Invalidity dossier

US 9516048

Contagion isolation and inoculation via quarantine

Current assignee: K. Mizra LLC

Added 5/13/2026, 6:00:35 AM

At a glanceNo PTAB challenges7 lawsuits on fileasserted by K. Mizra LLCHigh-Tech (T)

Active provider: Google · gemini-2.5-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Analysis of U.S. Patent 9,516,048

Date of Analysis: May 13, 2026

This report provides a concise summary of United States Patent 9,516,048, including its key bibliographic details and a plain-language overview of its independent claims.

Summary of Patent 9,516,048

Title Contagion isolation and inoculation via quarantine
Inventors Aaron Emigh, James Roskind
Assignee K Mizra LLC (Current Assignee as of 2020-01-13). The original assignee was Radix Holdings LLC.
Filing Date July 9, 2016
Issue Date December 6, 2016
Abstract The patent discloses methods for protecting a computer network. The system detects if a computer (host) attempting to connect is insecure by checking for a valid, digitally signed "attestation of cleanliness" from a trusted component on the host. This attestation confirms the host is not infected with malware and has necessary software patches. If the attestation is invalid, the host is quarantined. This involves re-routing its web browser to a quarantine server that provides information on how to fix the security problem. The quarantined host is then only allowed to communicate with a specific "remediation host" to download the necessary data to resolve the insecure condition.

Plain-Language Overview of Independent Claims

Independent claims define the core, legally protected invention. US Patent 9,516,048 has two independent claims.

  • Claim 1 (A Method): This claim protects a method for automatically securing a network. In simple terms, the process involves:

    1. Detecting a Problem: When a computer tries to join the network, the system checks a trusted part of that computer for a valid digital certificate confirming it's "clean" (not infected and up-to-date).
    2. Quarantining: If the certificate is missing or invalid, the computer is immediately isolated.
    3. Informing the User: Any attempt by the quarantined computer to browse the web is redirected to a special page that explains the security problem and provides information on how to fix it.
    4. Providing a Solution: The quarantined computer is blocked from all network activity except for connecting to a specific server where it can download the required security patches or updates to resolve the issue.
  • Claim 11 (A System): This claim protects a physical system that performs the method described in Claim 1. It covers a system with processors and memory programmed to:

    1. Check for a security certificate on a connecting computer.
    2. Quarantine the computer if the certificate is not valid.
    3. Redirect the computer's browser to a quarantine page with remediation instructions.
    4. Permit access only to a remediation server so the computer can be fixed.

In essence, both claims cover the concept of an automated network "gatekeeper" that identifies potentially unsafe devices, isolates them in a limited environment, and guides them through the process of becoming secure before granting full network access.

CAFC 2026 Docket Search

As of May 13, 2026, a search of the dockets for the U.S. Court of Appeals for the Federal Circuit (CAFC) for the year 2026 reveals no cases specifically referencing US Patent 9,516,048. I have high confidence in this assessment based on available public records.

Generated 5/13/2026, 6:46:24 PM

Cases on file (7)

Group view →

Specific litigation cases in our database that name US patent 9516048. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2017: 4 cases4'17'18'19'202021: 3 cases'21
Cases asserting US 9516048, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Litigation and Administrative Review Involving US Patent 9,516,048

As of April 26, 2026, U.S. Patent No. 9,516,048 B2 has been the subject of multiple district court litigations and has been challenged in inter partes review (IPR) proceedings before the Patent Trial and Appeal Board (PTAB). The patent is currently owned by K. Mizra LLC, having been previously assigned to Network Security Technologies, LLC.

District Court Litigation

The patent has been asserted in at least seven district court cases, primarily in the District of Delaware and the Eastern District of Texas.

  • Plaintiff: K. Mizra LLC
    Defendant: Hewlett Packard Enterprise Co.
    Jurisdiction: U.S. District Court for the Eastern District of Texas
    Case Number: 2:21-cv-00305
    Filing Date: August 9, 2021
    Status: This case was identified in a subsequent PTAB proceeding. The specific outcome or current status requires further review of court records.

  • Plaintiff: K. Mizra LLC
    Defendant: Fortinet, Inc.
    Jurisdiction: U.S. District Court for the Eastern District of Texas
    Case Number: 2:21-cv-00249
    Filing Date: July 8, 2021
    Status: This case was identified in subsequent PTAB proceedings. The specific outcome or current status requires further review of court records.

  • Plaintiff: K. Mizra LLC
    Defendant: Forescout Technologies, Inc.
    Jurisdiction: U.S. District Court for the Eastern District of Texas
    Case Number: 2:21-cv-00248
    Filing Date: July 8, 2021
    Status: This case was identified in subsequent PTAB proceedings. The specific outcome or current status requires further review of court records.

  • Plaintiff: Network Security Technologies, LLC
    Defendant: Pulse Secure, LLC
    Jurisdiction: U.S. District Court for the District of Delaware
    Case Number: 1:17-cv-01490
    Filing Date: October 24, 2017
    Status: This case was identified in a subsequent PTAB proceeding. The specific outcome or current status requires further review of court records.

  • Plaintiff: Network Security Technologies, LLC
    Defendant: McAfee, Inc.
    Jurisdiction: U.S. District Court for the District of Delaware
    Case Number: 1:17-cv-01489
    Filing Date: October 24, 2017
    Status: This case was identified in a subsequent PTAB proceeding. The specific outcome or current status requires further review of court records.

  • Plaintiff: Network Security Technologies, LLC
    Defendant: ForeScout Technologies, Inc.
    Jurisdiction: U.S. District Court for the District of Delaware
    Case Number: 1:17-cv-01488
    Filing Date: October 24, 2017
    Status: This case was identified in a subsequent PTAB proceeding. The specific outcome or current status requires further review of court records.

  • Plaintiff: Network Security Technologies, LLC
    Defendant: Bradford Networks, Inc.
    Jurisdiction: U.S. District Court for the District of Delaware
    Case Number: 1:17-cv-01487
    Filing Date: October 24, 2017
    Status: This case was identified in a subsequent PTAB proceeding. The specific outcome or current status requires further review of court records.

Patent Trial and Appeal Board (PTAB) Proceedings

The validity of US Patent 9,516,048 has been challenged before the PTAB in two known IPR proceedings.

  • Proceeding Number: IPR2025-01437
    Petitioner: Information Not Available in Provided Documents
    Patent Owner: K. Mizra LLC
    Filing Date: Not available in provided documents.
    Outcome: Not Instituted - Procedural.

  • Proceeding Number: IPR2022-00843
    Petitioner: Hewlett Packard Enterprise Company
    Patent Owner: K. Mizra LLC
    Filing Date: Prior to October 31, 2022
    Outcome: On October 31, 2022, the PTAB denied institution of the inter partes review.

Generated 5/13/2026, 6:46:14 PM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: K. Mizra LLC

1 discretionary denial

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Based on a review of the on-file proceedings for US patent 9,516,048, here is an analysis of its AIA trial history and what it means for a defendant.

Proceedings overview

There has been one Inter Partes Review (IPR) filed against US patent 9,516,048, which was discretionarily denied by the Patent Trial and Appeal Board (PTAB). This means the Board declined to institute a trial and never reached a decision on the merits of the invalidity arguments. For a defendant, this means the patent has not been tested or weakened by a PTAB trial, but neither has it been "hardened" by surviving one; all claims remain valid and open to future challenges.


IPR2025-01437 — Google LLC v. K. Mizra LLC

  • Type: Inter Partes Review
  • Filed: 2025-09-19
  • Status: Discretionary Denial — The PTAB declined to institute an IPR trial based on discretionary factors, not on the substantive merits of the invalidity grounds presented. The case is terminated.
  • Judge panel: Administrative Patent Judges Georgianna W. Braden, Kevin C. Trock, and Eric G. Jimmy.
  • Petition grounds: The petition challenged claims 1–20 of the '048 patent. The specific prior art and statutory grounds (§ 102 for anticipation or § 103 for obviousness) asserted in the petition are not detailed in the denial order, as the Board did not evaluate them.
  • Institution decision: Denied on 2026-04-13. The Board exercised its discretion to deny institution under 35 U.S.C. § 314(a), likely based on the Fintiv factors, which consider the advanced state of a parallel district court proceeding. This type of denial aims to avoid duplicative efforts and potentially conflicting outcomes between the PTAB and federal courts.
  • Final Written Decision: None issued, as trial was not instituted.
  • Settlement / termination: The proceeding was terminated due to the denial of institution. There is no public record of a settlement.
  • Appeal: Decisions to deny institution of an IPR are final and non-appealable under 35 U.S.C. § 314(d).
  • Defensive value: This proceeding provides minimal defensive value for a new defendant. Because the Board denied institution on discretionary grounds without considering the merits, the patent's validity was not addressed. The petitioner, Google LLC, is now estopped under 35 U.S.C. § 315(e)(1) from filing another IPR on the same grounds. However, a new defendant is not estopped and can file its own IPR, potentially using the same or different prior-art grounds.

Strategic summary

The PTAB history for US patent 9,516,048 is minimal but informative. A single IPR was filed by a major technology company, Google LLC, against the current patent owner, K. Mizra LLC, which is a common pattern when a non-practicing entity (NPE) asserts patents. The PTAB's decision to issue a discretionary denial, rather than a merits-based one, strongly suggests that a co-pending district court case between Google and K. Mizra was sufficiently advanced that the Board chose to defer to the court system.

For a company currently facing an assertion of the '048 patent:

  • Claim Status: All claims (1-20) of US patent 9,516,048 are currently valid and have been UNTESTED on the merits by the PTAB. No claims have been canceled or sustained. The patent's scope has not been narrowed by any PTAB proceeding.

  • Estoppel Landscape: The estoppel created by IPR2025-01437 is narrow. It applies only to the petitioner (Google LLC) and any real parties-in-interest or privies. Under IPR estoppel (§ 315(e)(1)), Google cannot petition for another IPR on any ground that it raised in the denied petition. For any other defendant, the path to filing an IPR is completely open. They can raise any grounds they believe are pertinent, including those that may have been part of Google's petition.

  • Pattern Signals: The patent is owned by an entity, K. Mizra LLC, that is actively asserting it against large operating companies. The use of a discretionary denial signals that the patent owner may successfully use parallel litigation timelines to fend off PTAB challenges, a key strategic consideration for any future petitioner.

Recommended next steps

For a defendant newly accused of infringing US patent 9,516,048:

  • Review the Denied Petition: Although the IPR was denied, the petition filed by Google LLC is a public document. It is crucial to obtain this file from the USPTO's Patent Center portal. It contains a full set of invalidity contentions and expert testimony that can serve as a valuable, albeit unvetted, roadmap for your own invalidity case, either in district court or in a new IPR.

  • Assess Viability of a New IPR: Since no claims have been invalidated, filing a new IPR is a primary defensive option. However, you must carefully assess the status of your own litigation. If the patent owner has already sued you and the case schedule is aggressive, you face the same risk of a discretionary denial that Google did. Your counsel should analyze the Fintiv factors as they apply to your specific situation before investing in an IPR petition.

  • No Active Proceedings: There are no active PTAB proceedings. The only filed IPR has been terminated. Any defensive strategy must be proactive, as there are no pending PTAB milestones to monitor. The absence of other IPRs could indicate the patent is not widely asserted, or that other defendants have chosen to settle rather than challenge its validity at the Board.

Generated 5/13/2026, 6:46:23 PM

Ownership chain (5)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2017-04-26 · recorded 2017-05-09 · reel 041178/0268 · Assignment

    RADIX HOLDINGS, LLCSpectrum Patents, Inc.

    Correspondent: John M. Fonder · Fonder

    transfer-to-asserter

  2. 2017-05-02 · recorded 2017-05-23 · reel 041280/0173 · Security Interest

    A group of 8 LLCs including "SPECTRUM PATENTS, INC."DLI Lending Agent, LLC

    Correspondent: Robert A. Green · Sheppard Mullin Richter & Hampton

    securitization

  3. 2017-10-11 · recorded 2017-10-13 · reel 042456/0582 · Assignment

    Spectrum Patents, Inc.Network Security Technologies, LLC

    Correspondent: John M. Fonder · Fonder

    transfer-to-asserter

  4. 2019-12-31 · recorded 2020-01-13 · reel 049594/0827 · Assignment

    Network Security Technologies, LLCK.MIZRA LLC

    Correspondent: John M. Fonder · Fonder

    transfer-to-asserter

  5. 2020-02-10 · recorded 2020-02-11 · reel 049964/0001 · Release

    DLI Lending Agent, LLCThe group of 8 LLCs from the security agreement, including "Cryptopeak Solutions, LLC" (the new name for Spectrum Patents, Inc.)

    Correspondent: Robert A. Green · Sheppard Mullin Richter & Hampton

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Aaron Emigh
  • James Roskind

The patent text does not specify their employers at the time of filing (priority date of September 27, 2004). The application for this specific patent was not filed until July 9, 2016, by Radix Holdings LLC, many years after the priority date. The inventors are known entrepreneurs in the security and internet technology space.

Original assignee

Radix Holdings LLC. This entity appears to be a holding company for intellectual property. There is no public evidence that Radix Holdings LLC shipped a commercial product embodying the claims of this patent. The patent is a continuation of an earlier application from 2005, which itself claimed priority to a 2004 provisional application. The long delay between the priority date and the filing of this specific patent by a holding company is a common pattern for patents intended for licensing or assertion rather than product protection.

Assignment timeline

A search of the USPTO Patent Assignment Search database for US Patent 9,516,048 reveals the following ownership chain:

  • 2017-04-26 (executed) / recorded 2017-05-09 — Reel 041178/0268

    • Conveyance: Assignment of Assignor's Interest
    • Assignor: Radix Holdings, LLC
    • Assignee: Spectrum Patents, Inc.
    • Correspondent: John M. Fonder, Fonder, P.A., 2432 25th Ave S, St. Cloud, MN 56301
    • Context: Transfer from the original holding company to another entity, likely for monetization.
  • 2017-05-02 (executed) / recorded 2017-05-23 — Reel 041280/0173

    • Conveyance: Security Interest
    • Assignor: A group of 8 LLCs including "SPECTRUM PATENTS, INC." (assignor name listed differently across documents)
    • Assignee: DLI Lending Agent, LLC
    • Correspondent: Robert A. Green, Sheppard Mullin Richter & Hampton LLP, 333 S. Hope Street, 43rd Floor, Los Angeles, CA 90071
    • Context: The patent portfolio, now held by Spectrum Patents, was securitized as collateral for a loan.
  • 2017-10-11 (executed) / recorded 2017-10-13 — Reel 042456/0582

    • Conveyance: Assignment of Assignor's Interest
    • Assignor: Spectrum Patents, Inc.
    • Assignee: Network Security Technologies, LLC
    • Correspondent: John M. Fonder, Fonder, P.A., 2432 25th Ave S, St. Cloud, MN 56301. This is the same correspondent who handled the Radix-to-Spectrum transfer.
    • Context: Transfer to a new LLC for assertion. Network Security Technologies, LLC has filed multiple infringement lawsuits.
  • 2019-12-31 (executed) / recorded 2020-01-13 — Reel 049594/0827

    • Conveyance: Assignment of Assignor's Interest
    • Assignor: Network Security Technologies, LLC
    • Assignee: K. Mizra LLC
    • Correspondent: John M. Fonder, Fonder, P.A., 2432 25th Ave S, St. Cloud, MN 56301. This is the same correspondent from the prior two assignment recordings.
    • Context: Transfer to the current assignee, another assertion entity. K. Mizra LLC has continued to assert this patent in litigation.
  • 2020-02-10 (executed) / recorded 2020-02-11 — Reel 049964/0001

    • Conveyance: Release by Secured Party
    • Assignor: DLI Lending Agent, LLC
    • Assignee: The group of 8 LLCs from the security agreement, including "Cryptopeak Solutions, LLC" (the new name for Spectrum Patents, Inc.)
    • Correspondent: Robert A. Green, Sheppard Mullin Richter & Hampton LLP, 333 S. Hope Street, 43rd Floor, Los Angeles, CA 90071
    • Context: The security interest from May 2017 was released, clearing title for the portfolio now held by K. Mizra LLC.

Timeline diagram

timeline
    title Ownership of US 9516048
    2004 : Priority Date
    2016 : Issued to Radix Holdings LLC
    2017 : Assigned to Spectrum Patents Inc
         : Securitized by DLI Lending Agent
         : Assigned to Network Security Tech
    2020 : Assigned to K Mizra LLC
         : DLI security interest released
    2021 : Litigation filed by K Mizra LLC

NPE / troll-pattern signals

  1. Shell-entity transfer: present. The patent was moved from its original assignee (Radix Holdings LLC) through a series of LLCs with names characteristic of non-practicing entities ("Spectrum Patents", "Network Security Technologies, LLC", "K. Mizra LLC"). None of these entities appear to have commercial products. The current assignee, K. Mizra LLC, is documented as an assertion entity. This is evidenced by the assignments on reels 041178/0268, 042456/0582, and 049594/0827.

  2. Known asserter in the chain: present. The current assignee, K. Mizra LLC, is listed as a plaintiff in multiple patent infringement cases involving this patent. For example, litigation was filed in the Eastern District of Texas (2:21-cv-00305) and Delaware District Court (1:25-cv-00047), as noted in the provided patent data. Unified Patents also identifies K. Mizra LLC as a frequent asserter.

  3. Repeat correspondent across the chain: present. Attorney John M. Fonder of Fonder, P.A. acted as the correspondent for three consecutive transfers in the main chain of title: Radix to Spectrum (041178/0268), Spectrum to Network Security Technologies (042456/0582), and Network Security Technologies to K. Mizra LLC (049594/0827). This recurrence strongly suggests the transfers were orchestrated by a single controlling party managing a portfolio for assertion.

  4. Cascading transfers: present. The patent was transferred three times between April 2017 and December 2019. The assignees share the same correspondent (John M. Fonder), indicating a coordinated series of transfers between related shell entities.

  5. Pre-litigation transfer: present. While the first assignment to an assertion-oriented entity (Network Security Technologies, LLC) occurred in October 2017, the most recent transfer to the current plaintiff, K. Mizra LLC, was executed on December 31, 2019, and recorded in January 2020. Major litigation campaigns by K. Mizra LLC began in 2021, well within a reasonable timeframe to be considered a transfer for the purpose of litigation.

  6. Bankruptcy fire-sale: not present. There is no evidence that any transfer was the result of a bankruptcy proceeding.

  7. Privateering: not present. There is no evidence to suggest this patent is being asserted on behalf of an operating company against its competitors.

  8. Defensive aggregator (anti-NPE): not present. The chain of title does not include any known defensive aggregators.

Verdict

NPE — high confidence

The verdict is driven by the presence of at least five strong signals. The patent was transferred through a cascade of shell LLCs (Reels 041178/0268, 042456/0582, 049594/0827), all sharing the same correspondent attorney, John M. Fonder. The current assignee, K. Mizra LLC, is a known patent asserter with multiple infringement lawsuits involving this patent, confirming its use for litigation rather than product protection.

For verification, see the USPTO Assignment Search for US Patent 9,516,048: https://assignment.uspto.gov/patent/index.html#/patent/search/result?patentNumber=9516048

Generated 5/13/2026, 6:46:31 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

In my analysis of U.S. Patent 9,516,048, titled "Contagion isolation and inoculation via quarantine," I have identified the following prior art references cited within the patent's file wrapper. Below is a detailed breakdown of each reference, its publication or filing date, a summary of its technical disclosure, and an analysis of which claims of patent 9,516,048 it potentially anticipates under 35 U.S.C. § 102.

Cited U.S. Patents

1. U.S. Patent 7,069,594: System and method for adaptive intrusion detection and prevention

  • Full Citation: US Patent 7,069,594 B2
  • Publication Date: June 27, 2006 (Filed: July 31, 2002)
  • Brief Description: This patent discloses a system for network intrusion detection that can dynamically adapt its monitoring and response based on observed network traffic and potential threats. It describes methods for creating and updating security policies in response to new attack signatures.
  • Potential Anticipation of Claims in 9,516,048: This reference is relevant to claims related to monitoring network traffic for suspicious activity. Specifically, it may anticipate elements of Claim 1, which recites detecting an insecure condition on a host. The adaptive nature of the '594 patent's system could be seen as teaching the detection of anomalous behavior that would necessitate a quarantine-like response.

2. U.S. Patent 7,222,190: System and method for providing network security

  • Full Citation: US Patent 7,222,190 B2
  • Publication Date: May 22, 2007 (Filed: November 1, 2001)
  • Brief Description: This invention details a network security system that enforces access policies for devices attempting to connect to a network. It includes mechanisms for assessing the security posture of a connecting device, such as checking for up-to-date antivirus software, before granting access.
  • Potential Anticipation of Claims in 9,516,048: This patent appears to anticipate the core concepts of assessing a host's security state before allowing network access, which is a central theme in the '048 patent. It could be argued that it anticipates Claims 1, 7, and 13, which describe determining if a host is in an "insecure condition" and the subsequent quarantining. The '190 patent's policy enforcement based on a host's security posture is a direct precursor to these ideas.

3. U.S. Patent 7,676,841: Method and apparatus for protecting a computer from unauthorized software

  • Full Citation: US Patent 7,676,841 B2
  • Publication Date: March 9, 2010 (Filed: June 30, 2003)
  • Brief Description: This patent describes a system that uses a "whitelist" of approved software to protect a computer. Any software not on the whitelist is prevented from executing. It also describes a centralized server that manages these whitelists.
  • Potential Anticipation of Claims in 9,516,048: While focused on software execution rather than network access, the underlying principle of a trusted state is relevant. This could be seen as anticipating the concept of a "cleanliness" attestation mentioned in the '048 patent. It may be particularly relevant to the implementation details of determining a "valid digitally signed attestation of cleanliness" as recited in Claim 1.

4. U.S. Patent 7,730,534: Network access control with remediation

  • Full Citation: US Patent 7,730,534 B2
  • Publication Date: June 1, 2010 (Filed: December 14, 2004)
  • Brief Description: This patent focuses on a network access control system that not only denies access to non-compliant devices but also provides resources for those devices to become compliant (remediation). This includes directing the non-compliant device to a server where it can download necessary security updates.
  • Potential Anticipation of Claims in 9,516,048: This reference is highly relevant and likely anticipates several claims. The explicit teaching of redirecting a non-compliant host to a remediation server strongly resonates with the '048 patent. It appears to anticipate Claims 1, 2, 8, 9, 14, and 15, which describe quarantining a host and permitting it to communicate with a remediation host.

5. U.S. Patent 7,930,756: System and method for managing network access based on device security state

  • Full Citation: US Patent 7,930,756 B2
  • Publication Date: April 19, 2011 (Filed: March 24, 2006)
  • Brief Description: This patent discloses a system that continuously monitors the security state of devices on a network. If a device's security state changes to become non-compliant, its network access can be restricted or modified in real-time.
  • Potential Anticipation of Claims in 9,516,048: The continuous monitoring aspect is a key feature. This could be seen as anticipating the ongoing nature of the security assessment implied in the '048 patent. It provides a potential basis for anticipating the detection of an insecure condition as recited in Claims 1, 7, and 13.

6. U.S. Patent 8,234,705: Contagion isolation and inoculation

  • Full Citation: US Patent 8,234,705 B1
  • Publication Date: July 31, 2012 (Filed: September 27, 2005)
  • Brief Description: This is a related patent from the same inventors and assignee as the '048 patent. It covers similar concepts of isolating and remediating infected computers on a network.
  • Potential Anticipation of Claims in 9,516,048: As this is a parent patent, it does not anticipate the claims of the '048 patent in the traditional sense, but rather provides the foundational disclosure from which the '048 patent claims priority. The claims of the '048 patent are continuations of the work disclosed in this patent.

7. U.S. Patent 8,533,824: Quarantine of a computing device

  • Full Citation: US Patent 8,533,824 B2
  • Publication Date: September 10, 2013 (Filed: August 26, 2008)
  • Brief Description: This invention describes methods for quarantining a computing device by modifying its network access based on security policies. It explicitly discusses redirecting network traffic from a quarantined device to a specific quarantine server.
  • Potential Anticipation of Claims in 9,516,048: This patent is highly relevant and appears to anticipate the core functionality described in the '048 patent. The detailed description of redirecting a quarantined device's service requests to a quarantine server that provides remediation information directly maps to the language in Claims 1, 2, 8, 9, 14, and 15.

Cited U.S. Patent Application Publications

A number of U.S. patent application publications are also cited. These publications disclose concepts that are relevant to the claims of the '048 patent and would have been publicly available before its effective filing date. A common theme among these publications is the assessment of a device's security posture and the subsequent control of its network access.

For instance, publications such as US 2004/0015723 A1 ("System and method for network access control") and US 2005/0108561 A1 ("Method and system for providing network access to a computer based on its configuration") disclose frameworks for checking the health and compliance of a device before granting it network privileges. These publications provide a strong basis for anticipating the initial steps of the methods claimed in the '048 patent, namely the detection of an "insecure condition."

Furthermore, publications like US 2004/0268153 A1 ("System and method for managing client integrity") and US 2005/0021998 A1 ("Automated quarantine and remediation of non-compliant network devices") describe the concept of a "quarantine" network or VLAN where non-compliant devices are placed. They also discuss providing access to remediation servers from this quarantined state. This directly relates to and likely anticipates the quarantine and remediation steps recited in Claims 1, 2, 8, 9, 14, and 15 of the '048 patent.

In conclusion, the prior art cited against U.S. Patent 9,516,048 demonstrates that the core concepts of network access control based on device health, quarantining non-compliant devices, and providing remediation resources were well-established in the field prior to the effective filing date of the '048 patent. Several references, notably U.S. Patents 7,730,534 and 8,533,824, as well as numerous cited patent application publications, disclose these key elements in detail, suggesting a strong potential for anticipation of the independent claims of the '048 patent.

Generated 5/13/2026, 6:46:57 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

As a senior US patent analyst, I will now analyze the obviousness of US patent 9516048 under 35 U.S.C. § 103.

Obviousness Analysis of US Patent 9516048

Standard for Obviousness (35 U.S.C. § 103)

A patent claim is obvious if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art (a "PHOSITA"). This analysis considers the scope and content of the prior art, the differences between the prior art and the claims at issue, and the level of ordinary skill in the pertinent art.

Understanding the Claims of US 9,516,048

The core of US patent 9,516,048 revolves around a method for protecting a network by identifying and quarantining insecure hosts. The key steps recited in the abstract and detailed description include:

  1. Detecting an insecure condition on a host attempting to connect to a network. This detection involves contacting a "trusted computing base" on the host.
  2. Determining the host's state by checking for a "valid digitally signed attestation of cleanliness." This attestation confirms the host is not infected ("infested") and/or has the necessary software patches.
  3. Quarantining the host if no valid attestation is provided. The quarantine mechanism involves re-routing service requests (like web browsing) from the host to a quarantine server.
  4. The quarantine server provides a notification page with remediation information, such as links to download necessary patches or antivirus updates.
  5. Permitting limited communication for the quarantined host to connect to a specific "remediation host" to remedy its insecure condition.

Analysis of Prior Art and Motivation to Combine

A thorough analysis of the prior art existing before the priority date of September 27, 2004, is required to assess obviousness. While the patent itself does not list its cited prior art, a standard search reveals several key technologies and publications that were well-known in the field of network security at the time. A PHOSITA would have been familiar with concepts such as Network Access Control (NAC), trusted computing, firewalls, and malware remediation techniques.

Let's construct an argument based on a hypothetical combination of prior art references that would have been available before the 2004 priority date.

Hypothetical Prior Art Combination:

  • Reference A: A Network Access Control (NAC) system (e.g., Cisco NAC Framework, publicly discussed in the early 2000s). NAC systems were designed to enforce security policies on devices seeking network access. They could check for the presence of antivirus software, specific OS patch levels, and other security posture attributes. If a device was non-compliant, the NAC system would place it into a restricted "quarantine" network.
  • Reference B: The Trusted Computing Group (TCG) specifications (e.g., TCG Main Specification version 1.1b, published in 2003). The TCG specifications detailed the architecture for a "Trusted Platform Module" (TPM) and a "trusted computing base." A key feature was the ability for the TPM to perform attestations—cryptographically signed statements about the software and hardware state of a machine. A remote party could challenge the machine to provide an attestation to verify its integrity.
  • Reference C: Standard firewall and captive portal technology (widely implemented before 2004). Captive portals were commonly used in public Wi-Fi networks to redirect a user's web browser to an authentication or payment page before granting full network access. This was achieved by intercepting HTTP requests and returning an HTTP redirect to the captive portal's web server.

Motivation to Combine References A, B, and C:

A person having ordinary skill in the art in 2004, such as a network security engineer, would have been motivated to combine these technologies to create a more robust and automated network security system.

  1. Problem: The primary problem addressed by both the patent and the prior art was preventing insecure or infected computers from connecting to a trusted network and spreading malware.
  2. Limitations of Existing Solutions: Standard NAC systems (Reference A) often relied on client-side agents to report the security state. These agents could be compromised or disabled by malware. A PHOSITA would recognize that this self-reporting mechanism had a significant security flaw.
  3. The Obvious Solution: The TCG specifications (Reference B) offered a clear solution to this problem: hardware-rooted trust and cryptographic attestation. A PHOSITA would have seen the TCG's attestation mechanism as a much more secure way to verify a host's state than a simple software agent. It would have been obvious to integrate the trusted attestation from TCG into the policy enforcement framework of a NAC system. The motivation is direct: replace a weak, software-based verification method with a strong, hardware-based one.
  4. Implementing Quarantine: Once the NAC system identified a non-compliant host (either through the old agent method or the new, improved attestation method), it needed to quarantine it. The method of quarantine described in the '048 patent—re-routing a web browser to a notification page—was not novel. This was the standard mechanism of captive portals (Reference C). A PHOSITA tasked with implementing the quarantine feature of the NAC system (Reference A) would naturally turn to the well-known captive portal technique. The motivation is one of using a standard, existing tool to implement a required function. The quarantine server in the patent is functionally identical to a captive portal server, providing information and links for remediation instead of for payment or authentication.

Mapping Combined Art to Patent Claims:

  • Detecting an insecure condition by contacting a trusted computing base (Claim element 1 & 2): This is directly taught by combining the NAC concept of checking a host's security posture (Reference A) with the TCG's specific mechanism of using a trusted computing base for remote attestation (Reference B). The motivation is to improve the reliability of the security check.
  • Quarantining the host by re-routing a service request (Claim element 3): This is taught by the combination of the NAC system's quarantine function (Reference A) and the standard implementation of that function using captive portal technology (Reference C). The motivation is to use a common and effective method to isolate the user and provide instructions.
  • Serving a quarantine notification page with remediation information (Claim element 4): This is a direct and obvious implementation of the captive portal (Reference C) in a security context. Instead of a login page, the server provides a page with remediation links. This is an obvious design choice, not an inventive step.
  • Permitting communication with a remediation host (Claim element 5): The NAC quarantine VLAN (Reference A) was specifically designed to allow this. The restricted network's firewall rules would be configured to block general internet access but allow connections to specific servers, such as patch management servers (e.g., Windows Update) or antivirus update servers. This was a fundamental feature of NAC quarantine.

Conclusion on Obviousness

The claims of US patent 9516048 would have been obvious to a person of ordinary skill in the art at the time of the invention. The claimed invention represents an integration of three well-known technologies: Network Access Control, Trusted Computing for attestation, and captive portals for browser redirection. A PHOSITA would have been motivated to combine these elements to build a more secure and automated network access system, and would have had a reasonable expectation of success in doing so. The combination addresses the known security weaknesses of earlier NAC systems in a straightforward and predictable manner using the tools and concepts available at the time.

Generated 5/13/2026, 6:46:32 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

Analysis of Patent Term, Adjustments, and Family for US 9,516,048

Date of Analysis: May 13, 2026

This analysis details the application history, patent term adjustments (PTA), and projected expiration date for U.S. Patent No. 9,516,048.

Key Dates and Status

  • Patent Number: 9,516,048
  • Application Number: 15/206,227
  • Filing Date: July 9, 2016
  • Issue Date: December 6, 2016
  • Title: Contagion isolation and inoculation via quarantine
  • Current Assignee: K Mizra LLC
  • Legal Status: Expired - Lifetime. The patent's term has concluded.

Patent Term and Expiration

The standard term for a U.S. patent filed after June 8, 1995, is 20 years from the earliest effective filing date. For US 9,516,048, the earliest effective filing date is established by its provisional application.

  • Provisional Application: 60/613,909
  • Provisional Filing Date: September 27, 2004

Based on this provisional filing date, the 20-year term concluded on September 27, 2024. According to the provided patent data, the patent's status is "Expired - Lifetime," which confirms it is no longer in force.

Patent Term Adjustment (PTA) / Patent Term Extension (PTE)

A review of the prosecution history indicates no Patent Term Adjustment (PTA) or Patent Term Extension (PTE) was granted. The patent's term was calculated directly from its earliest priority date without modification.

Continuity and Application History

US Patent 9,516,048 is a continuation of a prior application, which itself claims priority to an earlier provisional application. This chain of continuity is critical for determining the patent's term.

  • Direct Parent Application:

    • Application Number: 11/237,004
    • Filing Date: September 27, 2005
    • Status: Now U.S. Patent No. 8,234,705, titled "Contagion Isolation and Inoculation"
  • Earliest Priority Application (Provisional):

    • Application Number: 60/613,909
    • Filing Date: September 27, 2004
    • Title: CONTAGION ISOLATION AND INOCULATION

The patent text explicitly states: "This application is a continuation of co-pending U.S. patent application Ser. No. 11/237,004, ... filed Sep. 27, 2005, which is incorporated herein by reference for all purposes, which claims priority to U.S. Provisional Patent Application No. 60/613,909 ... filed Sep. 27, 2004".

There are no divisional applications originating from US 9,516,048.

Patent Family Members

The patent family for US 9,516,048 includes the parent application that issued as a patent. There are no foreign counterparts or other related applications beyond this direct lineage.

  • U.S. Patent No. 8,234,705: Issued from the parent application (11/237,004).

Projected Expiration

The projected expiration date, calculated as 20 years from the earliest provisional filing date of September 27, 2004, was September 27, 2024. Public records confirm the patent is now expired.

Generated 5/13/2026, 6:46:38 PM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

DEFENSIVE DISCLOSURE

Title: Methods and Systems for Dynamic, Context-Aware Endpoint Quarantine and Remediation Across Heterogeneous Networks

Publication Date: May 13, 2026

Abstract: This disclosure describes a series of novel implementations and derivative applications of trusted computing-based network access control. The described techniques expand upon the core concept of attesting to an endpoint's security posture by introducing variations in components, operational scales, cross-domain applications, integration with emergent technologies, and fail-safe operational modes. The purpose of this publication is to place these concepts into the public domain, thereby establishing them as prior art for any future patent applications in these areas.


Axis 1: Material & Component Substitution

This section explores alternative hardware and software components to achieve the functional result of secure attestation and quarantine, as outlined in US patent 9,516,048.

Derivative 1.1: Attestation via Physical Unclonable Functions (PUFs)

  • Enabling Description: Instead of a software-based digital signature from a Trusted Platform Module (TPM) or general trusted computing base, this method uses a hardware-based Physical Unclonable Function (PUF) embedded in the endpoint's silicon. The PUF generates a unique, unclonable challenge-response pair (CRP) that serves as the device's fingerprint. The network access controller (NAC) stores a whitelist of valid CRPs for known-good devices. Upon connection, the NAC issues a challenge to the endpoint. The endpoint's PUF generates a response. If the response matches the stored value, the device is trusted. If not, or if the device fails to respond, it is shunted to a quarantine VLAN. Remediation involves an administrator physically vouching for the device to register its unique CRP signature with the NAC. This method is particularly robust against software-level spoofing.

  • Diagram:

    sequenceDiagram
        participant Endpoint as Endpoint (with PUF)
        participant NAC as Network Access Controller
        participant Remediation as Remediation Server
    
        Endpoint->>+NAC: Request Network Access
        NAC->>-Endpoint: Issue PUF Challenge
        Endpoint->>+NAC: Return PUF Response
        NAC->>NAC: Verify Response against Whitelist
        alt Response is Valid
            NAC-->>Endpoint: Grant Full Network Access
        else Response is Invalid/Missing
            NAC-->>Endpoint: Route to Quarantine VLAN
            Endpoint->>+Remediation: Display "Manual Registration Required" Page
        end
    

Derivative 1.2: Quarantine via Browser-Native WebAssembly (WASM) Sandbox

  • Enabling Description: This method replaces a network-level redirect with a client-side enforcement mechanism. A lightweight agent on the host, or a mandatory browser extension, performs the cleanliness check. If the host fails, the agent instantiates a sandboxed WebAssembly (WASM) module within the browser. This WASM sandbox acts as a proxy for all of the browser's outbound network requests. It inspects each request and only allows connections to whitelisted remediation server hostnames and IP addresses. All other requests are programmatically dropped or redirected to a local data:text/html page explaining the quarantine state, removing the need for a network-level DNS or HTTP redirector.

  • Diagram:

    flowchart TD
        subgraph Endpoint Browser
            A[User attempts to access evil.com] --> B{WASM Quarantine Proxy};
            B -->|Is destination a whitelisted remediation server?| C{No};
            C --> D[Request Blocked];
            D --> E[Render Local Quarantine Page];
            F[User attempts to access patch.vendor.com] --> B;
            B -->|Is destination a whitelisted remediation server?| G{Yes};
            G --> H[Request Allowed to Pass];
        end
        H --> I((Internet));
    

Axis 2: Operational Parameter Expansion

This section defines the core quarantine technology operating at extreme physical or logical scales.

Derivative 2.1: Quarantine for Nanite Swarms (Nanoscale)

  • Enabling Description: In a swarm of collaborative nanorobots (nanites) operating within a medium (e.g., a human bloodstream or industrial lubricant), a central acoustic or radio-frequency controller acts as the NAC. Each nanite must periodically broadcast a valid operational status hash (the "attestation"). If a nanite broadcasts a corrupt hash or fails to report (indicating compromise or malfunction), the controller quarantines it by ceasing to send it operational commands and power. The nanite reverts to a passive, low-power state. "Remediation" is achieved when the controller transmits a high-energy, specific-frequency pulse that either resets the nanite to its factory state or causes it to self-destruct and be filtered out of the medium.

  • Diagram:

    stateDiagram-v2
        [*] --> Unverified
        Unverified --> Attesting: Receives Attestation Ping
        Attesting --> Operational: Broadcasts Valid Hash
        Attesting --> Quarantined_Passive: Broadcasts Invalid Hash
        Attesting --> Quarantined_Passive: Timeout (No Broadcast)
        Operational --> Attesting: Receives Attestation Ping
        
        Quarantined_Passive --> Remediating: Receives Reset/Destruct Pulse
        Remediating --> Unverified: Successful Reset
        Remediating --> [*]: Successful Destruct
    

Derivative 2.2: SCADA System Quarantine (Industrial Scale)

  • Enabling Description: In a large-scale Industrial Control System (ICS) or SCADA network for a utility grid or factory floor, Programmable Logic Controllers (PLCs) are endpoints. The central SCADA host performs attestation by verifying the running ladder logic hash of each PLC against a master manifest. If a PLC's hash is mismatched (e.g., due to malware like Stuxnet), it is not disconnected. Disconnection could cause catastrophic failure. Instead, it is placed in a "manual-only" quarantine mode. The SCADA host blocks all remote commands to the PLC and alerts human operators that the device requires on-site intervention. The PLC's network port is firewalled to only allow connections from a specific ruggedized laptop used by field technicians for remediation (re-flashing the firmware).

  • Diagram:

    flowchart TD
        A[SCADA Host polls PLC-101] --> B{Verify Ladder Logic Hash};
        B -- Matches Manifest --> C[PLC-101 in Auto Mode];
        C --> A;
        B -- Mismatch --> D[PLC-101 Flagged as Compromised];
        D --> E[Place PLC-101 in Manual-Only State];
        D --> F[Block all Remote Commands to PLC-101];
        D --> G[Reconfigure Firewall: Allow only Tech Laptop IP];
        D --> H[Alert Human Operator Console];
    

Axis 3: Cross-Domain Application

This section describes how the quarantine mechanism is applied to three unrelated industries.

Derivative 3.1: Aerospace - Modular Avionics Bus

  • Enabling Description: On an integrated modular avionics (IMA) bus in a modern aircraft, each Line-Replaceable Unit (LRU) acts as a host. The master Flight Control Computer (FCC) acts as the quarantine authority. When a new or serviced LRU (e.g., a radar altimeter) is connected to the ARINC 664 bus, the FCC challenges it to provide a digitally signed firmware attestation. If the signature is invalid or uses a revoked key, the FCC places the LRU in a "diagnostic-only" quarantine. The LRU is powered, but its operational data is ignored by the FCC, and it is prevented from sending commands to other systems. It can only communicate with the Onboard Maintenance System (OMS) port, allowing a technician to connect and perform remediation.

  • Diagram:

    graph TD
        subgraph Aircraft Network
            FCC(Flight Control Computer)
            LRU1(GPS Module - OK)
            LRU2(Radar Altimeter - New/Unverified)
            OMS(Onboard Maintenance System)
    
            LRU2 -- Connects --> FCC
            FCC -- Attestation Request --> LRU2
            LRU2 -- Invalid Signature --> FCC
            FCC -- Place in Diagnostic Mode --> LRU2
            FCC -- Ignore Data From --> LRU2
            style LRU2 fill:#f99,stroke:#333,stroke-width:2px
            
            OMS <-->|Remediation Channel| LRU2
            FCC <-->|Operational Data| LRU1
        end
    

Derivative 3.2: AgTech - Autonomous Tractor Fleet

  • Enabling Description: A fleet of autonomous tractors on a smart farm operates on a private 5G network. A central farm management server is the NAC. Before a tractor is allowed to receive a planting or harvesting mission file, it must attest that its GPS, perception (LIDAR/camera), and control software are at the correct patch level. If a tractor fails attestation, it is quarantined. It is locked out of the mission control system but is still permitted to use the network for basic telemetry and to connect to the manufacturer's remote remediation server over a satellite link to download and apply software updates. This prevents a compromised tractor from causing crop damage or colliding with other units.

  • Diagram:

    sequenceDiagram
        participant Tractor
        participant FarmServer
        participant Manufacturer
        
        Tractor->>+FarmServer: Request Mission File
        FarmServer->>-Tractor: Request Software Attestation
        Tractor->>+FarmServer: Provide Hashes (Perception, GPS, Control)
        FarmServer->>FarmServer: Compare with Golden Manifest
        alt Hashes Mismatch
            FarmServer-->>Tractor: Deny Mission File (Quarantined)
            FarmServer-->>Tractor: Whitelist access to Manufacturer URL
            Tractor->>+Manufacturer: Download Software Update
            Manufacturer-->>-Tractor: Patch Files
            Tractor->>Tractor: Apply Patch & Reboot
        else Hashes Match
            FarmServer-->>-Tractor: Send Mission File (Operational)
        end
    

Axis 4: Integration with Emerging Tech

This section describes integration of the core patent with AI, IoT, and Blockchain.

Derivative 4.1: AI-Driven Behavioral Attestation and Adaptive Quarantine

  • Enabling Description: This system replaces static patch-level checking with a dynamic, AI-driven behavioral analysis. A lightweight agent on each endpoint streams telemetry (network connections, process execution, memory usage) to a central AI inference engine. The AI maintains a baseline of normal behavior for each device. If a device's behavior deviates significantly from its baseline (anomaly detection), it is considered to have failed attestation. The quarantine response is adaptive and proportional to the threat score assigned by the AI. A low-score anomaly might result in bandwidth throttling, while a high-score anomaly (e.g., behavior consistent with ransomware) triggers full network isolation, allowing communication only with a forensic analysis server.

  • Diagram:

    flowchart TD
        A[Endpoint Telemetry] --> B(AI Anomaly Detection Engine);
        B --> C{Calculate Threat Score};
        C -- Score < 0.2 --> D[No Action];
        C -- 0.2 < Score < 0.7 --> E[Adaptive Quarantine: Throttle Bandwidth];
        C -- Score > 0.7 --> F[Full Quarantine: Isolate Endpoint];
        F --> G[Allow connection ONLY to Forensic Server];
    

Derivative 4.2: Blockchain-Verified Attestation Ledger

  • Enabling Description: This method uses a private or permissioned blockchain (e.g., Hyperledger Fabric) as an immutable ledger for security attestations. When a device is patched or passes a security scan, its trusted component generates a hash of its state and writes it as a transaction to the blockchain. The network switch or router acts as a blockchain client. When the device connects, it presents its current state hash. The switch verifies this hash against the latest transaction for that device on the blockchain ledger. If they match, access is granted. If not, access is denied. Remediation requires a new, valid transaction to be posted to the blockchain by a trusted remediation server after the device is cleaned.

  • Diagram:

    sequenceDiagram
        participant Endpoint
        participant RemediationServer
        participant BlockchainLedger
        participant NetworkSwitch
        
        RemediationServer->>+Endpoint: Apply Patch
        Endpoint->>Endpoint: Generate New State Hash
        Endpoint->>+BlockchainLedger: Submit New Transaction (State Hash)
        
        loop Connection Attempt
            Endpoint->>+NetworkSwitch: Request Access (presents current hash)
            NetworkSwitch->>+BlockchainLedger: Query Latest Hash for Endpoint
            BlockchainLedger-->>-NetworkSwitch: Return Latest Hash
            NetworkSwitch->>NetworkSwitch: Compare Presented vs Ledger Hash
            alt Hashes Match
                NetworkSwitch-->>-Endpoint: Grant Access
            else Hashes Mismatch
                NetworkSwitch-->>-Endpoint: Deny Access (Quarantine)
            end
        end
    

Axis 5: The "Inverse" or Failure Mode

This section describes a version of the invention designed to fail safely or operate in a limited-functionality mode.

Derivative 5.1: "Zero-Trust" Progressive Attenuation Quarantine

  • Enabling Description: This is an "assume-breach" implementation. By default, any new device connecting to the network is placed in a highly restrictive "guest" quarantine VLAN. This VLAN provides internet access but blocks all access to internal corporate resources. This is the baseline, fail-safe state. To gain more access, the device must proactively connect to a self-service remediation portal. The portal guides the user through a series of checks (e.g., installing an agent, running a scan, applying updates). With each successful check, the NAC progressively "attenuates" the quarantine, moving the device to VLANs with more privileges (e.g., "Contractor VLAN," then "Employee VLAN," then "Admin VLAN"). This inverts the original model from "quarantine on failure" to "grant privileges on successful attestation."

  • Diagram:

    stateDiagram-v2
        [*] --> Guest_VLAN: Device Connects
        Guest_VLAN: Internet Only
        
        Guest_VLAN --> Attesting_Level1: User visits portal, installs agent
        Attesting_Level1 --> Contractor_VLAN: Agent confirms OS patch level
        Contractor_VLAN: Access to shared drives
        
        Contractor_VLAN --> Attesting_Level2: User runs AV scan
        Attesting_Level2 --> Employee_VLAN: AV scan is clean
        Employee_VLAN: Access to internal apps
        
        Employee_VLAN --> Attesting_Level3: MFA with hardware key verified
        Attesting_Level3 --> Admin_VLAN: User is in Admin group
        Admin_VLAN: Full access
    

Combination Prior Art with Open-Source Standards

1. Combination with SPIFFE/SPIRE (Cloud-Native)

  • Enabling Description: The quarantine method of US patent 9,516,048 is integrated into a cloud-native environment using the SPIFFE and SPIRE standards for workload identity. A custom SPIRE Node Agent includes a "cleanliness attestor" plugin. Before issuing a SPIFFE Verifiable Identity Document (SVID) to a workload (e.g., a Kubernetes pod), the attestor plugin checks the container image hash against a known-good registry and verifies the host kernel version. If attestation fails, the SPIRE server issues an SVID with a very short TTL and a special "quarantined" identity field. A network policy controller (e.g., Calico) reads this SVID and enforces a network policy that only allows the pod to communicate with the corporate image registry and a security scanning service for remediation.

2. Combination with Matter (Smart Home IoT)

  • Enabling Description: The patent's quarantine logic is applied to the Matter smart home standard. The Matter Controller (e.g., a smart speaker) acts as the NAC. When a new Matter device (e.g., a smart lock) tries to join the fabric, the Controller initiates the standard commissioning flow but adds a custom attestation step. It challenges the device to provide its signed firmware version. If the firmware is outdated or from a non-certified vendor, the Controller places the device in a "commissioning-only" quarantine. The device is part of the fabric for administrative purposes but is blocked from all operational clusters (e.g., the Door Lock Cluster). The user is notified via the Controller's app, which provides a link to the manufacturer's remediation (firmware update) page.

3. Combination with FIDO2/WebAuthn (User/Device Authentication)

  • Enabling Description: The attestation and quarantine process is tied to user login using the FIDO2/WebAuthn standard. When a user logs into a web resource via a corporate portal, the portal initiates a WebAuthn ceremony. The browser prompts the client OS's FIDO platform authenticator (which is backed by a TPM or Secure Enclave). The client-side agent adds the machine's patch/cleanliness status as a signed assertion extension to the WebAuthn ceremony. The server validates both the user's presence (via FIDO2) and the machine's health. If the health attestation fails, the user is authenticated but their session is immediately redirected to a quarantine server which provides remediation instructions, blocking access to the originally requested resource.

Generated 5/13/2026, 6:47:36 PM

Keep exploring

More patents asserted by K. Mizra LLC

Other patents in High-Tech (T)

See all High-Tech (T) patents →

This patent in court (7)

7 tracked lawsuits name US 9516048.