Invalidity dossier

US 8387155

System for managing access to protected computer resources

Current assignee: Prism Technologies LLC

Added 10/1/2026, 3:55:13 PM

At a glanceNo PTAB challenges7 lawsuits on fileasserted by Prism Technologies LLCSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative records on this specific patent number before summarizing.

Let me pull the actual claim text and check for any 2026 appellate activity.

Let me try to retrieve the actual claim language and confirm the expiration/status record.

US 8,387,155 — Summary

Caveat on scope of my search: I worked from the authoritative full text of the patent supplied in the prompt (Google Patents, fetched 2026‑10‑01) plus targeted web searches. I was not able to query USPTO PatentCenter/PTAB or the CAFC docket system directly, and my searches returned no 2026 CAFC docket activity for this patent number; see the litigation note below for what I did find and what remains unverified.

Bibliographic data

Field Value
Patent number US 8,387,155 B2
Title System for managing access to protected computer resources
Inventors Richard L. Gregg; Sandeep Giri; Timothy C. Goeke
Assignee Prism Technologies LLC (originally Prism Resources; assignments recorded Jan.–Mar. 2011)
Application no. 12/944,473
Filing date 2010‑11‑11
Issue date 2013‑02‑26
Priority date 1997‑06‑11 (from US 08/872,710, now US 6,516,416)
Status Expired – Fee Related; anticipated expiration listed as 2017‑06‑11
Classification H04L 63/10; G06F 21/30–21/335; G06F 21/44
Family Continuation of 11/978,919 (US 8,127,345) → continuation of 10/230,638 (US 7,290,288) → CIP of 08/872,710 (US 6,516,416). Continuing apps include US 8,898,746; 9,369,469; 9,413,768; 9,544,314.

Abstract (as printed)

"A system for controlling access to protected computer resources provided via a network utilizing at least one Internet Protocol. The system includes at least one authentication server and at least one access server. The at least one authentication server is adapted to authenticate identity data associated with at least one client computer device, is adapted to authorize the at least one client computer device to receive at least a portion of protected computer resources, and is adapted to permit access to the at least a portion of the protected computer resources. The at least one access server is adapted to receive the identity data associated with the at least one client computer device and forward the identity data associated with the at least one claim [sic] computer device to the at least one authentication server."

Overview of the disclosure

The specification describes a "secure transaction system" for untrusted networks such as the Internet, with four components: a transaction clearinghouse (authentication server + SQL database + authentication daemon + transaction daemon), account holder administration software, a secure transaction server (shared object, session manager, login/re-authentication/application CGIs), and account holder/client software (browser plug-in plus an optional hardware key). Central themes: mutual authentication of client and server, session creation with a session ID in HTTP headers, periodic re-authentication by polling for the hardware key, transaction logging, and forwarding usage/transaction data to the clearinghouse. The hardware key is described as a hardware token (e.g., Rainbow iKey 1000 USB token), magnetic card reader, smart card reader, biometric reader, or a secure CPU/TPM-based identity.

Independent claims — plain language

Based on the claim text retrievable in search results (Justia's rendering of the '155 patent), the independent claims are at least claims 1, 38, and 75. I could not retrieve the full verbatim text of claim 1 and claim 38 from the sources returned, so those two descriptions are partial and flagged as such.

Claim 1 — "system" claim (authentication server + database). A system for controlling access to protected computer resources over a network using at least one Internet Protocol, comprising at least one authentication server with an associated database storing (i) identity data for at least one client computer device and (ii) data associated with the protected computer resources. Uncertainty: the remainder of claim 1 was truncated in the source I could reach; the abstract suggests it also recites an access server that receives client identity data and forwards it to the authentication server, with the authentication server authenticating/authorizing/permitting access.

Claim 38 — "system" claim (authentication server + access server architecture). Apparent independent system claim spanning authentication and access server functions. Evidence for its scope comes from its dependents, e.g., claim 61 ("authentication server is located on a computer separate from said at least one access server"), claim 62 (same computer), claim 63 (functions performed by another server), claims 64–68 (multiple client devices, multiple access servers, plural servers adapted to authenticate/authorize/permit access), and claims 69–74 (selectively prompting the client for identity data plus a username and/or password). Uncertainty: I did not retrieve claim 38's full preamble/body.

Claim 75 — "system" claim (subscriber identity module / SIM variant). A system for controlling access to protected computer resources over an IP network, comprising: (a) at least one authentication server with a database storing identity data of an access server, identity data of a subscriber identity module associated with a client device, and authorization data for the protected resources; (b) the authentication server adapted to register the SIM identity data; (c) the access server adapted to receive the SIM identity data and a request for protected resources from the client; (d) the client adapted to receive an acknowledgement of that request; (e) the access server adapted to forward its own identity data and the client's SIM identity data to the authentication server; (f) the authentication server adapted to authenticate both the access server identity and the SIM identity responsive to the client's request; (g) the authentication server adapted to authorize the client device to receive at least a portion of the resources based on the stored authorization data; (h) the authentication server adapted to permit access only upon successful authentication and successful authorization; (i) the access server and/or an associated server adapted to acquire usage data for billing purposes; and (j) the authentication server adapted to re-authenticate the SIM identity data. Claim 76, which depends from claim 75, adds that the client device is adapted to authenticate something (text truncated).

Claim count

The record I retrieved displays claim numbers at least up to claim 76. I do not have an independently confirmed total claim count for the '155 patent, so I will not state one as fact.

Litigation / validity history (2012–2019) and the 2026 question

  • Google Patents links the family to a Nebraska District Court case (8:12‑cv‑00125) and to a Darts‑ip family litigation record.
  • Prism Technologies, LLC v. Sprint Spectrum L.P., 849 F.3d 1360 (Fed. Cir. 2017), cert. denied, 138 S. Ct. 429 (2017) — affirmed a judgment of infringement and a ~$30M damages award to Prism involving, per the IPWatchdog account, the '345 and '155 patents. https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/
  • Prism Techs., LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. 2017) (Nos. 2016‑2031, 2016‑2049) — under Alice, the panel held the challenged claims of the Prism patents, expressly including the '155, invalid as directed to patent‑ineligible subject matter ("merely recite a host of elements that are indisputably generic computer components"). That decision was then used in Nebraska to vacate the Sprint judgment.
  • Prism Techs. LLC v. Sprint Spectrum L.P., 757 F. App'x 980 (Fed. Cir. 2019) — subsequent panel decision setting aside the 2015 Sprint judgment; Prism sought certiorari (S. Ct. No. 18‑1397, 2019). https://www.supremecourt.gov/DocketPDF/18/18-1397/98180/20190501124836955_Prism%20Technologies%20Petition.pdf
  • 2026 CAFC dockets: My searches returned no 2026 Federal Circuit docket, appeal, or IPR involving US 8,387,155. Given the patent's listed anticipated expiration of 2017‑06‑11 and its "Expired – Fee Related" status, active 2026 appellate activity would be surprising. This is a negative finding from web search only — I did not have direct access to the CAFC PACER/docket or PTAB APIs, so I cannot rule out a 2026 filing with certainty.

Bottom line / uncertainty notes

  1. Identifiers are reproduced literally as they appear in the sources (the abstract's "at least one claim computer device" is a typo in the printed patent, not a correction on my part).
  2. Highest-confidence data: title, inventors, assignee, application number 12/944,473, filing 2010‑11‑11, issue 2013‑02‑26, 1997‑06‑11 priority, abstract, and the full text of claim 75.
  3. Lower-confidence data: the complete verbatim text of independent claims 1 and 38, and the exact total claim count — sources returned truncated text.
  4. Validity note: the '155 was among the Prism patents held ineligible under § 101 by the Federal Circuit in the T‑Mobile appeal (non‑precedential, 696 F. App'x 1014), and the patent has since expired. Any statement about current enforceability should be treated as historical rather than a present legal conclusion.

Generated 10/1/2026, 4:01:12 PM

Cases on file (7)

Group view →

Specific litigation cases in our database that name US patent 8387155. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US patent 8387155 across multiple sources.

Let me verify the specific case details and outcomes across the litigation family.

Litigation Involving U.S. Patent No. 8,387,155 ("the '155 patent")

Executive summary: U.S. Patent 8,387,155 — System for Managing Access to Protected Computer Resources — issued February 26, 2013 to Prism Technologies LLC. All known litigation over the '155 patent was brought by Prism Technologies LLC as plaintiff. The asserted campaign was a five-defendant wireless-carrier action filed in the U.S. District Court for the District of Nebraska (Omaha), plus related appeals to the Court of Appeals for the Federal Circuit and two certiorari petitions to the U.S. Supreme Court. Every asserted claim of the '155 and companion '345 patents was ultimately held invalid as patent-ineligible under 35 U.S.C. § 101, and the campaign ended in dismissal/settlement with no surviving judgment. I found no litigation asserting the '155 patent by any plaintiff other than Prism Technologies LLC.

Note: Google Patents lists the patent's family litigation with the Nebraska case 8:12-cv-00125 as the flagged case, which is comported with the identified carrier litigation below.

Case List

# Plaintiff Defendant Jurisdiction / Court Case No. Filed Outcome / Status
1 Prism Technologies LLC AT&T Mobility LLC D. Neb. (Omaha) 8:12-cv-00122 04/04/2012 (complaint); amended 09/21/2012, 03/01/2013 to add '155 Settled — settled on the last day of trial, November 2014; court dismissed the parties' claims (see Prism Techs. LLC v. Sprint Spectrum L.P., Fed. Cir.).
2 Prism Technologies LLC Sprint Spectrum L.P. d/b/a Sprint PCS D. Neb. (Omaha) 8:12-cv-00123 (-LES-TDT) 04/04/2012 (amended 03/2013 to add '155) Jury verdict for Prism (06/2015); later vacated. Jury found infringement of claims 7 & 37 of '155 (and claims 1 & 33 of '345), awarding $30M reasonable royalty. Post-trial motions denied (Dec. 2015). Fed. Cir. affirmed denial of Sprint's post-trial motions (Mar. 2017), rehearing denied (May 2017). After the T-Mobile § 101 invalidity decision, D. Neb. granted Sprint relief from judgment under FRCP 60, vacating the $30M judgment (Aug. 8, 2017). Fed. Cir. affirmed on the collateral-estoppel/mandate issue, 757 F. App'x 980 (Fed. Cir. 2019); cert. denied June 10, 2019.
3 Prism Technologies LLC T-Mobile USA, Inc. D. Neb. (Omaha) 8:12-cv-00124 04/04/2012 (amended 03/2013 to add '155) Jury verdict for T-Mobile (non-infringement), Oct./Nov. 2015. On cross-appeal, Fed. Cir. reversed the district court's § 101 eligibility ruling and held the asserted claims patent-ineligible under Alice: Prism Techs. LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. June 23, 2017) (non-precedential). Prism's appeal dismissed as moot; en banc rehearing denied. Cert. denied (No. 17-716).
4 Prism Technologies LLC [United States Cellular Corporation d/b/a U.S. Cellular](/litigations/by-defendant/United%20States%20Cellular%20Corporation%20d%2Fb%2Fa%20U.S.%20Cellular) D. Neb. (Omaha) 8:12-cv-00125 (-LES-SMB) 04/04/2012 (amended to add '155) Stayed pending Sprint/T-Mobile appeals; after those resolutions, ordered to show cause (06/25/2019) and dismissed with prejudice, July 18, 2019 (parties to bear own costs).
5 Prism Technologies LLC [Cellco Partnership d/b/a Verizon Wireless](/litigations/by-plaintiff/Cellco%20Partnership%20d%2Fb%2Fa%20Verizon%20Wireless) D. Neb. (Omaha) 8:12-cv-00126 (-LES-SMB) 04/04/2012 (amended to add '155) Stayed pending Sprint/T-Mobile appeals; dismissed with prejudice, July 18, 2019 under the same order as the U.S. Cellular case.

Related Appellate Proceedings (raising the '155 patent)

  • Appeal No. 16-2031 (and 16-2049) — Prism Techs. LLC v. T-Mobile USA, Inc., 696 F. App'x 1014 (Fed. Cir. June 23, 2017). Non-precedential. Reversed § 101 eligibility ruling; held '345 and '155 claims patent-ineligible. Cross-appeal denied T-Mobile's § 285 exceptional-case request.
  • Appeal of the Sprint judgment — Fed. Cir. affirmed denial of Sprint's post-trial motions (opinion reported at Prism Techs. LLC v. Sprint Spectrum L.P., 2017 WL 1042042 and subsequent; rehearing denied May 8, 2017); and the 2019 Fed. Cir. decision at 757 F. App'x 980 upholding application of collateral estoppel to vacate the Sprint judgment.
  • Supreme Court No. 17-716 — Prism petition for certiorari (deference to district-court factual findings in § 101 analysis); denied.
  • Supreme Court No. 18-1397 — Prism petition for certiorari (collateral estoppel / mandate rule); denied June 10, 2019.

Key Factual / Procedural Notes

  1. Issuance timing: The '155 patent issued February 26, 2013 — after the initial April 4, 2012 complaints were filed. Prism added the '155 patent to each carrier case by amended complaint (amended Sept. 21, 2012 and/or Mar. 1, 2013). The original April 2012 suits asserted the '288 and '345 patents.
  2. Asserted claims: In the Sprint case, claims 7 and 37 of the '155 patent were found infringed (claims 1 and 33 of the '345 patent were also found infringed). The '155 patent is a continuation of the '345 patent; both descend from U.S. Patent 6,516,416.
  3. Common claim construction: The Nebraska court construed "Internet Protocol Network" as "an untrusted network using any protocol of the Internet Protocol Suite including at least one of IP, TCP/IP, UDP/IP, HTTP, and HTTP/IP," with "untrusted" meaning "a public network with no controlling organization, with the path to access the network being undefined and the user being anonymous."
  4. Earlier Prism cases are NOT '155 litigation: The earlier Prism Techs. LLC v. Research in Motion, Ltd. et al. (D. Neb. 8:08-cv-00537) and Prism Techs. LLC v. Adobe Systems Inc. et al. (D. Neb. 8:10-cv-00220) asserted only the '288 patent, not the '155 patent. Likewise Prism Tech. LLC v. Verisign, Inc. (Fed. Cir. 07-1315) and the earlier Delaware case involved the '416/'288 family. These are related-family but not '155-patent litigation and should not be listed as such.
  5. Current status: With the Federal Circuit's § 101 invalidity holding, the vacatur of the Sprint judgment, and the 2019 dismissals-with-prejudice of the U.S. Cellular and Verizon cases, the '155 patent has an expired / no enforceable claim posture (Google Patents lists anticipated expiration 2017-06-11 for the family and legal status "Expired – Fee Related"). No active '155 litigation is known as of the current date.

Verification / Caveats

  • Case numbers above are taken from the dockets and court orders (e.g., the D. Neb. show-cause and dismissal orders in 8:12-cv-00125 and 8:12-cv-00126, and the Federal Circuit opinions).
  • The '155 patent is included in the flagged litigation family at https://portal.unifiedpatents.com/litigation/Nebraska%20District%20Court/case/8%3A12-cv-00125.
  • I could not independently verify complete outcome data (e.g., exact docket resolution dates) for every district-court entry from PACER itself; the outcomes above are drawn from published court opinions, Federal Circuit decisions, Supreme Court docket filings, and Prism's SEC/press disclosures. If you need docket-level certainty (e.g., exact judgment dates, any sealed settlements), a PACER pull for each of the five Nebraska dockets is recommended.
  • I found no litigation involving U.S. Patent 8,387,155 brought by any party other than Prism Technologies LLC, and no assertion of this patent outside the Nebraska wireless-carrier campaign and its appeals.

If helpful, I can produce a one-page litigation history/timeline suitable for an IDS or a validity-position memo, or pull the specific claim-language and claim-construction record for the asserted '155 claims.

Generated 10/1/2026, 4:01:02 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Prism Technologies LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

PTAB / AIA Trial Analysis — US 8,387,155 B2

Patent: System for managing access to protected computer resources
Patent Owner / Current Assignee: Prism Technologies LLC (successor: Prism Technologies Group, Inc.)
Priority: 1997-06-11 (continuation of App. 11/978,919 ← 10/230,638 ← CIP of 08/872,710)
Issued: 2013-02-26 · Filing date: 2010-11-11 · Status at ODP: Expired – Fee Related (anticipated term expiration 2017-06-11)


Proceedings overview

Zero AIA trial proceedings on file — no IPR, PGR, or CBM petition against US 8,387,155 was ever instituted (or, based on the canonical ODP record and my own targeted searches, ever filed): active 0 / claims invalidated by PTAB 0 / claims sustained 0 / settled 0 / institution denied 0 — which means the patent's death came not from the PTAB but from the Federal Circuit on § 101 grounds in the parallel T-Mobile litigation, leaving a defendant today with a far stronger story than any IPR could have produced ("the asserted claims of this patent have been adjudicated invalid and the patent's term expired on 2017-06-11 — any demand letter citing it is dead on arrival").

What I checked and what I did not find. The structured "PTAB proceedings on file" block supplied in this prompt (USPTO ODP ingest) reports no AIA trial proceedings. Independent web searches for 8387155 / 8,387,155 combined with PTAB, IPR, CBM, and Prism Technologies surfaced no PTAB petition, institution decision, Final Written Decision, or appeal of an FWD for this patent. Because CBM review was available against financial-services-adjacent patents from 2012-09-16 through 2018-09-16, and this patent was in active litigation across five district court suits in that exact window, the absence of any CBM is a real (not merely administrative) data point — see the strategic summary below.

Important scoping note. The dispositions below are not PTAB proceedings. They are the district court and Federal Circuit proceedings from the Prism wireless-carrier campaign, which is where this patent was actually killed. I have labeled each card accordingly rather than dressing them up as AIA trials. I was unable to verify the Federal Circuit appeal docket numbers from the available sources and have not invented them.


Federal Circuit — Prism Technologies LLC v. T-Mobile USA, Inc. (cross-appeal on § 101) — claims invalidated

  • Type: NOT a PTAB proceeding — Federal Circuit appeal from D. Neb. No. 8:12-cv-124-LES-TDT.
  • Decided: June 2017 (exact day not confirmed in the sources retrieved).
  • Status: Judgment of invalidity — asserted claims held unpatentable under 35 U.S.C. § 101.
  • Judge panel: Chief Judge Sharon Prost; Circuit Judges Alan Lourie and Alvin A. Schall (as reported by IPWatchdog; reported name spelling corrected).
  • Claims at issue: The asserted claims tried against T-Mobile, which the Nebraska district court later identified as claims 1 and 33 of U.S. Patent No. 8,127,345 and claims 7 and 37 of U.S. Patent No. 8,387,155. The district court's 2017-08-08 Rule 60 order stated that "the claims at issue in the T-Mobile case were the same claims at issue in the present case" and that "all four of those claims were scrutinized by the Federal Circuit and adjudged to be invalid." (Source: Vitallaw/IP Law Daily summary of the Rule 60 order — treat the claim-number mapping as sourced-but-secondary; I did not read the FWD-equivalent opinion page-by-page.)
  • Disposition: The district court had granted Prism's cross-motion for summary judgment of § 101 eligibility; the jury then returned a verdict of non-infringement in T-Mobile's favor. On appeal, the Federal Circuit reversed the eligibility ruling and held the asserted claims directed to the abstract idea of "providing restricted access to resources," with generic computer components ("authentication server," "access server," "Internet Protocol network," "client computer device," and "database") supplying no inventive concept at Alice step two. The non-infringement verdict on the merits was left standing.
  • Key quote (claim 1 of the '345, recited "authentication server," "access server," "Internet Protocol network," "client computer device," and "database"): the court held these were "indisputably generic computer components" that did not "cover a concrete, specific solution to a real-world problem."
  • Appeal: This was the appeal. Review denied/not further appealed to SCOTUS as far as the retrieved sources show.
  • Defensive value: This is the single most valuable item in the file. The asserted claims of both patents-in-suit were held invalid as a matter of law. Any infringement theory built on '155 claims 7 or 37 (or on the commonly-asserted siblings) runs into a binding Federal Circuit invalidity adjudication — and unlike an IPR, a § 101 holding cannot be cured by claim amendments on the plaintiff's side.

Citations: CourtListener opinion — https://www.courtlistener.com/opinion/[4403153](/patent/4403153)/prism-technologies-llc-v-t-mobile-usa-inc/ · IPWatchdog summary — https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/ · Vitallaw (Rule 60 order summary) — https://www.vitallaw.com/news/patent-d-neb-sprint-relieved-of-30m-judgment-after-security-systems-patents-invalidated/ipm011d06cb407ccc10008ff290b11c2ac4f106


D. Neb. — Prism Technologies, LLC v. Sprint Spectrum L.P., No. 8:12-cv-123-LES-TDT (Rule 60 relief from $30M judgment)

  • Type: NOT a PTAB proceeding — district court order (Judge Lyle E. Strom), entered 2017-08-08.
  • Status: $30 million jury judgment vacated/set aside.
  • Background: June 2015 jury found Sprint infringed claims 1 and 33 of the '345 patent and claims 7 and 37 of the '155 patent, awarding $30M reasonable royalty plus ~$40,000 costs. The Federal Circuit affirmed the denial of Sprint's post-trial motions (March 2017; panel of Circuit Judges Richard Taranto, Richard Linn, and Raymond Chen) and denied rehearing (2017-05-08), expressly declining to reach validity because Sprint had not challenged it in that appeal.
  • Outcome: After the T-Mobile decision, Judge Strom granted Sprint relief under Fed. R. Civ. P. 60, holding that "Sprint should be relieved from the judgment when the patent claims were predicated on a nullity."
  • Defensive value: Confirms that the invalidity adjudication collaterally estops Prism from re-asserting these claims against parties who were in privity or who can invoke the judgment — and confirms the claims were held invalid, not merely unenforceable.

Citations: CourtListener — https://www.courtlistener.com/opinion/[4373125](/patent/4373125)/prism-technologies-llc-v-sprint-spectrum-lp/ · IPWatchdog (same article as above).


Related campaign facts (context only — no PTAB content)

  • Prism filed five parallel D. Neb. suits in April 2012 against AT&T Mobility (8:12-cv-122), Sprint (8:12-cv-123), T-Mobile (8:12-cv-124), U.S. Cellular (8:12-cv-125), and Cellco/Verizon (8:12-cv-126). Sources: Google Patents litigation panel; BusinessWire 2017-05-08 release.
  • AT&T settled on the eve of trial in late 2014 (dismissed 2014-12-29); the settlement agreement was later admitted in the Sprint trial over Sprint's objection.
  • U.S. Cellular and Verizon actions were stayed pending the Sprint and T-Mobile appeals.
  • Prism withdrew the '288 patent (U.S. 7,290,288) from the Sprint case in March 2014 "to further streamline the issues."
  • Do not mistake the Google Patents "Unified Patents Litigation Data" credit for Unified Patents activity. That attribution is a data-feed license credit on the Google Patents page, not evidence that Unified Patents filed an IPR/CBM against this patent. I found no defensive-aggregator filing.

Strategic summary

Canceled vs. sustained vs. untested. Nothing was canceled by the PTAB — because nothing went to the PTAB. But claims 7 and 37 of the '155 patent (the claims actually asserted and tried) were adjudicated invalid under § 101 by the Federal Circuit in the T-Mobile appeal, and that adjudication was applied to wipe out the parallel $30M Sprint judgment. Claims 1–6, 8–36, and 38+ of the '155 patent were never litigated to a claim-level validity determination in any forum I could identify — they are untested, though they rise or fall on the same specification, the same abstract-idea characterization ("providing restricted access to resources"), and the same generic-components analysis. Practically speaking, the surviving claim set is likely worth little: the Federal Circuit's reasoning was claim-agnostic as to the generic "authentication server / access server / database" architecture that pervades the patent. And separately, the patent term expired on 2017-06-11 (20 years from the 1997-06-11 earliest benefit date), and ODP lists it as "Expired – Fee Related."

Estoppel landscape. Because no IPR or PGR was ever instituted, there is no § 315(e)(2) estoppel on this patent. Every prior-art ground — § 102, § 103, § 112 — remains formally available to any defendant, and there is no petitioner-privity taint. That said, the practical value of an IPR today is close to zero: the patent is expired, so there is no live injunctive exposure and no ongoing royalty to defeat; and IPR cannot reach the § 101 defect that already killed the asserted claims in court. The strongest posture is not a new AIA petition — it is a collateral-estoppel / res judicata argument off the T-Mobile judgment plus a § 101 motion.

Pattern signals. (1) No repeat-petitioner pattern exists — there is no petitioner at all. (2) The patent owner did pursue appeals aggressively, but as an appellee/cross-appellant in district court litigation, not through PTAB appeals: Prism won affirmance of the $30M Sprint verdict in March 2017, lost rehearing in May 2017, and then lost the T-Mobile § 101 cross-appeal in June 2017, which unraveled the Sprint win in August 2017. (3) No defensive aggregator appears in the chain. (4) The most telling signal: despite five simultaneous district court suits and a patent family squarely in the financial/access-control space during the CBM window, no one filed a CBM or IPR. Defendants evidently concluded that a § 101 attack in district court (which can invalidate all methods of infringement and cannot be mooted by a claim amendment) was the better path — and that bet paid off.


Recommended next steps

  1. If you have received a demand citing US 8,387,155, do not treat this as a live patent. The term expired 2017-06-11, and the claims that were actually asserted and tried (claims 7 and 37) were adjudicated invalid by the Federal Circuit in Prism Technologies LLC v. T-Mobile USA, Inc. (June 2017) — see the opinion at https://www.courtlistener.com/opinion/4403153/prism-technologies-llc-v-t-mobile-usa-inc/. Demand letters asserting these claims in 2026 are, at minimum, sanction-worthy under Rule 11 if the sender knows the file.
  2. Pull and preserve the two primary documents. (a) The T-Mobile CAFC opinion (linked above) for the § 101 holding and the exact claim language; and (b) the 2017-08-08 D. Neb. Rule 60 order in No. 8:12-cv-123-LES-TDT for the finding that the four adjudicated claims are "a nullity." Confirm the precise claim numbers and CAFC docket numbers from the slips once you have PACER/CourtListener access — I flagged above that my claim-number mapping comes from a secondary (Vitallaw) summary, not from the opinion text itself.
  3. Assert issue preclusion, not a new IPR. If Prism (or an assignee) asserts the patent against you, run the Blonder-Tongue / collateral-estoppel analysis: a final judgment of invalidity on claims 7 and 37 precludes re-litigation of those claims against anyone, and the patent owner cannot avoid it by asserting a different, untested claim of the same patent without confronting the same § 101 record.
  4. No PTAB calendar to manage. There are no pending AIA proceedings, no institution deadlines, no FWD due dates, and no live § 315(e)(2) estoppel. Should a petition ever be filed against this (now expired) patent, it would face discretionary denial under the Director's current practice for weak/settled-expectation challenges — but that contingency is remote given the patent's status.
  5. Verify the "no activity" finding on the record. Before relying on the absence of PTAB proceedings in a brief, pull the Patent Trial and Appeal Board's own docket for this patent number: https://ptacts.uspto.gov/ptacts/ (PTAB E2E / PTAB Center search by patent number). The ODP ingest and my searches both show none, but a direct E2E screenshot is the citation-quality evidence.

Confidence and caveats. High confidence on: (i) zero instituted/filed AIA proceedings on '155 per ODP and my searches; (ii) the June 2017 CAFC § 101 invalidation in the T-Mobile case; (iii) the August 2017 Rule 60 vacatur of the Sprint judgment; (iv) the 2017-06-11 term expiration. Lower confidence on: the exact CAFC docket numbers and decision dates, the precise asserted-claim list, and whether any short-lived petition was filed and terminated without a public institution decision. I have not fabricated any proceeding number, and I have not attributed district court or Federal Circuit dispositions to the PTAB.

Generated 10/1/2026, 4:01:31 PM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2011-01-31 · Assignment

    Richard L. GreggPrism Resources

    title cleanup

  2. ? · recorded 2011-02-08 · Assignment

    Prism ResourcesPRISM TECHNOLOGIES LLC

    internal reorg

  3. ? · recorded 2011-03-01 · Assignment

    Sandeep Giri; Timothy C. GoekePrism Technologies, L.L.C.

    title cleanup

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment chain and litigation history for US 8387155. Let me run several searches in parallel.

Let me dig into the ownership chain, the Prism/IPC merger, and any recorded assignment details.

Ownership Reconstruction — US 8,387,155 B2 ("System for managing access to protected computer resources")

Source note / limitation. The USPTO Assignment Center (assignmentcenter.uspto.gov) and the legacy Assignment Search UI (assignment.uspto.gov) are JavaScript-rendered single-page apps; I could not retrieve their result tables as text in this session. The assignment events below are the reassignment records surfaced by Google Patents' legal-events feed plus corroborating SEC filings. Google Patents' legal events do not expose reel/frame or the recording correspondent, and I did not obtain those fields from another source — so reel/frame and correspondent are reported as "not retrieved" rather than guessed. Treat any reel/frame figure you see in this report as absent.


Inventors

Inventor Residence of record Employer at time of filing (determinable)
Richard L. Gregg Elkhorn / Omaha, Nebraska Prism Resources, Omaha, NE — the 1997 root case US 6,516,416 B2 is expressly "Assigned to Prism Resources, Omaha, Nebr."
Sandeep Giri Omaha, Nebraska Same — Prism Resources / successor Prism Technologies, LLC, Omaha, NE
Timothy C. Goeke Elkhorn, Nebraska Same — Prism Resources / successor Prism Technologies, LLC, Omaha, NE

All three are the original 1997 inventors carried forward through the continuation chain (08/872,710 → 10/230,638 → 11/978,919 → 12/944,473). They are Nebraska-based and appear to have been employees/founders of the Prism vehicle from the outset, not outside licensors.

Unusual pattern — present. The inventors' confirmatory assignments were executed/recorded ~14 years after the 1997 priority filing (records dated Jan–Mar 2011, per Google Patents; see timeline). That is not the "inventors leave within 12 months" fire-sale tell. It is better read as title cleanup immediately ahead of the 2012 enforcement campaign — the first carrier suits were filed April 4, 2012, roughly 13 months after the recording flurry. Note also that the inventors are not named as assignors on the two corporate-to-corporate links; only Gregg (2011-01-31) and Giri/Goeke (2011-03-01) appear as individual assignors.


Original assignee

Entity named on the issued patent: Prism Technologies LLC, Omaha, Nebraska (assignee of record on the '155 face; the same assignee appears on the sibling patents US 8,127,345, US 8,898,746, US 9,369,469, US 9,413,768, US 9,544,314).

Root-case assignee (1997): Prism Resources, Omaha, Nebraska — the assignee printed on US 6,516,416 B2.

  • Did they ship a product embodying the claims? No evidence of any product. Prism's own SEC registration statement (IPC S-4, Dec. 2014) describes the business model as "focused on intellectual property licensing and technology research and development," and states Prism "began enforcing its patents against third parties in 2005." Revenue was licensing revenue (~$40M gross in 2013, ~$9.4M in 2012), not product revenue.
  • Primary line of business: patent licensing and enforcement — a pure monetization business.
  • Corporate status: Prism Resources, Inc. was succeeded in August 2003 by Prism Technologies, LLC. Prism Technologies, LLC became a wholly owned subsidiary of Internet Patents Corporation (NASDAQ: PTNT) when the merger closed March 26, 2015 ($16.5M cash + 3.5M shares + earn-out). IPC renamed itself Prism Technologies Group, Inc. (NASDAQ: PRZM) effective Sept. 2015. The parent showed signs of financial distress by late 2016 (reported executive salary cuts to $12). The '155 patent itself carries Google Patents status "Expired – Fee Related," with an anticipated expiration of 2017-06-11 (20 years from the 1997 priority) — i.e., the family was allowed to lapse rather than maintained.

Assignment timeline

Recorded events (Google Patents legal-events feed; reel/frame and correspondent not retrieved):

  • Executed date not retrieved / recorded 2011-01-31 — Reel not retrieved

    • Conveyance: Assignment
    • Assignor: Richard L. Gregg
    • Assignee: Prism Resources
    • Correspondent: not retrieved — flag: cannot assess recurrence.
    • Context: inventor-to-company confirmatory assignment consolidating the 1997 patent family back into the original Nebraska assignee.
  • Executed date not retrieved / recorded 2011-02-08 — Reel not retrieved

    • Conveyance: Assignment
    • Assignor: Prism Resources Inc.
    • Assignee: Prism Technologies LLC
    • Correspondent: not retrieved — flag: cannot assess recurrence.
    • Context: internal reorg / successor-entity transfer (2003 succession recorded in 2011), not a sale to a third party.
  • Executed date not retrieved / recorded 2011-03-01 — Reel not retrieved

    • Conveyance: Assignment
    • Assignor: Sandeep Giri; Timothy C. Goeke
    • Assignee: Prism Technologies, L.L.C.
    • Correspondent: not retrieved — flag: cannot assess recurrence.
    • Context: inventor-to-company confirmatory assignment completing the chain into Prism Technologies, LLC.

No post-2015 assignment of the '155 patent is recorded. The March 2015 IPC/Prism transaction was a stock merger (Strategic Concepts Acquisition Corp. merged into Prism, with Prism surviving as a subsidiary), so it does not appear as a patent-assignment record on the '155 patent — the record owner remains Prism Technologies LLC, with Prism Technologies Group, Inc. as parent. If you need the reel/frame numbers and the recording correspondent, the only authoritative source is the Assignment Center search for 8,387,155 at https://assignment.uspto.gov/patent/index.html — those fields were not obtainable here.


Timeline diagram

timeline
    title Ownership of US 8387155
    1997 : Filed by Prism Resources
    2003 : Prism Technologies LLC formed
    2011 : Title assignments recorded
    2012 : First carrier suits filed
    2013 : Patent issued
    2015 : IPC acquires Prism Technologies LLC
         : Parent renamed Prism Technologies Group
    2017 : Claims held ineligible
         : Patent expires

NPE / troll-pattern signals

  1. Shell-entity transfer — present (with nuance). The patent sits in Prism Technologies LLC, a licensing-only entity with no products in commerce; the owner's own S-4 states the business is "intellectual property licensing" and that it "began enforcing its patents against third parties in 2005." Caveat that cuts against the classic "shell" tell: this is not a single-member anonymous LLC at a registered-agent address — it is a professional, publicly-parented licensing company with ~50 issued patents and staff. The transfer was licensing-vehicle → licensing-vehicle (Prism Resources → Prism Technologies LLC), so the "operating assignee → licensing LLC" element is absent. Score the signal on the no-products licensing-only owner, not on naming.

  2. Known asserter in the chain — present. Prism Technologies LLC is a documented high-frequency patent plaintiff: five parallel infringement suits filed April 4, 2012 in D. Neb. (AT&T 8:12-cv-00122, Sprint 8:12-cv-00123, T-Mobile 8:12-cv-00124, U.S. Cellular 8:12-cv-00125, Cellco/Verizon 8:12-cv-00126), plus an earlier action against VeriSign et al. (N.D. Ill. 1:05-cv-00214). It does not appear on the enumerated lists (Acacia, Marathon, IV, Wi-LAN, Mosaid/Conversant, etc.); it is an independent asserter whose litigation documents are indexed by RPX (insight.rpxcorp.com). Finding is based on assertion behavior, not list membership.

  3. Repeat correspondent across the chain — unclear. The recording correspondent for the 2011 assignments is not retrievable from the sources available here, so recurrence cannot be tested. (Litigation counsel is a separate question and does not establish the signal: Kramer Levin Naftalis & Frankel LLP and Koley Jessen P.C. appeared for Prism in the Nebraska cases.)

  4. Cascading transfers — not present. The three recorded assignments cluster in a single five-week window (2011-01-31 → 2011-03-01) and twice point at the same entity; they are a one-step title consolidation, not a chain of distinct LLCs cascading in under 24 months.

  5. Pre-litigation transfer — not present (as defined). The last recorded assignment (2011-03-01) predates the first carrier complaints (2012-04-04) by about 13 months, outside the 6-month window. The timing is still consistent with enforcement preparation, but it does not meet the signal's definition.

  6. Bankruptcy fire-sale — not present. Prism was acquired as a going concern on 2015-03-26 for $16.5M cash + stock + earn-out. There is no Chapter 7/11 sale in the record for this chain, despite later distress at the parent (reported 2016 salary cuts).

  7. Privateering — not present (for this chain). Prism Resources/Prism Technologies LLC was itself a licensing vehicle from formation; this patent was not transferred out of an operating company to attack that company's competitors. (The parent IPC did have operating roots — spun out of InsWeb after the Bankrate sale — but that concerns the InsWeb patents, not the Gregg family.)

  8. Defensive aggregator — not present. The chain terminates at Prism Technologies Group, Inc., a NASDAQ-listed patent monetization company. No RPX / AST / LOT / OIN link.


Verdict

NPE — high confidence.

Two or more strong signals are present on concrete facts, not naming: (i) the patent's owner of record, Prism Technologies LLC, is a licensing-and-enforcement entity with no product, per its own SEC S-4 description of the business model; (ii) that entity is a proven serial asserter — five simultaneous carrier suits filed 2012-04-04 (D. Neb. 8:12-cv-00122 through 00126) plus the earlier VeriSign action, with a $30M Sprint verdict in 2015; and (iii) the chain was absorbed by a NASDAQ-listed patent monetization parent (IPC → Prism Technologies Group), a subsidiary-only stock merger closing 2015-03-26 that left record title in Prism Technologies LLC. The 2011 confirmatory assignments (2011-01-31, 2011-02-08, 2011-03-01) look like record cleanup ahead of that campaign, and the '155 family was subsequently held §101-ineligible at the Federal Circuit (June 23, 2017, Nos. 2016-2031/2049) and allowed to lapse — Google Patents status "Expired – Fee Related."

Verify (and capture reel/frame + correspondent) here: https://assignment.uspto.gov/patent/index.html (search 8387155) and https://assignmentcenter.uspto.gov/. The reel/frame and recording-attorney fields — the strongest tell for recurring NPE counsel — were not retrievable in this session and should be pulled directly before any filing.

Not legal advice; assignment records are evidentiary leads, not legal conclusions.

Generated 10/1/2026, 4:01:29 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research US 8387155 directly and gather its cited references. Let me run several targeted searches.

I have the core reference list. Let me pull details on the most technically relevant cited references and confirm the full citation list.

Prior-Art Analysis — US 8387155 (as requested; identifiers interpreted literally)

1. Confirmation of the record (no auto-correction applied)

Field Value
Patent number US 8387155 B2
Title "System for managing access to protected computer resources"
Application 12/944,473 (filed 2010-11-11)
Grant date 2013-02-26
Pre-grant pub. US 2011/0061097 A1 (2011-03-10)
Inventors Richard L. Gregg; Sandeep Giri; Timothy C. Goeke
Assignee Prism Technologies LLC (Omaha, NE)
Priority claimed 1997-06-11 (from US 08/872,710, now US 6,516,416)
Continuity CIP of 10/230,638 (filed 2002-08-29, now US 7,290,288) → cont. of 11/978,919 (filed 2007-10-30, now US 8,127,345) → 12/944,473
Status Expired – Fee Related

Sources consulted: https://patents.google.com/patent/US8387155/en and the USPTO-mirror listing at https://www.freepatentsonline.com/[8387155](/patent/8387155).html.

⚠️ Scope caveat on the citation list. The authoritative front-page "References Cited" section was not included in the text I was able to retrieve, so the citation inventory below is reconstructed from the FreePatentsOnline record for US 8,387,155 and from the sibling-family front pages (US 8,127,345 and US 9,369,469). The list below is therefore substantially complete but not guaranteed exhaustive, and I could not verify every filing date to high confidence. Where I am not confident of a date I say so explicitly rather than guessing.


2. The § 102 date problem (critical threshold issue)

US 8,387,155 sits at the end of a continuation-in-part chain:

  • Earliest disclosure: 1997-06-11 (US 08/872,710)
  • CIP new matter: 2002-08-29 (US 10/230,638)

Under 35 U.S.C. § 102 the effective date assigned to a given claim governs whether a reference is prior art:

  1. If a claim is fully supported by the 1997 disclosure → prior art must predate 1997-06-11 (for § 102(a)/(b)) or be a U.S. patent/application filed before that date (for § 102(e)).
  2. If a claim depends on CIP new matter (e.g., the express "wireless" limitation of claim 3, the enumerated identity-data types, or the Trusted-Platform-Module material added for the 2002 filing) → the critical date shifts to 2002-08-29, making the many 1998–2001 cited patents available as § 102(e)/§ 102(b) art.

Consequence: Several of the most on-point cited patents are dated after 1997. They cannot be § 102(a)/(b) art against a 1997-date claim, but they can be § 102(e) art (or § 102(b) art) if the claim's support traces to the 2002 CIP. Any anticipation assertion below must be run through that gate first; I flag it for each reference.

A second threshold point: US 6,516,416 (Gregg et al., granted 2003-02-04) appears on the face of the patent, but it is the same family/parent and the same inventive entity's own earlier application. It is not § 102 prior art and cannot anticipate. In the table below I mark it "family — not art."


3. Most relevant cited references and claim mapping

A. US 6,377,994 B1 — Ault et al. ("Method and apparatus for controlling server access to a resource in a client/server system")

  • Assignee/inventors: IBM / D.F. Ault, J.C. Dayka, E. Finkelstein, R.H. Guski
  • App. 08/632,251; priority ~1996-04-14; granted 2002-04-22/23
  • Description: A host security server controls accesses to host resources requested "on behalf of" clients by an untrusted application server. On a client service request, the application server obtains a client security context; the security server later examines that context and grants access only if the client (and, for unauthenticated clients, the server) is authorized against access-control information in a security database. Distinguishes authenticated vs. unauthenticated clients.
  • § 102 posture: Filed before 1997-06-11, so it is § 102(e) art regardless of which priority date the claim receives — the strongest date posture of any cited reference.
  • Potentially anticipates: claim 1 (central authentication/authorization against stored identity data in response to a server request), claim 9 (server storing identity data and authenticating), claim 12 (method counterpart), and the server-authentication aspects of claim 8. It does not disclose an "access key associated with the client computer device" or derivation of identity data from such a key, so a clean § 102 hit on claim 1 as a whole is unlikely; it is strongest as § 103 art.
  • Source: https://patents.google.com/patent/US6377994 ; https://portal.unifiedpatents.com/patents/patent/US-[6377994](/patent/6377994)-B1

B. US 6,219,790 B1 — Lloyd et al. ("Centralized authentication, authorization and accounting server with support for multiple transport protocols and multiple client types")

  • Assignee/inventors: Lucent Technologies / B. Lloyd, G. McGregor
  • Filed 1998-06-19; granted 2001-04-17
  • Description: A centralized AAA server fronted by multiple transport-protocol modules; a DBMS stores user authentication, authorization and accounting data in a standard format. A five-phase process (Augmentation, Selection, Authentication, Authorization, Confirmation) authenticates the user record and checks a "permit" to authorize the requested service.
  • § 102 posture: § 102(e) art only if the claim's date is the 2002 CIP date (filed 1998-06-19); not prior art against a 1997 date.
  • Potentially anticipates: claim 1 (centralized server storing identity data, authenticating on request, authorizing), claims 5/6 (username/password identity data), claim 10 / 20 (billing & usage-tracking transaction data forwarded to the clearinghouse), claim 12. Lacks the hardware/access-key limitation of claim 1, so again § 103-oriented.
  • Source: https://patents.google.com/patent/[US6219790B1](/patent/US6219790B1) (its own search report cites Cisco TACACS+ (1995), US 5,586,260 to Hu (1996), and EP 0 949 788 A1 to Sun Microsystems (1999-10-13)).

C. US 6,256,737 B1 — Bianco et al. ("System, method and computer program product for allowing access to enterprise resources using biometric devices")

  • Assignee/inventors: BioNetrix Systems Corp. / P.G. Bianco, W.T. Boon, R.B. Sterling, K.R. Ware
  • Filed 1999-03-09; granted 2001-07-03
  • Description: A biometric server stores biometric templates, digital certificates, device IDs, etc.; "biometric policies" (OR/AND/CONTINGENT/RANDOM/THRESHOLD) govern how a user is authenticated before access to enterprise resources is granted. Enrollment/administration stations populate the server.
  • § 102 posture: § 102(e) art only under the 2002-CIP-date scenario; not prior art against a 1997-date claim.
  • Potentially anticipates: claims 5 and 6 (identity data comprising biometric data, and combinations), claims 15/16 (method counterparts), and the biometric-reader aspect of the "access key" in claims 1/4 and 12/15. Directly on point for the patent's FIG. 24 biometric embodiment.
  • Sources: https://patents.google.com/patent/US6256737 ; https://patentimages.storage.googleapis.com/4a/54/bd/62035ab52c2de4/US6256737.pdf

D. US 6,226,744 B1 — Murphy et al. ("Method and apparatus for authenticating users on a network using a smart card")

  • Granted 2001-05-01
  • Description: Network user authentication using a smart card as the token. Maps to the patent's FIG. 23 smart-card embodiment and the "access key" concept.
  • § 102 posture: Date-dependent; I did not verify its filing date to high confidence — flag for verification.
  • Potentially anticipates: claims 5/6 ("card based data," "hardware identification data"), claims 4/15 (hardware memory device storing identity data), the smart-card aspect of claims 1/12.

E. US 6,075,860 — Ketcham ("Apparatus and method for authentication and encryption of a remote terminal over a wireless link")

  • Granted 2000-06-13
  • Description: Authentication and encryption of a remote terminal over a wireless link — maps to the express wireless limitation.
  • § 102 posture: Post-1997 grant; § 102(e)/(b) relevance only under the 2002-CIP-date scenario (filing date not verified here).
  • Potentially anticipates: claims 3 and 14 ("server is adapted to receive said identity data wirelessly").

F. US 6,510,236 — Crane et al. ("Authentication framework for managing authentication requests from multiple authentication devices")

  • Granted 2003-01-21
  • Description: A framework that fields authentication requests from multiple heterogeneous authentication devices and manages them centrally — conceptually parallel to a clearinghouse authenticating many client/device types.
  • § 102 posture: Date-dependent (filing date not verified); relevant only under the 2002-CIP-date scenario.
  • Potentially anticipates: claim 11 (second clearinghouse / multiple authentication entities) and the "multiple access key types" concept underlying claims 4–6 / 15–16.

G. US 6,041,357 — Kunzelman et al. ("Common session token system and protocol")

  • Granted 2000-03-21
  • Description: Common session token/system protocol for authenticating sessions across systems — relevant to the patent's session-ID / re-authentication architecture (FIGS. 9–12, 18–19).
  • § 102 posture: Post-1997 grant; § 102(e)/(b) only under the CIP-date scenario (filing date not verified).
  • Potentially anticipates: the session-establishment/re-authentication subject matter; note that claim 1 as published does not expressly recite a session, so this is better § 103 material than § 102 art against claim 1.

H. US 6,005,939 — Fortenberry et al. ("Method and apparatus for storing an internet user's identity and access rights to world wide web resources")

  • Granted 1999-12-21
  • Description: Storing a user's identity and access rights for access to WWW resources — maps to the "database to store identity data" and "authorize based on data associated with the requested protected computer resources."
  • § 102 posture: Post-1997 grant; date-dependent.

I. US 6,052,785 — Lin et al. ("Multiple remote data access security mechanism for multitiered internet computer networks")

  • Granted 2000-04-18
  • Description: Multi-tiered Internet security with a separate security/authentication tier — structurally analogous to the access-server/authentication-server split.
  • § 102 posture: Post-1997 grant; date-dependent.

J. US 6,088,451 — He et al. ("Security system and method for network element access")

  • Granted 2000-07-11 — network-element access security; secondary relevance to claims 1/8/12 (server-side and network-element authentication).

K. US 6,212,634 — Geer, Jr. et al. ("Certifying authorization in computer networks")

  • Granted 2001-04-03 — digital-certificate-based certifying of authorization between network parties; supports claims 5 ("digital certificate") and 1/8.

L. US 6,070,243 — See et al. ("Deterministic user authentication service for communication network")

  • Granted 2000-05-30 — centralized/deterministic user authentication service; supports claim 1's central-authentication concept.

M. US 6,223,984 — Renner et al. ("Distinct smart card reader having wiegand, magnetic strip and bar code types emulation output")

  • Granted 2001-05-01 — reader hardware supporting multiple card types; supports claims 22 (as spec'd: magnetic/smart card reader as hardware key) and 2/4/15.

N. US 6,516,416 B2 — Gregg et al. ("Subscription access system for use with an untrusted network")

  • Filed 1997-06-11; granted 2003-02-04; named same inventors, same assignee.
  • Family reference — NOT § 102 prior art. Listed here only because it appears on the face of US 8,387,155.

4. Secondary cited references (lower § 102 relevance — general "storing/downloading/protected-content" art)

These appear on the face of the patent or its siblings but map only to peripheral claim elements (server, database, network delivery). All are post-1997 grants, so they are § 102(e)/(b) art only under a 2002-CIP-date claim:

Patent Inventor Grant Brief description
US 7,039,021 Kokudo 2006-05-02 Auth. method/apparatus for wireless LAN
US 2004/0024764 A1 Hsu et al. 2004-02-05 (pub.) Assignment & management of authentication/authorization
US 6,615,258 Barry et al. 2003-09-02 Integrated customer interface for web-based data management
US 6,553,492 Hosoe 2003-04-22 Client-server access authentication w/ memory medium
US 6,249,873 Richard et al. 2001-06-19 Secure distributed directory services / PKI
US 6,247,011 Jecha et al. 2001-06-12 Computerized prepress authoring
US 6,185,587 Bernardo et al. 2001-02-06 Building a web site with automated help
US 6,173,403 DeMont 2001-01-09 Distributing information products
US 6,108,420 Larose et al. 2000-08-22 Networked installation of customized, authenticable software
US 6,044,471 Colvin 2000-03-28 Securing software to reduce unauthorized use
US 6,041,411 Wyatt 2000-03-21 Defining/verifying user access rights
US 6,035,402 Vaeth et al. 2000-03-07 Virtual certificate authority
US 6,021,202 Anderson et al. 2000-02-01 Processing electronic documents
US 6,006,332 Rabne et al. 1999-12-21 Rights management for digital media

Foreign art on the face: EP 0 268 141 A2 (1988); EP 0 456 920 A2 (1990). Other publications: the "Prism Technologies LLC v. Verisign, Inc., Civil Action No. 05-214 JJF" § 282 notice and invalidity contentions, plus numerous pre-1997 periodical/marketing materials listed on the sibling US 8,127,345 / US 9,369,469 front pages (see https://patents.justia.com/patent/[8127345](/patent/8127345)#14).


5. Bottom line on § 102 anticipation

  1. No cited reference appears to anticipate claim 1 (or claim 12) as a whole. The distinguishing element across the cited art is the combination of (a) a central "clearinghouse" authentication server, (b) an "access key … associated with the client computer device" from which identity data is derived, and (c) the server forwarding that identity data to the clearinghouse for authentication-and-authorization on a per-transaction basis. The cited patents individually supply one or two of these, not all three.
  2. Best § 102(e)-dated candidates: US 6,377,994 (Ault) is the only cited reference I confirmed as filed before the 1997 priority date, so it is prior art on any theory — but it lacks the access-key limitation and is therefore an obviousness (not anticipation) reference for claim 1. US 6,219,790 (Lloyd) and US 6,256,737 (Bianco) are the strongest § 102(e) candidates only if the claim at issue draws support from the 2002 CIP.
  3. Claim-specific § 102 targets (subject to the date gate):
    • Identity-data types (claims 5/6/15/16): Bianco (biometric), Murphy (smart card, not verified), Geer (digital certificate).
    • Wireless (claims 3/14): Ketcham.
    • Multiple/alternate clearinghouse or multi-device authentication (claims 9/11/19): Crane, Ault.
    • Transaction/billing/usage data reporting (claims 10/20): Lloyd.
    • Access-key hardware (claims 2/4/15): Renner (readers), plus the token/card readers described in the specification's FIGS. 21–25.
  4. Most relevant overall prior art = US 6,377,994 (Ault), on the strength of its date posture, with US 6,219,790 (Lloyd) and US 6,256,737 (Bianco) as the leading secondary references.

6. Important non-§ 102 note on this patent's actual fate

The prior-art question is somewhat academic for US 8,387,155, because the patent was held invalid under 35 U.S.C. § 101 (Alice) rather than on § 102/§ 103 grounds. In Prism Technologies LLC v. T-Mobile USA (Fed. Cir. 2017), the panel (Prost, Lourie, Stoll) affirmed ineligibility of the Prism claims (including the '155 family), which nullified the related $30M Sprint verdict. See https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/.


7. Explicit statement of limits on this analysis

  • I could not retrieve the complete, verbatim "References Cited" front page for US 8,387,155 from the sources available; the inventory above is reconstructed from the FreePatentsOnline record and the sibling patents US 8,127,345 and US 9,369,469. It may omit items.
  • I did not verify the filing dates for US 6,226,744, US 6,075,860, US 6,510,236, US 6,041,357, US 6,005,939, US 6,052,785, US 6,088,451, US 6,212,634, US 6,070,243, US 6,223,984, or the table in § 4 to high confidence. Any § 102(e) conclusion about them should be re-checked against the official USPTO PatentCenter/PatFT record.
  • Claim numbers referenced are those of the pre-grant publication US 2011/0061097 A1 (claims 1–20), which corresponds to the granted US 8,387,155 B2; if the granted claims were renumbered or amended during prosecution, the mapping should be conformed to the printed claims.
  • Per the operating rules, all identifiers are reproduced literally as they appear (e.g., US 8,387,155, US 923,473/12/944,473, US 6,516,416, US 9,369,469) without auto-correction.

Generated 10/1/2026, 4:01:41 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll gather prior-art context for this analysis. Let me run several searches in parallel.

Let me pull the specific cited references and litigation prior-art contentions.

Let me get the claim text and more on the key references.

Obviousness Analysis — U.S. Patent No. 8,387,155 B2

("System for managing access to protected computer resources")

Assignee: Prism Technologies LLC · Inventors: Gregg, Giri, Goeke · Filed: Nov. 11, 2010 · Granted: Feb. 26, 2013 · Priority date on the cover: June 11, 1997


0. Threshold disclosure — what the record does and does not contain

Two honesty caveats before the analysis, because they materially affect how strong any §103 conclusion can be stated:

  1. There is no §103 adjudication of the '155 claims. The only validity judgment of record for this family is a §101 (Alice) holding. In Prism Technologies LLC v. T-Mobile USA, Inc., the Federal Circuit held the asserted claims of the '345 and '155 patents ineligible as directed to the abstract idea of "providing restricted access to resources" implemented on generic hardware; that holding then collapsed the $30M Sprint verdict. See https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/ and the opinion text at https://storage.courtlistener.com/harvard_pdf/[4403153](/patent/4403153).pdf. So the §103 analysis below is predictive, not a report of an existing holding.

  2. The "Prior art keywords" and "Prior art date 1997-06-11" shown on the Google Patents page are the page's own derived metadata, not a legal determination. The page states the priority date is "an assumption and is not a legal conclusion." That disclaimer matters enormously here (see §1).

I do not have the full verbatim text of claim 1 of the '155 — the fetched page gives only the abstract and the specification. The claim-scope discussion below is built from the abstract and from the sibling claims of the same specification that I can verify (e.g., claims reproduced in US 8,127,345). I flag where I am inferring.


1. Priority date is the single biggest §103 issue, and it splits the claims

The '155 is a continuation of Ser. No. 11/978,919 (now US 8,127,345) → continuation of Ser. No. 10/230,638, filed Aug. 29, 2002 (now US 7,290,288) → continuation-in-part of Ser. No. 08/872,710, filed June 11, 1997 (now US 6,516,416). This is stated verbatim in the Description section of the page.

Because the '155 descends through a CIP, the June 11, 1997 date can only reach subject matter that was actually disclosed in the 1997 application. Two categories of claim limitations are very likely entitled only to the Aug. 29, 2002 date:

  • The hardware-key species described in FIGS. 21–25, which the specification identifies by name as the "iKey 1000 USB Smart Token device manufactured by Rainbow Technologies of Irvine, Calif." A commercial product identified by model number in a 2002 CIP is strong evidence that this disclosure was added in the CIP, not carried over from 1997.
  • The TPM / secure-CPU species of FIG. 25 and the "Trusted Platform Module (TPM)" discussion, which post-dates 1997 as a standardized concept.

Consequence: Any claim reciting "a hardware token access device, a magnetic card access device, a smart card access device, a biometric identification access device, or a central processing unit with a unique embedded digital identification" is measured against the 2002 state of the art. That sweeps in a large block of the face-of-patent references that would otherwise post-date 1997 — most importantly Murphy (US 6,226,744, "authenticating users on a network using a smart card"), Bianco (US 6,256,737, enterprise resources using biometric devices), Crane (US 6,510,236, authentication framework managing authentication requests from multiple authentication devices), Renner (US 6,223,984, smart card reader with Wiegand/magnetic-strip/bar-code emulation output), Kokudo (US 7,039,021), Grawrock (US 7,117,376, secure boot enforcing proper user authentication and hardware configuration) and Villavicencio (US 7,231,661, authorization services with external authentication).

A §103 challenge should therefore be pleaded in the alternative with explicit priority-date bracketing per claim, not as a single-date ground. Pleading only the 1997 date will forfeit the strongest references.


2. Person of ordinary skill in the art (POSITA)

For the 1997-dated claims: a B.S. in CS/EE plus ~2 years in network security, or equivalent, familiar with HTTP/CGI web serving, TCP/IP sockets, session management, symmetric/public-key cryptography, RADIUS, Kerberos, DCE, and token/smart-card authentication.

For the 2002-dated (CIP) claims: the same person with ~2–3 additional years, adding familiarity with PKI/certificates, SSL/TLS mutual authentication, smart-card middleware (PC/SC), biometric readers, and trusted-platform/secure-boot concepts. That person is highly likely to have read the RFC series and the Handbook of Applied Cryptography — indeed, the RIM invalidity charts in this very family include a 124-page chart on the Handbook of Applied Cryptography (listed in the file-history enumeration printed in US 8,127,345).


3. Claim scope (from the abstract + verified sibling claims)

The '155 is the apparatus/system counterpart to the '345 method patent. Its abstract recites a system for controlling access to protected computer resources provided via a network utilizing at least one Internet Protocol, comprising:

Element Claimed function
(A) at least one authentication server "adapted to authenticate identity data associated with at least one client computer device"
(B) " "adapted to authorize the at least one client computer device to receive at least a portion of protected computer resources"
(C) " "adapted to permit access to the at least a portion"
(D) at least one access server "adapted to receive the identity data associated with the at least one client computer device and forward the identity data … to the at least one authentication server"

(Note: the page renders element (A)/(D) as "client computer device" in the body but as "claim computer device" in the abstract. I have not auto-corrected this — it is reproduced literally and is itself a potential indefiniteness/prosecution-history issue worth checking against the printed patent.)

The verified dependents in the sibling '345 patent (claims 39–91 shown at https://patentimages.storage.googleapis.com/a2/c5/e9/df13d97de9e2d8/US8127345.pdf) teach that the family adds: database storage of identity data at the authentication server; authorization levels (claim 39); storing resources on a server associated with the access server (claims 73–77); encrypting at least a portion of the resources (claim 78); and locating the authentication server on a separate computer from the access server (claim 79). Those limitations are the ones most exposed to prior art.

Construction note: because the '155 uses "adapted to" rather than "means for," most of its system claims should not invoke 35 U.S.C. §112 ¶6 — but the Delaware court in Prism v. Verisign (Markman order, Apr. 2, 2007, https://ipmall.info/sites/default/files/hosted_resources/Markman/pdfFiles/2007.04.02_PRISM_TECHNOLOGIES_LLC_v._VERISIGN_INC.pdf) did construe family terms and addressed §112 ¶6 for means-plus-function elements. A §103 petitioner should run the analysis under the broadest reasonable construction of "adapted to."


4. Prior-art inventory (the "Prior Art" section of the page, plus the patent's own face)

Prior-art keywords derived on the page: server; client computer; computer device; access; identity data — i.e., the page's own classification says the inventive core is the server↔client↔identity-data access relationship, which is exactly the axis on which the prior art is densest.

References cited on the face of the '155 (from FreePatentsOnline's References Cited list, https://www.freepatentsonline.com/8387155.html), the most probative being:

  • US 6,219,790 (Lloyd et al.) — "Centralized authentication, authorization and accounting server with support for multiple transport protocols and multiple client types." Directly reads on elements (A)–(D).
  • US 6,510,236 (Crane et al.) — "Authentication framework for managing authentication requests from multiple authentication devices."
  • US 6,226,744 (Murphy et al.) — "authenticating users on a network using a smart card."
  • US 6,256,737 (Bianco et al.) — "allowing access to enterprise resources using biometric devices."
  • US 6,223,984 (Renner et al.) — smart card reader with Wiegand/magnetic-strip/bar-code emulation output.
  • US 7,117,376 (Grawrock) — "Platform and method of creating a secure boot that enforces proper user authentication and enforces hardware configurations."
  • US 7,231,661 (Villavicencio et al.) — "Authorization services with external authentication."
  • US 6,553,492 (Hosoe) — "Client-server system, server access authentication method … and issuance device."
  • US 6,073,243 (See et al.) — "Deterministic user authentication service for communication network."
  • US 6,085,451 (He et al.) — "Security system and method for network element access."
  • US 6,075,860 (Ketcham) — "Authentication and encryption of a remote terminal over a wireless link."
  • US 6,377,994 (Ault et al.) — "controlling server access to a resource in a client/server system."
  • US 6,052,785 (Lin et al.) — "Multiple remote data access security mechanism for multitiered internet computer networks."
  • US 2004/0024764 (Hsu et al.) — "Assignment and management of authentication & authorization."
  • US 6,615,258 (Barry et al.) — "Integrated customer interface for web based data management."
  • Supporting session/token/PKI art: US 6,041,357 (Kunzelman, common session token), US 6,035,402 (Vaeth, virtual certificate authority), US 6,212,634 (Geer, certifying authorization in computer networks), US 6,173,403 (DeMont), US 6,249,873 (Richard, distributed directory services and PKI), US 6,108,420 (Larose), US 6,044,471 (Colvin), US 6,041,411 (Wyatt), US 6,006,332 (Rabne), US 6,021,202 (Anderson), US 6,247,011 (Jecha), US 6,185,587 (Bernardo).
  • Foreign: EP 0 268 141 A2; WO 94/26044 (listed in the sibling '314).

Prior art also placed in the record by the Delaware/Nebraska litigation for this family (enumerated in US 8,127,345's printed file history and US 9,544,314):

  • US 5,708,780 (Levergood et al.), "Internet Server Access Control and Monitoring Systems" — see also the extensive description of Levergood in the IPR declaration at https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1516636](/patent/1516636)/... and the same reference used in IPR2018-01134 (Ex. 2008).
  • RADIUS / RFC 2058 (Willens et al.) — Exhibit B to RIM's Preliminary Invalidity Contentions.
  • OSF DCE (192-page chart), Kerberos V5 (46-page chart), Netegrity SiteMinder (61-page chart), Handbook of Applied Cryptography (124-page chart), plus charts on Akiyama, Yu, Tabuki, Teper, Grawrock, Crane, Murphy, He, Ketcham, Krajewski.

⚠️ Identifier anomaly I will not silently "fix": one PDF snippet in the record (US 8,127,345, page 20) renders the reference list as "5,708,780 A 1/1998 Tabuki" immediately followed by "5,710,884 A * 1/1998 Levergood et al." — i.e., the numbers and names appear column-shifted. Every independent source I found (the Tittel declaration in the '601 IPR; the US 7,953,791 reference list; the Soverain/CMU copy of the Levergood patent itself, http://euro.ecom.cmu.edu/people/faculty/mshamos/[7272639](/patent/7272639).pdf) attributes US 5,708,780 to Levergood. I am flagging the discrepancy rather than auto-correcting it, per instruction; the citation should be verified against the printed patent before being used in a filing.


5. Obviousness grounds

All references below are in the same field of endeavor (network access control / authentication of clients and servers) and are therefore a fortiori analogous art. Under KSR Int'l v. Teleflex, 550 U.S. 398 (2007), the motivation need not be found expressly in the references; it can come from design incentives, market forces, and the "interrelated teachings" of the art.

Ground 1 — Levergood '780 in view of RADIUS (RFC 2058 / Willens) and Kerberos

'155 element Where taught
System for controlling access to protected resources over a network using an Internet Protocol Levergood: controls/monitors access to content on the Internet via HTTP; protected resources are access-controlled files ("protection domains")
Access server receives identity data and forwards it to an authentication server Levergood: when a user requests an access-controlled file, "the server subjects the request to a secondary server which determines whether the client has an authorization or valid account"; the content server redirects the user to the authentication server where the user logs in
Authentication server authenticates identity data Levergood: authentication server verifies the client has a "valid account" before an SID issues
Authentication server authorizes and permits access Levergood: on verification the user "is provided with a session identification which allows the user to access the requested file as well as any other files within the present protection domain"
Separate authentication server, distinct from access server Levergood, expressly — two-server architecture
Server-side authentication of the (access) server by the authenticator RADIUS: NAS and RADIUS server share a secret and mutually validate; Kerberos V5: mutual authentication of client and server via tickets
Authorization levels (dependent claims) RADIUS: authorization attributes returned with the Access-Accept; DCE privilege service / ACL manager
Resource encryption (dependent claim 78) Handbook of Applied Cryptography §8.1 (listed in the record) / SSL

Motivation: Both references solve the same problem — centralized control of who may reach protected content. A POSITA seeking to scale a web content server's access-control beyond a local user file would look to the already-standardized RADIUS AAA model to centralize authentication and authorization, and to Kerberos for mutual client/server authentication (an explicit requirement of the claimed "clearinghouse … authenticate the identity of the first server computer"). The combination is a "simple substitution of one known element for another to obtain predictable results" — the KSR paradigm.

Ground 2 — Lloyd '790 in view of Crane '236, further in view of Murphy '744 (or Bianco '6,737) and Renner '3,984

  • Lloyd is the closest single reference: a centralized authentication/authorization/accounting server supporting multiple transport protocols and multiple client types. That literally supplies elements (A)–(D): a central authentication server, distinct access points, and authorization data.
  • Crane supplies the "identity data … associated with a client computer device" breadth: an authentication framework that manages authentication requests from multiple authentication devices — i.e., it teaches normalizing multiple client-side credential sources into one authentication pipeline.
  • Murphy supplies the hardware key that generates a digital ID: network user authentication using a smart card. Renner supplies the magnetic-strip/reader counterpart. Bianco supplies the biometric counterpart. Together these cover the FIG. 22–24 species verbatim.
  • Any claim reciting the generic "hardware key … adapted to generate a digital identification" limitation is met by Murphy/Renner alone.

Motivation: The '155 specification itself supplies the motivation, which is fatal to any "teaching away" argument: it concedes that the purpose of the hardware key is to defeat credential sharing, noting that "username-password schemes are vulnerable to password fraud because account holders can share their usernames and password by word of mouth or through Internet news groups" (Background, and the FIG. 21 discussion). Murphy, Bianco and Renner were all directed at exactly that problem and were already being deployed for network/enterprise logon. A POSITA combining a centralized AAA server (Lloyd) with a device-based credential source (Murphy) is doing nothing more than applying a known solution to a known problem, which KSR holds is obvious.

Ground 3 — Grawrock '376 in view of Lloyd '790 (for the TPM / "secure CPU" claims)

For claims reciting a "central processing unit with a unique embedded digital identification" (the FIG. 25 / TPM species):

  • Grawrock ("Platform and method of creating a secure boot that enforces proper user authentication and enforces hardware configurations") teaches a hardware root of trust that measures and attests the platform and binds authentication to it — the functional equivalent of the claimed TPM with a unique digital ID, including the "integrity metric"/digest concept the '155 describes ("a statistically unique digital fingerprint of the PC's basic input/output system (BIOS) firmware at boot time … also called an integrity metric or cryptographic digest").
  • Lloyd supplies the centralized server-side authentication/authorization architecture.

Motivation: Coupling platform identity to network authorization was the express commercial purpose of trusted-computing initiatives, and the '155's own TPM discussion is essentially a recitation of the TPM specification. Combining a TPM-based device identity with a central AAA server is a predictable aggregation of two known mechanisms with no unexpected result.

Ground 4 — DCE / Kerberos V5 / Netegrity SiteMinder (the "single sign-on" and "re-authentication" grounds)

These three are not merely cumulative; they target the two limitations most likely to be argued as the point of novelty:

  1. "the clearinghouse … is adapted to authenticate the identity of the first server computer responsive to the client computer making the request."

    • Kerberos V5 provides mutual authentication: the client obtains a ticket-granting ticket and then a service ticket, and the server proves its identity to the client (and vice versa) via the shared session key.
    • SSL/TLS server certificates were commercially deployed well before both priority dates and authenticate exactly this.
    • DCE builds a full distributed security service on Kerberos, with a cell directory, privilege service and delegated credentials — the specification's "clearinghouse" is structurally a DCE cell.
  2. "periodically … polling the account holder software to insure that the hardware key continues to be attached" (spec's FIG. 18 re-authentication).

    • Kerberos ticket lifetimes and RADIUS session/accounting timeouts are the canonical prior-art mechanisms for forcing periodic re-verification of an authenticated principal.
    • Netegrity SiteMinder (web SSO with agents on web servers, centralized policy/authorization server, session cookies, single sign-on across multiple web servers) supplies the multi-web-server "single sign-on scenario" that the '155 describes in connection with FIGS. 26–27.

Motivation: The '155's own specification states the commercial driver: "Once an account holder is authenticated at one of the system enabled web sites, that account holder can access other likewise enabled web sites transparently using the same username, password, PIN combination, and the optional digital ID … thus creating a single sign-on scenario." Single sign-on across heterogeneous web servers was a recognized, well-funded problem in the 1997–2002 window, and SiteMinder was the commercial answer; adding Kerberos-style ticket lifetimes to it is routine.


6. Recurring motivations a POSITA would articulate (usable across all grounds)

  1. Same field, same problem. Every reference addresses restricting access to network resources by authenticating a client and/or server — the page's own prior-art keywords ("server; client computer; computer device; access; identity data").
  2. Known problem, known solution. Password sharing/fraud was the acknowledged problem; device-bound credentials and centralized AAA were the acknowledged solutions.
  3. Finite, predictable design space. By the priority dates there were a small number of standard architectures for centralized authentication (RADIUS, Kerberos/DCE, TACACS+, web-SSO agents). KSR: "when there is a design need or market pressure to solve a problem and there are a finite number of identified, predictable solutions, a person of ordinary skill has good reason to pursue the known options."
  4. No unexpected results / no criticality. The '155's architecture is a two-tier client/authentication-server split with an intermediary access server — the same topology as DCE and RADIUS. Nothing in the specification alleges a synergistic or unpredictable result from the combination.
  5. The specification confirms, rather than contradicts, the combination. Its own admissions (password fraud; TPM integrity metrics; single sign-on demand) constitute applicant-admitted prior-art problems.

7. Anticipated rebuttals and how the record bears on them

Patent-owner argument Response grounded in the record
"No reference teaches authenticating the server by the clearinghouse." Kerberos V5 mutual authentication; SSL server certificates; RADIUS shared secrets.
"No reference teaches periodic re-polling of a hardware key." Ticket/session lifetimes in Kerberos and RADIUS; smart-card removal-detection was known in card-reader art.
"The references are non-analogous (wireless/WLAN/biometrics)." All are network authentication; KSR rejects rigid field boundaries where the problem is shared.
"Secondary considerations." Note that the 2015 Sprint verdict of ~$30M was vacated after the Federal Circuit's §101 affirmance of invalidity in Prism v. T-Mobile, so it cannot carry nexus weight; there is no express §103 finding to the contrary in the family's history.
"The claims are means-plus-function and the structure is only the disclosed clearinghouse/session-manager." That argument cuts against the patent owner here: under §112 ¶6 the claim scope narrows to the disclosed algorithms (session manager + daemons), which are exactly the DCE/RADIUS/SiteMinder architectures.

8. Conclusions and express limitations of this analysis

  1. The '155 claims are, in my assessment, vulnerable under §103 on at least four independent grounds, the strongest being Lloyd '790 (centralized AAA server) in view of Crane '236, and further in view of Murphy '744 / Renner '3,984 for the hardware-key species, and Levergood '780 in view of RADIUS RFC 2058 and Kerberos V5 for the core client/access-server/authentication-server-forwarding architecture.

  2. Priority date is dispositive of which ground applies. Claims reciting the token/magnetic-card/smart-card/biometric/TPM species almost certainly get Aug. 29, 2002, not June 11, 1997. Any §103 challenge pleaded only against the 1997 date will forfeit Murphy, Bianco, Crane, Renner, Kokudo, Grawrock and Villavicencio — the very references the examiner already cited on the face of the '155.

  3. I have not verified the full claim text of the '155 (only the abstract and sibling claims). Element-by-element mapping must be re-run against the printed claims before any filing.

  4. The "claim computer device" typo in the abstract and the "5,708,780 / Tabuki" vs. "5,708,780 Levergood" identifier discrepancy are reproduced literally here and should be resolved against the printed patent/PAIR before being relied upon. I have not auto-corrected either.

  5. No §103 ruling exists for this patent. The invalidity of record is a §101 holding from the Federal Circuit, cited above. My §103 conclusions are predictive and should be treated as such.


Sources relied upon: US 8,387,155 B2 page (https://patents.google.com/patent/[US8387155B2](/patent/US8387155B2)/en); FreePatentsOnline References Cited (https://www.freepatentsonline.com/8387155.html); US 8,127,345 printed claims and file-history enumeration (https://patentimages.storage.googleapis.com/a2/c5/e9/df13d97de9e2d8/US8127345.pdf); US 9,544,314 file-history enumeration (https://patents.justia.com/patent/[9544314](/patent/9544314)); Levergood description in the '601 IPR declaration (https://ptacts.uspto.gov/ptacts/public-informations/petitions/1516636); Levergood patent text (http://euro.ecom.cmu.edu/people/faculty/mshamos/7272639.pdf); Prism v. Verisign Markman order (https://ipmall.info/sites/default/files/hosted_resources/Markman/pdfFiles/2007.04.02_PRISM_TECHNOLOGIES_LLC_v._VERISIGN_INC.pdf); Prism v. T-Mobile Federal Circuit opinion (https://storage.courtlistener.com/harvard_pdf/4403153.pdf) and IPWatchdog summary (https://ipwatchdog.com/2017/08/28/cafc-finding-patent-invalidity-prism-t-mobile-undoes-30m-damages-award-sprint/).

Generated 10/1/2026, 4:01:52 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Prism Technologies LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (7)

7 tracked lawsuits name US 8387155.