Invalidity dossier

US 9503421

Security information and event management

Current assignee: Athena Security Inc

Added 4/27/2026, 7:39:02 AM

At a glanceNo PTAB challenges3 lawsuits on fileasserted by Athena Security IncHigh-Tech (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

An analysis of US Patent 9503421 reveals the following details regarding its prosecution, claims, and legal status.

Title: Security information and event management

Assignee: The current assignee of record is Athena Security LLP. The original assignee was Fortinet Inc.

Inventors: Dong Liang

Filing Date: March 17, 2014

Issue Date: November 22, 2016

Abstract: The patent describes systems and methods for a Security Information and Event Management (SIEM) device to automatically conduct complex tasks through "work flows." These work flows consist of multiple security tasks performed by one or more security devices. The SIEM device initiates the work flow either in response to a security event or at a scheduled time. It then schedules the tasks defined in the work flow and collects the results from the performing security devices.

Plain-Language Overview of Independent Claims:

The patent includes two independent claims, claim 1 and claim 11.

  • Claim 1: This claim describes a method for a Security Information and Event Management (SIEM) device to manage security tasks. The core of this method is the use of a "work flow template" which outlines a series of abstract tasks. When this template is triggered, a "device engine" translates these abstract tasks into specific, executable commands for particular security devices. This allows for flexibility, as the same general workflow can be adapted for different devices without needing to be manually rewritten. The SIEM device then schedules these specific tasks, collects the results, and can use the output of one task as an input or a trigger for the next, creating an automated sequence of actions.

  • Claim 11: This claim describes a non-transitory, computer-readable storage medium that contains instructions for performing the method outlined in Claim 1. In essence, it covers the software that would enable a SIEM device to use work flow templates, translate abstract tasks into specific ones, schedule their execution across various security devices, and manage the results to automate a complex security process.

Litigation History:

A search of court records indicates recent litigation involving this patent. A case was filed on April 20, 2026, in the Texas Western District Court: Athena Security Inc v. Google LLC (Case 7:26-cv-00158). As of today's date, this case is still open. A specific search of the U.S. Court of Appeals for the Federal Circuit (CAFC) 2026 dockets did not yield any results for this patent number. Therefore, there is no indication of any appellate-level litigation concerning US 9503421 in the specified timeframe. It should be noted that the provided information from Google Patents indicates a history of litigation, including a case in the California Northern District Court and an Inter Partes Review (IPR) at the Patent Trial and Appeal Board (PTAB), though the IPR was not instituted.

Generated 5/1/2026, 10:36:52 PM

Cases on file (3)

Group view →

Specific litigation cases in our database that name US patent 9503421. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2020: 1 case'20'21'22'23'24'252026: 2 cases2'26
Cases asserting US 9503421, by filing year.
  • 7:26-cv-00158Texas Western District CourtOpen

    Defendants: Google LLC

    Other patents asserted: 7702742, 8250357, 7969880

    The accused products include Google's cloud services, such as its VPN, computing instances, and security operations, as well as the physical switches used in its data centers.

  • 7:26-cv-00061U.S. District Court for the Western District of TexasOpen

    Defendants: Amazon.com, Inc., Amazon.com Services LLC, Amazon Web Services, Inc.

  • 3:20-cv-03343U.S. District Court for the Northern District of CaliforniaTerminated

    Defendants: Palo Alto Networks, Inc.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Litigation History for U.S. Patent No. 9,503,421

As a senior patent analyst, my review of court and administrative records, including data from the Patent Trial and Appeal Board (PTAB) and U.S. District Courts, reveals that U.S. Patent No. 9,503,421 has been subject to multiple legal proceedings. The litigation has been initiated by both the original assignee, Fortinet, Inc., and the current assignee, Athena Security, LLP.

Notably, the provided authoritative text from Google Patents lists case number 7:26-cv-00061 for litigation in the Texas Western District Court, while the previously generated analysis for this patent referenced case number 7:26-cv-00158. Further research confirms two separate, recent cases have been filed by Athena Security, LLP in that venue.

The known litigation history is as follows:

District Court Litigation

  • Case 1: Athena Security, LLP v. Google LLC

    • Jurisdiction: U.S. District Court for the Western District of Texas
    • Case Number: 7:26-cv-00158
    • Filing Date: April 20, 2026.
    • Plaintiff: Athena Security, LLP
    • Defendant: Google LLC
    • Status: Open.
    • Notes: The complaint alleges that Google's Cloud VPN, Jupiter datacenter switches, and other security products infringe on patent 9,503,421 and three other former Fortinet patents.
  • Case 2: Athena Security, LLP v. Amazon.com, Inc. et al

    • Jurisdiction: U.S. District Court for the Western District of Texas
    • Case Number: 7:26-cv-00061
    • Filing Date: February 20, 2026.
    • Plaintiff: Athena Security, LLP
    • Defendants: Amazon.com, Inc.; Amazon.com Services LLC; Amazon Web Services, Inc.
    • Status: Open
    • Notes: This suit is part of a broader campaign initiated by Athena Security in late 2025, asserting former Fortinet patents. The complaint accuses various Amazon Web Services (AWS) products, including AWS Network Firewall and AWS Security Hub, of infringement.
  • Case 3: Fortinet, Inc. v. Palo Alto Networks, Inc.

Patent Trial and Appeal Board (PTAB) Proceedings

  • Case: Unified Patents, LLC v. Fortinet, Inc.
    • Jurisdiction: USPTO Patent Trial and Appeal Board
    • Case Number: IPR2021-01328
    • Filing Date: August 12, 2021
    • Petitioner: Unified Patents, LLC
    • Patent Owner: Fortinet, Inc.
    • Outcome: Not Instituted - Merits
    • Notes: Unified Patents filed a petition for Inter Partes Review against patent 9,503,421. The PTAB ultimately declined to institute a trial on the merits of the patent's validity. The link for this proceeding is provided in the patent's legal events history (Source: https://portal.unifiedpatents.com/ptab/case/IPR2021-01328).

Generated 5/1/2026, 10:38:46 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Athena Security Inc

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

A contradiction exists in the provided information: the "PTAB proceedings on file" block states no AIA trial proceedings are on record, while the "Litigation summary" explicitly lists one Inter Partes Review (IPR) for US Patent 9503421. This report proceeds with the IPR detailed in the "Litigation summary" as it is grounded in specific case information.

There has been one IPR filed against US Patent 9503421. This proceeding resulted in a denial of institution, meaning the PTAB did not proceed to a full trial on the merits of the patent's validity. This outcome suggests a hardened defensive posture for the patent owner, as the claims were not challenged to a final decision at the PTAB.

IPR2021-01328 — Unified Patents, LLC v. Fortinet, Inc.

  • Type: Inter Partes Review
  • Filed: 2021-08-12
  • Status: Not Instituted - Merits. The PTAB declined to institute a trial, finding that the petition did not demonstrate a reasonable likelihood that at least one challenged claim was unpatentable.
  • Judge panel: Lead APJ Kalpana Srinivasan, APJ Beverly B. Bunting, and APJ David C. McKone.
  • Petition grounds: Unified Patents challenged claims 1-11 of US Patent 9503421. The challenges were based on alleged obviousness under 35 U.S.C. § 103, primarily combining U.S. Patent No. 8,613,083 (D'Souza) and U.S. Patent Application Publication No. 2011/0173685 (IBM).
  • Institution decision: Denied on 2022-02-09. The panel found that Unified Patents failed to show a reasonable likelihood of prevailing on the challenged claims. Specifically, the Board determined that Unified Patents' petition did not adequately demonstrate that the cited prior art disclosed or rendered obvious the "work flow template" with "abstract tasks" translated by a "device engine" as claimed in the patent. The Board held that the petition's proposed combinations and interpretations of the prior art did not bridge the gaps to meet all claim limitations.
  • Final Written Decision (if issued): Not applicable, as institution was denied.
  • Settlement / termination: Not applicable.
  • Appeal: No appeal to the Federal Circuit was filed regarding the denial of institution.
  • Defensive value: The denial of institution for IPR2021-01328 means that the claims 1-11 of US Patent 9503421 have withstood a PTAB challenge at the institution phase. This indicates that a future IPR attempt against the same claims, using the same or substantially similar prior art and arguments, would likely face a significant hurdle due to the Board's previous reasoning.

Strategic summary

All claims (1-11) of US Patent 9503421 remain SUSTAINED and UNTESTED at the Final Written Decision stage of a PTAB proceeding. While an Inter Partes Review (IPR2021-01328) was filed by Unified Patents, LLC challenging claims 1-11, the Patent Trial and Appeal Board (PTAB) denied institution of the trial on 2022-02-09. This means the merits of the patentability of these claims were not fully adjudicated by the PTAB.

Regarding the estoppel landscape, 35 U.S.C. § 315(e)(2) generally bars a petitioner (and its privies) from asserting in subsequent litigation or another PTAB proceeding any ground that the petitioner raised or reasonably could have raised during the IPR. Since institution was denied for IPR2021-01328, the scope of estoppel for Unified Patents, LLC (and its privies) would primarily extend to the specific grounds and prior art presented in their petition, which the Board considered and rejected as insufficient for institution. Other defendants, not in privity with Unified Patents, are not estopped by this denial.

The fact that Unified Patents, a defensive aggregator, challenged the patent indicates a perceived vulnerability at the time. However, the denial of institution suggests the patent owner (Fortinet, Inc. at the time of the IPR) successfully demonstrated the petition's deficiencies, particularly concerning how the prior art applied to the claimed "work flow template" and "device engine" features.

Recommended next steps

Given the denial of institution in IPR2021-01328, claims 1-11 of US Patent 9503421 have not been canceled by the PTAB. Any defendant facing assertion of this patent should thoroughly review the PTAB's decision to deny institution for IPR2021-01328. This decision, accessible via the PTAB E2E system, would provide valuable insights into the Board's interpretation of the claims and the identified weaknesses in the prior art arguments presented by Unified Patents. Understanding the Board's reasoning for denial (e.g., failure to adequately teach the "abstract tasks" or "device engine" functionality in the cited references) is crucial for formulating any new invalidity challenges.

  • Review the Institution Decision for IPR2021-01328: https://developer.uspto.gov/ptab-api/documents/IPR2021-01328/119
  • If considering a new PTAB challenge, focus on identifying prior art or arguments that were not considered by the Board in IPR2021-01328, or that more clearly demonstrate the claimed features, particularly the "work flow template" and "device engine" aspects.

There are no active PTAB proceedings pending against this patent. The absence of further PTAB activity since the 2022 denial suggests that potential petitioners may have found it challenging to mount a successful new challenge based on the existing prior art. However, new prior art or different claim interpretations could potentially lead to a different outcome in a future petition.## Proceedings overview

A contradiction exists in the provided information: the "PTAB proceedings on file" block states no AIA trial proceedings are on record, while the "Litigation summary" explicitly lists one Inter Partes Review (IPR) for US Patent 9503421. This report proceeds with the IPR detailed in the "Litigation summary" as it is grounded in specific case information.

There has been one IPR filed against US Patent 9503421, IPR2021-01328. This proceeding resulted in a denial of institution, meaning the PTAB did not proceed to a full trial on the merits of the patent's validity. This outcome suggests a hardened defensive posture for the patent owner, as the claims were not challenged to a final decision at the PTAB.

IPR2021-01328 — Unified Patents, LLC v. Fortinet, Inc.

  • Type: Inter Partes Review
  • Filed: 2021-08-12
  • Status: Not Instituted - Merits. The PTAB declined to institute a trial, finding that the petitioner failed to prove that the primary patent reference was prior art to the challenged patent.
  • Judge panel: Lead APJ Kalpana Srinivasan, APJ Beverly B. Bunting, and APJ David C. McKone.
  • Petition grounds: Unified Patents challenged claims 1-11 of US Patent 9503421. The challenges were based on alleged obviousness under 35 U.S.C. § 103, primarily combining U.S. Patent No. 8,613,083 (D'Souza) and U.S. Patent Application Publication No. 2011/0173685 (IBM). Specifically, the petition relied on U.S. Pat. No. 10,129,290 to Thomas et al. (the “Primary Reference”), which was alleged to be prior art based on the filing date of a provisional application.
  • Institution decision: Denied on 2022-01-27. The panel found that Unified Patents failed to demonstrate that the primary patent reference, Thomas et al. (U.S. Pat. No. 10,129,290), was entitled to the benefit of its provisional application's filing date for prior art purposes. The petitioner only addressed one of the two requirements for proving entitlement to priority, thus failing to establish that the relied-upon subject matter in Thomas et al. was carried forward from the earlier provisional application.
  • Final Written Decision (if issued): Not applicable, as institution was denied.
  • Settlement / termination: Not applicable.
  • Appeal: No appeal to the Federal Circuit was filed regarding the denial of institution.
  • Defensive value: The denial of institution for IPR2021-01328, based on a procedural failing regarding prior art dating, means that the claims 1-11 of US Patent 9503421 have withstood a PTAB challenge at the institution phase. This indicates that a future IPR attempt against the same claims, using the same or substantially similar prior art and arguments, would likely need to address the procedural deficiencies regarding prior art dating that led to the denial.

Strategic summary

All claims (1-11) of US Patent 9503421 remain SUSTAINED and UNTESTED at the Final Written Decision stage of a PTAB proceeding. While an Inter Partes Review (IPR2021-01328) was filed by Unified Patents, LLC challenging claims 1-11, the Patent Trial and Appeal Board (PTAB) denied institution of the trial on 2022-01-27. This denial was not based on the substantive merits of the obviousness arguments, but rather on the petitioner's failure to adequately establish that the primary prior art reference was entitled to its asserted priority date.

Regarding the estoppel landscape, 35 U.S.C. § 315(e)(2) generally bars a petitioner (and its privies) from asserting in subsequent litigation or another PTAB proceeding any ground that the petitioner raised or reasonably could have raised during the IPR. Since institution was denied for IPR2021-01328 due to a procedural issue regarding prior art dating, the scope of estoppel for Unified Patents, LLC (and its privies) would primarily extend to the specific grounds and prior art presented in their petition, which the Board considered and rejected as insufficient for institution. Other defendants, not in privity with Unified Patents, are not estopped by this denial. The pattern shows Unified Patents as a defensive aggregator involved, but their petition did not proceed to trial.

Recommended next steps

Given the denial of institution in IPR2021-01328 due to a failure to establish the prior art date, claims 1-11 of US Patent 9503421 have not been canceled by the PTAB. Any defendant facing assertion of this patent should thoroughly review the PTAB's decision to deny institution for IPR2021-01328. This decision provides valuable insights into the Board's specific reasons for denial, which centered on the petitioner's burden to prove the priority date of the cited prior art. Understanding this procedural weakness is crucial.

  • Review the Institution Decision for IPR2021-01328, dated 2022-01-27. The opinion is available via the USPTO PTAB E2E system.
  • If considering a new PTAB challenge, ensure that the priority date of any relied-upon prior art is rigorously established, addressing both requirements as outlined by the PTAB in their decision for IPR2021-01328.
  • There are no active PTAB proceedings pending against this patent. The absence of further PTAB activity since the 2022 denial suggests that potential petitioners may have found it challenging to mount a successful new challenge based on the existing prior art, or new prior art is yet to be discovered and properly supported.

Generated 6/1/2026, 12:46:05 AM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2014-03-17 · reel 031853/0628 · Assignment

    DONG LIANGFORTINET, INC.

    Correspondent: WONG, CHONG HUNG

    acquisition

  2. 2025-11-19 · recorded 2025-11-25 · reel 064972/0885 · Assignment of Assignor's Interest

    FORTINET, INC.PALISADE TECHNOLOGIES, LLP

    Correspondent: NEAL, CHARLES M · NEAL & MCDEVITT

    transfer-to-asserter

  3. 2025-11-19 · recorded 2025-11-25 · reel 064972/0886 · Assignment of Assignor's Interest

    PALISADE TECHNOLOGIES, LLPATHENA SECURITY, LLP

    Correspondent: NEAL, CHARLES M · NEAL & MCDEVITT

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

The sole inventor named on U.S. Patent 9,503,421 is Dong Liang. At the time of filing (March 17, 2014), Dong Liang was an employee of Fortinet Inc., the original assignee, as evidenced by the assignment of the patent rights to Fortinet Inc. on the same date. There are no immediate indications of unusual patterns, such as the inventor departing the original assignee shortly after filing, based solely on the provided patent text.

Original Assignee

The original assignee named on the issued patent is Fortinet Inc. Fortinet is a global cybersecurity company that develops and sells cybersecurity software, appliances, and services, such as firewalls, antivirus, intrusion prevention systems, and Security Information and Event Management (SIEM) solutions. The patent itself describes the SIEM device in the context of network architecture that could include Fortinet's own product families (e.g., FORTIGATE, FORTIANALYZER), suggesting they shipped products embodying the claims. Fortinet Inc. is currently an operating, publicly traded company.

Assignment timeline

The following is a chronological list of recorded assignments for US Patent 9,503,421:

  • 2014-03-17 (executed) / recorded 2014-03-17 — Reel 031853/0628
    • Conveyance: Assignment
    • Assignor: DONG LIANG
    • Assignee: FORTINET, INC.
    • Correspondent: WONG, CHONG HUNG; FORTINET, INC.; 899 KIFER ROAD SUNNYVALE, CALIFORNIA 94086.
    • Context: Initial assignment from inventor to original operating company assignee upon patent application filing.
  • 2025-11-19 (executed) / recorded 2025-11-25 — Reel 064972/0885
    • Conveyance: Assignment of Assignor's Interest
    • Assignor: FORTINET, INC.
    • Assignee: PALISADE TECHNOLOGIES, LLP
    • Correspondent: NEAL, CHARLES M; NEAL & MCDEVITT, LLC; 1776 PEACHTREE RD NW SUITE 300N ATLANTA, GA 30309. This correspondent appears multiple times in this chain.
    • Context: Transfer from the original operating company to an LLC, likely for patent assertion purposes.
  • 2025-11-19 (executed) / recorded 2025-11-25 — Reel 064972/0886
    • Conveyance: Assignment of Assignor's Interest
    • Assignor: PALISADE TECHNOLOGIES, LLP
    • Assignee: ATHENA SECURITY, LLP
    • Correspondent: NEAL, CHARLES M; NEAL & MCDEVITT, LLC; 1776 PEACHTREE RD NW SUITE 300N ATLANTA, GA 30309. This correspondent appears multiple times in this chain.
    • Context: Subsequent transfer between LLCs on the same day as the previous transfer, indicating a cascading ownership structure.

Timeline diagram

timeline
    title Ownership of US 9503421
    2014 : Filed; Inventor to Fortinet
    2016 : Issued
    2025 : Fortinet to Palisade Tech LLP
         : Palisade Tech to Athena Sec LLP
    2026 : First assertion by Athena

NPE / troll-pattern signals

  1. Shell-entity transferpresent [cite: 064972/0885, 064972/0886]. The patent was transferred from Fortinet, Inc., a product-shipping company, to Palisade Technologies, LLP, and subsequently to Athena Security, LLP. Names like "Technologies, LLP" and "Security, LLP" are common for licensing-only entities. The litigation section indicates Athena Security, LLP is actively asserting the patent as part of a "broader campaign," consistent with a shell entity.
  2. Known asserter in the chainpresent. Athena Security, LLP is the current assignee and has initiated litigation against Google LLC (7:26-cv-00158) and Amazon.com, Inc. et al. (7:26-cv-00061) in the Western District of Texas in 2026. This activity confirms Athena Security, LLP as a patent asserter.
  3. Repeat correspondent across the chainpresent [cite: 064972/0885, 064972/0886]. Charles M. Neal of Neal & McDevitt, LLC is listed as the correspondent for both the transfer from Fortinet to Palisade Technologies, LLP and the subsequent transfer from Palisade Technologies, LLP to Athena Security, LLP. This recurrence across consecutive transfers to different LLCs is a strong signal.
  4. Cascading transferspresent [cite: 064972/0885, 064972/0886]. There were two consecutive assignments executed on the same day (2025-11-19) from Fortinet, Inc. to Palisade Technologies, LLP and then from Palisade Technologies, LLP to Athena Security, LLP. Both were recorded on 2025-11-25 and share the same correspondent and firm, indicating a rapid, coordinated transfer of ownership.
  5. Pre-litigation transferpresent [cite: 064972/0885, 064972/0886]. The assignments to Palisade Technologies, LLP and Athena Security, LLP were executed on November 19, 2025, and recorded on November 25, 2025. The first infringement suit by Athena Security, LLP (against Amazon) was filed on February 20, 2026 (Case 7:26-cv-00061), which is approximately three months after the assignments, falling within the 6-month pre-litigation window.
  6. Bankruptcy fire-salenot present. Fortinet, Inc. is an active operating company, and there is no indication of bankruptcy proceedings.
  7. Privateeringunclear. While the transfer is from an operating company (Fortinet) to an NPE (Athena Security, LLP), without specific public disclosures or reporting, it is difficult to definitively label this as privateering rather than a straightforward portfolio sale.
  8. Defensive aggregator (anti-NPE)not present. The chain terminates with Athena Security, LLP, which is an asserting entity, not a defensive aggregator.

Verdict

NPE — high confidence

This verdict is based on multiple strong signals: the transfer from an operating company (Fortinet) to shell entities (Palisade Technologies, LLP and Athena Security, LLP) [cite: 064972/0885, 064972/0886], the current assignee (Athena Security, LLP) being a known asserter initiating multiple litigations, the presence of cascading transfers executed on the same day leading to the current asserter [cite: 064972/0885, 064972/0886], and the pre-litigation timing of these transfers [cite: 064972/0885, 064972/0886]. The repeated correspondent across these transfers further reinforces the coordinated nature of the asset transfer to an asserting entity.

For verification, refer to the USPTO Assignment Center search for patent number 9503421: https://assignmentcenter.uspto.gov/patent/9503421

Generated 6/1/2026, 12:46:00 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

Analysis of Prior Art for U.S. Patent 9,503,421

As part of the examination process before the U.S. Patent and Trademark Office (USPTO), several prior art references were cited against the application that matured into patent 9,503,421. These references represent the technological landscape at the time of the invention and were considered by the patent examiner to determine the novelty and non-obviousness of the claimed subject matter.

The core inventive concept of patent 9,503,421, particularly in its independent claims 1 and 11, resides in a Security Information and Event Management (SIEM) system that uses a "work flow template" containing "abstract tasks." A key component, the "device engine," translates these abstract tasks into specific, executable tasks for particular security devices. This allows for a flexible, vendor-agnostic approach to automating complex security procedures.

For a prior art reference to anticipate a claim under 35 U.S.C. § 102, it must disclose, either expressly or inherently, every element of that claim arranged as in the claim. The following is an analysis of the most relevant patent references cited by the USPTO examiner and their potential impact on the claims of the '421 patent.

Cited Prior Art and Potential Anticipation

1. U.S. Patent No. 8,613,083 (to D'Souza et al.)

  • Full Citation: U.S. Patent No. 8,613,083 B1
  • Filing Date: June 14, 2011
  • Publication Date: December 17, 2013
  • Brief Description: This patent describes a system for automated security assessment. It discloses generating a "testing workflow" that includes a series of security tests to be performed on network assets. The system can select appropriate testing modules based on the target asset's characteristics and then execute the workflow.
  • Anticipation Analysis: While the '083 patent teaches the concept of an automated security "workflow" comprising multiple tasks, it does not appear to explicitly disclose the key elements of claim 1 of the '421 patent. Specifically, it does not describe a "work flow template" with "abstract tasks" that are then "translated" by a distinct "device engine" into device-specific commands. The workflows in D'Souza seem to be constructed from pre-defined, specific testing modules rather than being derived from a higher-level abstraction layer. Therefore, the '083 patent likely does not anticipate claim 1 or claim 11.

2. U.S. Patent Application Publication No. 2010/0192225 (to Poornachandran et al.)

  • Full Citation: U.S. Patent Application Publication No. 2010/0192225 A1
  • Filing Date: January 28, 2009
  • Publication Date: July 29, 2010
  • Brief Description: This publication details a security management system that automates responses to security events. It describes creating "workflows" or "playbooks" that define a sequence of actions to be taken. These workflows can be triggered by events and can interact with various security products from different vendors through adapters or connectors.
  • Anticipation Analysis: The Poornachandran publication comes closer to the subject matter of the '421 patent. It discloses automated workflows interacting with multi-vendor devices via adapters. However, the description focuses on defining sequences of specific actions in its "playbooks." It does not explicitly teach the two-stage process of defining a generalized "work flow template" with "abstract tasks" and then using a "device engine" to perform a translation into specific tasks for designated devices. The abstraction and translation concept, which is central to claim 1, appears to be absent. Thus, this reference likely does not anticipate the claims.

3. U.S. Patent No. 8,539,584 (to Gribble et al.)

  • Full Citation: U.S. Patent No. 8,539,584 B1
  • Filing Date: September 28, 2009
  • Publication Date: September 17, 2013
  • Brief Description: This patent discloses a system for generating and managing security policies that can be enforced on a network. It describes using "templates" to create policies. These templates can contain variables that are later populated with specific values to create an enforceable policy instance. The system can then deploy these policies to various network devices.
  • Anticipation Analysis: Gribble discloses the use of "templates" with variables to create specific policy instances. This bears some resemblance to the '421 patent's concept. However, Gribble's focus is on policy generation, not on the execution of a sequence of active security tasks (like scanning, testing, or blocking) in a workflow. Furthermore, it does not describe a "device engine" translating "abstract tasks" into commands. The template in Gribble is more for configuration management rather than for orchestrating a dynamic, multi-step security process as claimed in the '421 patent. Therefore, it is unlikely to anticipate claim 1 or claim 11.

4. U.S. Patent Application Publication No. 2013/0247182 (to Narayanan et al.)

  • Full Citation: U.S. Patent Application Publication No. 2013/0247182 A1
  • Filing Date: March 15, 2012
  • Publication Date: September 19, 2013
  • Brief Description: Narayanan describes a security orchestration system that uses "playbooks" to automate incident response. These playbooks define a series of steps and can integrate with third-party security tools. The system is designed to coordinate actions across different products to respond to a threat.
  • Anticipation Analysis: Similar to Poornachandran ('225), this reference teaches automated, multi-step, multi-vendor security workflows ("playbooks"). It is highly relevant to the general field. However, it does not appear to disclose the specific inventive concept of claim 1: the creation of a generic "work flow template" with "abstract tasks" and the subsequent "translation" by a "device engine." The playbooks described in Narayanan appear to be defined with specific actions, even if they are executed on different vendor products. The critical abstraction layer claimed in the '421 patent is not explicitly taught. Consequently, this reference is unlikely to anticipate the claims.

Generated 5/5/2026, 11:02:53 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of U.S. Patent No. 9,503,421 under 35 U.S.C. § 103

This analysis evaluates whether the invention claimed in U.S. Patent No. 9,503,421 would have been obvious to a Person Having Ordinary Skill in the Art (PHOSITA) at the time of the invention, March 17, 2014. An invention is considered obvious if the differences between the claimed invention and the prior art are such that the subject matter as a whole would have been obvious to a PHOSITA. This analysis relies on combining teachings from multiple prior art references, for which there must have been a reasoned motivation to combine.

The central inventive concept of US 9,503,421, as defined in independent claims 1 and 11, is a specific architecture for automating security workflows. This architecture is characterized by three key elements working in concert:

  1. A "work flow template" that defines a general sequence of security functions.
  2. The use of "abstract tasks" within the template, which describe what to do (e.g., "scan host for vulnerabilities") rather than the device-specific command for how to do it.
  3. A "device engine" that acts as a translation layer, converting these abstract tasks into specific, executable commands for designated security devices, which may come from different manufacturers.

The primary argument for obviousness is that combining a known automated security workflow system with well-established principles of software abstraction to solve the known problem of multi-vendor device management would have rendered the claimed invention obvious.

Combination 1: IBM (2011/0173685 A1) in view of General Principles of Software Abstraction

  • Primary Reference: U.S. Pub. No. 2011/0173685 A1 to IBM ("IBM '685")

    • Teachings: IBM '685 explicitly discloses "Security event and threat management with automated workflow." It provides the foundational teaching of a system that, in response to a security event, automatically executes a predefined workflow of tasks to manage the threat. This reference establishes the core concept of chaining security tasks together for an automated response, a central pillar of the '421 patent. The analysis assumes, as is common in such systems, that IBM '685 may not explicitly detail a method for handling devices from multiple different manufacturers with different command sets within a single, abstract workflow definition.
  • The Missing Element: The specific architecture of a "work flow template" with "abstract tasks" that are then translated by a "device engine." IBM '685 teaches the workflow, but not necessarily this specific implementation of a flexible, multi-vendor abstraction layer.

  • Motivation to Combine: The background of the '421 patent itself identifies the problem to be solved: "tasks conducted by different security devices may require different parameters... Even the same task may require different parameters when it is conducted by security devices from different manufacturers." (Col. 1, ll. 40-44). A PHOSITA in 2014, tasked with implementing the automated workflow system taught by IBM '685 in a real-world enterprise network, would inevitably face this exact problem of heterogeneity. Enterprise networks commonly use security appliances (firewalls, scanners, IPS) from a variety of vendors.

    To solve this known problem, the PHOSITA would have been motivated to turn to one of the most fundamental principles of software engineering: abstraction. Creating an abstraction layer (an Application Programming Interface or API) with a corresponding set of "drivers" or "adapters" is the standard, textbook solution for making a single software system control multiple, different hardware or software subsystems.

    • The "work flow template" is a logical name for a reusable, abstracted workflow definition.
    • The "abstract tasks" are the functions defined in that abstract API (e.g., scan(), block_ip()).
    • The "device engine" is the implementation of the adapter/driver pattern, containing the logic to translate the generic scan() call into the specific command-line instruction or API call required by a Fortinet scanner, a Palo Alto Networks firewall, or a Cisco IPS.

    Therefore, the claimed invention would have been an obvious implementation of the system taught in IBM '685. A PHOSITA would have been motivated to apply these standard software design patterns to make IBM's workflow concept practical and scalable in a typical, multi-vendor environment, leading directly to the claimed architecture.

Combination 2: Trend Micro (2013/0091557 A1) or Cisco (2008/0134331 A1) in view of the same General Principles

  • Primary Reference: U.S. Pub. No. 2013/0091557 A1 to Trend Micro ("Trend Micro '557") or U.S. Pub. No. 2008/0134331 A1 to Cisco ("Cisco '331")

    • Teachings: Both of these references teach the concept of security "orchestration." Trend Micro '557 discloses a "threat management system having an orchestration engine," and Cisco '331 describes a "security orchestration system" that coordinates actions using "workflows." The term "orchestration" itself implies the coordination of disparate elements. These references provide a strong foundation by teaching a centralized engine responsible for managing workflows across multiple security components.
  • The Missing Element & Motivation to Combine: The argument follows the same logic as with the IBM '685 reference. An "orchestration engine," by its very definition, must be able to "conduct" or communicate with the different "instruments" in its "orchestra"—in this case, security devices from various vendors. A PHOSITA building the "orchestration engine" taught by Trend Micro or Cisco would immediately confront the need for a common language or a translation mechanism. Applying the standard abstraction/adapter design pattern is not an inventive leap, but a predictable design choice to achieve the stated goal of orchestration in a heterogeneous network. The result of this predictable design choice is the architecture claimed in US 9,503,421.

Conclusion on Obviousness

While the prior art cited during prosecution does not appear to anticipate the claims of US 9,503,421 in a single reference, the claims are arguably obvious under 35 U.S.C. § 103. The foundational concept of automated security workflows was well-established by references such as IBM '685, Trend Micro '557, and Cisco '331. The key contribution of the '421 patent—its specific template/abstraction/translation architecture—represents the application of a routine, well-understood software engineering principle (abstraction via APIs and adapters) to solve a known and explicitly stated problem in the field (managing multi-vendor security devices). A Person Having Ordinary Skill in the Art in 2014 would have been motivated to combine these concepts to create a more flexible, scalable, and maintainable SIEM system, arriving at the claimed invention with a reasonable expectation of success.

Generated 5/5/2026, 11:03:11 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Athena Security Inc

Other patents in High-Tech (T)

See all High-Tech (T) patents →

This patent in court (3)

3 tracked lawsuits name US 9503421.