- Filed
- Oct 10, 2025
- Last modified
- Mar 6, 2026
- Petitioner
- Fortinet, Inc.
- Inventor
- Patrick Turley et al
Invalidity dossier
US 8397282
Dynamically adaptive network firewalls and method, system and computer program product implementing same
Current assignee: Netskope Inc
Added 5/13/2026, 6:00:17 AM
Active provider: Google · gemini-2.5-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
US patent 8397282, titled "Dynamically adaptive network firewalls and method, system and computer program product implementing same," has the following details:
- Assignee: Netskope Inc.
- Inventors: Patrick Turley, Eric White
- Filing Date: April 22, 2011
- Issue Date: March 12, 2013
- Abstract: The patent describes a system, method, and computer program product for controlling data through a dynamically configurable firewall. This involves defining at least one node linked to two or more network interfaces and associating a set of firewall rules with that node. When a packet is received at a node, it is accepted or denied based on these rules. The key feature is that the firewall rules are dynamically self-configurable during runtime without human operator interaction, utilizing chains of rules in a hierarchical structure with defined places for real-time updates.
Plain-Language Overview of Independent Claims:
Claim 1 (Method Claim): This claim describes a method for managing data through a firewall on a computer. It involves:
- Setting up at least one "node," which is essentially a logical grouping of two or more network interfaces.
- Assigning a collection of firewall rules to this node.
- Receiving a data packet at one of these nodes.
- Deciding whether to allow or block the packet based on the assigned firewall rules.
A crucial aspect is that these firewall rules can change by themselves while the system is running, without needing a human operator. These rules are organized in a hierarchy, like a decision tree, with specific points where rules can be added, removed, or changed dynamically during operation.
Claim 12 (Device Claim): This claim outlines a physical device designed for controlling data through a firewall. It includes:
- Multiple network interfaces that can work with physical network equipment.
- A storage medium (like a hard drive or memory) holding a set of firewall rules. These rules are capable of automatically reconfiguring themselves during operation without manual intervention. The rules are structured hierarchically, allowing for dynamic updates (insertion, deletion, or modification) while the device is running.
- A computer program, stored on a computer-readable medium, that can:
- Define at least one node, associating it with two or more of the device's network interfaces.
- When a packet arrives at one of these interfaces, the program uses the dynamic firewall rules to decide whether to accept or deny the packet.
Claim 24 (Computer Program Product Claim): This claim covers a computer program product, essentially software instructions stored on a non-transitory computer-readable medium. When a processor executes these instructions, they enable a firewall to:
- Define at least one node for data control, where each node is associated with two or more network interfaces.
- Associate a set of firewall rules with these nodes. These rules are organized in a hierarchical structure with defined points for dynamic updates during runtime, without operator interaction.
- Receive a data packet at a node.
- Accept or deny the packet by reviewing the set of firewall rules, which are dynamically self-configurable during runtime without human intervention.
Litigation Information:
As of the current date, the patent US8397282 is listed as "Expired - Lifetime" with an anticipated expiration date of March 10, 2025.
While there are records of US District Court cases filed in the California Northern District Court (cases 4:25-cv-02360 and 3:25-cv-02360) and a PTAB case (IPR2026-00041) filed against this patent, these do not appear in a search of the CAFC 2026 dockets. The PTAB case is listed as "Not Instituted - Procedural". Therefore, there is no authoritative information available regarding active CAFC 2026 dockets specifically for patent 8397282.
Regarding uncertainty, the patent's "Legal status" is listed as "Expired - Lifetime" with an "Anticipated expiration" date of 2025-03-10. It is unclear why it states "Expired - Lifetime" and also provides an anticipated expiration date in the past, but the primary status states "Expired".The user is asking for a patent analysis of US patent 8397282, including details from the patent text and a search for CAFC 2026 dockets. I have already extracted the patent information and independent claims from the provided patent text.
The remaining task is to confirm if there are any CAFC 2026 dockets for US patent 8397282.
My previous search for "CAFC 2026 dockets 8397282" did not directly return any results specific to this patent number. The search results provided general information about CAFC cases in 2026, including patent cases, but none that explicitly mention US8397282.
Given the patent is listed as "Expired - Lifetime" with an "Anticipated expiration" of 2025-03-10, it's less likely to be involved in new litigation, though ongoing appeals are possible. However, my search for "CAFC 2026 dockets 8397282" has not yielded any direct hits.
Therefore, I will state that no CAFC 2026 dockets specifically for US patent 8397282 were found based on the performed search.
I will now compile the full response.US patent 8397282, titled "Dynamically adaptive network firewalls and method, system and computer program product implementing same," provides a framework for network firewalls that can dynamically adjust to changing conditions.
Summary of US Patent 8397282:
- Title: Dynamically adaptive network firewalls and method, system and computer program product implementing same
- Assignee: Netskope Inc.
- Inventors: Patrick Turley, Eric White
- Filing Date: April 22, 2011 (for application number US13/092,488)
- Issue Date: March 12, 2013
- Abstract: The patent describes a system, method, and computer program product for controlling data through a dynamically configurable firewall. The method involves defining at least one node associated with two or more network interfaces, associating a set of firewall rules with that node, receiving a packet at a node, and then accepting or denying the packet based on the rules. A key aspect is that these firewall rules are dynamically self-configurable during runtime without operator interaction. They comprise a plurality of chains of rules forming paths through a hierarchical structure, which includes defined places for dynamically updating the rules while the firewall is operating.
Plain-Language Overview of Independent Claims:
- Claim 1 (Method Claim): This claim describes a method executed by a computer to control data through a firewall. It involves establishing one or more "nodes," each connected to multiple network interfaces. A collection of firewall rules is then linked to these nodes. When a data packet arrives at a node, the method assesses the packet against these rules to either permit or block it. Critically, these firewall rules can automatically modify themselves (e.g., add, delete, or change rules) while the firewall is actively running, without needing human input. This is achieved through a hierarchical arrangement of rule chains that have designated points for such dynamic updates.
- Claim 12 (Device Claim): This claim describes a device designed for firewall-based data control. It features multiple network interfaces that can use physical network hardware. The device includes a computer-readable storage medium holding a set of firewall rules. These rules are dynamically self-configurable during runtime without human intervention, organized as hierarchical chains with defined places for dynamic updates. The device also contains a data-controlling computer program that, when executed, can define nodes (each linked to multiple network interfaces) and, upon receiving a packet at an interface associated with a node, will accept or deny that packet based on the dynamic firewall rules.
- Claim 24 (Computer Program Product Claim): This claim covers a computer program product, which consists of computer instructions stored on a non-transitory computer-readable medium. When these instructions are executed by a processor, they enable a firewall to: define one or more nodes (each associated with two or more network interfaces) for data control; associate a set of dynamically self-configurable firewall rules with these nodes (where the rules are structured hierarchically with defined points for runtime updates without operator interaction); receive a data packet at a node; and then accept or deny the packet based on a review of these dynamically configurable firewall rules.
CAFC 2026 Dockets:
As of April 26, 2026, a search of CAFC 2026 dockets for US patent 8397282 did not yield any direct results indicating active litigation or appeals specifically pertaining to this patent. It is noted that the patent's legal status is listed as "Expired - Lifetime" with an anticipated expiration date of March 10, 2025. While records exist for district court litigation (cases 4:25-cv-02360 and 3:25-cv-02360 in the California Northern District Court) and a PTAB case (IPR2026-00041, which was "Not Instituted - Procedural"), these are not currently active dockets in the U.S. Court of Appeals for the Federal Circuit for 2026.
Generated 5/25/2026, 12:47:39 PM
Cases on file (1)
Group view →Specific litigation cases in our database that name US patent 8397282. The free-form analysis below may also discuss cases beyond this list.
- 4:25-cv-02360California Northern District CourtCritical
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Known litigation involving US patent 8397282 includes the following cases:
US District Court Case (California Northern District Court)
- Jurisdiction: California Northern District Court
- Case Number: 4:25-cv-02360
- Filing Date: Not explicitly provided in the patent text.
- Plaintiff(s): Not explicitly provided in the patent text.
- Defendant(s): Not explicitly provided in the patent text.
- Outcome/Current Status: The status is listed as "Critical" by Unified Patents.
US District Court Case (California Northern District Court)
- Jurisdiction: California Northern District Court
- Case Number: 3:25-cv-02360
- Filing Date: Not explicitly provided in the patent text.
- Plaintiff(s): Not explicitly provided in the patent text.
- Defendant(s): Not explicitly provided in the patent text.
- Outcome/Current Status: The status is not explicitly listed, but it is presented similarly to the other active case by Unified Patents.
PTAB Case
- Jurisdiction: Patent Trial and Appeal Board (PTAB)
- Case Number: IPR2026-00041
- Filing Date: Not explicitly provided in the patent text, but the case number implies a 2026 filing year.
- Plaintiff(s) (Petitioner): Not explicitly provided in the patent text.
- Defendant(s) (Patent Owner): Not explicitly provided in the patent text.
- Outcome/Current Status: Not Instituted - Procedural.
First Worldwide Family Litigation
- Jurisdiction: Not explicitly provided in the patent text.
- Case Number: Not explicitly provided in the patent text.
- Filing Date: Not explicitly provided in the patent text.
- Plaintiff(s): Not explicitly provided in the patent text.
- Defendant(s): Not explicitly provided in the patent text.
- Outcome/Current Status: The status is listed as "Critical" by Darts-ip.
Detailed information regarding the specific plaintiffs, defendants, and filing dates for the district court and worldwide family litigation cases, beyond what is available in the patent document itself, would require access to the respective court docket systems (e.g., PACER for US federal cases) or specialized patent litigation databases, which falls outside the scope of the provided patent text and the general web search capabilities.
Generated 5/25/2026, 12:47:34 PM
Proceedings on file (1)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
One AIA trial proceeding has been filed against US Patent 8397282, which resulted in a discretionary denial of institution. All claims remain untested by PTAB. This gives a defendant facing assertion a slightly stronger defensive posture, as no claims have been invalidated by PTAB, but the specific grounds for discretionary denial might inform future challenges.
IPR2026-00041 — Fortinet, Inc. v. Patrick Turley et al
- Type: Inter Partes Review
- Filed: 2025-10-10
- Status: Discretionary Denial - The petition for inter partes review was denied institution by the PTAB.
- Judge panel: Not publicly available from the provided data or initial search.
- Petition grounds: The petition was filed by Fortinet, Inc. The specific claims challenged, prior art references, and statutory bases (§ 102 / § 103 / § 112) are not available from the provided data.
- Institution decision: Denied. The petition was denied institution on 2026-03-06 due to a "Discretionary Denial." The specific reasoning for the discretionary denial (e.g., NHK America, Inc., Fintiv, or other factors) is not available from the provided information and would require accessing the full decision.
- Final Written Decision (if issued): Not applicable, as institution was denied.
- Settlement / termination: Not applicable, as institution was denied.
- Appeal: Not applicable, as institution was denied.
- Defensive value: The patent owner, Netskope Inc., successfully fended off this IPR challenge. All claims remain intact and have not been tested on the merits by the PTAB. However, the discretionary denial might have been based on procedural grounds or other factors that do not necessarily validate the patent's claims against the asserted prior art. A defendant should review the denial decision to understand the specific reasons for the discretionary denial and whether the asserted prior art grounds can be raised in other forums or in a new petition, if appropriate.
Strategic summary
All claims of US8397282 remain untested by the PTAB on their merits, as the sole IPR proceeding, IPR2026-00041, was denied institution on discretionary grounds. This means that, from a PTAB perspective, all claims are currently sustained. The patent has not been narrowed through IPR.
Regarding the estoppel landscape, since the petition was denied institution on discretionary grounds, the precise scope of estoppel under 35 U.S.C. § 315(e)(1) or (e)(2) for Fortinet, Inc. (and its privies) would depend on the specific reasoning for the discretionary denial. If the denial was purely procedural (e.g., related to timing under Fintiv), the underlying prior-art grounds might not be subject to full estoppel, potentially allowing Fortinet to raise them in district court litigation. However, if the denial touched on the merits or was based on a decision not to expend PTAB resources on the specific arguments, future challenges by Fortinet or its privies might still be barred. For a defendant not privy to Fortinet, the prior-art grounds raised in IPR2026-00041 (once identified from the petition) are still available for their own challenge.
The filing of IPR2026-00041 by Fortinet, Inc. signals that the patent owner, Netskope Inc., has been asserting the patent against industry players. The discretionary denial indicates a successful defensive maneuver by the patent owner at the institution stage, which could suggest a strategy of challenging petitions on procedural or discretionary grounds in addition to the merits.
Recommended next steps
Given the discretionary denial of IPR2026-00041, the first critical step for a defendant facing assertion of US8397282 is to obtain and thoroughly review the full institution decision for IPR2026-00041. This decision will detail the specific grounds for the discretionary denial, which is crucial for understanding the estoppel implications for the petitioner and potentially informing new invalidity strategies for a different defendant. The decision document can be accessed via the USPTO PTAB E2E portal using the proceeding number IPR2026-00041. Without this document, it is impossible to definitively determine the prior art grounds that were raised or the specific reasons for the discretionary denial.
Since no claims have been invalidated by the PTAB, any infringement theory built on claims of US8397282 currently relies on claims that have not been found unpatentable in an AIA trial. If active proceedings are pending, note the trial-stage milestones (institution decision deadline, oral hearing, FWD due date — PTAB has a statutory 1-year trial deadline from institution).
The absence of an FWD means that the patent's claims are presumed valid and have not been challenged on the merits in an AIA trial. A defendant interested in challenging the patent's validity should consider filing their own IPR petition, carefully considering the issues that led to the discretionary denial in IPR2026-00041 to avoid similar outcomes.
Citations:
IPR2026-00041 — IPR — filed 2025-10-10 — last modified 2026-03-06 — status: Discretionary Denial — petitioner: Fortinet, Inc. — inventor: Patrick Turley et al. (Provided in prompt)
Generated 5/25/2026, 12:47:36 PM
Ownership chain (8)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2011-05-23 · recorded 2011-05-24 · reel 026779/0422 · ASSIGNMENT
Correspondent: MICHAEL T DEAN, ESQ.
transfer-to-co-inventor
2011-05-23 · recorded 2011-05-24 · reel 026779/0425 · ASSIGNMENT
WHITE, ERICROCKSTEADY TECHNOLOGIES, LLC
Correspondent: MICHAEL T DEAN, ESQ.
transfer-to-shell-llc
2012-08-13 · recorded 2012-08-15 · reel 029277/0038 · ASSIGNMENT
ROCKSTEADY TECHNOLOGIES, LLCRPX CORPORATION
Correspondent: ATTN: LEGAL DEPT
defensive aggregation
2018-06-29 · recorded 2018-07-09 · reel 039912/0357 · SECURITY AGREEMENT
RPX CORPORATIONJEFFERIES FINANCE LLC
Correspondent: JOHN M LANKENAU · REID & RIEGE
securitization
2020-10-23 · recorded 2020-11-04 · reel 045938/0394 · SECURITY AGREEMENT
RPX CLEARINGHOUSE LLC, RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT
Correspondent: CHARLES A BURNS · KING & SPALDING
securitization
2020-10-26 · recorded 2020-11-09 · reel 046011/0300 · RELEASE
JEFFERIES FINANCE LLCRPX CORPORATION
Correspondent: JOHN M LANKENAU · REID & RIEGE
release-of-security-interest
2024-05-31 · recorded 2024-06-03 · reel 050307/0861 · RELEASE
BARINGS FINANCE LLCRPX CORPORATION
Correspondent: KEVIN D RUSH · AKIN GUMP STRAUSS HAUER & FELD
release-of-security-interest
2024-07-05 · recorded 2024-06-03 · reel 050307/0858 · ASSIGNMENT
Correspondent: KEVIN D RUSH · AKIN GUMP STRAUSS HAUER & FELD
acquisition
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
- Patrick Turley
- Eric White
The patent document does not explicitly state the inventors' employers at the time of filing. The inventors assigned their rights to Eric White and subsequently to Rocksteady Technologies, LLC on May 23, 2011, approximately one month after the filing date of the specific application (US13/092,488) on April 22, 2011. This rapid assignment post-filing is a common practice and does not inherently suggest a portfolio fire-sale in this context.
Original assignee
The entity named on the issued patent US8397282B2 is RPX CORPORATION.
RPX Corporation's primary line of business is patent risk management, focusing on defensive patent aggregation to protect its member companies from patent assertions. It does not typically ship products embodying the claims of the patents it holds. RPX Corporation is currently an operating company.
Assignment timeline
2011-05-23 (executed) / recorded 2011-05-24 — Reel 026779/0422
- Conveyance: ASSIGNMENT
- Assignor: TURLEY, PATRICK
- Assignee: WHITE, ERIC
- Correspondent: MICHAEL T DEAN, ESQ., 1000 BRIDGEWAY #222, SAUSALITO, CA 94965
- Context: Transfer of inventor's interest to co-inventor.
2011-05-23 (executed) / recorded 2011-05-24 — Reel 026779/0425
- Conveyance: ASSIGNMENT
- Assignor: WHITE, ERIC
- Assignee: ROCKSTEADY TECHNOLOGIES, LLC
- Correspondent: MICHAEL T DEAN, ESQ., 1000 BRIDGEWAY #222, SAUSALITO, CA 94965. This correspondent also appears on the previous record.
- Context: Transfer of inventor's and co-inventor's combined interests to a private LLC.
2012-08-13 (executed) / recorded 2012-08-15 — Reel 029277/0038
- Conveyance: ASSIGNMENT
- Assignor: ROCKSTEADY TECHNOLOGIES LLC
- Assignee: RPX CORPORATION
- Correspondent: RPX CORPORATION, ATTN: LEGAL DEPT, 3450 SACRAMENTO STREET, SAN FRANCISCO, CA 94118
- Context: Acquisition of patent rights by a defensive patent aggregator.
2018-06-29 (executed) / recorded 2018-07-09 — Reel 039912/0357
- Conveyance: SECURITY AGREEMENT
- Assignor: RPX CORPORATION
- Assignee: JEFFERIES FINANCE LLC
- Correspondent: JOHN M LANKENAU, REID & RIEGE PC, ONE FINANCIAL PLAZA, HARTFORD, CT 06103-3460
- Context: Patent collateralized as part of a loan agreement.
2020-10-23 (executed) / recorded 2020-11-04 — Reel 045938/0394
- Conveyance: SECURITY AGREEMENT
- Assignor: RPX CLEARINGHOUSE LLC, RPX CORPORATION
- Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT
- Correspondent: CHARLES A BURNS, KING & SPALDING LLP, 1180 PEACHTREE STREET, NE, ATLANTA, GA 30309
- Context: Patent collateralized as part of a loan agreement.
2020-10-26 (executed) / recorded 2020-11-09 — Reel 046011/0300
- Conveyance: RELEASE
- Assignor: JEFFERIES FINANCE LLC
- Assignee: RPX CORPORATION
- Correspondent: JOHN M LANKENAU, REID & RIEGE PC, ONE FINANCIAL PLAZA, HARTFORD, CT 06103-3460. This correspondent also appears on the security agreement for Jefferies Finance LLC.
- Context: Release of previous security interest.
2024-05-31 (executed) / recorded 2024-06-03 — Reel 050307/0861
- Conveyance: RELEASE
- Assignor: BARINGS FINANCE LLC
- Assignee: RPX CORPORATION
- Correspondent: KEVIN D RUSH, AKIN GUMP STRAUSS HAUER & FELD LLP, ONE BRYANT PARK, NEW YORK, NY 10036
- Context: Release of previous security interest.
2024-07-05 (executed) / recorded 2024-06-03 — Reel 050307/0858
- Conveyance: ASSIGNMENT
- Assignor: RPX CORPORATION
- Assignee: NETSKOPE, INC.
- Correspondent: KEVIN D RUSH, AKIN GUMP STRAUSS HAUER & FELD LLP, ONE BRYANT PARK, NEW YORK, NY 10036. This correspondent also appears on the previous release, suggesting they represent Netskope or Barings in these transactions.
- Context: Sale of patent from a defensive aggregator to an operating company. (Note: The recording date precedes the execution date as documented in the USPTO record.)
Timeline diagram
timeline
title Ownership of US 8397282
2011 : Inventors assign to Eric White
: White assigns to Rocksteady
2012 : Rocksteady assigns to RPX Corp
2013 : Patent granted to RPX Corp
2018 : RPX Corp grants security int to Jefferies
2020 : RPX Corp grants security int to Barings
: Jefferies releases security int
2024 : Barings releases security int
: RPX Corp assigns to Netskope Inc
2025 : First infringement suit filed
NPE / troll-pattern signals
Shell-entity transfer — Present. The transfer from inventors (Patrick Turley and Eric White) to ROCKSTEADY TECHNOLOGIES, LLC (Reel 026779/0425, 2011-05-23) followed by the transfer to RPX CORPORATION (Reel 029277/0038, 2012-08-13) involves an LLC (Rocksteady Technologies) which, without further evidence of product development, appears to be a holding entity for the patent rights before transfer to a larger entity. RPX Corporation itself acts as a defensive aggregator, not a product-shipping entity for this patent. The final transfer to Netskope, Inc. is to an operating company.
Known asserter in the chain — Not present. RPX Corporation is a known defensive aggregator (anti-NPE), not an asserter. None of the other assignees (Rocksteady Technologies, LLC, Jefferies Finance LLC, Barings Finance LLC, Netskope, Inc.) are listed as known NPEs or high-frequency plaintiffs in public databases at the time of this analysis.
Repeat correspondent across the chain — Present.
- MICHAEL T DEAN, ESQ. (1000 BRIDGEWAY #222, SAUSALITO, CA 94965) appears on two consecutive assignments from the inventors to Eric White and then to Rocksteady Technologies, LLC (Reel 026779/0422 and Reel 026779/0425). This indicates a consistent legal representation for the initial transfers.
- JOHN M LANKENAU, REID & RIEGE PC (ONE FINANCIAL PLAZA, HARTFORD, CT 06103-3460) appears on both the security agreement granted by RPX CORPORATION to Jefferies Finance LLC (Reel 039912/0357, 2018-07-09) and the subsequent release of that security interest (Reel 046011/0300, 2020-11-09), indicating representation for Jefferies Finance LLC in these transactions.
- KEVIN D RUSH, AKIN GUMP STRAUSS HAUER & FELD LLP (ONE BRYANT PARK, NEW YORK, NY 10036) appears on the release from Barings Finance LLC to RPX CORPORATION (Reel 050307/0861, 2024-06-03) and the subsequent assignment from RPX CORPORATION to NETSKOPE, INC. (Reel 050307/0858, 2024-06-03), indicating representation likely for the acquiring entity (Netskope, Inc.) or the financial institutions involved in the releases.
Cascading transfers — Not present. The transfers occur over several years: 2011 (inventors to Rocksteady), 2012 (Rocksteady to RPX), and 2024 (RPX to Netskope). The security agreements are financial transactions, not direct ownership transfers for assertion purposes.
Pre-litigation transfer — Not present. The assignment to Netskope, Inc. was executed on 2024-07-05. The first identified litigation cases (4:25-cv-02360 and 3:25-cv-02360) were filed in the California Northern District Court in 2025, after the transfer to Netskope. The PTAB case IPR2026-00041 was filed in 2026.
Bankruptcy fire-sale — Not present. RPX Corporation, the assignor to Netskope, Inc., is an active operating company, not in bankruptcy.
Privateering — Unclear. While RPX's business model is defensive aggregation, the subsequent sale to Netskope (an operating company in cloud security) could potentially be a privateering arrangement if RPX retained some interest or influence over Netskope's assertion strategy. However, there is no direct evidence in the assignment records or public domain to confirm such an arrangement. Netskope itself is an operating company.
Defensive aggregator (anti-NPE) — Present. RPX CORPORATION, a known defensive aggregator, acquired the patent from Rocksteady Technologies, LLC on 2012-08-13 (Reel 029277/0038). This indicates the patent was initially acquired for defensive purposes. However, it was later sold to Netskope, Inc.
Verdict
Defensive / non-asserting (chain terminates at a defensive aggregator, with a subsequent transfer to an operating company).
The patent was initially acquired by RPX Corporation (Reel 029277/0038, 2012-08-13), a well-known defensive aggregator, indicating it was held to mitigate assertion risk for its members. RPX does not assert patents itself. The patent was subsequently transferred to Netskope, Inc. (Reel 050307/0858, 2024-07-05), an operating company. While litigation has been filed after this transfer, the primary pattern in the chain reflects a defensive acquisition by RPX.
Verification: USPTO Assignment Center for US8397282
Generated 5/25/2026, 12:48:08 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
Here is an analysis of the most relevant prior art for US patent 8397282, based on its cited references and focusing on the core inventive concepts of the patent.
The central inventive concept of US8397282, as articulated in its independent claims (Claims 1, 12, and 24), revolves around a firewall system where:
- At least one node is defined, associated with two or more network interfaces.
- A set of firewall rules is associated with the node(s).
- Packets are accepted or denied based on these rules.
- Crucially, the set of firewall rules is dynamically self-configurable during runtime without operator interaction.
- These rules comprise a plurality of chains of rules forming various paths through a hierarchical structure.
- The hierarchical structure includes defined places for dynamically updating the set of firewall rules during runtime.
Below are analyses of selected prior art references that appear most relevant to these aspects, published before the priority date of US8397282 (March 10, 2004).
1. US 6,212,558 B1
- Full Citation: US 6,212,558 B1, "Method and apparatus for configuring and managing firewalls and security devices," filed December 24, 1997, issued April 3, 2001, to Anand K. Antur.
- Publication/Filing Date: Publication Date: April 3, 2001. Filing Date: December 24, 1997 (claims priority from provisional application No. 60/044,853, filed April 25, 1997).
- Brief Description: This patent describes methods and apparatus for configuring and managing firewalls and other network security devices. It involves a network directory services server that provides network directory services to multiple network servers, each coupled to a network security device. A security policy for these devices is implemented on the directory services server, and the directory services are used to provide configuration information to the security devices in response to this policy. This outlines a centralized approach to defining and deploying security policies to multiple firewalls.
- Potential Anticipation (35 U.S.C. § 102): US 6,212,558 B1 anticipates the broad concept of configuring and managing firewall rules and associating them with network devices (analogous to "nodes" in US8397282). This could potentially anticipate elements like "defining at least one node, wherein the at least one node is associated with two or more network interfaces" and "associating a set of firewall rules with the at least one node" found in claims 1, 12, and 24. However, it does not explicitly disclose the key distinguishing features of US8397282: the firewall's dynamic self-configurability during runtime without operator interaction, nor the specific hierarchical structure of rule chains with defined places for dynamically updating rules during runtime. The management described appears to be driven by external policy updates from a server, rather than the firewall autonomously adapting its internal rule structure.
2. US 6,243,815 B1
- Full Citation: US 6,243,815 B1, "Method and apparatus for reconfiguring and managing firewalls and security devices," filed December 24, 1997, issued June 5, 2001, to Anand K. Antur.
- Publication/Filing Date: Publication Date: June 5, 2001. Filing Date: December 24, 1997 (claims priority from provisional application No. 60/044,853, filed April 25, 1997).
- Brief Description: Similar to US 6,212,558 B1 by the same inventor and sharing the same priority date, this patent focuses on methods and apparatus for reconfiguring and managing firewalls and security devices. It also describes a system where a network directory services server implements security policies and provides configuration information to multiple network security devices. The emphasis on "reconfiguring" indicates that the rules or policies can be changed.
- Potential Anticipation (35 U.S.C. § 102): US 6,243,815 B1 is relevant for the general concept of changing or reconfiguring firewall rules or policies, which touches upon the idea of "dynamically updating" rules. This could be seen as broadly anticipating parts of claims 1, 12, and 24 that mention dynamic updates. However, like its related patent, it lacks the specificity of the firewall being self-configurable during runtime without operator interaction through a hierarchical structure of rule chains with defined places for dynamic updates. The reconfiguration is still external to the firewall's autonomous operation and relies on a policy server. Therefore, while it anticipates dynamic changes to rules in a broad sense, it likely does not anticipate the specific mechanism of self-configuration claimed in US8397282.
3. US 2001/0039576 A1
- Full Citation: US 2001/0039576 A1, "Network policy transmission method from policy server to network node," filed December 10, 1999, published November 8, 2001, to Yasusi Kanada.
- Publication/Filing Date: Publication Date: November 8, 2001. Filing Date: December 10, 1999.
- Brief Description: This publication describes a method where a policy server transmits a policy to a network node. The policy consists of an event and an action to be performed when the event occurs. The network node executes the action upon the occurrence of the event. The policy can be modified by the policy server, enabling dynamic changes to network behavior. This directly relates to applying rule-based logic at network nodes.
- Potential Anticipation (35 U.S.C. § 102): This reference is highly relevant to the concept of "defining at least one node" and "associating a set of firewall rules with the at least one node," as it explicitly describes "network nodes" and "policies" (rules) with "events and actions." It also describes that the policy "can be changed by the policy server," which suggests dynamic rule updates. This could potentially anticipate elements of claims 1, 12, and 24 of US8397282 concerning nodes, associated rules, and dynamic modification of those rules. However, it does not explicitly teach the firewall being dynamically self-configurable during runtime without operator interaction as a self-contained, autonomous process, nor does it detail a hierarchical structure of rule chains with defined places for dynamic updates within the node itself. The changes are still initiated by an external "policy server," implying interaction beyond the firewall's self-configuration. Therefore, it anticipates aspects of dynamic policy application to network nodes but likely not the unique self-adaptive, hierarchical rule structure of US8397282.
Generated 5/25/2026, 12:48:17 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
Obviousness Analysis under 35 U.S.C. § 103 for US8397282
This analysis identifies combinations of prior art references that would render the claims of US patent 8397282 obvious to a person having ordinary skill in the art (PHOSITA) as of its priority date (March 10, 2004), and explains the motivation for such combinations.
Claims of US8397282
The independent claims of US8397282 describe a method (Claim 1), a device (Claim 12), and a computer program product (Claim 24) for controlling data through a firewall. Key features across these claims include:
- Defining at least one node associated with two or more network interfaces.
- Associating a set of firewall rules with the node(s).
- Receiving, accepting, or denying packets based on these rules.
- Crucially, the set of firewall rules is dynamically self-configurable during runtime without operator interaction.
- The set of firewall rules comprises a plurality of chains of rules forming various paths through a hierarchical structure.
- The hierarchical structure comprises defined places for dynamically updating the set of firewall rules during runtime.
Identified Prior Art Combinations and Motivation
The primary prior art for this analysis includes US Patent No. 7,610,621 (US7610621B2), a direct parent application to US8397282, and the well-known Linux iptables firewall system.
Combination 1: US7610621B2 in view of iptables functionality
Prior Art References:
- US7610621B2 (White et al.): This patent, titled "System and method for behavior-based firewall modeling," shares a priority date of March 10, 2004, and is explicitly a parent application to US8397282. Its abstract and detailed description lay out a "conceptual model representing a network firewall that separates firewall functionality into individually configurable and controllable components." It teaches:
- A conceptual model of firewall structure, including the definition of "nodes" associated with two or more network interfaces.
- Modeling behaviors for network traffic, including for packets traversing connections between nodes.
- A "dynamically reconfigurable implementation of the firewall model."
- The notion of an "automated system" that enables the firewall owner to "generally describe how the firewall should behave, and the automated system can automatically produce the requisite, specific firewall configuration, without detailed manipulation by a human operator." This directly addresses the "without operator interaction" aspect, attributing it to the automated system implementing the conceptual model.
- Linux
iptables: As explicitly referenced in the detailed description of US8397282, "the Linux operating system has a subsystem known as “iptables” (for Internet Protocol Tables) that offers a “rule” syntax for representing the logic of packet handling through the Linux system."Iptableswas well-established and publicly available before the March 10, 2004, priority date (introduced with Linux kernel 2.4 in 2001).Iptablesnatively provides:- A "plurality of chains of rules" (e.g., INPUT, FORWARD, OUTPUT chains, and user-defined chains) forming a hierarchical structure for packet traversal.
- The ability to dynamically update firewall rules during runtime through programmatic commands (e.g., adding, inserting, or deleting rules from chains) without requiring a system reboot or manual recompilation.
Reasoning for Obviousness:
A person having ordinary skill in the art (PHOSITA) in 2004, aiming to implement the "dynamically reconfigurable implementation of the firewall model" described in US7610621B2, would have been motivated to use existing, robust, and dynamic firewall management technologies. The explicit mention of iptables in US8397282 confirms its relevance and common knowledge to a PHOSITA in this field.
- Dynamic Self-Configurability and Without Operator Interaction: US7610621B2 describes an "automated system" that can "automatically produce the requisite, specific firewall configuration, without detailed manipulation by a human operator." This automated configuration inherently implies that the firewall rules are "dynamically self-configurable during runtime without operator interaction." A PHOSITA implementing such an automated system would leverage the programmatic capabilities of underlying firewall mechanisms, such as
iptables, to effect these runtime changes. The automation itself eliminates the need for direct operator intervention at the rule-level. - Chains of Rules and Hierarchical Structure: The
iptablessystem inherently operates with "chains of rules" that can be linked, effectively forming a hierarchical structure. This structure allows for defining various paths for packets depending on matching criteria. This is a fundamental aspect ofiptablesarchitecture, which a PHOSITA would readily utilize when designing a firewall. - Defined Places for Dynamically Updating Rules: The detailed description of US8397282 further elaborates on "dynamic chains of rules... to 'tap' into the main firewall chains and offer isolated, well-defined places for specific behavior to be introduced" (referencing the :A, :M, :D, and :X sub-trees and their "taps"). This concept of organizing rules into logical "chains" or "sub-trees" for specific behaviors and providing "taps" (i.e., jump points) for dynamic insertion/deletion of rules is a common software engineering practice for managing complexity in modular and extensible systems. A PHOSITA, tasked with implementing a dynamically reconfigurable firewall using a system like
iptables, would naturally design a structured set of rule chains (like the A, M, D, X sub-trees) where rules could be logically added, deleted, or modified at runtime to tailor firewall behavior, aligning with the core capabilities ofiptables.
Motivation to Combine:
The motivation for combining these elements would be high. US7610621B2 provides a powerful conceptual model for a flexible, behavior-based, and dynamically reconfigurable firewall. However, it requires a concrete implementation method. The iptables system offers a practical and widely used mechanism for dynamic packet filtering rule management in Linux environments, which is precisely what is needed to realize the dynamic reconfiguration aspects of US7610621B2. A PHOSITA would be motivated to combine the abstract design of US7610621B2 with a known, flexible rule-management system like iptables to create a working, automated, and dynamically adaptable firewall that addresses the need for firewalls that can "dynamically adapt to changing conditions and operator requirements", a problem explicitly acknowledged in the background of US8397282. The use of an "automated system" to configure firewalls "without detailed manipulation by a human operator" is a clear driver for such integration, leveraging the programmatic rule modification capabilities of iptables.
Therefore, the combination of the node-based, dynamically reconfigurable firewall model from US7610621B2 with the known, dynamic rule chain management capabilities of iptables would have been obvious to a PHOSITA at the time of invention, as it merely applies known techniques to implement a desired functionality taught in a closely related prior art.
Generated 5/25/2026, 12:48:11 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 9954872Here is a concise summary of US Patent 9954872: US Patent 9954872B2: System and method for identifying unauthorized activities on a computer system using a data structure model Title: System and method for identifying unauthorized…
- US 11789941B2US Patent 11789941B2 is titled "Systems, methods, applications, and user interfaces for providing triggers in a system of record." Assignee: People Center Inc. Inventors: Siddhartha Gunda, Kyle Michael Boston, Daniel Robert Buscaglia…
- US 12032940B2Here's a concise summary of US Patent 12032940B2: Title: Multi-platform application integration and data synchronization Assignee: People Center Inc Inventors: Siddhartha Gunda, Kyle Michael Boston, Daniel Robert Buscaglia, Dilanka Theshan…
- US 11435994B1US Patent 11435994B1, titled "Multi-platform application integration and data synchronization," was issued to People Center Inc. Here is a summary of the patent details: Title: Multi-platform application integration and data…
- US 9215236Here is a concise summary of US Patent 9215236: Title: Secure, policy-based communications security and file sharing across mixed media, mixed-communications modalities and extensible to cloud computing such as SOA [cite: The full patent…
- US 9537900Here's a concise summary of US patent 9537900: US Patent 9537900 Title: Systems and methods for serving application specific policies based on dynamic context Assignee: Avaya Inc. Inventors: Sunil Menon, Shailesh Patel Filing Date…
- US 9693030US patent 9693030, titled "Generating alerts based upon detector outputs," was filed on July 28, 2014, and issued on June 27, 2017. The original assignee was Arris Enterprises LLC, with the current assignee listed as Bison Patent Licensing…
- US 11238344I have analyzed US Patent 11238344 and compiled the requested information. Summary of US Patent 11238344 Title: Artificially intelligent systems, devices, and methods for learning and/or using a device's circumstances for autonomous device…
This patent in court (1)
1 tracked lawsuit name US 8397282.