Invalidity dossier

US 8621627

Intrusion detection and prevention processing within network interface circuitry

Current assignee: Speednic LLC

Added 4/27/2026, 7:40:26 AM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by Speednic LLCHigh-Tech (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

As a senior US patent analyst, I have conducted a thorough review of US Patent 8,621,627 as of May 1, 2026. Below is a concise summary of the patent and its legal status.

Summary of US Patent 8,621,627

Title: Intrusion detection and prevention processing within network interface circuitry

Assignee: The original assignee is Chelsio Communications Inc. The patent has been assigned multiple times, including to various banks as security interests, but the most recent assignments on record with the USPTO show these security interests have been released. As of the latest available information, Chelsio Communications Inc. appears to be the current assignee.

Inventors:

  • Asgeir Thor Eiriksson
  • Wael Noureddine
  • Anamaya Sullerey

Filing Date: February 12, 2010

Issue Date: December 31, 2013

Abstract:
The patent describes a network interface controller (NIC) designed to work with a host computer that runs multiple virtual machines. The NIC is capable of receiving a data frame, determining if that frame requires additional processing (such as for security purposes), and if so, sending it to the host for that processing. After the host completes the additional processing, the NIC receives the frame back and directs it to its intended destination. This allows for efficient handling of tasks like intrusion detection in a virtualized environment by offloading some of the decision-making to the NIC.

Plain-Language Overview of Independent Claims

US Patent 8,621,627 has three independent claims: Claim 1, Claim 7, and Claim 24. Here is a plain-language overview of each:

Claim 1: This claim describes a Network Interface Controller (NIC) that connects a host computer with multiple virtual machines to a network. The core of this claim is a three-step process:

  1. The NIC receives a data frame and decides if it needs special processing.
  2. If special processing is needed, the NIC sends the frame to the host computer to perform that task.
  3. After the host is finished, the NIC takes the processed frame back and sends it to its final destination.

Claim 7: This claim is also for a NIC with a "data frame processing pipeline." The key aspect here is that the NIC makes the decision to send a frame for additional processing based on a specific "indication" within the data frame itself. After the host performs the additional processing, the NIC then sends the frame on to its destination.

Claim 24: This claim outlines a broader method performed by a NIC. It involves:

  1. Receiving a data frame.
  2. Determining if additional processing is required.
  3. If so, sending the frame for this additional processing before it goes to its final destination.
  4. Finally, receiving the processed frame back and steering it to its destination.

Litigation Status

A search of the U.S. Court of Appeals for the Federal Circuit (CAFC) dockets for the year 2026 revealed no cases specifically citing US Patent 8,621,627. I have a high degree of confidence that there is no ongoing litigation involving this patent at the CAFC in 2026.

Generated 5/1/2026, 10:51:22 PM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 8621627. The free-form analysis below may also discuss cases beyond this list.

  • 7:26-cv-00148Texas Western District CourtJudge David CountsOpen

    Defendants: Nvidia Corp, Dell Technologies Inc

    Other patents asserted: 8060644, 7760733, 7826350, 8589587

    The accused products are Dell's PowerEdge servers and AI platforms that use Nvidia components. Nvidia's own networking hardware, including its BlueField, ConnectX, and Spectrum-X product lines, and related software are also accused of infringement.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Litigation Search for US Patent 8,621,627

As of May 1, 2026, a comprehensive search of patent litigation databases reveals one known case involving US Patent 8,621,627.

This appears to be a recent filing, and no outcome has been determined. Searches of PACER, Unified Patents, and other dockets revealed no other historical or ongoing litigation specifically naming US patent 8,621,627.

Generated 5/1/2026, 10:52:48 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Speednic LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There are no AIA trial proceedings on file for US Patent 8,621,627. This means that all claims of the patent remain untested in an AIA trial setting.

Strategic summary

As there are no PTAB proceedings on file for US Patent 8,621,627, all claims (1-29) remain unchallenged and are considered sustained from a PTAB perspective. This also means there is no estoppel landscape established by AIA trials, leaving all prior-art grounds available for potential future challenges. The absence of PTAB activity could indicate that the patent has not been extensively asserted, or that previous assertions have not led to defensive PTAB filings.

Recommended next steps

If facing an assertion of US Patent 8,621,627, a defendant would have the full range of prior art and statutory grounds available for a potential PTAB challenge (e.g., IPR, PGR, CBM), as no claims have been canceled or sustained through such proceedings. There are no active proceedings or upcoming milestones to monitor. The absence of PTAB challenges also suggests that if considering an IPR, a thorough prior art search would be crucial to identify strong invalidity grounds, as the patent has not been subjected to this scrutiny before.

Generated 5/30/2026, 12:48:34 PM

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Asgeir Thor Eiriksson (Chelsio Communications Inc.)
  • Wael Noureddine (Chelsio Communications Inc.)
  • Anamaya Sullerey (Chelsio Communications Inc.)

Original assignee

Chelsio Communications Inc. is an operating company that primarily designs and manufactures high-performance network adapters and other hardware for data centers. They ship products embodying the claims of US 8621627, as their NICs are designed to offload network processing and security functions. Chelsio Communications Inc. is currently operating.

Assignment timeline

  • 2010-02-09 (executed) / recorded 2010-02-19 — Reel 023965/0447
    • Conveyance: Assignment
    • Assignor: EIRIKSSON, ASGEIR THOR; NOUREDDINE, WAEL; SULLEREY, ANAMAYA
    • Assignee: CHELSIO COMMUNICATIONS, INC., CALIFORNIA
    • Correspondent: Bjoern Nicolai, NIXON PEABODY LLP, 200 S. WACKER DRIVE, 36TH FLOOR, CHICAGO, ILLINOIS 60606. This correspondent does not recur in this chain.
    • Context: Original assignment from inventors to the filing company.
  • 2013-05-09 (executed) / recorded 2014-03-19 — Reel 032479/0089
    • Conveyance: Security Interest
    • Assignor: CHELSIO COMMUNICATIONS, INC.
    • Assignee: EAST WEST BANK, MASSACHUSETTS
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent does not recur in this chain.
    • Context: Securitization of assets by Chelsio Communications Inc.
  • 2014-10-07 (executed) / recorded 2014-10-21 — Reel 033989/0930
    • Conveyance: Release by Secured Party
    • Assignor: EAST WEST BANK
    • Assignee: CHELSIO COMMUNICATIONS, INC., CALIFORNIA
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous entry.
    • Context: Release of security interest by East West Bank back to Chelsio Communications Inc.
  • 2014-10-14 (executed) / recorded 2014-10-21 — Reel 033990/0451
    • Conveyance: Security Interest
    • Assignor: CHELSIO COMMUNICATIONS, INC.
    • Assignee: SILICON VALLEY BANK, CALIFORNIA
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous two entries.
    • Context: Securitization of assets by Chelsio Communications Inc.
  • 2014-10-07 (executed) / recorded 2016-07-15 — Reel 039360/0596
    • Conveyance: Release by Secured Party
    • Assignor: EAST WEST BANK
    • Assignee: CHELSIO COMMUNICATIONS, INC., CALIFORNIA
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous three entries.
    • Context: Release of security interest by East West Bank back to Chelsio Communications Inc. (duplicate filing date, likely a corrective or delayed recording).
  • 2016-07-29 (executed) / recorded 2016-07-29 — Reel 039296/0550
    • Conveyance: Security Interest
    • Assignor: CHELSIO COMMUNICATIONS, INC.
    • Assignee: NOVIRIAN CAPITAL, CALIFORNIA
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous four entries.
    • Context: Securitization of assets by Chelsio Communications Inc.
  • 2017-04-11 (executed) / recorded 2017-04-25 — Reel 042142/0232
    • Conveyance: Release by Secured Party
    • Assignor: NOVIRIAN CAPITAL
    • Assignee: CHELSIO COMMUNICATIONS, INC., CALIFORNIA
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous five entries.
    • Context: Release of security interest by Novirian Capital back to Chelsio Communications Inc.
  • 2019-08-09 (executed) / recorded 2019-08-14 — Reel 050050/0396
    • Conveyance: Security Interest
    • Assignor: CHELSIO COMMUNICATIONS, INC.
    • Assignee: WESTERN ALLIANCE BANK, AN ARIZONA CORPORATION, CAL
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous six entries.
    • Context: Securitization of assets by Chelsio Communications Inc.
  • 2019-08-09 (executed) / recorded 2019-08-15 — Reel 050112/0234
    • Conveyance: Corrective Assignment
    • Assignor: CHELSIO COMMUNICATIONS, INC.
    • Assignee: WESTERN ALLIANCE BANK, AN ARIZONA CORPORATION, CAL
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous seven entries.
    • Context: Corrective assignment related to the security interest.
  • 2024-01-22 (executed) / recorded 2025-12-18 — Reel 073264/0525
    • Conveyance: Release of Security Interest
    • Assignor: WESTERN ALLIANCE BANK, AN ARIZONA CORPORATION
    • Assignee: CHELSIO COMMUNICATIONS, INC., CALIFORNIA
    • Correspondent: David J. Pierre, Rutan & Tucker LLP, 600 Anton Boulevard, 14th Floor, Costa Mesa, CA 92626. This correspondent recurs on the previous eight entries.
    • Context: Release of security interest by Western Alliance Bank back to Chelsio Communications Inc.

Timeline diagram

timeline
    title Ownership of US 8621627
    2010 : Filed by Chelsio Communications Inc
    2013 : Issued to Chelsio Communications Inc
    2014 : Security Interest to East West Bank
         : Release by East West Bank
         : Security Interest to Silicon Valley Bank
    2016 : Release by East West Bank
         : Security Interest to Novirian Capital
    2017 : Release by Novirian Capital
    2019 : Security Interest to Western Alliance Bank
         : Corrective Assignment
    2025 : Release by Western Alliance Bank

NPE / troll-pattern signals

  1. Shell-entity transfernot present. The patent has consistently been assigned to and from Chelsio Communications Inc. and various banks for security interests. Chelsio is an operating company.
  2. Known asserter in the chainnot present. Neither Chelsio Communications Inc. nor any of the banks appear on public NPE lists.
  3. Repeat correspondent across the chainpresent. David J. Pierre of Rutan & Tucker LLP is the correspondent on multiple security interest and release filings from 2014 to 2025 (Reel 032479/0089, Reel 033989/0930, Reel 033990/0451, Reel 039360/0596, Reel 039296/0550, Reel 042142/0232, Reel 050050/0396, Reel 050112/0234, Reel 073264/0525). This recurrence is a strong indicator of a consistent legal representative for Chelsio's patent-related financial transactions.
  4. Cascading transfersnot present. The transfers primarily involve Chelsio Communications Inc. and various banks in a securitization context, not rapid transfers between shell entities.
  5. Pre-litigation transferunclear. The latest assignment (a release back to Chelsio) was recorded on 2025-12-18 (executed 2024-01-22), while Speednic LLC v. Nvidia Corp et al. was filed on April 16, 2026. This is a period of roughly 4 months between the last recorded transfer and the litigation filing. However, the last actual transfer of ownership was the release back to Chelsio, which means Chelsio owned the patent leading up to the Speednic litigation. If Speednic LLC is an NPE, then the patent could have been transferred to Speednic shortly before the litigation, but this transfer is not yet publicly recorded.
  6. Bankruptcy fire-salenot present. There is no indication in the assignment records or general knowledge that Chelsio Communications Inc. has undergone bankruptcy proceedings that resulted in a patent sale.
  7. Privateeringnot present. There is no evidence to suggest Chelsio Communications Inc. transferred this patent to an NPE to assert on their behalf.
  8. Defensive aggregator (anti-NPE)not present. The chain does not terminate at a known defensive aggregator.

Verdict

Insufficient data to definitively declare NPE status. While there is current litigation in Speednic LLC v. Nvidia Corp et al., the assignment records available via USPTO Assignment Center (as of 2026-05-30) do not show a transfer from Chelsio Communications Inc. to Speednic LLC. All recorded assignments reflect security interests and releases, with Chelsio Communications Inc. consistently remaining the assignee. Without a recorded transfer to Speednic LLC or further evidence regarding Speednic LLC's nature, a high-confidence NPE verdict is not warranted based solely on the assignment chain.

USPTO Assignment Center search page: https://assignmentcenter.uspto.gov/

Generated 5/30/2026, 12:48:44 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

To identify the most relevant prior art for US patent 8,621,627, I will examine the "Citations" section of the patent itself, as this lists the prior art considered by the patent examiner during prosecution.

Most Relevant Prior Art for US Patent 8,621,627

Below are the patent citations listed for US Patent 8,621,627, along with their publication/filing dates, a brief description, and which claim(s) they potentially anticipate under 35 U.S.C. § 102. The current date is April 26, 2026.

Note: The analysis of which claims are potentially anticipated is based on the descriptions provided in US8621627 and the cited patents' titles/abstracts. A full anticipation analysis would require a detailed claim-by-claim comparison.

Cited US Patents:

  1. US6594268B1 (Lucent Technologies Inc.)

    • Full Citation: US6594268B1, "Adaptive routing system and method for QOS packet networks".
    • Publication Date: July 15, 2003.
    • Filing Date: March 11, 1999.
    • Brief Description: This patent generally relates to adaptive routing and quality of service (QoS) in packet networks. While not directly addressing virtual machine intrusion detection, it deals with packet handling and routing based on network conditions and QoS requirements.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (potentially, concerning the general concept of steering frames in a network, but likely not the specific virtual machine/intrusion detection context).
  2. US6798743B1 (Cisco Technology, Inc.)

    • Full Citation: US6798743B1, "Packet prioritization processing technique for routing traffic in a packet-switched computer network".
    • Publication Date: September 28, 2004.
    • Filing Date: March 22, 1999.
    • Brief Description: This patent describes techniques for prioritizing packet processing and routing in a packet-switched network. Similar to US6594268B1, it focuses on network traffic management rather than virtualized security.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (potentially, regarding general packet processing and routing, but less likely the specific security offload to a VM).
  3. US20020039366A1 (Nec Corporation)

    • Full Citation: US20020039366A1, "Packet switch and multicasting control system used for the same".
    • Publication Date: April 4, 2002.
    • Filing Date: October 4, 2000.
    • Brief Description: This patent application details a packet switch and a multicasting control system. It covers aspects of switching and replication of data frames, which is relevant to the MPS functionality in US8621627.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 20, 21, 24 (potentially, concerning the replication and steering of frames to multiple destinations, particularly in the context of multicast, but without the specific intrusion detection component).
  4. US6792502B1 (Freescale Semiconductor, Inc.)

    • Full Citation: US6792502B1, "Microprocessor having a content addressable memory (CAM) device as a functional unit therein and method of operation".
    • Publication Date: September 14, 2004.
    • Filing Date: October 12, 2000.
    • Brief Description: This patent describes a microprocessor incorporating a CAM for various operations. While CAMs can be used in packet filtering, this patent does not specifically detail their use for intrusion detection offload in a virtualized NIC context.
    • Potential Anticipation (35 U.S.C. § 102): May be relevant to the underlying hardware mechanisms for filter processing (e.g., Claim 5, 22, 28) if such filtering relies on CAMs for rule matching, but unlikely to anticipate the overall system and method.
  5. US7031267B2 (802 Systems Llc)

    • Full Citation: US7031267B2, "PLD-based packet filtering methods with PLD configuration data update of filtering rules".
    • Publication Date: April 18, 2006.
    • Filing Date: December 21, 2000.
    • Brief Description: This patent discusses packet filtering methods using Programmable Logic Devices (PLDs) and dynamic updates of filtering rules. This is highly relevant to the "filter functionality" (Claim 5, 22, 28) and configurable rules (Claim 6, 23, 29) described in US8621627.
    • Potential Anticipation (35 U.S.C. § 102): Claims 5, 6, 22, 23, 28, 29 (highly relevant to the concept of NIC-based filtering and dynamically configurable rules, although not explicitly tied to intrusion detection in a virtual machine environment as the primary goal).
  6. US20060209693A1 (Pmc-Sierra Ltd.)

    • Full Citation: US20060209693A1, "Feedback priority modulation rate controller".
    • Publication Date: September 21, 2006.
    • Filing Date: January 31, 2001.
    • Brief Description: This patent generally describes a rate controller for modulating feedback priority, likely in a communication system. Its relevance to US8621627's core claims appears limited.
    • Potential Anticipation (35 U.S.C. § 102): Unlikely to directly anticipate any of the independent claims.
  7. US20040003094A1 (Michael See)

    • Full Citation: US20040003094A1, "Method and apparatus for mirroring traffic over a network".
    • Publication Date: January 1, 2004.
    • Filing Date: June 27, 2002.
    • Brief Description: This patent application describes mirroring network traffic, which could be used for monitoring or intrusion detection purposes by sending a copy of traffic to a security appliance. This has some conceptual overlap with sending frames for "additional processing" (Claim 1, 7, 24).
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (to the extent that "additional processing" could involve mirroring, but it lacks the explicit steering and host-based VM processing unique to US8621627).
  8. US7474670B2 (Brooktree Broadband Holding, Inc.)

    • Full Citation: US7474670B2, "Method and system for allocating bandwidth".
    • Publication Date: January 6, 2009.
    • Filing Date: July 8, 2002.
    • Brief Description: This patent is about allocating bandwidth. It does not directly relate to intrusion detection or offloading security processing to a NIC in a virtualized environment.
    • Potential Anticipation (35 U.S.C. § 102): Unlikely to directly anticipate any of the independent claims.
  9. US6717946B1 (Cisco Technology Inc.)

    • Full Citation: US6717946B1, "Methods and apparatus for mapping ranges of values into unique values of particular use for range matching operations using an associative memory".
    • Publication Date: April 6, 2004.
    • Filing Date: October 31, 2002.
    • Brief Description: This patent focuses on mapping value ranges for efficient matching using associative memory, likely for routing or filtering. Similar to US6792502B1, it describes a mechanism that could be used for filtering but not the specific application described in US8621627.
    • Potential Anticipation (35 U.S.C. § 102): May be relevant to the underlying hardware mechanisms for filter processing (e.g., Claim 5, 22, 28) if such filtering relies on associative memory for rule matching, but unlikely to anticipate the overall system and method.
  10. US20040213235A1 (Marshall John W.)

    • Full Citation: US20040213235A1, "Programmable packet classification system using an array of uniform content-addressable memories".
    • Publication Date: October 28, 2004.
    • Filing Date: April 8, 2003.
    • Brief Description: This patent application describes a programmable packet classification system using CAMs. This is highly relevant to the filtering capabilities of a NIC.
    • Potential Anticipation (35 U.S.C. § 102): Claims 5, 6, 22, 23, 28, 29 (relevant to the technical means for implementing filter processing with configurable rules).
  11. US20050083935A1 (Kounavis Michael E.)

    • Full Citation: US20050083935A1, "Method and apparatus for two-stage packet classification using most specific filter matching and transport level sharing".
    • Publication Date: April 21, 2005.
    • Filing Date: October 20, 2003.
    • Brief Description: This patent application details a two-stage packet classification method using specific filter matching. This is another example of advanced packet filtering that could be relevant to the NIC's filter functionality.
    • Potential Anticipation (35 U.S.C. § 102): Claims 5, 6, 22, 23, 28, 29 (relevant to advanced filter processing techniques).
  12. US20050135412A1 (Fan Kan F.)

    • Full Citation: US20050135412A1, "Method and system for transmission control protocol (TCP) retransmit processing".
    • Publication Date: June 23, 2005.
    • Filing Date: December 19, 2003.
    • Brief Description: This patent application is concerned with TCP retransmit processing. It relates to protocol offload functions (Claim 2, 3, 8, 9, 14, 25, 26) but not directly to intrusion detection or the specific steering mechanism.
    • Potential Anticipation (35 U.S.C. § 102): Claims 2, 3, 8, 9, 14, 25, 26 (relevant to the concept of protocol offload processing on the NIC).
  13. US20050135396A1 (Mcdaniel Scott)

    • Full Citation: US20050135396A1, "Method and system for transmit scheduling for multi-layer network interface controller (NIC) operation".
    • Publication Date: June 23, 2005.
    • Filing Date: December 19, 2003.
    • Brief Description: This patent application describes transmit scheduling for multi-layer NIC operations, which is related to NIC functionality and data handling.
    • Potential Anticipation (35 U.S.C. § 102): Could broadly relate to general NIC operation and data handling (Claim 1, 7, 24) but lacks the specific security and VM offloading aspects.
  14. US20050135378A1 (Nortel Networks Limited)

    • Full Citation: US20050135378A1, "Service aware policer with efficient handling of in-profile traffic".
    • Publication Date: June 23, 2005.
    • Filing Date: December 22, 2003.
    • Brief Description: This patent application discusses a service-aware policer for traffic management. It's related to network control and filtering.
    • Potential Anticipation (35 U.S.C. § 102): Claims 5, 22, 28 (general filtering and traffic management on a NIC).
  15. US20050289246A1 (International Business Machines Corporation)

    • Full Citation: US20050289246A1, "Interpreting I/O operation requests from pageable guests without host intervention".
    • Publication Date: December 29, 2005.
    • Filing Date: May 27, 2004.
    • Brief Description: This patent application relates to handling I/O requests from virtual machine "guests" without host intervention. This touches on virtualized environments and offloading host tasks, which is a foundational concept in US8621627.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (relevant to the concept of offloading processing from the host in a virtualized environment).
  16. US7583596B1 (Juniper Networks, Inc.)

    • Full Citation: US7583596B1, "Priority scheduling using per-priority memory structures".
    • Publication Date: September 1, 2009.
    • Filing Date: June 28, 2004.
    • Brief Description: This patent focuses on priority scheduling in network devices. Its direct relevance to intrusion detection offload is limited.
    • Potential Anticipation (35 U.S.C. § 102): Unlikely to directly anticipate any of the independent claims.
  17. US7408883B2 (Nettest, Inc.)

    • Full Citation: US7408883B2, "Apparatus and method for performing a loopback test in a communication system".
    • Publication Date: August 5, 2008.
    • Filing Date: September 1, 2004.
    • Brief Description: This patent describes a loopback test in a communication system. While US8621627 utilizes a "loopback" to send frames to a VM for intrusion detection, this patent refers to a diagnostic test, not a security processing mechanism.
    • Potential Anticipation (35 U.S.C. § 102): Not directly anticipating the purpose or function of the loopback in US8621627, but conceptually relates to the idea of a frame being sent back within the system.
  18. US20060075480A1 (Noehring Lee P)

    • Full Citation: US20060075480A1, "System and method for controlling a flow of data a network interface controller to a host processor".
    • Publication Date: April 6, 2006.
    • Filing Date: October 1, 2004.
    • Brief Description: This patent application describes controlling data flow between a NIC and a host processor, which is fundamental to US8621627's interaction between the NIC and the host for additional processing.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (highly relevant to the interaction and data transfer between the NIC and the host for processing).
  19. US20060080733A1 (International Business Machines Corporation)

    • Full Citation: US20060080733A1, "Offline analysis of packets".
    • Publication Date: April 13, 2006.
    • Filing Date: October 8, 2004.
    • Brief Description: This patent application relates to offline analysis of packets, which could involve intrusion detection, but doesn't explicitly describe offloading the decision and steering to a NIC in a virtualized environment.
    • Potential Anticipation (35 U.S.C. § 102): Could broadly relate to the concept of analyzing packets for security, but lacks the specific NIC-based steering and host-based VM processing.
  20. US20060133267A1 (Utstarcom, Inc.)

    • Full Citation: US20060133267A1, "Processing platform selection method for data packet filter installation".
    • Publication Date: June 22, 2006.
    • Filing Date: December 21, 2004.
    • Brief Description: This patent application describes selecting processing platforms for packet filter installation. This is relevant to the configurability and deployment of filtering rules.
    • Potential Anticipation (35 U.S.C. § 102): Claims 5, 6, 22, 23, 28, 29 (relevant to the configuration of filter processing).
  21. US20060206300A1 (Microsoft Corporation)

    • Full Citation: US20060206300A1, "VM network traffic monitoring and filtering on the host".
    • Publication Date: September 14, 2006.
    • Filing Date: March 11, 2005.
    • Brief Description: This patent application specifically addresses monitoring and filtering VM network traffic on the host. This is highly relevant as it describes a problem that US8621627 aims to solve by offloading some of this to the NIC. It anticipates the need for such processing for VMs.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (highly relevant to the context of VM network security, but likely describes host-based solutions that US8621627 seeks to improve upon by offloading to the NIC).
  22. US20060221832A1 (Sun Microsystems, Inc.)

    • Full Citation: US20060221832A1, "Virtualized partitionable shared network interface".
    • Publication Date: October 5, 2006.
    • Filing Date: April 4, 2005.
    • Brief Description: This patent application discusses a virtualized and partitionable shared network interface. This relates to NICs in virtualized environments, a core context for US8621627.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (relevant to the general architecture of a NIC supporting virtual machines).
  23. US20060281451A1 (Zur Uri E)

    • Full Citation: US20060281451A1, "Method and system for handling connection setup in a network".
    • Publication Date: December 14, 2006.
    • Filing Date: June 14, 2005.
    • Brief Description: This patent application describes handling connection setup. Its direct relevance to intrusion detection offload is limited.
    • Potential Anticipation (35 U.S.C. § 102): Unlikely to directly anticipate any of the independent claims.
  24. US20070070901A1 (Eliezer Aloni)

    • Full Citation: US20070070901A1, "Method and system for quality of service and congestion management for converged network interface devices".
    • Publication Date: March 29, 2007.
    • Filing Date: September 29, 2005.
    • Brief Description: This patent application deals with QoS and congestion management in converged NICs. While related to NIC functionality, it doesn't address the specific security offload described in US8621627.
    • Potential Anticipation (35 U.S.C. § 102): Unlikely to directly anticipate any of the independent claims.
  25. US7899864B2 (Microsoft Corporation)

    • Full Citation: US7899864B2, "Multi-user terminal services accelerator".
    • Publication Date: March 1, 2011.
    • Filing Date: November 1, 2005.
    • Brief Description: This patent relates to accelerating multi-user terminal services. While it deals with efficiency in a multi-user context, its relevance to NIC-based intrusion detection for VMs is not direct.
    • Potential Anticipation (35 U.S.C. § 102): Unlikely to directly anticipate any of the independent claims.
  26. US7660306B1 (Chelsio Communications, Inc.)

    • Full Citation: US7660306B1, "Virtualizing the operation of intelligent network interface circuitry".
    • Publication Date: February 9, 2010.
    • Filing Date: January 12, 2006.
    • Brief Description: This patent, assigned to the same entity as US8621627, describes virtualizing the operation of intelligent network interface circuitry. This is extremely relevant as it lays groundwork for NICs operating in virtualized environments.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (highly relevant to the general concept of intelligent NICs in virtualized environments, and likely foundational to the problem solved by US8621627).
  27. US7925795B2 (Broadcom Corporation)

    • Full Citation: US7925795B2, "Method and system for configuring a plurality of network interfaces that share a physical interface".
    • Publication Date: April 12, 2011.
    • Filing Date: April 30, 2007.
    • Brief Description: This patent focuses on configuring multiple network interfaces that share a physical interface. This is relevant to NIC architecture in virtualized or multi-function scenarios.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24 (relevant to the configuration and management of NICs in a shared environment, potentially contributing to the architecture enabling US8621627).
  28. US20090254990A1 (Mcgee William Gerald)

    • Full Citation: US20090254990A1, "System and method for intelligent coordination of host and guest intrusion prevention in virtualized environment".
    • Publication Date: October 8, 2009.
    • Filing Date: April 5, 2008.
    • Brief Description: This patent application is highly relevant as it directly addresses intelligent coordination of host and guest intrusion prevention in a virtualized environment. This clearly describes the problem domain and solutions that US8621627 aims to improve upon.
    • Potential Anticipation (35 U.S.C. § 102): Claims 1, 7, 24, and dependent claims related to intrusion detection and virtual machines (very high relevance, likely anticipates the need and general concept of coordinating intrusion prevention between host and guest, even if the specific NIC-offload mechanism differs).

Most Directly Relevant Prior Art:

Based on the descriptions, the following patents appear to be most directly relevant to the core innovations of US8621627:

  • US7031267B2 (802 Systems Llc): Highly relevant to NIC-based filtering and dynamically configurable rules.
  • US20040213235A1 (Marshall John W.): Relevant to programmable packet classification systems using CAMs for filtering.
  • US20050289246A1 (International Business Machines Corporation): Relevant to offloading processing from the host in a virtualized environment.
  • US20060075480A1 (Noehring Lee P): Highly relevant to the interaction and data transfer between the NIC and the host for processing.
  • US20060206300A1 (Microsoft Corporation): Highly relevant to the context of VM network security and the problem US8621627 addresses.
  • US7660306B1 (Chelsio Communications, Inc.): Extremely relevant as it describes virtualizing intelligent NIC operations, likely a foundational patent for the assignee.
  • US20090254990A1 (Mcgee William Gerald): Most directly relevant as it addresses intelligent coordination of host and guest intrusion prevention in a virtualized environment, directly anticipating the problem space.

These documents collectively establish a prior art landscape that includes NIC-based packet filtering, offloading host tasks in virtualized environments, and the need for intrusion prevention in virtual machine settings. The novelty of US8621627 likely resides in the specific architectural design and methods for efficiently steering data frames for intrusion detection processing to a host-based VM and receiving them back for final routing, specifically leveraging NIC functionality to offload and optimize this process.

Generated 5/30/2026, 12:49:03 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis under 35 U.S.C. § 103 for US Patent 8,621,627

This analysis considers combinations of prior art references that would render the claims of US Patent 8,621,627 obvious to a person having ordinary skill in the art (POSA) at the time of the invention (filing date: February 12, 2010). The motivation to combine these references is also discussed.

The core innovation of US Patent 8,621,627 lies in offloading intrusion detection and prevention processing to a virtual machine on the host, with a Network Interface Controller (NIC) intelligently steering traffic for this processing, and potentially performing initial filtering itself. The patent emphasizes the efficiency gains and latency reduction compared to conventional software virtual switches or external appliances.

Prior Art References for US8621627:

The patent itself lists several prior art documents. While some are general, others are more directly relevant to the claimed invention.

  • US 2006/0206300 A1 (Microsoft Corporation): "VM network traffic monitoring and filtering on the host"
    • This reference describes monitoring and filtering VM network traffic on the host. This directly addresses intrusion detection in a virtualized environment.
  • US 2009/0254990 A1 (McGee, William Gerald): "System and method for intelligent coordination of host and guest intrusion prevention in virtualized environment"
    • This patent application explicitly discusses intelligent coordination of host and guest intrusion prevention, which aligns with the overall goal of US8621627.
  • U.S. patent application Ser. No. 11/250,894 (Chelsio Communications, Inc.): "Filtering Ingress Packets In Network Interface Circuitry."
    • This is explicitly incorporated by reference into US8621627 and describes filter functionality within the NIC, applying accept/reject actions and additional filtering rules.

Obviousness Combinations:

Combination 1: US 2006/0206300 A1 (Microsoft) in view of US 2009/0254990 A1 (McGee) and general knowledge of NIC capabilities.

  • Rationale: US 2006/0206300 A1 teaches monitoring and filtering VM network traffic on the host, which covers the "additional processing" aspect (intrusion detection) being performed by a VM on the host. US 2009/0254990 A1 further details "intelligent coordination of host and guest intrusion prevention," reinforcing the concept of a dedicated VM for such security tasks. A POSA would understand that traditional software virtual switches can be performance bottlenecks, as acknowledged in the background of US8621627. Given the known capabilities of NICs to offload network processing (e.g., TCP/IP offload engines were already prevalent), a POSA would have been motivated to offload some of the network traffic steering and initial filtering related to intrusion detection to the NIC itself to improve performance and reduce host overhead. The motivation would be to enhance the efficiency of the intrusion detection system by leveraging hardware acceleration available in NICs. This combination would likely render Claim 1 obvious, as it teaches receiving a data frame, determining if additional processing (intrusion detection from US 2006/0206300 A1 and US 2009/0254990 A1) is needed, sending it to the host VM for that processing, and then receiving it back and steering it to the destination.

Combination 2: Combination 1 further in view of U.S. patent application Ser. No. 11/250,894 (Chelsio).

  • Rationale: Building on Combination 1, U.S. patent application Ser. No. 11/250,894 (Chelsio) directly teaches "Filtering Ingress Packets In Network Interface Circuitry." This reference explicitly describes filter functionality within the NIC that can apply accept/reject actions and modify frames. A POSA, seeking to further optimize the performance of the intrusion detection system described in Combination 1, would be motivated to integrate the NIC's filtering capabilities to pre-process frames. This pre-processing would allow the NIC to drop clearly malicious or unnecessary frames before they even reach the host-based intrusion detection VM, thereby reducing the load on the host and the intrusion detection VM. This combination would particularly render Claim 5 and Claim 22 obvious, which claim that the NIC can drop frames that would otherwise be sent to the host for additional processing. It would also contribute to the obviousness of Claim 7, as the filtering rules applied by the NIC could be considered an "indication in the data frame" (or derived from it) upon which the determination for additional processing is based. Furthermore, the configuration of these filter rules by the host-based intrusion detection processing, as mentioned in US8621627, aligns with the "intelligent coordination" described in McGee.

Combination 3: Combination 2 further in view of the "oVLAN tag" concept (Embodiment 2) or "MAC-in-MAC encapsulation" (Embodiment 3) from the specification of US8621627 and general networking knowledge.

  • Rationale: The specification of US8621627 introduces specific mechanisms like oVLAN tags (Embodiment 2) and MAC-in-MAC encapsulation (Embodiment 3) for the NIC to indicate that a frame needs intrusion detection processing and for steering. These are well-known networking techniques for tagging and encapsulating traffic to influence forwarding decisions. A POSA, having the motivation to use the NIC for intelligent steering (as established in Combination 1 and 2), would readily apply these established networking techniques to differentiate and steer traffic to the intrusion detection VM. For example, adding an oVLAN tag to frames requiring inspection or encapsulating them in a MAC-in-MAC header with a specific destination MAC address (e.g., for the IDS VM) would be an obvious implementation choice to signal the NIC to route the traffic appropriately. This specifically addresses the "based on an indication in the data frame" aspect of Claim 7 and Claim 13 (adding an indication) and Claim 19 (Ethernet header as an indication). The patent itself notes that an oVLAN tag refers to a 4-byte IEEE 802.1 Q-in-Q encapsulation according to Ethernet standards, indicating it as a known technology.

Motivation to Combine:

The primary motivation for a POSA to combine these prior art references would be to overcome the performance bottlenecks and latency issues associated with host-based software virtual switches and external network appliances for intrusion detection in virtualized environments, as explicitly identified in the background of US8621627. The desire to improve efficiency, reduce CPU overhead on the host, and minimize communication latency for security processing would drive a POSA to leverage the capabilities of a NIC to offload and intelligently steer network traffic for intrusion detection. The existing knowledge of NIC offload functions and standard networking encapsulation techniques would provide the tools for implementing such a solution.

Generated 5/30/2026, 12:48:46 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Speednic LLC

Other patents in High-Tech (T)

See all High-Tech (T) patents →

This patent in court (1)

1 tracked lawsuit name US 8621627.