Invalidity dossier

US 8327426

Single sign on with proxy services

Current assignee: Unified Patents

Added 5/13/2026, 6:00:21 AM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by Unified PatentsSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US Patent 8327426, titled "Single sign on with proxy services," was filed on June 1, 2006, and issued on December 4, 2012. The original assignee was Novell Intellectual Property Holdings Inc, and the current assignee is Netskope Inc. The inventors are Stephen Hugh Kinser, Lloyd Leon Burch, and Cameron Craig Morris.

Abstract:
The patent describes techniques for providing single sign-on (SSO) with proxy services. A principal authenticates to a first identity service, which has a trusted relationship with a second identity service. An authentication request, including an authentication response from the first identity service, is sent to the second identity service. This response, provided after successful authentication to the first identity service, allows the principal to be authenticated for access to the second identity service. Furthermore, targeted services accessible through the second identity service are proxied to and from the principal during interactions between the principal and an external service.

Plain-Language Overview of Independent Claims:

  • Claim 1: This claim outlines a computer-implemented method for transparent single sign-on. When a user (principal) tries to access an external service, their authentication request is intercepted by a first identity service. After the first identity service authenticates the user, it creates a new "authentication message" containing both a request and a response, which vouches for the user's authentication. This message is sent to a second "identity service" to grant the user single sign-on access to that service and its associated services (including the original external service). The principal is unaware that these proxying and authentication steps are happening. The new authentication response also dictates whether a single or multiple authentication steps are needed for access to other services.

  • Claim 8: This claim describes a computer-implemented method from the perspective of a "receiving identity service." This service indirectly receives an authentication request and response for a single sign-on transaction. These messages are generated by an "original identity service" (acting as a transparent proxy) after it has authenticated the user. The receiving identity service, which has a secure relationship with the original identity service, then detects an "instruction" within the received authentication response. Based on a dynamic, real-time evaluation of its policies, the receiving identity service takes action to authenticate the user for access to its "targeted services." Access to these targeted services also happens transparently through proxied sessions via this receiving identity service.

  • Claim 14: This claim details a computer-implemented method for providing proxied access to a targeted service. A request for access is received from a user (principal), containing two authentication tokens. The first token indicates authentication with a "first identity service," and the second indicates authentication with a "second identity service." The second identity service automatically issues the second token based on the first token, due to a secure, trusted relationship where it relies on the first identity service's authentication. The second token also signifies that the first identity service can authorize the principal to access a specific "targeted service" controlled by the second identity service. A "service token" for this targeted service is then acquired and supplied to the first identity service. The first identity service then passes this service token to the principal, acting as a proxy to make the targeted service accessible. The principal perceives direct interaction with the targeted service, even though it was originally only available within the second identity service's environment and is being proxied through the first identity service.

Litigation Status:
The patent is currently active and is noted to expire on April 24, 2029.

According to the patent's legal status information, the family of this patent has litigation. Specifically:

  • A PTAB case (IPR2026-00026) was filed, though it was "Not Instituted - Procedural."
  • First worldwide family litigation was filed.
  • Two US cases were filed in the California Northern District Court: 3:25-cv-02360 and 4:25-cv-02360.

No specific CAFC 2026 docket information for US8327426 was found during the current search, though the general CAFC case information portal was identified. However, the patent document itself provides more direct litigation details as noted above.

Generated 5/25/2026, 12:49:06 AM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 8327426. The free-form analysis below may also discuss cases beyond this list.

  • IPR2026-00026Patent Trial and Appeal Board (PTAB)Not Instituted - Procedural

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

As a patent attorney, I've searched for litigation records related to US patent 8327426. Here's what I've found:

Litigation Involving US Patent 8327426

1. PTAB Case IPR2026-00026

  • Plaintiff(s): Unified Patents (identified as Petitioner)
  • Defendant(s): Not explicitly stated as a defendant in the provided snippet, but Unified Patents typically files IPRs against patent owners.
  • Jurisdiction: Patent Trial and Appeal Board (PTAB)
  • Case Number: IPR2026-00026
  • Filing Date: The patent information indicates "PTAB case IPR2026-00026 filed (Not Instituted - Procedural)" .
  • Outcome or Current Status: Not Instituted - Procedural .

2. US Case filed in California Northern District Court (Unified Patents Data)

  • Plaintiff(s): Not explicitly stated in the provided snippet, but Unified Patents tracks this litigation.
  • Defendant(s): Not explicitly stated in the provided snippet.
  • Jurisdiction: California Northern District Court
  • Case Number: 3:25-cv-02360
  • Filing Date: The case was filed in 2025 (implied by "3:25-cv-02360").
  • Outcome or Current Status: Ongoing, as of the current date.

3. US Case filed in California Northern District Court (Unified Patents Data)

  • Plaintiff(s): Not explicitly stated in the provided snippet, but Unified Patents tracks this litigation.
  • Defendant(s): Not explicitly stated in the provided snippet.
  • Jurisdiction: California Northern District Court
  • Case Number: 4:25-cv-02360
  • Filing Date: The case was filed in 2025 (implied by "4:25-cv-02360").
  • Outcome or Current Status: Ongoing, as of the current date.

It's important to note that the Unified Patents portal specifically mentions these cases in relation to US8327426. For more detailed information on specific parties and outcomes beyond the current status, accessing the full court dockets through PACER would be necessary, which may involve fees .Known litigation involving US patent 8327426 includes the following:

  • PTAB Case IPR2026-00026

    • Plaintiff(s): Unified Patents (Petitioner)
    • Defendant(s): Not specified in the provided information.
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Case Number: IPR2026-00026
    • Filing Date: The case was filed in 2026, as indicated by the case number.
    • Outcome or Current Status: Not Instituted - Procedural.
  • US Case filed in California Northern District Court

    • Plaintiff(s): Not specified in the provided information.
    • Defendant(s): Not specified in the provided information.
    • Jurisdiction: California Northern District Court
    • Case Number: 3:25-cv-02360
    • Filing Date: The case was filed in 2025, as indicated by the case number.
    • Outcome or Current Status: Ongoing.
  • US Case filed in California Northern District Court

    • Plaintiff(s): Not specified in the provided information.
    • Defendant(s): Not specified in the provided information.
    • Jurisdiction: California Northern District Court
    • Case Number: 4:25-cv-02360
    • Filing Date: The case was filed in 2025, as indicated by the case number.
    • Outcome or Current Status: Ongoing.

Generated 5/25/2026, 12:49:03 AM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Unified Patents

1 discretionary denial

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

A single AIA trial proceeding has been filed against US patent 8327426. This proceeding, IPR2026-00026, resulted in a discretionary denial of institution, meaning no claims were adjudicated on their merits by the PTAB. From a defensive posture, the patent has survived one IPR challenge at the institution stage, making it hardened against the specific petitioner for the grounds that could have been reasonably raised. All claims of the patent remain untested by a full PTAB trial.

IPR2026-00026 — Fortinet, Inc. v. Netskope, Inc.

  • Type: Inter Partes Review
  • Filed: 2025-10-07
  • Status: Discretionary Denial. This means the Patent Trial and Appeal Board (PTAB) exercised its discretion not to institute the inter partes review, often for reasons unrelated to the merits of the prior art, such as existing parallel district court litigation or policy considerations.
  • Judge panel: The specific panel of Administrative Patent Judges for this proceeding is not publicly available from the search results. In early 2026, institution decisions were made by the Director in consultation with at least three PTAB judges as part of a centralized process.
  • Petition grounds: The specific claims challenged, prior art asserted, and statutory bases (§ 102 / § 103 / § 112) of the petition are not publicly available from the search results.
  • Institution decision: Denied institution. While the exact date of the institution decision for IPR2026-00026 is not explicitly stated in the provided search results, the proceeding's "last modified" date of 2026-03-02 indicates a decision was rendered around that time. The denial was a discretionary denial, likely based on factors such as those outlined in Fintiv precedent concerning parallel district court litigation, or potentially the newer factors introduced by Director Squires in March 2026 that consider U.S. manufacturing footprint and small business status.
  • Final Written Decision (if issued): Not issued, as institution of the IPR was denied.
  • Settlement / termination: Not applicable, as the IPR was not instituted.
  • Appeal: Not applicable, as institution was denied. Decisions denying institution are generally considered non-appealable to the Federal Circuit.
  • Defensive value: The patent owner, Netskope, Inc., successfully prevented institution of this IPR. This means the patent claims challenged in this petition remain unchallenged through a PTAB final written decision. Fortinet, Inc., and its privies, are now estopped under 35 U.S.C. § 315(e)(2) from asserting in other venues the grounds raised or that reasonably could have been raised in this petition. For other potential infringers, this proceeding has no direct impact on their ability to challenge the patent.

Strategic summary

US patent 8327426 has been the subject of only one PTAB proceeding, IPR2026-00026, which concluded with a discretionary denial of institution. Consequently, all claims of US8327426 are now UNTESTED on their merits by the PTAB; none have been canceled or sustained through a final written decision. The patent's scope remains undiminished by PTAB proceedings.

Regarding the estoppel landscape, Fortinet, Inc., as the petitioner in IPR2026-00026, along with its privies, is statutorily estopped under 35 U.S.C. § 315(e)(2) from asserting invalidity grounds under §§ 102 or 103 that were raised or reasonably could have been raised in that petition in any subsequent civil action or International Trade Commission (ITC) proceeding. However, this estoppel does not apply to other potential defendants who were not parties or privies to this IPR. These other parties retain the full range of prior-art grounds available for challenging the patent's validity.

The patent owner, Netskope, Inc., acquired the patent from RPX Corporation in July 2024, indicating a potential strategy to assert the patent. The discretionary denial of IPR2026-00026, especially in the context of ongoing parallel district court litigation (Netskope, Inc. v. Fortinet, Inc., Case No. 4:25-cv-02360-HSG in the Northern District of California), aligns with a broader trend at the PTAB in early 2026. Under Director John Squires's leadership, there has been a centralization of institution authority and a shift towards policies that increasingly favor patent owners through discretionary denials, often considering factors like the stage of parallel litigation (Fintiv factors) and domestic manufacturing presence.

Recommended next steps

For a defendant facing assertion of US8327426 today, the primary consideration is that the patent's claims have not been subjected to a full validity review by the PTAB.

  • Given the PTAB's current environment emphasizing discretionary denials, any potential new IPR petition should be carefully strategized. Petitioners must thoroughly address and distinguish their case from the PTAB's prevailing discretionary factors, particularly the Fintiv factors (e.g., the stage of any parallel district court litigation, overlap of invalidity contentions between forums) and the Director's new guidance on U.S. manufacturing and small business status, if applicable.
  • Currently, no PTAB proceedings are active for US patent 8327426. The absence of instituted IPRs, despite a challenge, could be interpreted as a signal of the patent's resilience under the current PTAB discretionary institution policies.

Generated 5/25/2026, 12:49:33 AM

Ownership chain (13)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2006-05-30 · recorded 2006-06-01 · reel 017947/0322 · Assignment

    BURCH, LLOYD LEON; MORRIS, CAMERON CRAIG; KINSER, STEPHEN HUGHNOVELL,INC.

    initial assignment

  2. 2011-04-27 · recorded 2011-11-30 · reel 027465/0227 · Assignment

    NOVELL,INC.CPTN HOLDINGS LLC

    acquisition

  3. 2011-09-09 · recorded 2011-11-30 · reel 027465/0206 · Assignment

    CPTN HOLDINGS LLCNOVELL INTELLECTUAL PROPERTY HOLDINGS, INC.

    internal reorg

  4. 2011-09-09 · recorded 2011-12-01 · reel 027325/0131 · Assignment

    CPTN HOLDINGS LLCNOVELL INTELLECTUAL PROPERTY HOLDINGS, INC.

    internal reorg

  5. 2016-02-08 · recorded 2016-02-11 · reel 037809/0057 · Assignment

    NOVELL INTELLECTUAL PROPERTY HOLDINGS, INC.RPX CORPORATION

    defensive aggregation

  6. 2016-02-26 · recorded 2016-03-09 · reel 038041/0001 · Security Agreement

    RPX CORPORATION; RPX CLEARINGHOUSE LLCJPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT

    securitization

  7. 2017-12-22 · recorded 2018-01-02 · reel 044970/0030 · Release

    JPMORGAN CHASE BANK, N.A.RPX CLEARINGHOUSE LLC, RPX CORPORATION

    securitization

  8. 2018-06-19 · recorded 2018-06-29 · reel 046486/0433 · Security Interest

    RPX CORPORATIONJEFFERIES FINANCE LLC

    securitization

  9. 2020-08-23 · recorded 2020-10-23 · reel 054244/0566 · Patent Security Agreement

    RPX CLEARINGHOUSE LLC, RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT

    securitization

  10. 2020-10-23 · reel 054198/0029 · Patent Security Agreement

    RPX CLEARINGHOUSE LLC, RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT

    securitization

  11. 2020-10-23 · recorded 2020-10-26 · reel 054486/0422 · Release of Security Interest

    JEFFERIES FINANCE LLCRPX CORPORATION

    securitization

  12. 2024-05-31 · reel 067596/0606 · Release of Security Interest in Specified Patents

    BARINGS FINANCE LLCRPX CORPORATION

    securitization

  13. 2024-06-30 · recorded 2024-07-05 · reel 067918/0690 · Assignment

    RPX CORPORATIONNetskope, Inc.

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Stephen Hugh Kinser: Likely employed by Novell, Inc. or an affiliated entity at the time of filing, as he assigned his interest to Novell, Inc. on the filing date.
  • Lloyd Leon Burch: Likely employed by Novell, Inc. or an affiliated entity at the time of filing, as he assigned his interest to Novell, Inc. on the filing date.
  • Cameron Craig Morris: Likely employed by Novell, Inc. or an affiliated entity at the time of filing, as he assigned his interest to Novell, Inc. on the filing date.

(Based on the initial assignment dated 2006-06-01 to NOVELL,INC. (Reel 017947/0322), it is highly probable the inventors were employees of Novell, Inc. or an affiliated entity at the time of filing.)

Original assignee

The entity named on the issued patent is Novell Intellectual Property Holdings Inc.. Novell, Inc. was a prominent software company known for network operating systems (e.g., Novell NetWare), email, identity services, and directory services products. The patent describes how its techniques can be implemented in "Novell® network and proxy server products, email products, identity service products, operating system products, and/or directory services products distributed by Novell®, Inc., of Provo, Utah," indicating they shipped products embodying the claims. Novell, Inc. was acquired by Attachmate in 2011, which was subsequently acquired by Micro Focus International in 2014. The Novell intellectual property assets were part of these larger corporate transactions.

Assignment timeline

  • 2006-06-01 (signed from 2006-05-30 to 2006-06-01) / recorded 2006-06-01 — Reel 017947/0322

    • Conveyance: Assignment
    • Assignor: BURCH, LLOYD LEON; MORRIS, CAMERON CRAIG; KINSER, STEPHEN HUGH (Inventors)
    • Assignee: NOVELL,INC., UTAH
    • Correspondent: Not specified in the provided data.
    • Context: Initial assignment of patent rights from inventors to the operating company/affiliated entity.
  • 2011-11-30 (effective 2011-04-27) / recorded 2011-11-30 — Reel 027465/0227

    • Conveyance: Assignment
    • Assignor: NOVELL,INC.
    • Assignee: CPTN HOLDINGS LLC, WASHINGTON
    • Correspondent: Not specified in the provided data.
    • Context: Transfer of patent rights from Novell, Inc. as part of a larger corporate acquisition or IP transaction.
  • 2011-11-30 (effective 2011-09-09) / recorded 2011-11-30 — Reel 027465/0206

    • Conveyance: Assignment
    • Assignor: CPTN HOLDINGS LLC
    • Assignee: NOVELL INTELLECTUAL PROPERTY HOLDINGS, INC., WASHI
    • Correspondent: Not specified in the provided data.
    • Context: Transfer of patent rights from CPTN Holdings LLC back to a Novell intellectual property holding entity.
  • 2011-12-01 (effective 2011-09-09) / recorded 2011-12-01 — Reel 027325/0131

    • Conveyance: Assignment
    • Assignor: CPTN HOLDINGS LLC
    • Assignee: NOVELL INTELLECTUAL PROPERTY HOLDING, INC., WASHIN
    • Correspondent: Not specified in the provided data.
    • Context: Another assignment from CPTN Holdings LLC to a Novell intellectual property holding entity, likely related to the same broader corporate transaction.
  • 2016-02-11 (effective 2016-02-08) / recorded 2016-02-11 — Reel 037809/0057

    • Conveyance: Assignment
    • Assignor: NOVELL INTELLECTUAL PROPERTY HOLDINGS, INC.
    • Assignee: RPX CORPORATION, CALIFORNIA
    • Correspondent: Not specified in the provided data.
    • Context: Transfer to a defensive patent aggregator.
  • 2016-03-09 (effective 2016-02-26) / recorded 2016-03-09 — Reel 038041/0001

    • Conveyance: Security Agreement
    • Assignor: RPX CORPORATION; RPX CLEARINGHOUSE LLC
    • Assignee: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT, ILLINOIS
    • Correspondent: Not specified in the provided data.
    • Context: Securitization of assets by RPX.
  • 2018-01-02 (effective 2017-12-22) / recorded 2018-01-02 — Reel 044970/0030

    • Conveyance: Release
    • Assignor: JPMORGAN CHASE BANK, N.A.
    • Assignee: RPX CLEARINGHOUSE LLC, RPX CORPORATION
    • Correspondent: Not specified in the provided data.
    • Context: Release of security interest from JPMorgan Chase Bank, N.A.
  • 2018-06-29 (effective 2018-06-19) / recorded 2018-06-29 — Reel 046486/0433

    • Conveyance: Security Interest
    • Assignor: RPX CORPORATION
    • Assignee: JEFFERIES FINANCE LLC, NEW YORK
    • Correspondent: Not specified in the provided data.
    • Context: Another securitization of assets by RPX.
  • 2020-10-23 (effective 2020-10-23) / recorded 2020-10-23 — Reel 054198/0029

    • Conveyance: Patent Security Agreement
    • Assignor: RPX CLEARINGHOUSE LLC; RPX CORPORATION
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT, NORTH CAROLINA
    • Correspondent: Not specified in the provided data.
    • Context: Further securitization of assets by RPX.
  • 2020-10-23 (effective 2020-08-23) / recorded 2020-10-23 — Reel 054244/0566

    • Conveyance: Patent Security Agreement
    • Assignor: RPX CLEARINGHOUSE LLC; RPX CORPORATION
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT, NORTH CAROLINA
    • Correspondent: Not specified in the provided data.
    • Context: Another Patent Security Agreement to Barings Finance LLC, likely related to the same financing arrangement.
  • 2020-10-26 (effective 2020-10-23) / recorded 2020-10-26 — Reel 054486/0422

    • Conveyance: Release of Security Interest
    • Assignor: JEFFERIES FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: Not specified in the provided data.
    • Context: Release of security interest from Jefferies Finance LLC.
  • 2024-05-31 (effective 2024-05-31) / recorded 2024-05-31 — Reel 067596/0606

    • Conveyance: Release of Security Interest in Specified Patents
    • Assignor: BARINGS FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: Not specified in the provided data.
    • Context: Release of security interest from Barings Finance LLC.
  • 2024-07-05 (effective 2024-06-30) / recorded 2024-07-05 — Reel 067918/0690

    • Conveyance: Assignment
    • Assignor: RPX CORPORATION
    • Assignee: NETSKOPE, INC., CALIFORNIA
    • Correspondent: Not specified in the provided data.
    • Context: Transfer from a defensive patent aggregator to an operating company.

Timeline diagram

timeline
    title Ownership of US 8327426
    2006 : Inventors assign to Novell Inc
    2011 : Assigned to CPTN Holdings LLC
         : Assigned to Novell IP Holdings Inc
    2012 : Patent issued
    2016 : Assigned to RPX Corporation
         : RPX securitized by JPMorgan
    2018 : JPMorgan release to RPX
         : RPX securitized by Jefferies
    2020 : RPX securitized by Barings
         : Jefferies release to RPX
    2024 : Barings release to RPX
         : Assigned to Netskope Inc

NPE / troll-pattern signals

  1. Shell-entity transfer: Not present. While Novell Intellectual Property Holdings Inc. and CPTN Holdings LLC are IP-holding entities, they served specific roles as an IP subsidiary of an operating company and an IP acquisition vehicle by a consortium of operating companies, respectively, not as typical shell entities for offensive assertion. The current assignee, Netskope, Inc., is an operating company.
  2. Known asserter in the chain: Not present (inverse signal present). RPX Corporation is a known defensive aggregator, appearing in the chain from 2016-02-11 (Reel 037809/0057) until 2024-07-05 (Reel 067918/0690).
  3. Repeat correspondent across the chain: Unclear. The provided legal event data from Google Patents does not include correspondent information.
  4. Cascading transfers: Present. Three assignments occurred within a two-day period (recorded 2011-11-30, 2011-12-01), with effective dates in 2011, involving Novell, CPTN Holdings LLC, and Novell Intellectual Property Holdings, Inc. (Reel 027465/0227, 027465/0206, 027325/0131). These represent a rapid series of transfers, consistent with complex IP management during a corporate acquisition.
  5. Pre-litigation transfer: Present. The assignment to Netskope, Inc. occurred on 2024-07-05 (effective 2024-06-30) (Reel 067918/0690), preceding the filing of at least two US district court cases in the California Northern District Court (3:25-cv-02360 and 4:25-cv-02360) in 2025. This transfer happened within six months of the subsequent litigation.
  6. Bankruptcy fire-sale: Not present. Novell was acquired, not dissolved through bankruptcy, and subsequent transfers do not indicate a bankruptcy sale.
  7. Privateering: Unclear/Not present. The patent was transferred from a defensive aggregator (RPX) to an operating company (Netskope, Inc.) which then appears to be asserting it against a competitor (Fortinet, Inc.). This is more characteristic of an operating company asserting its own acquired IP for competitive reasons, rather than a privateering arrangement where an operating company transfers patents to an NPE to sue on its behalf while remaining undisclosed.
  8. Defensive aggregator (anti-NPE): Present. RPX Corporation, a known defensive aggregator, acquired the patent on 2016-02-11 (Reel 037809/0057) and held it until 2024-07-05 (Reel 067918/0690). However, the patent was subsequently sold by RPX to an operating company.

Verdict

Operating-company assertion.
The current assignee, Netskope, Inc., is an operating company in the cybersecurity industry. The patent was transferred to Netskope from RPX Corporation (a defensive aggregator) on 2024-07-05 (Reel 067918/0690) and subsequently became involved in litigation (e.g., California Northern District Court cases 3:25-cv-02360 and 4:25-cv-02360 in 2025) where Netskope is likely the plaintiff against a competitor. This pattern, including the pre-litigation transfer to the operating company, indicates Netskope is asserting the patent as part of its business strategy.

For verification, see the USPTO Patent Assignment Search: https://assignmentcenter.uspto.gov/ (search for patent number 8327426).

Generated 5/25/2026, 6:46:05 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

The following patent citations are identified as prior art for US patent 8327426, based on the provided patent text. The analysis for potential anticipation under 35 U.S.C. § 102 is based on the titles and general descriptions of the cited patents, compared against the independent claims (Claims 1, 8, and 14) of US8327426. All listed citations have priority dates preceding the June 1, 2006 priority date of US8327426.

Cited Patent References:

1. US5913025A

  • Full Citation: US5913025A, Novell, Inc., "Method and apparatus for proxy authentication"
  • Publication/Filing Date: Priority Date: 1996-11-14; Publication Date: 1999-06-15
  • Brief Description: This patent generally describes a method and apparatus for authentication through a proxy.
  • Potential Anticipation (35 U.S.C. § 102): This patent anticipates the general concept of "proxy authentication," which is a foundational element in US8327426. However, its title does not suggest the specific features of single sign-on (SSO), transparent proxying across multiple identity services, or the dynamic communication of authentication interaction policies as detailed in Claims 1, 8, and 14 of US8327426. It could potentially anticipate the "authenticating, by the machine, the principal" step (Claim 1) or a generic aspect of proxying.

2. US5991810A

  • Full Citation: US5991810A, Novell, Inc., "User name authentication for gateway clients accessing a proxy cache server"
  • Publication/Filing Date: Priority Date: 1997-08-01; Publication Date: 1999-11-23
  • Brief Description: This patent describes a system for user name authentication for clients accessing a proxy cache server via a gateway.
  • Potential Anticipation (35 U.S.C. § 102): Similar to US5913025A, this reference broadly covers user authentication and proxying, specifically in the context of a proxy cache server. It likely anticipates general authentication and proxy concepts but lacks the specific multi-identity service SSO architecture and transparent proxying of services described in US8327426's independent claims.

3. US6182141B1

  • Full Citation: US6182141B1, Intel Corporation, "Transparent proxy server"
  • Publication/Filing Date: Priority Date: 1996-12-20; Publication Date: 2001-01-30
  • Brief Description: This patent describes a proxy server designed to operate transparently to the client.
  • Potential Anticipation (35 U.S.C. § 102): This patent is highly relevant as it explicitly teaches a "transparent proxy server." This directly anticipates the "transparently to the principal" aspect mentioned in Claim 1 and Claim 8, and the "principal believes that the principal is directly interacting with the target service" in Claim 14. While it establishes the transparency of proxying as prior art, it may not anticipate the complex SSO features, authentication message structures between multiple identity services, or policy-driven determination of authentication interactions found in US8327426.

4. US6421768B1

  • Full Citation: US6421768B1, First Data Corporation, "Method and system for authentication and single sign on using cryptographically assured cookies in a distributed computer environment"
  • Publication/Filing Date: Priority Date: 1999-05-04; Publication Date: 2002-07-16
  • Brief Description: This patent describes a method and system for achieving single sign-on (SSO) using cryptographically secured cookies in a distributed computing environment.
  • Potential Anticipation (35 U.S.C. § 102): This patent is highly relevant due to its explicit teaching of "single sign on" in a "distributed computer environment." This directly anticipates the fundamental SSO objective of US8327426, as outlined in Claims 1, 8, and 14. While the specific mechanism (cryptographically assured cookies) and potentially the precise multi-identity service proxying architecture of US8327426 may differ, the core concept of a single authentication granting access to multiple services is taught.

5. US6728885B1

  • Full Citation: US6728885B1, Networks Associates Technology, Inc., "System and method for network access control using adaptive proxies"
  • Publication/Filing Date: Priority Date: 1998-10-09; Publication Date: 2004-04-27
  • Brief Description: This patent describes a system and method for controlling network access using proxies that can adapt their behavior.
  • Potential Anticipation (35 U.S.C. § 102): The concept of "adaptive proxies" and "network access control" could potentially anticipate elements related to policy-driven decision making ("dynamic and real-time evaluation of policies" in Claim 8) and general proxy functionality. However, it does not explicitly disclose the comprehensive SSO framework involving specific authentication message exchanges between distinct identity services for transparent service proxying as claimed in US8327426.

6. US20040128392A1

  • Full Citation: US20040128392A1, International Business Machines Corporation, "Method and system for proof-of-possession operations associated with authentication assertions in a heterogeneous federated environment"
  • Publication/Filing Date: Priority Date: 2002-12-31; Publication Date: 2004-07-01
  • Brief Description: This patent describes using "authentication assertions" for proof-of-possession in "heterogeneous federated environments."
  • Potential Anticipation (35 U.S.C. § 102): This patent is highly relevant. US8327426 extensively uses "authentication statements" or "tokens" (which can be assertions, as noted in the patent description) and operates in an environment with a first and second "identity service," which constitutes a "federated environment." This reference could potentially anticipate significant aspects of the inter-identity service communication, the use of assertions to vouch for authentication, and the fundamental idea of federated identity management, particularly affecting Claims 1, 8, and 14.

7. US20050015490A1

  • Full Citation: US20050015490A1, Saare John E., "System and method for single-sign-on access to a resource via a portal server"
  • Publication/Filing Date: Priority Date: 2003-07-16; Publication Date: 2005-01-20
  • Brief Description: This patent describes a system and method for providing single sign-on (SSO) access to a resource through a portal server.
  • Potential Anticipation (35 U.S.C. § 102): This patent directly teaches "single-sign-on access to a resource." Similar to US6421768B1, it anticipates the core SSO concept found across Claims 1, 8, and 14 of US8327426. The "via a portal server" might specify a particular implementation, but the overarching principle of SSO is present.

8. US6892307B1

  • Full Citation: US6892307B1, Sun Microsystems, Inc., "Single sign-on framework with trust-level mapping to authentication requirements"
  • Publication/Filing Date: Priority Date: 1999-08-05; Publication Date: 2005-05-10
  • Brief Description: This patent describes a single sign-on framework that incorporates mapping of trust levels to specific authentication requirements.
  • Potential Anticipation (35 U.S.C. § 102): This patent is highly relevant. It directly teaches a "Single sign-on framework" and, critically, "trust-level mapping to authentication requirements." This strongly anticipates the policy-driven determination of authentication interactions (e.g., single vs. multiple interactions) as described in Claim 1, and the reliance on trusted relationships between identity services (Claims 8 and 14) to facilitate authentication for SSO.

9. US20050193427A1

  • Full Citation: US20050193427A1, Pramod John, "Secure enterprise network"
  • Publication/Filing Date: Priority Date: 2004-02-26; Publication Date: 2005-09-01
  • Brief Description: This patent describes a secure enterprise network.
  • Potential Anticipation (35 U.S.C. § 102): The title "Secure enterprise network" is very broad. Without further details from the patent itself, it is difficult to determine specific anticipation of the detailed SSO and proxy service features of US8327426's claims. It likely covers general security principles rather than the specific inventive concepts.

10. US20060021010A1

  • Full Citation: US20060021010A1, International Business Machines Corporation, "Federated identity brokering"
  • Publication/Filing Date: Priority Date: 2004-06-28; Publication Date: 2006-01-26
  • Brief Description: This patent describes the concept of brokering identities in a federated environment.
  • Potential Anticipation (35 U.S.C. § 102): This is arguably one of the most relevant prior art citations. "Federated identity brokering" precisely describes the core interaction between the first and second identity services in US8327426. Claim 8 describes an "original identity service acting as a proxy on behalf of the principal" to another "identity service." Claim 14 details a "first identity service" facilitating the issuance of a token by a "second identity service" based on a trusted relationship, and then proxying services. This patent has a very high potential to anticipate the core federated identity, multi-identity service interaction, and proxying logic embedded in Claims 1, 8, and 14.

11. US20070143836A1

  • Full Citation: US20070143836A1, Quest Software, Inc., "Apparatus system and method to provide authentication services to legacy applications"
  • Publication/Filing Date: Priority Date: 2005-12-19; Publication Date: 2007-06-21
  • Brief Description: This patent describes an apparatus, system, and method for providing authentication services specifically to legacy applications.
  • Potential Anticipation (35 U.S.C. § 102): While it deals with "authentication services," its specific focus on "legacy applications" likely narrows its scope. It might anticipate general authentication service provision but is less likely to anticipate the broader, transparent SSO with proxy services for various external services, particularly the sophisticated inter-identity service communication and service token exchange described in US8327426's independent claims.

Most Relevant Prior Art:

Based on the titles and their direct alignment with the key features of US8327426's independent claims (Claims 1, 8, and 14), the following patents are identified as the most relevant prior art:

  • US20060021010A1 ("Federated identity brokering"): Directly addresses the multi-identity service interaction, where one identity service acts on behalf of a principal to another, which is a central theme of Claims 1, 8, and 14.
  • US20040128392A1 ("Method and system for proof-of-possession operations associated with authentication assertions in a heterogeneous federated environment"): Highly relevant to the use of authentication assertions/tokens and the operation within a federated environment of multiple identity services, as described in Claims 1, 8, and 14.
  • US6892307B1 ("Single sign-on framework with trust-level mapping to authentication requirements"): Directly teaches an SSO framework that incorporates trust levels to determine authentication requirements, which is a key aspect of Claim 1's policy-driven interaction determination and the trusted relationships in Claims 8 and 14.
  • US6421768B1 ("Method and system for authentication and single sign on using cryptographically assured cookies in a distributed computer environment"): Fundamentally teaches "single sign on" in a distributed environment, directly anticipating the core SSO aspect of all independent claims.
  • US6182141B1 ("Transparent proxy server"): Directly teaches the "transparent proxy" concept, which is a specific element of Claim 1, Claim 8, and Claim 14 related to the principal's perception of direct interaction.

Generated 5/25/2026, 6:46:21 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

The obviousness analysis of US Patent 8327426 under 35 U.S.C. § 103 considers whether the claimed invention would have been obvious to a person having ordinary skill in the art (PHOSITA) at the time of the invention's priority date, June 1, 2006. The patent addresses the well-known problem of users needing to manage multiple authentication credentials for various Internet services, even when those services could securely interact. The solution involves single sign-on (SSO) combined with transparent proxy services across multiple identity domains.

The following prior art references are considered for this analysis:

Patent Citations from US8327426 (Pre-June 1, 2006):

  • US5913025A (Novell, Inc.): Method and apparatus for proxy authentication.
  • US5991810A (Novell, Inc.): User name authentication for gateway clients accessing a proxy cache server.
  • US6182141B1 (Intel Corporation): Transparent proxy server.
  • US6421768B1 (First Data Corporation): Method and system for authentication and single sign on using cryptographically assured cookies in a distributed computer environment.
  • US6728885B1 (Networks Associates Technology, Inc.): System and method for network access control using adaptive proxies.
  • US20040128392A1 (International Business Machines Corporation): Method and system for proof-of-possession operations associated with authentication assertions in a heterogeneous federated environment.
  • US20050015490A1 (Saare John E.): System and method for single-sign-on access to a resource via a portal server.
  • US6892307B1 (Sun Microsystems, Inc.): Single sign-on framework with trust-level mapping to authentication requirements.
  • US20050193427A1 (Pramod John): Secure enterprise network.
  • US20060021010A1 (International Business Machines Corporation): Federated identity brokering.

Non-Patent Citations from US8327426 (Pre-June 1, 2006):

  • "Brokered Authentication:Security Token Service (STS)." MSDN. Dec. 2005. Microsoft.
  • "Federation of Identities in a Web Services World." MSDN. Microsoft Corporation. 2003.
  • "The Enterprise Single Sign-On Service and associated BizTalk Server 2004 services fail after you install Windows XP Service Pack 2 (SP2)". 2004.
  • "Web Services Federation Language (WSSpecification), Version 1." Jul. 8, 2003. Siddartha Bajaj et al.
  • Cohen, F., "Using Web services for e-Commerce single sign-in ". Jan. 1, 2002.
  • Patterson, Pat et al., "Federated Identity: Single Sign-On Among Enterprises." Oct. 14, 2004.

Additionally, US8327426 incorporates by reference three Novell applications filed in early 2004, titled "Techniques for Dynamically Establishing and Managing Authentication and Trust Relationships" (U.S. Ser. No. 10/765,523), "Techniques for Establishing and Managing a Distributed Credential Store" (U.S. Ser. No. 10/767,884), and "Techniques for Establishing and Managing Trust Relationships" (U.S. Ser. No. 10/770,677). While specific publication numbers for these serial numbers could not be definitively retrieved as direct patent grants to Novell in the given search context, their titles indicate they broadly cover concepts foundational to the present invention concerning identity services, authentication, and trust relationships.

Obviousness Analysis of Independent Claims (Claims 1, 8, and 14)

The core inventive concepts of US8327426 revolve around:

  1. A first identity service authenticating a principal.
  2. The first identity service generating an authentication message (request + response/token/instruction) for a second identity service.
  3. This message facilitating SSO to the second identity service, potentially automatically or after further interaction based on policy.
  4. Transparent proxying of targeted services from the second identity service to the principal, often via the first identity service.
  5. Browser redirection to manage the flow of authentication messages and tokens.

A PHOSITA in 2006 would have been motivated to combine existing SSO solutions, federated identity management, and proxy technologies to improve user experience, enhance security, and enable seamless access to distributed services, directly addressing the known problem of multiple logins.

Combination 1: US6421768B1 (First Data) + US6182141B1 (Intel) + US20060021010A1 (IBM) + "Federation of Identities in a Web Services World" (Microsoft 2003)

This combination would render Claim 1 obvious.

  • US6421768B1 (First Data) teaches the fundamental concept of SSO in a distributed environment using authentication tokens (cryptographically assured cookies) to avoid re-authentication.
  • US6182141B1 (Intel) discloses a transparent proxy server that intercepts network communications without the client's explicit knowledge. This directly addresses the "intercepted by the method for receipt" and "principal believing interactions are with the external service, which is one of the other services that the identity service controls access to, and a determination as to whether to use a single interaction or multiple interactions for authentication of the principal to the other services is automatically communicated in the new authentication response" elements of Claim 1, by making the SSO process seamless and invisible to the principal.
  • US20060021010A1 (IBM) describes federated identity brokering, where an identity provider (analogous to the "first identity service") brokers identity information to a service provider (analogous to the "identity service" or "second identity service") to grant access to resources. This includes the exchange of authentication assertions or tokens between trusted entities, forming the "authentication message" with an "authentication request and as a new authentication response" that "vouches for authentication of the principal to the identity service."
  • "Federation of Identities in a Web Services World" (Microsoft 2003) further details federated identity concepts, where trust relationships enable one domain's authentication of a principal to be accepted by another domain through security tokens.

Motivation to Combine:
A PHOSITA would combine these references to create a more efficient and user-friendly SSO system for federated environments. The transparent proxy from Intel would allow seamless interception of initial requests, redirecting them to the SSO mechanism (First Data) and federated identity broker (IBM, Microsoft NPL) to streamline authentication across trusted identity services. This combination directly enables the "identity service acts as a proxy for access sessions to the other services on behalf of the principal, the principal's access sessions occur indirectly through the identity service and transparently to the principal" recited in Claim 1. The concept of including instructions for single or multiple authentication interactions (as taught by US6892307B1 (Sun) through "trust-level mapping to authentication requirements") would be an obvious enhancement for a PHOSITA desiring to balance security and usability based on policy in a federated system.

Combination 2: US20040128392A1 (IBM) + US5913025A (Novell) + US6892307B1 (Sun)

This combination would render Claim 8 obvious.

  • US20040128392A1 (IBM) teaches the use of authentication assertions in a federated environment, where these assertions provide "proof-of-possession" and can be used by relying parties (the "identity service" in Claim 8) to establish trust and grant access. This provides the "authentication request and an authentication response as a single sign-on transaction from a principal" received indirectly from an "original identity service."
  • US5913025A (Novell) discloses methods for proxy authentication, where a proxy system authenticates a client to a remote server on the client's behalf. This supports the "original identity service acting as a proxy on behalf of the principal and actions of that original identity service are transparent to the principal."
  • US6892307B1 (Sun) describes an SSO framework with "trust-level mapping to authentication requirements." This reference provides the clear teaching for the "detecting, by a machine and from an identity service, an instruction, which is represented in the authentication response" and "taking, by the machine, an action in response to the instruction to authenticate the principal for access to targeted services, access to the target services occur via proxied sessions through the identity service and transparent to the principal, wherein the action taken is dynamic and a real-time evaluation of policies processed by the identity service." Sun's patent explicitly suggests that authentication requirements can vary based on trust and policy.

Motivation to Combine:
A PHOSITA would combine these references to build a federated identity system where a receiving identity service dynamically evaluates authentication instructions received from a trusted original identity service. Novell's proxy authentication would enable the original identity service to act transparently on behalf of the principal. IBM's teachings provide the specifics of authentication assertions for this exchange. Sun's framework provides the motivation and mechanism for policy-driven, dynamic authentication decisions ("action taken is dynamic and a real-time evaluation of policies"). Extending access to "targeted services" via proxied sessions after successful authentication is a logical next step to complete the SSO experience.

Combination 3: US20060021010A1 (IBM) + US5913025A (Novell) + US6421768B1 (First Data) + "Brokered Authentication:Security Token Service (STS)" (Microsoft 2005)

This combination would render Claim 14 obvious.

  • US20060021010A1 (IBM) focuses on federated identity brokering, where an identity provider (e.g., the "first identity service") acts as a broker to authenticate a principal to a service provider (e.g., the "second identity service") to grant access to resources.
  • US5913025A (Novell) describes proxy authentication, where a proxy obtains authentication for a client to a remote service.
  • US6421768B1 (First Data) teaches SSO using cryptographically assured cookies, which are a form of authentication tokens.
  • "Brokered Authentication:Security Token Service (STS)" (Microsoft 2005) describes Security Token Services that issue security tokens (assertions) after authenticating a principal. These tokens are used for brokered authentication across different services/domains and directly support the concept of a "first authentication token" and a "second authentication token."

Motivation to Combine:
A PHOSITA would be motivated to combine these to achieve a comprehensive and seamless federated SSO and proxy service solution. The Microsoft NPL and IBM's patent establish the industry-standard mechanisms for federated identity and brokered authentication, leading to the issuance of authentication tokens (First Data) from a first identity service and then a second identity service (relying on the first's token due to a secure relationship). Novell's proxy authentication directly teaches the mechanism for the "first identity service acting as a proxy for features of the target service and using the service token," and then "making the targeted service accessible from and to the principal." The concept of the principal believing direct interaction is occurring, even while proxied, would be a desired user experience improvement.

Conclusion

Considering the well-known challenges in identity management and SSO prior to June 2006, a PHOSITA would have been highly motivated to combine existing technologies to provide a more integrated and user-friendly solution. The prior art collectively discloses all the fundamental elements of US Patent 8327426, including SSO, federated identity, authentication tokens/assertions, trusted relationships between identity services, policy-driven authentication, and various forms of proxying, including transparent proxies. The combinations outlined above demonstrate how a PHOSITA would have arrived at the claimed methods by logically integrating these known components to solve known problems, thereby rendering Claims 1, 8, and 14, and by extension the entire patent, obvious under 35 U.S.C. § 103.

Generated 5/25/2026, 6:46:31 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Unified Patents

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 8327426.