrieved
- Conveyance: Assignment (inferred from the "Assigned to" event type)
- Assignor: Richard L. Gregg
- Assignee: Prism Resources (recorded as "Prism Resources"; the priority patent's Delaware AO-120 lists the holder as "Prism Resources")
- Correspondent: not retrieved
- Context: internal chain completion — the named inventor's rights restored to the pre-2003 developer entity, reviving title that had been in limbo since Prism Resources wound down around 2001.
2011-02-08 — Reel not retrieved
- Conveyance: Assignment
- Assignor: Prism Resources Inc.
- Assignee: Prism Technologies LLC
- Correspondent: not retrieved
- Context: internal reorg / transfer-to-licensor — the historic Prism Resources rights move into the 2003-vintage licensing LLC.
2011-03-01 — Reel not retrieved
- Conveyance: Assignment
- Assignor: Sandeep Giri; Timothy C. Goeke
- Assignee: Prism Technologies, L.L.C.
- Correspondent: not retrieved
- Context: chain completion — the remaining two co-inventors' rights are folded in, closing the co-ownership defect created by the split between the 2011-01-31 and 2011-03-01 transfers.
- Literal-record caution: the assignee string in this third link is punctuated "Prism Technologies, L.L.C." with internal commas, whereas the 2011-02-08 link reads "Prism Technologies LLC." I am reporting both strings as recorded rather than normalizing. Whether this is a genuine second legal name or a formatting artifact in the indexing layer cannot be resolved without the reel/frame image.
2015-03-26 (executed) — Reel not retrieved; no corresponding 2015 entry found
- Conveyance: Merger (reverse triangular merger of Strategic Concepts Acquisition Corp. into Prism Technologies, LLC)
- Assignor/constituent: Prism Technologies, LLC (surviving subsidiary)
- Assignee/parent: Internet Patents Corporation (later Prism Technologies Group, Inc.)
- Correspondent: not retrieved
- Context: transfer-to-asserter / monetization — the patent-holding LLC was acquired in full by a public licensing company for cash plus a contingent revenue share.
- Finding: the Google Patents legal-events panel for US 8,127,345 shows no 2015 reassignment entry. That is consistent with a merger in which the subsidiary survived and retained record title (so no assignment of the '345 needed recording, the LLC's ownership simply became indirect). It is also consistent with an unrecorded transfer. I cannot distinguish the two without the Assignment Center record set, and I note as a related (different-patent) data point that counsel in 2021 reported that USPTO records still showed the '375,212 / '688,990 auth-token patents assigned to Prism Technologies LLC even while a third party was asserting them — i.e., this family has a documented habit of unrecorded downstream transfers (https://www.thompsoncoburn.com/insights/non-practicing-entities-increasingly-are-targeting-banks-and-financial-institutions-in-patent-litigation-102jbks/).
Correspondent analysis: not possible on this record. I retrieved zero correspondent values for the '345 chain, so I cannot call recurrence or non-recurrence. One explicit warning for whoever completes this: do not backfill the correspondent field with litigation counsel. Kramer Levin Naftalis & Frankel LLP appears as Prism's litigation counsel in the Bentham funding instructions (https://contracts.justia.com/companies/prism-technologies-group-inc-16325/contract/[506099](/patent/506099)/), and Prism's appellate brief carries a different signature block — neither is the assignment correspondent unless the reel/frame image says so.
Timeline diagram
timeline
title Ownership of US 8127345
1997 : Priority application filed
: Invented by Gregg Giri and Goeke
2003 : Priority patent 6516416 issues
: Prism Technologies LLC formed
2005 : Prism sues Verisign and RSA on 6516416
2007 : Continuation application filed
2011 : Three confirmatory assignments recorded
2012 : Patent 8127345 issues
: Five carrier suits filed in Nebraska
: Bentham funds the litigation
2015 : Prism acquired by Internet Patents Corp
: Sprint jury awards 30 million dollars
2017 : Claims held invalid under section 101
2019 : Patent expires as fee related
NPE / troll-pattern signals
1. Shell-entity transfer — present (moderate-to-strong). The chain runs from the developer-era entity (Prism Resources, 1991–2001) into Prism Technologies LLC (formed Aug. 2003), which shipped no product and by its parent's own description operated only a "patent licensing and enforcement business," generating $0 revenue in 2014 and $700,000 in 2015. The transfer out of Prism Technologies LLC to Internet Patents Corporation — itself a repurposed former operating company — is the shell/roll-up step. Caveat I am holding to: I have no reel/frame for any link, so naming alone is not doing the work here; the SEC 8-K and 10-K disclosures are. The registered-agent/address evidence the prompt asks for (single-member Delaware LLC, agent address) was not retrieved.
2. Known asserter in the chain — present (strong). Prism Technologies LLC / Prism Technologies Group, Inc. is documented as an NPE by third-party coverage, not merely by naming: Thompson Coburn (Nov. 9, 2021) states plainly that "Prism Technologies LLC is a subsidiary of Prism Technologies Group, Inc., which is a non-practicing entity that is publicly traded as an over-the-counter (OTC), penny stock." Prism is not on the prompt's enumerated list (Acacia, Marathon, IV, IPNav, Wi-LAN, Round Rock, etc.), so I score this on the documented-NPE-status evidence rather than on list membership. Assertion volume supports it: five Nebraska carrier suits on this patent (8:12-cv-00122 through -00126, filed 2012-04-04), plus Prism v. RIM/Microsoft (8:08-cv-537, filed Dec. 29, 2008, on the sibling '288), plus a docket spanning Nintendo, EMC and PNC Bank. This does not contradict the prior Litigation section — no additional '345 suits exist; the extra defendant names come from sibling-patent campaigns.
3. Repeat correspondent across the chain — unclear. No correspondent value exists in my retrieved record for any of the four links. Cannot be called either way. This is the gap most worth closing, because it is the cheapest way to tie Prism to other asserted portfolios.
4. Cascading transfers — present (weak-to-moderate). Three assignments recorded within 29 days (2011-01-31 → 2011-02-08 → 2011-03-01) moving rights through Prism Resources → Prism Technologies LLC → Prism Technologies, L.L.C., followed by a merger up to Internet Patents Corporation in 2015. The 2011 sequence is a rapid three-hop chain, but it is a clean-up cascade within a single control group rather than a march through unrelated LLCs, which is why I score it below the strongest tier.
5. Pre-litigation transfer — not present. The 2011 recordings precede the first '345 assertion (2012-04-04) by roughly 13 months, outside the 6-month window. The 2015 merger occurred during the Sprint and T-Mobile litigations, not before them. Timing alone does not support this signal. (Separately, the 2011 clean-up came about two years after the Dec. 2008 RIM/Microsoft '288 suit — the chain was perfected for the later, larger assertion wave.)
6. Bankruptcy fire-sale — not present / unclear. No bankruptcy filing by Prism Technologies LLC or Prism Technologies Group was identified; the '345 was never sold through an estate. The company did show severe distress — a $23.4M portfolio impairment and three missed installment payments (due 2015-12-31, 2016-06-30, 2016-12) per the Q3 2017 10-Q — but distress is not a fire-sale, and I do not upgrade it.
7. Privateering — not present. There is no operating-company parent transferring to an NPE to assert on its behalf. The patent sat in the licensing entity throughout its monetization life.
8. Defensive aggregator (anti-NPE) — not present. The chain terminates at an asserting party, not at RPX, AST, LOT, Unified Patents or OIN. Inverse signal does not apply.
Additional signal not on the prompt's list — third-party litigation finance — present (strong, and independently corroborating). Prism Technologies LLC entered a Litigation Funding Agreement with Bentham Capital LLC, first dated November 29, 2012, replaced/extended by an agreement dated December 15, 2016, with Security Finance LLC as collateral agent and an irrevocable instruction directing Kramer Levin to pay litigation proceeds to Bentham before Prism, and granting Bentham a security interest in the claims (https://contracts.justia.com/companies/prism-technologies-group-inc-16325/contract/506099/). A further $500,000 non-recourse financing closed December 21, 2016, repayable at 2.5x–3x out of Sprint Litigation proceeds, with a security interest in the proceeds of "any other patent infringement cases" (8-K coverage: https://marketexclusive.com/prism-technologies-group-inc-nasdaqprzm-files-an-8-k-entry-into-a-material-definitive-agreement/2016/12/). Contingent-fee litigation funding with a claim-level security interest is a hallmark of assertion-driven monetization, and it explains the revenue-share structure of the 2015 acquisition.
Verdict
NPE — high confidence.
The chain runs from a developer-era entity through a licensing-only LLC with no products and $0 licensing revenue in 2014, up into a publicly traded non-practicing entity — Prism Technologies LLC → Internet Patents Corporation / Prism Technologies Group, Inc. via the March 26, 2015 reverse triangular merger ($16.5M cash + 3.5M shares + up to $49.5M contingent revenue share; SEC 8-K, https://getfilings.com/sec-filings/150330/Internet-Patents-Corp_8-K/), with the parent's own 10-K confirming an enforcement-only business and booking a $23.4M impairment of the acquired Prism portfolio. That supplies two strong signals on its own — shell/roll-up transfer and documented-NPE-in-the-chain — and a third independent one: Bentham Capital's claim-level, security-interest-bearing litigation funding (Nov. 29, 2012; Dec. 15, 2016) of the very suits asserting this patent. The 2011-01-31 → 2011-03-01 three-hop clean-up cascade inside Prism's control group adds a further, weaker cascade indicator.
Two limits on this verdict, stated so it is not over-read: (i) no reel/frame or correspondent value was retrieved for any link, so the "repeat correspondent" signal is unresolved and the shell-transfer call rests on SEC/press evidence rather than on the assignment images; and (ii) the asserted claims of the '345 were held ineligible under 35 U.S.C. § 101 in Prism Technologies LLC v. T-Mobile USA, 696 F. App'x 1014 (Fed. Cir. June 23, 2017), and the patent expired 2019-01-17 — so the monetization campaign is historical, and "current assignee" should be read as of the last recorded event, not as of 2026.
Verification links: https://assignmentcenter.uspto.gov/ · https://assignment.uspto.gov/patent/index.html · https://patents.google.com/patent/US8127345/en (legal events panel).
Generated 10/1/2026, 4:02:16 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll verify the specific patent and its cited prior art against live sources before compiling anything.
The search results didn't surface the front-page "References Cited" list. Let me pull the patent's own citation data directly.
Prior Art Analysis — US 8,127,345 B2
Search performed: targeted web queries against Google Patents, Justia, FreePatentsOnline, Unified Patents, PTAB/PTACTS, and general web indices, on 2026-10-01.
Flag on the task parameters: the task header states the current date is April 26, 2026, while my operating context for this session is October 1, 2026. I am not reconciling these silently — I report both. Neither date materially affects a patent that expired 2019‑01‑17, but the discrepancy is noted per instructions.
1. Patent identification — confirmed
| Field | Value |
|---|---|
| Number | US 8,127,345 B2 (literal, as queried) |
| Title | Method and system for managing access to protected computer resources provided via an internet protocol network |
| Inventors | Richard L. Gregg; Sandeep Giri; Timothy C. Goeke |
| Assignee | Prism Technologies LLC |
| Appl. No. / Filed | 11/978,919 / 2007‑10‑30 |
| Granted | 2012‑02‑28 |
| Priority | 1997‑06‑11 (from US 08/872,710) |
| Status | Expired – Fee Related; adjusted expiration 2019‑01‑17 |
Source: https://patents.google.com/patent/US8127345/en
I did not return or blend results for similar numbers (e.g., US 8,387,155, US 9,544,314, US 8,127,344). Where sibling patents appear below, they are identified explicitly as siblings, not substituted.
2. ⚠️ Critical gap: I could not retrieve the '345 front page "References Cited" table
Stating this plainly rather than fabricating a chart:
- The authoritative Google Patents full text I was supplied terminates at the abstract. It contains the specification (summary, figures, detailed description, component tables) but omits both the claims section and the "References Cited" / "Patent Citations" tables.
- My live searches for the specific citation table — including
"8127345" "References Cited", Justia's '345 page, and the granted-PDF front page — did not return a source containing that table. I reached my step limit before exhausting alternative routes (PatentCenter, Global Dossier, the granted-PDF OCR atpatentimages.storage.googleapis.com). - Consequently, I cannot state, as fact, which references appear on the face of US 8,127,345, nor which examiner cited them, nor what the examiner's § 102/§ 103 rejections relied on during prosecution.
Any answer that presented a confident, itemized "References Cited" list for this patent would be reconstructed from memory and would violate the instruction not to fabricate. I have not done that.
What follows is what is documentable, with its provenance and its limitations stated at each step.
3. Documented reference-level art for this specification
The '345 shares its specification with the family's earlier published application US 2003/0046589 A1 ("System and Method for Securing Transactions and Computer Resources with an Untrusted Network"). Unified Patents publishes a machine-generated citation map for that publication, listing 99 references. The following were returned in my search of that page. Treat these as citation-map references for the shared specification — not as verified front-page citations of the '345 itself.
Source: https://portal.unifiedpatents.com/patents/patent/US-20030046589-A1
| Reference | Earliest priority shown | Title / subject | Originator |
|---|---|---|---|
| US 5,708,780 | 1995‑06‑06 | Internet Server Access Control and Monitoring Systems | Open Market Inc. (now Data Return Managed Services / Soverain IP) |
| US 5,841,970 | 1995‑09‑07 | Authentication Method for Networks | Identity Verification Solutions LLC |
| US 5,754,864 | 1992‑04‑09 | Software Piracy Detection System | Charles E. Hill & Assoc. |
| US 5,229,764 | 1991‑06‑19 | Continuous Biometric Authentication Matrix | — |
| US 5,721,781 | 1995‑09‑12 | Authentication System and Method for Smart Card Transactions | Microsoft Technology Licensing |
| US 5,032,979 | 1990‑06‑21 | Distributed Security Auditing Subsystem for an Operating System | IBM |
| US 5,357,573 | 1991‑08‑11 | — | Intelligent Solution Services GmbH |
| US 6,047,376 | 1996‑10‑17 | Client-Server System, Server Access Authentication Method, Memory Medium, Issuance Device | Toshiba Information Systems Japan |
| US 5,592,553 | 1993‑07‑29 | Authentication System Using One-Time Passwords | — |
| US 4,916,738 | 1986‑11‑04 | Remote Access Terminal Security | — |
| US 5,379,343 | 1993‑02‑25 | Detection of Unauthorized Use of Software Applications in Communication Units | Motorola |
| US 5,371,794 | 1993‑11‑01 | Method and Apparatus for Privacy and Authentication in Wireless Networks | Oracle America |
| US 5,485,409 | 1992‑04‑29 | Automated Penetration Analysis System and Method | — |
| US 4,864,494 | 1986‑03‑20 | Software Usage Authorization System with Key | Computerized Data Systems for Manufacturing |
| US 5,629,980 | 1994‑11‑22 | System for Controlling the Distribution and Use of Digital Works | ContentGuard Holdings |
| US 5,659,616 | 1994‑07‑18 | Method for Securely Using Digital Signatures in a Commercial Cryptographic System | — |
| US 5,502,831 | — | Method for Detecting Unauthorized Modification of a Communication or Broadcast Unit | — |
| US 5,774,552 | 1995‑12‑12 | Method and Apparatus for Retrieving X.509 Certificates from an X.500 Directory | NCR |
| US 5,497,421 | 1992‑04‑27 | Method and Apparatus for Protecting the Confidentiality of Passwords in a Distributed Data Processing System | Hewlett-Packard |
| US 5,416,842 | 1994‑06‑09 | Method and Apparatus for Key-Management Scheme for Use with Internet Protocols at Site Firewalls | — |
| US 5,081,676 | 1990‑10‑03 | Method and Apparatus for Protecting Multiple Copies of Computer Software from Unauthorized Use | — |
| US 4,885,789 | 1988‑01‑31 | Remote Trusted Path Mechanism for Telnet | — |
| US 5,499,297 | 1992‑04‑16 | System and Method for Trusted Path Communications | McAfee |
| US 5,546,463 | 1994‑07‑11 | Pocket Encrypt (secure portable data) | Thales e-Security |
Publication dates: for each of these I have the earliest priority date as surfaced by the citation map, not the issue/publication date. I flag this because it matters: a § 102(a)/102(b) analysis turns on the patent's issue date or application publication date, not its priority date. I would need the front page of each reference to state those dates with confidence. Every one of these references has an effective date before 1997‑06‑11, which is why they populate the family's citation map at all — but I have not individually verified issue dates.
Google Patents' "Prior art keywords" for the '345 are: client computer, computer device, server, identity data, authentication server. These are algorithmic similarity terms, not references, and should not be cited as prior art.
4. Non-patent literature and litigation-identified prior art
The later Prism continuations (US 9,369,469; US 9,544,314) carry an unusually long "Other References" list drawn from Prism's earlier enforcement campaigns. Verifiable entries include:
- Willens, S., et al., RADIUS, draft-ietf-nasreq-radius-01.txt / RFC 2058 (Apr. 10, 2002, 33 pp.) — filed as Exhibit B to Research In Motion Ltd.'s Preliminary Invalidity Contentions in Prism Technologies, LLC v. Research in Motion, Ltd. and Microsoft Corp., No. 8:08‑cv‑00537‑LES‑TDT (D. Neb.) (Jul. 24, 2009).
- Defendants' Joint Invalidity Contentions, Prism Technologies LLC v. VeriSign, Inc., et al., No. 05‑214‑JJF (D. Del.), Sep. 5, 2006 (118 pp.); and Second Supplemental Joint 35 U.S.C. § 282 Notice.
- Microsoft Corporation's Preliminary Invalidity Contentions, No. 8:08‑cv‑00537 (68 pp. of claim charts).
- RIM's Amended Invalidity Contentions (Sep. 18, 2009) charting, by inventor/reference name: Akiyama, Yu, Tabuki, Teper, Grawrock, Crane, Murphy, He, Ketcham, Krajewski, and DCE (192‑pp. redacted chart).
Source: https://patents.justia.com/patent/[9544314](/patent/9544314)
Important caveat, stated so it is not mistaken for an admission: these contentions were served in 2006–2009, i.e., before the '345 issued (2012). They were directed at the earlier family members (the '416 and its siblings), not at the '345's claims. They are probative of what the family's competitors considered material art, and they are the best-documented invalidity record in this family — but they are not the '345's cited references and cannot be presented as such.
5. Candidate § 102 references, with claim mapping — provisional and expressly unverified
Because (a) I lack the verified References Cited table and (b) the only verbatim claim language I hold is the fragmented claim 1 from Prism Techs. LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. 2017), I cannot deliver a competent § 102 anticipation chart. What I can offer is a candid candidate ranking against claim 1's four recited steps, clearly labelled as requiring verification:
Claim 1's recited steps (as quoted by the CAFC, ellipses in the original): (a) receiving at the authentication server a request from the client computer device for protected resources; (b) authenticating, by the authentication server, identity data forwarded by an access server, the identity data being stored in the authentication server; (c) authorizing based on stored data associated with the requested protected resources; (d) permitting access upon successful authentication and successful authorization.
| Candidate | § 102-type | Which claim-1 step(s) it could plausibly supply | Confidence |
|---|---|---|---|
| US 5,708,780 (Levergood, Open Market) | § 102(b) predating 1997‑06‑11 priority | (a) request interception; (d) conditional grant of access to protected content. The pre-Alice description of the family's core was "controlling access to protected computer resources." | Moderate that it is the single most material reference; but Levergood's session-identifier/access-control-server architecture may not disclose the recited separate authentication server holding stored identity data and stored resource data. Would need element-by-element charting. |
| US 5,841,970 (Authentication Method for Networks) | § 102(b) | (b), (c): third-party authentication of a network client against stored credentials. | Moderate |
| US 5,721,781 (Microsoft, smart-card authentication) | § 102(b) | The identity data / hardware key limitations — relevant to claims 5 ("hardware components"), 90 (prompting for identity data), 91 (querying the client device to generate identity data), 92. | Moderate for those dependents; low for claim 1 |
| US 5,774,552 (NCR, X.509 retrieval) | § 102(b) | "Digital identification" storage/format limitations. | Low–moderate |
| US 5,629,980 (ContentGuard) | § 102(b) | Authorization-levels limitations (claims 39, 87). | Low for claim 1 |
| US 5,032,979 (IBM, distributed security auditing) | § 102(b) | Transaction tracking/metering (claim 29); G06F2221/2135 "metering" is a granted classification on the '345. | Low for claim 1 |
| US 5,659,616 (secure digital signatures) | § 102(b) | Encryption-of-resources limitations (claim 78). | Low |
| US 5,371,794 (Oracle, wireless privacy/auth) | § 102(b) | Noted because the '345 was asserted against wireless carriers' authentication servers; relevant to the commercial-embodiment question, not necessarily novelty. | Low |
| RADIUS / RFC 2058 (Rigney, Willens, et al.) — NPL | § 102(b) if publicly available before 1997‑06‑11 (the 1997-06-11 date is the patent's priority; note the exhibit copy bears a 2002 date, so earlier RADIUS drafts would need to be located) | (a)–(d): access server requesting authentication from a separate authentication server against stored identity data, then permitting access. Structurally the closest analogue to the claimed architecture. | Provisional — the date question is dispositive and unresolved on my record |
None of the above rises to a § 102 anticipation opinion. A reference anticipates only if it discloses every element as arranged in the claim; several of these disclose subsystems, which supports § 103 rather than § 102. And critically:
The '345's asserted claims (1, 33, 77, 87) were held invalid under 35 U.S.C. § 101 in 2017, and that holding was applied preclusively to vacate the $30M Sprint judgment and to drive dismissal with prejudice of the U.S. Cellular and Verizon actions. Prior-art novelty of the '345 is therefore of historical and defensive-interest only.
6. Contradictions and corrections against the previously generated sections
- No contradiction found with the earlier Patent summary or Litigation summary on bibliographic data, abstract, § 101 outcome, or the negative 2026 CAFC docket finding.
- New fact not in the earlier sections: the RADIUS / RFC 2058 Exhibit B and the Akiyama/Yu/Tabuki/Teper/Grawrock/Crane/Murphy/He/Ketcham/Krajewski/DCE invalidity charts from the RIM and Microsoft matters. These are family-level (pre-2012) contentions and must not be merged into the '345's own citation record.
- Consistent with the earlier caveat that no PTAB (IPR/PGR/CBM) proceedings were identified — my searches likewise surfaced none, but this remains a negative search result, not a certified absence.
- Correction of emphasis: the Google Patents page's "Prior art keywords" line (client computer, computer device, server, identity data, authentication server) is generated by an algorithm and is not a citation list. If a downstream reader treats it as such, that is an error.
7. To close the gap (recommended next steps)
Only these will produce the verified citation table I could not obtain:
- USPTO PatentCenter — https://patentcenter.uspto.gov — application 11/978,919, "References Cited" and the full prosecution history (Office Actions, Form PTO‑892, examiner's § 102/§ 103 rejections).
- Granted-PDF front page — the (56) block, via the Google Patents "Download PDF" link on https://patents.google.com/patent/US8127345/en.
- USPTO Global Dossier and Espacenet — family-level citation data and the corresponding EPO search report for the same specification, which frequently identifies art the US examiner did not.
- PTAB / PTACTS docket — to confirm the absence of any IPR/PGR/CBM on the '345.
- PACER (D. Neb.) for the 2012–2019 docket files, which would contain Prism's and the defendants' actual § 102 contentions for the '345 itself.
Bottom line: Patent 8,127,345 is confirmed and correctly identified. I have a strong, sourced picture of the family-level prior-art landscape and a provisional candidate ranking, but I do not have — and have deliberately not invented — the verified front-page References Cited list for the '345, nor the verbatim claim set beyond a fragmented claim 1. Any itemized § 102 chart built on what I hold today would be unreliable; the sources in § 7 are required to produce one.
Generated 10/1/2026, 4:02:16 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll ground this analysis in the actual prior-art record for the '345 patent rather than relying on memory.
Obviousness Analysis — U.S. Patent No. 8,127,345 B2 under 35 U.S.C. § 103
0. Threshold notes, including one contradiction to flag
Flagged contradiction (date): the previously generated sections and the source-header state today's date as 2026-10-01, while this task's header states April 26, 2026. I treat the task header as controlling for this section but note the discrepancy rather than silently reconciling it.
Source limitation carried forward from the prior section (consistent, not contradictory): the Google Patents text I was given ends at the abstract and contains no claims section and no "References Cited" front-page list. Accordingly:
- My claim mapping uses the reconstructed claim 1 language quoted by the Federal Circuit in Prism Techs. LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. June 23, 2017) (from '345 col. 34 ll. 17–42), with OCR gaps marked.
- The prior-art record below comes from (a) the "Prior art keywords" line and the external-priority entry that constitute the only prior-art content in the supplied page, and (b) a "Patent Art (99)" listing surfaced by search on the related Prism publication US 2003/0046589 A1 ("System and Method for Securing Transactions and Computer Resources with an Untrusted Network"), plus the non-patent literature appearing in the reference list of the related Prism patent US 9,608,826. I cannot confirm that the Examiner cited these on the '345 itself.
Flagged analytic point that should not be lost: the '345's asserted claims were invalidated under § 101, not § 103. The Federal Circuit held the claims "merely recite a host of elements that are indisputably generic computer components." There is therefore no judicial § 103 holding on the '345, and the Sprint case produced a jury non-infringement verdict in T-Mobile and a $30M infringement verdict in Sprint (later vacated) with validity not appealed. Any § 103 conclusion here is my analysis, not a restatement of a court ruling.
1. Governing legal standard
| Item | Determination |
|---|---|
| Statute | Pre-AIA 35 U.S.C. § 103(a) — application 11/978,919 filed Oct. 30, 2007 but all claims carry the June 11, 1997 effective filing date (priority to US 08/872,710 → US 6,516,416), so no claim has an AIA (post-March 16, 2013) effective date. Caution: if any claim were ever shown to lack 1997 written-description support, AIA § 102/103 would govern that claim. |
| § 102 window | § 102(b): before June 11, 1996. § 102(a)/(e): before June 11, 1997. Pre-AIA § 102(e) dates use the U.S. filing date — the Hilmer doctrine denies § 102(e) benefit to foreign priority dates. |
| Obviousness framework | Graham v. John Deere; KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007); MPEP §§ 2141–2144. KSR rationales 1–7 all apply here (predictable combination of known elements, design choice, obvious to try, TSM). |
| PHOSITA (mid-1997) | Engineer with 2–4 years in network/computer security; familiar with HTTP/CGI, TCP/IP, HTML forms, cookies, SSL, X.509 certificates, Kerberos, RADIUS, session-ID management, and smart-card/token authentication hardware. |
2. The prior-art record (as required, "from the Prior Art section of this page")
(a) What the page itself supplies:
- Prior art keywords: client computer, computer device, server, identity data, authentication server. This keyword set is effectively the examiner's own statement of the claimed inventive subject matter and confirms that the five element classes are the whole of the invention's concept space.
- External priority: US 08/872,710 (1997-06-11) → US 6,516,416, "Subscription access system for use with an untrusted network" — the same-family prior disclosure, whose specification is the '345's own admitted technical background and expressly identifies the problem as: "[a]uthentication ... typically implemented through traditional user name-password schemes. Such schemes are vulnerable to password fraud because subscribers can share their user names and password by word of mouth or through Internet news groups." That is a binding admission of the prior art and of the problem to be solved.
(b) Patent Art (99) list, associated with US 2003/0046589 A1 (Prism family):
| Reference | Priority/filing date | Title (as listed) | § 103 role |
|---|---|---|---|
| US 5,708,780 (Levergood, Open Market) | 1995-06-06 | Internet Server Access Control and Monitoring Systems | Primary reference |
| US 5,841,970 | 1995-09-07 | Authentication Method for Networks | Network authentication / auth server |
| US 5,721,781 (Microsoft) | 1995-09-12 | Authentication System and Method for Smart Card Transactions | Hardware-key / digital-ID element |
| US 5,229,764 | 1991-06-19 | Continuous Biometric Authentication Matrix | Periodic re-authentication |
| US 5,592,553 | 1993-07-29 | Authentication System Using One-time Passwords | Token/identity data |
| US 5,371,794 (Oracle) | 1993-11-01 | Privacy and Authentication in Wireless Networks | Central auth of devices |
| US 6,047,376 (Toshiba) | 1996-10-17 | Client-server System, Server Access Authentication Method ... | Client+server mutual authentication |
| US 5,774,552 (NCR) | 1995-12-12 | Retrieving X.509 Certificates from an X.500 Directory | Storing/looking up digital IDs in a directory |
| US 5,416,842 | 1994-06-09 | Key-management Scheme for Internet Protocols at Site Firewalls | Encrypted server↔auth-server channel |
| US 5,497,421 (HP) | 1992-04-27 | Protecting the Confidentiality of Passwords in a Distributed Data Processing System | Encrypted credential transmission |
| US 5,629,980 (ContentGuard) | 1994-11-22 | System for Controlling the Distribution and Use of Digital Works | Authorization levels / usage rights |
| US 5,032,979 (IBM) | 1990-06-21 | Distributed Security Auditing Subsystem | Transaction logging / audit trail |
| US 4,864,494, US 5,081,676, US 5,754,864, US 5,379,343 | 1986–1993 | Software usage authorization, piracy detection, usage detection | Metering of resource usage (cf. CPC 2221/2135) |
(c) Non-patent literature (from the related Prism family's reference list):
- Sirbu et al., "NetBill: An Internet Commerce System Optimized for Network Delivered Services," IEEE Personal Comm. 34–39 (Aug. 1995) — a central commerce/authentication server that authenticates users, meters transactions and bills them.
- Hastings et al., "A Case Study of Authenticated and Secure File Transfer: The Iowa Campaign Finance Reporting System (ICPRS)" (Feb. 1997).
- Kerberos V5, RFC 1510 (Sept. 1993) — dedicated authentication server (AS) + ticket-granting server issuing time-limited, renewable session tickets, with mutual client/server authentication.
- RADIUS, RFC 2058 (Jan. 1997) / RFC 2138 (Apr. 1997) — a network access server forwards a user's credentials to a central authentication server, which returns Access-Accept (authentication plus authorization attributes) or Access-Reject.
- Netscape SSL 3.0 (1996) and HTTP cookies (1995).
3. Claim 1 mapping (provisional, given the OCR-fragmented claim text)
| Claim 1 element (as reconstructed) | Primary disclosure |
|---|---|
| "receiving, at the at least one authentication server … with a request from the at least one client computer device for the protected computer resources" | Levergood '780: access-control server receives requests for protected content; RADIUS: auth server receives Access-Request |
| "authenticating, by the at least one authentication server … at least one access server, the identity data being stored in the at least one authentication server" | Levergood (session ID validated against server-side store); RADIUS (NAS → authentication server); US 5,841,970 |
| authorizing based on "data … associated with the requested protected computer resources … stored in the … authentication server" | RADIUS Access-Accept attributes; US 5,629,980 (resource-level usage rights) |
| "permitting access … upon successfully authenticating … and … successfully authorizing" | Levergood (permission granted to content server only on valid session); RADIUS |
| "Internet Protocol network" (construed by the CAFC in Prism v. Sprint to include the Internet itself) | HTTP/TCP-IP + SSL |
| "digital identification" / "identity data" of hardware components (claim 5, cited by CAFC) | US 5,721,781 (smart card); US 5,592,553; US 5,229,764; the '345's own admitted Rainbow iKey 1000 USB Smart Token |
The single most important § 103 fact in the whole record: the '345 specification expressly identifies the hardware key as an off-the-shelf commercial product — "the iKey 1000 USB Smart Token device manufactured by Rainbow Technologies of Irvine, Calif." — and describes magnetic readers, smart-card readers and biometric readers as interchangeable, commercially available devices ("Smart card readers that interface to RS232 serial ports, USB ports, PCMCIA slots, ... are presently available"). The hardware element is thus admitted prior art, and its combination with a server-side authentication architecture is a classic KSR predictable combination.
4. Combinations rendering the claims obvious
Combination 1 — Levergood '780 + Kerberos/RFC 1510 + SSL 3.0 (+ cookie-based session IDs)
Covers: claim 1 and its distribution-of-functions dependents (multiple servers; authentication server on the same or a separate machine from the access server).
Motivation: Levergood already teaches a server-side authentication server controlling access to protected HTTP resources across an internetwork via a session identifier. Kerberos supplies the mutual (two-way) authentication of the access server to the authentication server that claim 1 recites, and SSL supplies the transport encryption. A PHOSITA building a commercial 1997 subscription/e-commerce site would combine them because each does exactly what it was already known to do (KSR, 550 U.S. at 417), with a reasonable expectation of success.
Combination 2 — RADIUS (RFC 2058/2138) + Levergood '780 + US 5,841,970
Covers: claim 1, and — critically — the CDMA2000/3GPP2 AAA architecture that Prism itself accused. Per IPWatchdog's account of Prism's Sprint complaint: "Sprint's wireless services which comply with industry standards including CDMA2000 and 3GPP2 included technologies which utilize authentication servers ... those systems used access servers, authentication servers and databases for storing digital identifications." When a patentee's own infringement theory describes the accused products as standards-conformant, the corresponding standard (here RADIUS/AAA, published before the 1997 priority date) is powerful § 103 art.
Motivation: RADIUS exists precisely to let a central server authenticate and authorize a client device (or user) on the basis of data forwarded by an access server, and to meter usage — i.e., the "authentication + authorization + accounting" triad maps onto claim 1 plus the metering dependents.
Combination 3 — Levergood '780 + US 5,721,781 (Microsoft smart card) or US 5,592,553 + US 5,774,552
Covers: dependent claims reciting a hardware component / digital ID, prompting for identity data plus username/password (claim 90), and querying the client device to generate identity data (claim 91).
Motivation — strongest of all: the '416-family specification's stated motivation is preventing password sharing ("vulnerable to password fraud because subscribers can share their user names and password"). Two-factor authentication with a physical token is the art's recognized answer, and Microsoft's '781 and the one-time-password art supply it. Adding a card reader to a PC was, by the patent's own admission, routine commercial practice in 1997. The result — user knows a password, holds a token — is the expected, not unexpected, outcome.
Combination 4 — US 5,629,980 / US 5,032,979 / US 4,864,494 (or NetBill) + Combination 1
Covers: transaction counting and session-level transaction data (claim 29 dependents), authorization levels assigned to resources and to identity data (claims 39, 87), and "encrypting the protected resources" (claim 78).
Motivation: Digital-rights and software-metering art already taught assigning differentiated access rights to resources and logging usage per user; NetBill already taught a central server that authenticates, meters and bills network-delivered services. Wiring those into a session-based HTTP access-control system is design choice among a finite number of identified options.
Combination 5 — US 6,047,376 + US 5,416,842 + US 5,497,421
Covers: the client-forwarding-its-identity-data dependent (claim 89), the server-authentication element, the encrypted credential/challenge-response dependents, and "changing identity data at the access server and forwarding it to the authentication server" (claim 92).
Caveat: US 6,047,376's listed 1996-10-17 date may be a foreign (JP) priority; under Hilmer its pre-AIA § 102(e) date is its U.S. filing date. Verify before relying on it.
5. Why a PHOSITA would have combined these (consolidated KSR rationales)
- Same field, same problem, known solutions. All references address authenticating users/devices across an untrusted network — the '345's own field.
- Predictable result from known elements. Each claim element (authentication server, access server, identity data store, resource-authorization data, conditional permission) performs its ordinary function in the combination — exactly the KSR "predictable variation" category.
- Design choice / finite options. "Authentication server on the same machine as, or a machine separate from, the access server" (claims 79–80) is the KSR "obvious to try" placement decision; distributing functions across multiple servers (claims 81, 84–86) was standard n-tier design.
- Art-recognized motivation. Password sharing → two-factor authentication is stated in the patentee's own family specification.
- Commercial demand. 1997 was peak commercial-Internet buildout; subscription content, e-commerce billing (NetBill) and ISP dial-in AAA (RADIUS) all created demand for exactly this architecture.
- Admitted prior art. The hardware token, the card readers, and the biometric reader are all described in the '345 as existing commercial products, and the "untrusted network" problem is described as pre-existing.
- Prosecution posture. Nothing about the '345 reads on a technical advance over these references — the Federal Circuit's characterization that the claims recite only "generic computer components" performing their ordinary functions is, in substance, the same observation a § 103 analysis makes under KSR.
6. Dependent-claim treatment
| Claim theme (per the prior section's Justia-derived list) | Disposing combination |
|---|---|
| Number of transactions (29) | Comb. 4 (metering/audit art; NetBill) |
| Authorization levels, resources and identity data (39, 87) | Comb. 4 (US 5,629,980) |
| Prompt for identity data + username/password (90) | Comb. 3 |
| Query client device to generate identity data (91) | Comb. 3 |
| Encrypt protected resources (78) | SSL + Comb. 4 |
| Auth server same/separate machine (79, 80) | Comb. 1 + design choice |
| Distribute auth/authz/permission functions (81, 84–86) | Comb. 1 (n-tier design) |
| Multiple client devices and access servers (82, 83) | Comb. 1/2 (Levergood; RADIUS NAS multiplicity) |
| Require client to forward identity data (89) | Comb. 5 |
| Change identity data at access server, forward to auth server (92) | Comb. 5 (directory/credential-update art) |
Because every dependent claim in the claim 49 family merely adds a conventional scale, placement, or logging feature, each is obvious for the same reasons as claim 1 plus the secondary reference performing its known function.
7. Anticipated rebuttals
- "References are non-analogous." Not available: all address network authentication and access control.
- Teaching away. Levergood, Kerberos, SSL and RADIUS are complementary, not contradictory; none criticizes hardware tokens or central authorization.
- Secondary considerations. No probative nexus appears in the record I reviewed. The $30M Sprint verdict speaks to infringement and damages, not to non-obviousness, and it was vacated — it cannot be pressed as evidence of "commercial success" of the claimed invention. The $30M figure is also plausibly attributable to licensing leverage, not to unexpected technical merit.
- § 101 vs. § 103. A § 101 invalidation does not compel a § 103 invalidation, and vice versa; they are separate analyses. My § 103 conclusion rests on the references, not on the Alice holding — but the CAFC's "generic components" reasoning is corroborative.
8. Caveats I am obligated to state
- I lack the '345's verbatim claim set and its front-page "References Cited" list. The element-by-element chart in § 3 is provisional. The independent-claim inventory (1 and 49) remains an inference from dependency structure.
- Reference-to-element mappings for Levergood '780, RADIUS, Kerberos and SSL rely on my knowledge of those documents, consistent with their titles as surfaced in the search, not on quoted passages I retrieved. Confirmed-by-search for those documents: existence, titles, and dates only.
- Dates should be re-verified for § 102(e) purposes, especially US 6,047,376 (Hilmer), and I recommend confirming RFC numbers/dates and the actual "Patent Art" list against the '345's own front page and file history (USPTO PatentCenter for 11/978,919; Global Dossier; and the PCT/US98/12111 search report, which I was unable to retrieve).
- No PTAB (IPR/PGR/CBM) proceeding involving the '345 was identified — the absence is unverified, as previously stated.
9. Bottom line
The '345 claims a central authentication server that (i) stores client identity data and resource-authorization data, (ii) authenticates identity data forwarded by an access server, (iii) authorizes the client against the stored resource data, and (iv) permits access only on success. On the record available, each element and each dependent-claim feature is disclosed or rendered obvious by pre-1997 art: Levergood US 5,708,780 + Kerberos (RFC 1510) + SSL 3.0 for the core claim; add RADIUS (RFC 2058/2138) for the access-server→authentication-server AAA architecture and the metering dependents; add Microsoft US 5,721,781 / US 5,592,553 / US 5,229,764 for the hardware digital-ID and re-authentication features; add US 5,629,980 / US 5,032,979 / NetBill for authorization levels and transaction logging. Motivation is supplied by the patentee's own admitted problem of password sharing, by the specification's admission that the hardware token and card readers are off-the-shelf products, and by KSR's predictable-combination and design-choice rationales. I would rate the obviousness case strong as to claim 1 and the metering/hardware/placement dependents, and moderate-to-strong as to the mutual-server-authentication and credential-update dependents, subject to the verification items in § 8.
Generated 10/1/2026, 4:02:53 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Prism Technologies LLC
- US 7290288I'll verify this patent against live sources, then summarize. Let me check for any 2026 appellate activity and the post-reexamination claim set. Let me check the reexamination outcome and any recent/2026 activity. US 7,290,288 B2 —…
- US 8387155I'll search for authoritative records on this specific patent number before summarizing. Let me pull the actual claim text and check for any 2026 appellate activity. Let me try to retrieve the actual claim language and confirm the…
Other patents in Software Technology & Computing Systems (T)
- US 8387155I'll search for authoritative records on this specific patent number before summarizing. Let me pull the actual claim text and check for any 2026 appellate activity. Let me try to retrieve the actual claim language and confirm the…
- US 11659381US 11,659,381 B2 — Verification Summary Sources used: the authoritative full text of US 11,659,381 B2 supplied in this matter (Google Patents, fetched 2026-10-01), plus live web results including Unified Patents, Docket Alarm/PACER-derived…
- US 8898260I'll search for authoritative information on this specific patent number and any 2026 CAFC activity. Let me dig deeper into the 2026 docket activity and the reexamination/PTAB status specifically for the '260 patent. One more targeted…
- US 8756336I'll search for authoritative information on this specific patent number. US Patent 8,756,336 B2 — Summary I searched for the specific number 8756336 (treated literally, no auto-correction). The authoritative full text (provided) is…
- US 7289772I'll search for authoritative information on this patent, including any 2026 litigation activity. US Patent 7,289,772 — Summary Note on identifiers: I interpreted "7289772" literally as US 7,289,772 B1. I did not find any CAFC 2026 docket…
- US 6868283I'll search for authoritative information on this patent, including any 2026 CAFC docket activity. Let me search for the litigation history and any 2026 appellate activity specifically referencing this patent. Search scope and confidence…
- US 6473006I'll search for authoritative information on US patent 6473006, including any 2026 CAFC docket activity. Let me run a couple more targeted checks for any 2026 litigation or Federal Circuit activity involving this specific patent. US Patent…
- US 7765414I'll verify the patent identifiers and check for any current docket activity before summarizing. Verification note Search results confirm that US 7,765,414 B2 is a real, granted U.S. patent titled "Circuit and operating method for…
This patent in court (7)
7 tracked lawsuits name US 8127345.