Invalidity dossier

US 9565213

Current assignee: Centripetal Networks, Inc.

Added 8/29/2026, 6:50:01 PM

At a glanceNo PTAB challenges5 lawsuits on fileasserted by Centripetal Networks, Inc.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search the USPTO database and CAFC dockets for this specific patent number.

I have solid data on the patent itself. Now let me find the actual claim text and check for CAFC 2026 docket entries specific to this patent.

US Patent 9,565,213 — Verified Summary

Bibliographic Data (confirmed from the USPTO-issued patent PDF and Google Patents)

Field Value
Patent number US 9,565,213 B2 (Appl. No. 14/253,992)
Title Methods and Systems for Protecting a Secured Network
Inventors Steven Rogers (Leesburg, VA); Sean Moore (Hollis, NH); David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH)
Applicant / Assignee Centripetal Networks, Inc., Reston, VA (now Centripetal Networks, LLC; name change recorded 2023-01-20)
Filing date April 16, 2014
Issue date February 7, 2017
Earliest priority date October 22, 2012 (continuation of US 13/657,010, which issued as US 9,137,205 B2)
Claims / drawings 16 claims, 13 drawing sheets; subject to a terminal disclaimer
Examiner / firm Primary Examiner Harunur Rashid; Banner & Witcoff, Ltd.
Anticipated expiration April 16, 2034 (per Google Patents)

Sources: Google Patents US9565213B2; USPTO patent PDF; DocketAlarm — file history (Cisco Ex. 1002, IPR2018-01512).

Abstract (verbatim)

"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets."

Independent Claims — Plain-Language Overview

The patent has 16 claims. Based on the specification, the published application (US20150304354A1), the priority application's structure, and the IPR records, the independent claims are claim 1 (method), and — in parallel form — claim 11 (system) and claim 16 (computer-readable media). My confidence is high for claim 1 (its text matches the abstract/summary exactly) and moderate for claims 11 and 16 (I could not verify the exact issued text of those two from an authoritative source in this search, so treat their wording as inferred from the family).

Claim 1 — Method (high confidence): A method performed at each of one or more packet security gateways that are associated with a security policy management server. Each gateway (a) receives a dynamic security policy from the management server, (b) receives packets associated with the network the gateway protects, and (c) performs — on a packet-by-packet basis — at least one of multiple packet transformation functions specified by that policy, where at least one performed transformation function is something other than simply forwarding or dropping the packets (e.g., rerouting, encapsulating, queueing, or logging).

Plain language: A centrally managed security gateway applies centrally pushed, changeable policies to traffic at network boundaries, and the policy must include at least one action beyond a simple allow/deny decision.

Claim 11 — System (moderate confidence, inferred): A system comprising one or more packet security gateways (and associated hardware/processors) configured to carry out the claim 1 method — i.e., receive the dynamic security policy from the management server, receive packets of the protected network, and perform the non-forward/drop packet transformation functions on a packet-by-packet basis.

Claim 16 — Computer-readable media (moderate confidence, inferred): One or more non-transitory computer-readable media storing instructions that, when executed, cause a computing system (the packet security gateway) to perform the same claim 1 method steps.

Representative dependent claims (for context, claims 2–15): series-configured gateways (2); allowlist/blocklist rules (4–5); tiered "phased restoration" policies (6–7); differentiated forwarding queues (8); routing matching packets (e.g., by SIP URI) to an alternate address such as a monitoring device (9); forwarding into/out of the protected network, to an IPsec stack, or dropping (11); five-tuple rule matching (12); DSCP-based rules (13); network-layer-transparent operation (14); and rules built from a malicious-host subscription feed (15). (Numbering as published; dependent-claim-to-independent-claim mapping may shift slightly if claims 11/16 are the system/media counterparts.)


CAFC 2026 Docket Status — What I Could Verify (and what I could not)

I did not find a 2026 CAFC disposition that is confirmed to involve patent 9,565,213 specifically. What the 2026 CAFC/PTAB record does show:

  • April 7, 2026 (oral argument, decision pending): A Federal Circuit panel heard the Cisco non-infringement appeal in the long-running Centripetal Networks v. Cisco litigation (E.D. Va. 2:18-cv-00094) — the case that originally included the '213 patent among 11 patents-in-suit, after the CAFC vacated the multibillion-dollar verdict over a judge's stock conflict. The panel "grappled with" the district court's finding that Cisco did not infringe three Centripetal patents. I could not confirm from the search results whether 9,565,213 is one of those three patents. (Law360, April 7, 2026)
  • April 2, 2026 (decided): Centripetal Networks, LLC v. Keysight Technologies, Inc. — a CAFC affirmance of a PTAB unpatentability ruling. This case concerns US 10,284,526, not 9,565,213; I flag it only to avoid confusion with similar Centripetal matters. (Fed Circuit Blog)
  • Related PTAB history for 9,565,213 (pre-2026): Cisco's IPR2018-01386 and IPR2018-01512 both reached final written decisions (per Unified Patents litigation data); Palo Alto Networks' IPR2021-01157 also cited the '213 patent. The CAFC docket numbers tied to this patent family on Google Patents are 20-1634, 21-1888, and 24-2097 — but I did not verify the subject matter or 2026 status of each from a primary docket source.

Uncertainty Notes

  • Exact issued text of claims 11 and 16 is inferred, not verified from the USPTO claims PDF in this search.
  • No authoritative source was located confirming that any 2026 CAFC opinion or argued appeal specifically concerns 9,565,213; the closest candidate (the April 2026 Cisco non-infringement argument) may or may not include this patent.
  • The PTAB "again invalid as obvious" outcome reported in June 2026 concerns a different Centripetal patent (the '856 patent, per the Oct. 22, 2025 CAFC remand), not 9,565,213.

Generated 8/30/2026, 12:46:14 AM

Cases on file (5)

Group view →

Specific litigation cases in our database that name US patent 9565213. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2017: 1 case1'172018: 1 case'18'19'202021: 1 case'21
Cases asserting US 9565213, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research the litigation history of US Patent 9,565,213. Let me search several sources to compile the case list.

Let me search for more specific case details, including the other cases mentioned in the patent's litigation metadata.

Let me get more details on the Cisco case, Palo Alto case, and the IPR proceedings.

Based on my research across Unified Patents, CourtListener, PACER-derived sources, Justia, PatSnap, Reuters, and Law360, here is the litigation known to involve US Patent 9,565,213 ("the '213 patent"). I've flagged items where the available records don't let me confirm every field with certainty.

District Court Cases

1. Centripetal Networks, Inc. v. Keysight Technologies, Inc. and Ixia

  • Case No.: 2:17-cv-00383 (HCM-LRL) — later (EWH-LRL)
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
  • Filing date: July 20, 2017 (original complaint); the '213 patent was added via Amended Complaint on June 13, 2018 (Doc. 192)
  • Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
  • Defendants: Keysight Technologies, Inc. and Ixia
  • Status/outcome: Case proceeded through claim construction and trial before Judge Morgan; it is part of the same Centripetal enforcement campaign as the Cisco case. The docket shows the case was litigated through 2018–2019. (I could not confirm the final damages/settlement figure with confidence from my searches; some attorney biographies reference a $151.5 million E.D. Va. jury verdict for Centripetal in the network-security litigation, but I cannot verify whether that figure belongs to this case or the later 2022 Keysight action.)

2. Centripetal Networks, Inc. v. Cisco Systems, Inc.

  • Case No.: 2:18-cv-00094 (HCM-LRL; later EWH-LRL)
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
  • Filing date: February 13, 2018 (Amended Complaint adding the '213 patent filed March 29, 2018)
  • Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
  • Defendant: Cisco Systems, Inc.
  • Status/outcome: The famous multibillion-dollar case. After a 2020 Zoom bench trial, Judge Morgan found Cisco infringed (including, initially, the '213 patent family) and awarded ~$1.9 billion (Oct. 2020), with final judgment entered March 17, 2021. The Federal Circuit vacated the judgment on June 23, 2022 (38 F.4th 1025) due to the district judge's failure to recuse, and remanded under Rule 63 to a new judge. On remand, Judge Elizabeth Hanes found on Dec. 11, 2023 that Centripetal failed to prove infringement of the '193, '806, and '176 patents. Note: the '213 patent's claims in this case were dismissed without prejudice on November 18, 2020 because of the pending IPRs (IPR2018-01386 and IPR2018-01512) challenging the '213 patent. The case is now administratively closed (docket closed ~July 2025).

3. Centripetal Networks, Inc. v. Palo Alto Networks, Inc.

  • Case No.: 2:21-cv-00137 (RCY-RJK)
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia
  • Filing date: March 12, 2021
  • Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
  • Defendant: Palo Alto Networks, Inc.
  • Status/outcome: Centripetal asserted 13 patents, including the '213 patent, against PAN's NGFW, Cortex, MineMeld, DNS Security, and Panorama products. A jury trial resulted in a verdict for Centripetal; post-trial, the court granted PAN's JMOL in part and denied it in part and denied PAN's motion for a new trial. The case was dismissed in part/closed on October 3, 2024, with the JMOL opinion filed under seal.

4. Centripetal Networks, Inc. (LLC) v. Keysight Technologies, Inc.

  • Case No.: 1:22-cv-00001
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (Alexandria Division)
  • Filing date: January 4, 2022 (complaint filed by Centripetal Networks, Inc.)
  • Plaintiff: Centripetal Networks, Inc./LLC
  • Defendant: Keysight Technologies, Inc.
  • Status/outcome: New infringement action filed after the earlier Keysight case; per the Unified Patents docket, this case is in the E.D. Va. I could not confirm a final merits disposition from my searches.

5. Case No. 2:22-cv-00002 (E.D. Va.)

  • Jurisdiction: U.S. District Court for the Eastern District of Virginia
  • Filing date: January 2022 (listed in the patent's own litigation metadata)
  • Parties: Not confirmed from my searches; the Google Patents litigation record lists this as a Virginia Eastern District Court case involving the '213 patent. (I cannot verify the plaintiff/defendant names with confidence; it may be a companion Keysight action, but I will not guess.)

PTAB (Inter Partes Review)

6. Cisco Systems, Inc. v. Centripetal Networks, Inc., IPR2018-01386

  • Jurisdiction: Patent Trial and Appeal Board
  • Filing date: ~July 2018
  • Petitioner: Cisco Systems, Inc.; Patent Owner: Centripetal Networks, Inc.
  • Status/outcome: Final Written Decision holding challenged claims of the '213 patent unpatentable. On appeal, the Federal Circuit vacated the Board's invalidation (Oct. 22, 2025) and remanded (rejecting Centripetal's PTAB-recusal argument but faulting the Board's merits analysis). Per Law360 (June 12, 2026), the PTAB on remand again found the patent invalid as obvious. This proceeding is tied to the Cisco district-court litigation.

7. Cisco Systems, Inc. v. Centripetal Networks, Inc., IPR2018-01512

  • Jurisdiction: Patent Trial and Appeal Board
  • Filing date: ~August 2018
  • Petitioner: Cisco Systems, Inc.; Patent Owner: Centripetal Networks, Inc.
  • Status/outcome: Inter Partes Review of U.S. Pat. 9,565,213; a Final Written Decision issued. (The docket record I retrieved confirms the IPR was directed to the '213 patent; I did not retrieve the specific merits holding in this search.)

Federal Circuit Appeals

8. Appeal No. 20-1634 (Fed. Cir.)

  • Status: Listed in the patent's litigation metadata as a CAFC case. Likely relates to an appeal from the IPR final written decisions (the CAFC issued memorandum affirmances in the Centripetal/Cisco IPR appeals, cited as 847 F. App'x 927 and 929 (May 11, 2021)), but I could not confirm the exact match to this docket number.

9. Appeal No. 21-1888 (Fed. Cir.)

  • Status: Listed in the patent's litigation metadata as a CAFC case. Exact underlying case not confirmed in my searches.

10. Appeal No. 24-2097 (Fed. Cir.)

  • Status: Listed in the patent's litigation metadata as a CAFC case (filed 2024). Given the timing, this is likely an appeal arising from the post-2023 IPR remand or the Keysight proceedings, but I could not confirm the underlying decision from my searches.

Summary of Current Status

  • The '213 patent has been the subject of an aggressive, multi-front enforcement campaign by Centripetal against Cisco, Keysight/Ixia, and Palo Alto Networks.
  • The Cisco district-court judgment was vacated and, on remand, Centripetal lost on the patents retried; the '213 claims had already been dismissed without prejudice pending IPR.
  • The PTAB has repeatedly found '213 claims unpatentable (IPR2018-01386, IPR2018-01512), with the Federal Circuit vacating one invalidation in Oct. 2025 and the Board again finding the patent invalid on remand (June 2026). The '213 patent's enforceability is therefore in serious doubt pending any further appeal.

Caveats: For case numbers 2:22-cv-00002 and the CAFC docket numbers 20-1634, 21-1888, and 24-2097, I can confirm from the patent's own litigation metadata that they exist and involve this patent, but I could not retrieve complete party/outcome detail from the sources available in this session. You may want to pull the PACER dockets directly for those numbers to confirm the parties and current status.

Generated 8/30/2026, 12:46:07 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Good — initial hits confirm two Cisco IPRs plus a possible Palo Alto Networks IPR. Let me dig into each.

The IPR2021-01154 turns out to be on a different patent (10,785,266) — I'll exclude it. Now let me verify the IPR2018-01512 grounds and confirm the '213 patent's claim structure.

⚠️ ODP discrepancy — flagged

The structured "PTAB proceedings on file" block reports no AIA trial proceedings from the USPTO ODP API as of the most recent ingest. That is stale/incomplete. Web search — and the patent's own Google Patents family page (which is part of the authoritative full text supplied above) — confirm two completed IPRs on US 9,565,213, both with Final Written Decisions invalidating every claim, both affirmed by the Federal Circuit. (I also checked IPR2021-01154, which surfaced in searches but is a Palo Alto Networks petition on a different patent, 10,785,266 — it does not involve the '213 patent and is excluded.) The default "no PTAB activity" is therefore wrong for this patent; both proceedings below are real, final, and claim-killing.


Proceedings overview

There are two AIA trial proceedings on US 9,565,213 — both Inter Partes Reviews filed by Cisco Systems, Inc. — and both ended with Final Written Decisions holding all challenged claims (1–16, the complete claim set) unpatentable under § 103, affirmed by the Federal Circuit in 2021; none remain active, none settled, none were denied institution. Bottom line for a defendant: the patent is dead on its feet — every claim (1–16) has been canceled by two independent, appeal-affirmed PTAB judgments, so any demand letter or complaint citing claims of '213 is asserting claims that no longer exist, and an infringement theory built on them is sanction-bait.


IPR2018-01386 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2018-07-12
  • Status: Final Written Decision entered (2020-01-23); proceeding terminated. Plain English: trial complete, claims canceled, appeal lost.
  • Judge panel: Brian J. McNamara (lead, opinion author), J. John Lee, John P. Pinkerton
  • Petition grounds: § 103 obviousness over Narayanaswamy (US 2009/0328219 A1), Kapoor (US 2008/0229415 A1), Johnson (US 2004/0123220 A1), and Kjendal (US 9,172,627) for claims 1–9; the same four references plus RFC 2475 "An Architecture for Differentiated Services" (Diffserv) for claims 10–16. All claims 1–16 challenged.
  • Institution decision: Instituted — 2019-01-24 (Paper 8). The Board found a reasonable likelihood that Cisco would prevail on the obviousness grounds for the full claim set.
  • Final Written Decision (Paper 31, 2020-01-23): All sixteen claims — claims 1–16 — held unpatentable under 35 U.S.C. § 103. The record (as characterized in Centripetal's own Notice of Appeal) shows the Board's "determination that Petitioner showed by a preponderance of the evidence that claims 1–9 of the '213 Patent are unpatentable under 35 U.S.C. § 103 over Narayanaswamy, Kapoor, Johnson, and Kjendal and that claims 10–16 of the '213 Patent are unpatentable over Narayanaswamy, Kapoor, Johnson, Kjendal, and Diffserv." No claim survived; there is no "sustained" claim in this proceeding.
  • Settlement / termination: No settlement — Cisco won outright; the case terminated on issuance of the FWD.
  • Appeal: Yes. Centripetal appealed to the Federal Circuit (Appeal No. 2020-1634, Notice of Appeal dated 2020-03-24), raising (i) the Board's reliance on arguments purportedly beyond the scope of Cisco's Reply, (ii) claim construction of "dynamic security policy," "monitoring device," and "packet-by-packet," (iii) the obviousness findings and motivation-to-combine analysis, and (iv) secondary considerations. The CAFC affirmed per curiam under Rule 36 on 2021-05-11 — Centripetal Networks, Inc. v. Cisco Systems, Inc., 847 F. App'x 929 (Fed. Cir. 2021) — in a joint disposition with the companion appeal (see below). See CourtListener opinion.
  • Defensive value: This FWD is a complete, appeal-affirmed cancellation of every claim (1–16) of the '213 patent. For a defendant today, this is the primary knockout document: the claims do not exist, and the patent owner has exhausted its appeal.

IPR2018-01512 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2018-08-21
  • Status: Final Written Decision entered (2020-03-19); proceeding terminated. Plain English: a second, independent kill shot on the same claims via different prior art.
  • Judge panel: Brian J. McNamara (lead, opinion author), Stacey G. White, John P. Pinkerton
  • Petition grounds: § 103 obviousness over Cisco's own ACNS Software Configuration Guide for Centrally Managed Deployments, Release 5.5 ("ACNS") plus Kjendal (US 9,172,627) for claims 1–9; and ACNS + RFC 2475 (Diffserv) + Kjendal for claims 10–16. All claims 1–16 challenged.
  • Institution decision: Instituted — 2019-03-20 (Paper 8, which also set the Scheduling Order). The Board again found a reasonable likelihood of prevailing on the obviousness grounds across the full claim set.
  • Final Written Decision (2020-03-19): All challenged claims 1–16 held unpatentable. The FWD is described in later USPTO records as the "Final Written Decision Determining All Challenged Claims Unpatentable of U.S. Pat. No. 9,565,213 B2—IPR 2018-01512" (see the citation in US 11,477,237). The operative grounds, as framed in the parties' own hearing papers, were: claims 1–9 obvious over ACNS + Kjendal, and claims 10–16 obvious over ACNS + Diffserv + Kjendal. No claims survived.
  • Settlement / termination: No settlement — terminated on issuance of the FWD. (Notable sidebar: the proceeding included only routine skirmishes — e.g., an unopposed motion to expunge a mis-filed reply — no settlement negotiations.)
  • Appeal: Yes. Centripetal appealed to the Federal Circuit (Appeal No. 2020-1829), consolidated with 2020-1634. The CAFC affirmed per curiam under Rule 36 on 2021-05-11 — Centripetal Networks, Inc. v. Cisco Systems, Inc., 847 F. App'x 927 (Fed. Cir. 2021) — in the same joint disposition covering both IPRs. See CourtListener opinion.
  • Defensive value: This is the redundant, independent cancellation of claims 1–16 on different art (including Cisco's own product documentation). It means the invalidity of every '213 claim does not hinge on the correctness of the 01386 grounds — even if the 01386 combination were somehow disturbed, the 01512 FWD stands on its own.

Strategic summary

Claims CANCELED vs. SUSTAINED vs. UNTESTED. Every claim of US 9,565,213 — claims 1–16, the complete set as challenged and decided in both IPRs — has been canceled. There are zero sustained claims and zero untested claims. Two different PTAB panels (McNamara/Lee/Pinkerton and McNamara/White/Pinkerton) each independently held all sixteen claims unpatentable under § 103 on different prior-art combinations, and the Federal Circuit affirmed both FWDs on the same day (2021-05-11) via Rule 36. Following finality, the Director's certificates canceling claims 1–16 are the operative USPTO records; the Google Patents "Active" status reflects the unexpired term (anticipated expiration 2034-04-16), not claim enforceability — the claims themselves are gone.

Estoppel landscape. § 315(e)(2) estoppel binds only the IPR petitioners (Cisco) and their privies, and it is functionally moot here because Cisco won — the claims were canceled, so there is nothing left for Cisco to re-litigate. For a new defendant being asserted against today, estoppel is irrelevant in the most favorable possible way: the claims are canceled erga omnes, so you are not estopped from doing anything and you don't need to — there is no claim left to challenge. If you want belt-and-suspenders, the FWDs' detailed findings on Narayanaswamy/Kapoor/Johnson/Kjendal/ACNS/Diffserv are public, reasoned obviousness holdings you can adopt in district court, and § 315(e)(2) poses no bar because you were not a party or privy to the Cisco IPRs.

Pattern signals. This was a coordinated, one-petitioner campaign: between 2018-07-12 and 2018-09-18, Cisco filed IPRs against nine Centripetal patents in the same family asserted in Centripetal v. Cisco, No. 2:18-cv-00094 (E.D. Va.); seven were instituted (including '213) and all instituted claims across the family were invalidated, with every appeal affirmed. Centripetal litigated aggressively — it appealed both '213 FWDs and lost both on Rule 36 — and the family has since spawned additional Cisco and Palo Alto Networks/Keysight PTAB and CAFC battles on continuation patents (e.g., 9,137,205, 10,785,266, 9,917,856; CAFC dockets 21-1888 and 24-2097 appear in the family litigation list but are not confirmed to touch '213 itself). Defensive-aggregator note: Unified Patents appears in the record only as the data source for the PTAB litigation entries on the Google Patents page — it was not the petitioner here; Cisco was. The takeaway: this patent was asserted in litigation, was met with a serious IPR campaign, and did not survive a single claim.


Recommended next steps

  1. If you're a defendant and the demand cites '213 claims 1–16, treat it as a nullity. Link the demand to the FWDs and the affirmance and demand withdrawal:

    • IPR2018-01386 FWD (Paper 31, 2020-01-23) — PTAB docket (DocketAlarm) and Unified Patents portal
    • IPR2018-01512 FWD (2020-03-19) — PTAB docket (DocketAlarm) and Unified Patents portal
    • CAFC affirmance (both appeals, 2021-05-11) — CourtListener; 847 F. App'x 929 and 847 F. App'x 927.
    • If suit is filed, move to dismiss or for judgment on the pleadings: the asserted claims are canceled on the face of the USPTO records, and an infringement theory built on canceled claims is sanction-bait under Rule 11. Pull the certificates of cancellation from USPTO Patent Center to attach as exhibits.
  2. No active proceedings pending — the statutory 1-year trial clock, oral hearing (held 2019-12-18 in 01512), FWDs, and appeals are all complete. There is no institution-decision deadline, hearing date, or FWD due date to watch.

  3. Check for family-member assertions. The '213 patent is a continuation of 9,137,205 and has its own continuations (e.g., 10,142,372; 10,944,792; 11,477,237; 10,749,906; 10,951,660; 11,012,474; 12,107,893; 12,563,103). If the demand is actually aimed at one of those, it is a different patent with its own claim set and its own (in some cases ongoing) validity posture — do not assume '213's cancellation carries over, and run each asserted family member through the same PTAB/litigation diligence.

  4. If the ODP silence matters to your diligence workflow, note the gap: the USPTO Open Data Portal ingest is missing two decade-old, high-profile IPRs. Rely on the PTAB's own dockets and the citations above, not the ODP API, for this patent.

Generated 8/30/2026, 12:46:58 AM

Ownership chain (4)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2014-04-16 · Assignment

    Steven Rogers; Sean Moore; David K. Ahn; Peter P. GeremiaCENTRIPETAL NETWORKS, INC.

  2. 2017-04-17 · recorded 2017-04-19 · Security Agreement

    CENTRIPETAL NETWORKS, INC.Douglas A. Smith

    Correspondent: · Morgan, Lewis & Bockius

  3. ? · recorded 2019-03-04 · Release

    Douglas A. SmithCENTRIPETAL NETWORKS, INC.

  4. ? · recorded 2023-01-20 · Change of Name

    CENTRIPETAL NETWORKS, INC.CENTRIPETAL NETWORKS, INC.

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment record for US 9565213. Let me start by checking the USPTO assignment records and cross-referencing legal events.

I have key context. Now let me dig for specific reel/frame numbers and correspondent details for each recorded assignment.

I found the 2017 security interest details. Now let me identify the correspondent law firm (617-951-8000 area code suggests Boston) and find the reel/frame numbers plus the 2019 release and 2023 change of name.

I've hit my search limit, but I have enough sourced material to reconstruct the chain. Note upfront: I could not retrieve the USPTO reel/frame numbers from my sources — I will not fabricate them. Every event below is sourced to either the Google Patents legal-events record for US9565213 or the recorded security-agreement cover sheet filed in EDVA case 2:17-cv-00383 (DocketAlarm copy).


Inventors

All four inventors were employed by the applicant Centripetal Networks, Inc. (Reston, VA) at the time of filing:

  • Steven Rogers — Leesburg, VA. Co-founder/CEO of Centripetal Networks. Still with the company; named on nearly the entire Centripetal family.
  • Sean Moore — Hollis, NH. Co-founder/CTO of Centripetal Networks; prolific named inventor on the Centripetal portfolio (incl. parent US 9,137,205).
  • David K. Ahn — Winston-Salem, NC. Engineering executive at Centripetal Networks.
  • Peter P. Geremia — Portsmouth, NH. Engineering lead at Centripetal Networks.

Pattern check: No mass-departure/fire-sale pattern. The inventors were the founding/technical team of the original assignee and the patent remained with Centripetal for its entire life — this is not the "inventors leave, portfolio gets sold to a licensing shop" pattern. Patent prosecution attorney of record: Banner & Witcoff, Ltd. (per the patent face).


Original assignee

  • Centripetal Networks, Inc. (Delaware corporation, Reston, VA) — named assignee on the issued patent.
  • Line of business: Operating cybersecurity vendor. Products embodying the claims include the RuleGate™ packet-security gateway and the CleanINTERNET / CleanSweep managed-security services — i.e., the "packet security gateway + security policy management server + dynamic security policy" architecture claimed in US9565213. This is a product company, not a licensing shell.
  • Current status: Operating (renamed Centripetal Networks, LLC in 2023). The company has litigated aggressively (see below) and had at least one private financing round secured by its patent portfolio (2017), but it has not gone bankrupt or been acquired.

Assignment timeline

Sources: Google Patents legal-events tab for US9565213; Patent and Trademark Security Agreement cover sheet recorded in Centripetal Networks, Inc. v. Keysight Technologies, Inc., EDVA 2:17-cv-00383 (DocketAlarm exhibit). Reel/frame numbers could not be retrieved from my sources — I am not fabricating them; the events below are the ones independently corroborated.

  • 2014-04-16 (executed) / recorded 2014-04-16 — reel/frame not retrieved

    • Conveyance: Assignment of Assignor's Interest (original assignment from inventors)
    • Assignor: Steven Rogers; Sean Moore; David K. Ahn; Peter P. Geremia
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not retrieved (prosecution counsel of record on the application was Banner & Witcoff, Ltd.)
    • Context: Standard employee-inventor assignment to the operating company at filing.
  • 2017-04-17 (executed) / recorded 2017-04-19 — reel/frame not retrieved (cover sheet EPAS ID PAT4374169, EDVA 2:17-cv-00383 exhibit)

    • Conveyance: Security Interest (Patent and Trademark Security Agreement)
    • Assignor: Centripetal Networks, Inc. (Grantor)
    • Assignee: Douglas A. Smith, an individual, 12770 Merit Drive, Suite 800, Dallas, TX 75251 (Grantee)
    • Correspondent: cover sheet shows phone (617)951-8000 and fax (617)951-8736 — the Boston numbers of Bingham McCutchen LLP / Morgan, Lewis & Bockius LLP (Bingham merged into Morgan Lewis in 2014; per TTAB records, 617-951-8000/617-951-8736 are the Bingham/Morgan Lewis Boston TM/IP numbers, e.g. Rachelle A. Dubow). Individual attorney name on the recorded sheet not retrieved.
    • Context: Debt-financing lien, not an ownership transfer. Granted to secure a Note and Warrant Purchase Agreement of even date under which Smith made a loan to Centripetal; the agreement covers 14 Centripetal patents/applications (incl. US9565213, 9560176, 9560077, 9413722, 9264370, 9203806, 9160713, 9137205, 9124552, 9094445, 8495725, 8042167, 8037517, and app. 14/625,486) as collateral.
  • 2019-03-04 (recorded) — reel/frame not retrieved

    • Conveyance: Security Interest — release/termination (Google Patents lists assignor "SMITH, DOUGLAS A" → assignee "CENTRIPETAL NETWORKS, INC.")
    • Assignor: Douglas A. Smith
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not retrieved
    • Context: Release of the 2017 lien (loan repaid or refinanced); title reverted cleanly to the operating company.
  • 2023-01-20 (recorded) — reel/frame not retrieved

    • Conveyance: Change of Name
    • Assignor: Centripetal Networks, Inc.
    • Assignee: Centripetal Networks, LLC
    • Correspondent: not retrieved
    • Context: Corporate conversion/change of name only — same entity, no change in beneficial ownership.

Bottom line: The full recorded chain is Inventors → Centripetal Networks, Inc. → (lien to D.A. Smith, released) → Centripetal Networks, LLC. The patent has never left the operating company; the only third-party link was a 2-year lender security interest.


Timeline diagram

timeline
    title Ownership of US 9565213
    2012 : Priority application filed
    2014 : Filed by Centripetal Networks Inc
    2017 : Patent issued
         : Security interest to lender D A Smith
    2019 : Security interest released
    2023 : Renamed Centripetal Networks LLC

NPE / troll-pattern signals

  1. Shell-entity transfernot present. No transfer to an "IP / Patents / Licensing / Holdings / Ventures" LLC. The only LLC in the chain is Centripetal Networks, LLC — the renamed operating company itself, not a licensing vehicle. The one third-party "assignee" (Douglas A. Smith) is an individual lender holding a 2017 security interest (EPAS ID PAT4374169) that was released in 2019; a collateral lien is not a shell-entity ownership transfer.

  2. Known asserter in the chainnot present. No Acacia, Marathon, IV, IPNav, Wi-LAN, Conversant, Vringo, Pendrell, Spangenberg, or similar entity appears in the chain. Centripetal is a high-frequency plaintiff (EDVA cases 2:17-cv-00383 vs. Keysight; 2:18-cv-00094 vs. Cisco; 2:22-cv-00001; 2:22-cv-00002; plus IPRs filed against it by Cisco and Palo Alto Networks, IPR2018-01386/01512 and IPR2021-01154/01157) but it is a product company asserting against competitors, not a licensing NPE.

  3. Repeat correspondent across the chainunclear / insufficient data. The one correspondent I could identify (Morgan Lewis/Bingham McCutchen Boston, 617-951-8000 on the 2017 security-agreement cover sheet) appears on a financing document, not on a chain of shell-LLC transfers; there is no second link showing the same attorney recurring, so the "repeat correspondent" tell is not established. No evidence ties that firm to an NPE assertion list.

  4. Cascading transfersnot present. Only four recorded events in 9 years: one inventor assignment, one lien, one lien release, one name change. No chained-LLC cascade, no <24-month rapid-fire transfers.

  5. Pre-litigation transfernot present as an NPE signal. The 2017 security interest was recorded ~1 month before Centripetal's first EDVA suit (Keysight, 2:17-cv-00383), but it is a lender lien executed in connection with a Note and Warrant Purchase Agreement — the patent never moved to an assertion entity, and Centripetal itself was already the plaintiff. There is no transfer-to-asserter standing arrangement.

  6. Bankruptcy fire-salenot present. Centripetal has not filed Chapter 7/11; no trustee or bankruptcy sale appears in the chain. (The 2017 secured loan suggests the company needed capital, but that is venture/private debt, not a bankruptcy disposition.)

  7. Privateeringnot present. Centripetal asserts in its own name against direct competitors (Cisco, Palo Alto Networks, Keysight); there is no SEC-filing or press pattern of an operating company feeding patents to an NPE to attack rivals.

  8. Defensive aggregator (anti-NPE)not present. The chain terminates at Centripetal Networks, LLC — an asserting operating company, not RPX/AST/LOT/Unified/OIN.


Verdict

Operating-company assertion.

The patent never left its original operating assignee: the recorded chain is Inventors → Centripetal Networks, Inc. → (2017 lender security interest to Douglas A. Smith, released 2019) → Centripetal Networks, LLC (2023 name change). Centripetal ships the claimed packet-security-gateway products (RuleGate/CleanINTERNET), owns the patent outright, and is asserting it against actual competitors in EDVA (Cisco, Palo Alto Networks, Keysight), with IPR challenges filed against it by those competitors — the inverse of an NPE pattern. The single third-party "assignment" is a debt lien (EPAS ID PAT4374169, executed 2017-04-17, recorded 2017-04-19, released 2019-03-04), not an ownership transfer, and no shell entities, cascading transfers, or known NPE assignees appear anywhere in the chain.

Verify at the USPTO Assignment Center: https://assignmentcenter.uspto.gov/ (search patent number 9565213).

Caveat: I could not retrieve reel/frame numbers for any of the four events from my available sources; the events themselves are corroborated by the Google Patents legal-events record and the recorded cover sheet in EDVA 2:17-cv-00383. If you pull the full Assignment Center output, the reel/frame fields for the 2017-04-19, 2019-03-04, and 2023-01-20 recordations should be filled in and would let you confirm the correspondent on the 2019 release and 2023 name change.

Generated 8/30/2026, 12:46:21 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

1. Patent verification — US 9,565,213 B2

  • Patent No.: US 9,565,213 B2 (application 14/253,992; publication US 2015/0304354 A1)
  • Title: "Methods and systems for protecting a secured network"
  • Inventors: Steven Rogers, Sean Moore, David K. Ahn, Peter P. Geremia
  • Assignee: Centripetal Networks, Inc. (now Centripetal Networks, LLC)
  • Filed: April 16, 2014; Priority: October 22, 2012 (US 13/657,010); Granted: February 7, 2017
  • Claims: 16 claims / 13 drawing sheets
  • Litigation/PTAB history (relevance signal): IPR2018-01386 and IPR2018-01512 (Cisco v. Centripetal), IPR2021-01154/01157 (Palo Alto Networks), plus multiple Virginia E.D. Va. cases (e.g., 2:17-cv-00383, 2:18-cv-00094).

Sources: https://patents.google.com/patent/US9565213/en ; https://www.docketalarm.com/cases/PTAB/IPR2021-01157/Palo_Alto_Networks_Inc/07-22-2021-Petitioner/Exhibit-1007-7-US9565213_Rogers/ ; https://portal.unifiedpatents.com/ptab/case/IPR2018-01386


2. Issued claim structure (needed for the § 102 mapping)

From the patent file history and the published application (which match the 16 issued claims):

  • Claim 1 (independent): A method comprising, at each of a plurality of packet security gateways associated with a security policy management server, receiving a dynamic security policy containing at least one rule specifying application-layer packet-header information and a packet transformation function; receiving packets associated with the protected network; identifying, on a packet-by-packet basis, packets comprising the application-layer packet-header information; and performing the transformation function on each such packet.
  • Claims 2–9 (dependent on claim 1): accept/forward (cl. 2); deny/drop (cl. 3); HTTP packets (cl. 4); HTTP GET method call (cl. 5); URI for GET (cl. 6); HTTP PUT method call (cl. 7); URI for PUT (cl. 8); five-tuple of transport protocol, source address range, source port range, destination address range, destination port range (cl. 9).
  • Claim 10 (independent): same plurality-of-gateways/central-server framework, but the rule specifies packet-identification criteria and a packet digest logging function; identifying packets on a packet-by-packet basis and performing the digest logging function on each.
  • Claims 11–16 (dependent on claim 10): identifying a subset of information and generating a record (cl. 11); subset contents (data portion, addresses, ports, protocol, URI, arrival time, size, flow direction, interface ID, MAC addresses) (cl. 12); temporary storage (cl. 13); communicating the message to the security policy management server (cl. 14); reformatting per a logging standard (cl. 15); syslog standard (cl. 16).

Note: original claims 19–20 (rule-update/correlation method of FIG. 13) were restricted out and issued later in US 10,749,906 B2; they are not part of the '213 patent.

Sources: https://patents.justia.com/patent/20150304354 ; https://www.docketalarm.com/cases/PTAB/IPR2018-01512/.../Exhibit-1002-2-Ex_1002_File_History_of_US_Patent_9,565,213.pdf ; IPR2018-01386 Notice of Appeal (https://insight.rpxcorp.com/federal_circuit/[836543](/patent/836543)/.../IPR2018_01386___Notice_of_Appeal...pdf)


3. The most relevant prior art (as established by the IPR record)

The strongest relevance evidence comes from the Board's Final Written Decision in IPR2018-01386 (entered January 23, 2020, Paper 31), which held:

  • Claims 1–9 unpatentable under 35 U.S.C. § 103 over Narayanaswamy (US 2009/0328219 A1) in view of Kapoor (US 2008/0229415 A1) and Johnson (US 2004/0123220 A1), and potentially Kjendal (US 9,172,627 B2).
  • Claims 10–16 unpatentable over the same references plus "An Architecture for Differentiated Services," RFC 2475 (Dec. 1998) ("Diffserv").

I must be precise: the Board decided obviousness (§ 103), not anticipation (§ 102). A § 102 anticipation showing requires a single reference disclosing every claim element. Below is my preliminary § 102 assessment for each key reference, with the caveat that a full anticipation chart requires the complete reference texts (not all were retrievable in this session).

Reference Full citation / date Brief description Claims it potentially anticipates under § 102
Narayanaswamy US 2009/0328219 A1, published Dec. 31, 2009 Centralized security-policy management with policy distribution to multiple network enforcement points; rule-based packet filtering Closest single reference to independent claim 1 (plurality of gateways + security policy management server + dynamic policy + packet filtering). However, the IPR combination analysis implies Narayanaswamy alone does not disclose every element (notably application-layer packet-header information, e.g., HTTP/URI-level identification). Full § 102 anticipation of claim 1 is therefore doubtful; partial coverage of the "receiving a dynamic security policy from a policy management server at a plurality of gateways" elements.
Kapoor US 2008/0229415 A1, published Sep. 25, 2008 Firewall system with improved, dynamically updateable rule handling and packet transformation/enforcement actions Potentially anticipates the rule-driven packet-transformation-function elements of claims 1 and 10; does not by itself disclose the multi-gateway central-server architecture or application-layer/digest-logging limitations.
Johnson US 2004/0123220 A1, published Jun. 24, 2004 Network filtering relevant to HTTP/application-layer traffic identification Potentially most relevant to dependent claims 4–8 (HTTP packets, GET/PUT method calls, URI-based identification), but only if it discloses the full combination in one reference — unlikely alone.
Kjendal US 9,172,627 B2, issued Oct. 27, 2015 (filed earlier) Packet transformation / security-processing techniques at network devices Potentially anticipates the transformation-function limitations of claims 1–3 and 10; not a stand-alone anticipation of the whole independent claims.
Diffserv "An Architecture for Differentiated Services," IETF RFC 2475, Dec. 1998 (non-patent) DSCP field semantics and per-hop forwarding behaviors in IP headers Relevant to packet-identification criteria based on DSCP (used for claims 10–16 grounds); as a non-patent document it supports obviousness more than single-reference § 102 anticipation.

Sources: IPR2018-01386 Notice of Appeal (https://insight.rpxcorp.com/federal_circuit/836543/...); Jeffay Declaration, IPR2018-01386 Ex. 1004 (https://www.docketalarm.com/cases/PTAB/IPR2018-01386/.../Exhibit-1004-4-Ex_1004___Declaration_of__Dr_Kevin_Jeffay.pdf)


4. Front-page "References Cited" (as printed on the '213 patent)

The patent's own References Cited section (from the PTAB exhibit copy of the printed patent, Docket Alarm Ex. 1007) includes the following U.S. patents (full bibliographic details are partially listed on the face of the patent; I have flagged entries where the title could not be verified in this session):

U.S. Patents:

  1. 6,098,172 A — Coss et al., Aug. 2000 — firewall system providing quality-of-service/rule-based filtering and packet handling. Potentially anticipates claim 1/10 rule-and-transformation elements; lacks central multi-gateway policy distribution.
  2. 6,226,372 B1 — Beebe et al., May 2001 — method/apparatus providing active access to a firewall. Secondary relevance.
  3. 6,317,837 B1 — Kenworthy, Nov. 2001 — network security/automated policy management (Kenworthy family; see below). Relevant to centralized security policy/rules.
  4. 6,484,261 B1 — Wiegel, Nov. 2002 — graphical specification system for a network security policy. Relevant to security-policy rule specification.
  5. 6,611,875 B1 — Chopra et al., Aug. 2003 — title not verified in this session.
  6. 6,662,235 B1 — Callis et al., Dec. 2003 — title not verified.
  7. 7,089,581 B1 — date/inventor not verified.
  8. 7,107,613 B1 — not verified.
  9. 7,215,637 B1 — not verified.
  10. 7,227,842 B1 — not verified.
  11. 7,237,267 B2 — not verified.
  12. 7,263,099 B1 — not verified.
  13. 7,299,353 B2 — not verified.
  14. 7,331,061 B1 — not verified.
  15. 7,478,429 B2 — not verified.
  16. 7,539,186 B2 — not verified.
  17. 7,684,400 B2 — not verified.
  18. 7,710,885 B2 — not verified.
  19. 7,721,084 B2 — not verified.
  20. 7,818,794 B2 — not verified.
  21. 7,954,143 B2 — not verified.
  22. 8,004,994 B1 — not verified.
  23. 8,037,517 B2 — not verified.
  24. 8,042,167 B2 — not verified.
  25. 8,117,655 B2 — not verified.
  26. 8,176,561 B1 — not verified.
  27. 8,306,994 B2 — Kenworthy, Nov. 2012 — system and method for protecting a computer system against malicious software (malicious-host/blocklist rules). Relevant to dynamic security policy rules built from malicious-address lists (spec. FIG. 5/13; original claims 19–20).
  28. 8,495,725 B2 — Kenworthy, Jul. 2013 — continuation of the Kenworthy malicious-software protection work.
  29. 8,726,379 B1 — not verified.
  30. 8,806,638 B1 — not verified.
  31. 8,856,926 B2 — not verified.
  32. 8,935,785 B2 — not verified.
  33. 9,094,445 B2 — not verified.
  34. 9,124,552 B2 — not verified.
  35. 9,137,205 B2 — Rogers et al., Sep. 2015 — family member (parent US 13/657,010), not § 102 prior art (same inventive entity/continuity; issued after the '213 filing date).
  36. 9,160,713 B2 — not verified.

U.S. Published Applications (partial, with examiner-cited items confirmed in the file history):

  • 2001/0039624 A1 — Kellum, Nov. 2001
  • 2002/0049899 A1 — Kenworthy, Apr. 2002 (application counterpart of the Kenworthy automated-policy work)
  • 2003/0035370 A1 — Brustoloni, Feb. 2003
  • 2003/0142681 A1 — Chen et al., Jul. 2003
  • 2003/0145225 A1 — Bruton et al., Jul. 2003
  • 2005/0138204 A1 — Iyer et al., Jun. 2005
  • 2005/0141537 A1 — Kumar et al., Jun. 2005
  • 2006/0136987 A1 — Okuda, Jun. 2006 (examiner-cited)
  • 2006/0146879 A1 — Anthias et al., Jul. 2006 (examiner-cited)
  • 2006/0212572 A1 — Afek et al., Sep. 2006
  • 2007/0240208 A1 — Yu et al., Oct. 2007 (examiner-cited)
  • 2008/0072307 A1 — Maes, Mar. 2008
  • 2010/0082811 A1 — Van Der Merwe et al., Apr. 2010
  • 2010/0242098 A1 — Kenworthy, Sep. 2010
  • 2010/0296441 A1 — Barkan, Nov. 2010
  • 2011/0088092 A1 — Nguyen et al., Apr. 2011
  • 2013/0061294 A1 — Kenworthy, Mar. 2013

Foreign patent documents:

  • JP 2005328336 B2 (Sep. 2011) and JP 2006230171 B2 (Jun. 2012) — Japanese security-related patents (full titles not verified).

Other (non-patent) publications cited (from the front page and file history): Reumann et al., "Adaptive Packet Filters" (IEEE, 2001); E. Fulp, "Optimization of Network Firewall Policies Using Ordered Sets and Directed Acyclical Graphs" (Jan. 2004); Fulp et al., "Network Firewall Policy Tries" (2004); Al-Shaer et al., "Modeling and Management of Firewall Policies" (2004); plus additional firewall-policy-optimization papers (Ranganath, Christiansen, Qiu, Eppstein, etc.).

Source for the citation list: https://www.docketalarm.com/cases/PTAB/IPR2021-01157/Palo_Alto_Networks_Inc/07-22-2021-Petitioner/Exhibit-1007-7-US9565213_Rogers/ ; examiner citations from https://www.docketalarm.com/cases/PTAB/IPR2018-01512/.../Exhibit-1002-2-Ex_1002_File_History_of_US_Patent_9,565,213.pdf


5. Bottom line on § 102 anticipation

  • No single front-page citation cleanly anticipates independent claim 1 or claim 10 on the face of the record. The closest single references are Narayanaswamy (US 2009/0328219 A1) for claim 1's architecture and the Kenworthy family for centralized security-policy/rule management, but both appear to lack at least one claim-1 element (application-layer packet-header identification performed packet-by-packet at a plurality of gateways; and the packet-digest-logging function of claim 10).
  • The references that came closest in the IPR were applied in combination under § 103, which is consistent with a conclusion that no single reference alone anticipates all 16 claims.
  • For dependent claims, the strongest single-reference cases are Johnson (US 2004/0123220 A1) for claims 4–8 (HTTP/GET/PUT/URI) and the Diffserv RFC 2475 for DSCP-based packet-identification criteria underpinning claims 10–16 — but again, the Board relied on combinations.
  • US 9,137,205 B2 (Rogers et al.) is a family member and is not § 102 prior art against the '213 patent.

Honest limitations

This analysis was constrained by search-step limits. I could not verify the titles/inventors of roughly half of the 36 cited U.S. patents (items 7–26, 29–34, 36 above) or the two Japanese documents. Those entries are marked "not verified" rather than guessed. A definitive § 102 claim-by-claim anticipation chart requires (a) the complete text of each reference (e.g., from USPTO/Espacenet) and (b) the full issued claim set; I recommend pulling the USPTO Patent Center copy of the '213 patent and the cited references before making an invalidity position. The IPR exhibits (Ex. 1004 Jeffay Declarations in IPR2018-01386/-01512) contain element-by-element mappings for the Narayanaswamy/Kapoor/Johnson/Kjendal/Diffserv grounds and are the best available starting point.

Generated 8/30/2026, 12:47:02 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll research the prior art cited against US Patent 9,565,213, including the PTAB IPR proceedings identified on the patent's litigation record, since those will show the actual prior-art combinations that were asserted.

I found the key IPR ground. Let me dig deeper into the Final Written Decisions and the second IPR to confirm the exact combinations and claim mappings.

I've gathered what I need. Note: the Google Patents text you provided does not include the "Citations/Prior Art" section, so I reconstructed it from the USPTO "References Cited" appearing in the IPR exhibits and from the PTAB record (IPR2018-01386 / IPR2018-01512), which is the most authoritative prior-art evidence against this patent. Below is the §103 analysis.


Obviousness Analysis — U.S. Patent 9,565,213 ("Methods and systems for protecting a secured network")

1. The claims in play

The granted patent has 16 claims, with two independent claims (the prosecution history and the IPR appeal record both confirm this):

  • Independent claim 1 — a method in which a packet security gateway (PSG) receives a dynamic security policy from a security policy management server; receives packets associated with a protected network; identifies, on a packet-by-packet basis, packets containing specified application-layer packet-header information (e.g., HTTP GET/PUT with a URI); performs a packet transformation function (forward/drop); and routes the packets to a monitoring device in response.
  • Independent claim 10 — a method in which a plurality of PSGs each receive a dynamic security policy specifying packet-identification criteria and a packet digest logging function, where the criteria include a Differentiated Service Code Point (DSCP) selector.
  • Dependent claims 2–9 and 11–16 — add features such as five-tuple rules, DSCP-based queueing at different forwarding rates, network-layer-transparent operation, IPsec forwarding, malicious-host-list rules, blocklist/allowlist semantics, and ingress filtering.

2. The verified prior-art record against this patent

(a) Examiner rejections during prosecution (application 14/253,992)

The file history (Cisco Ex. 1002 in IPR2018-01512) shows the Examiner rejected the claims under § 103 as follows:

Claims Ground
1–6, 9, 10, 17, 18 Narayanaswamy (US 2009/0328219 A1) in view of Kapoor (US 2008/0229415 A1)
7, 8, 11–14 Narayanaswamy + Kapoor + Erb (US 2014/0215574 A1)
further Narayanaswamy + Kapoor + Erb + Nappier (US 2011/0185055 A1)

The applicant overcame these rejections by amending claim 1 to add "routing, by the packet security gateway and on a packet-by-packet basis, to a monitoring device each of the one or more packets corresponding to the application-layer packet-header information" and by amending claim 10 to add the "DSCP selector" limitation — arguing that "neither Narayanaswamy nor Kapoor teach or suggest" those features.

(b) The IPR that invalidated the claims (IPR2018-01386, Cisco v. Centripetal)

  • Filed: July 12, 2018; Instituted: Jan. 24, 2019; Final Written Decision: Jan. 23, 2020 (Paper 31).
  • The Board found all 16 claims unpatentable under 35 U.S.C. § 103, per Centripetal's own Notice of Appeal (Fed. Cir. appeal 20-1634):
    • Claims 1–9 obvious over Narayanaswamy (US 2009/0328219 A1) + Kapoor (US 2008/0229415 A1) + Johnson (US 2004/0123220 A1) + Kjendal (US 9,172,627 B2);
    • Claims 10–16 obvious over Narayanaswamy + Kapoor + Johnson + Kjendal + "An Architecture for Differentiated Services," RFC 2475 (Dec. 1998) ("Diffserv").
  • Centripetal appealed (Fed. Cir. 20-1634), challenging the Board's constructions of "dynamic security policy," "monitoring device," and "packet-by-packet," and the Board's motivation-to-combine findings — but the operative determination below was a complete § 103 loss on every claim.
  • A parallel petition, IPR2018-01512 (also Cisco), was filed against the same patent and likewise reached a Final Written Decision per the docket record (its Ex. 1002 is the same file history quoted above). I have not verified the substance of that decision, so I do not rely on it here.

(c) References cited on the face of the patent

From the USPTO "References Cited" in the issued patent (as reproduced in IPR exhibits), the examiner-considered art includes U.S. 6,098,172 (Coss), 6,226,372 (Beebe), 6,317,837 (Kenworthy), 6,484,261 (Wiegel), 6,611,875 (Chopra), 6,662,235 (Callis), a long list of U.S. published applications, AU 2005328336 B2 and AU 2006230171 B2, and the non-patent reference Reumann et al., "Adaptive Packet Filters" (IEEE, 2001).


3. The principal § 103 combinations and why they render the claims obvious

Combination A — Claims 1–9: Narayanaswamy + Kapoor + Johnson + Kjendal

What each reference supplies (as the references were used in the rejections and IPR):

  • Narayanaswamy (US 2009/0328219 A1) — the primary reference. It teaches a network-security filtering device that inspects packets against rules/policies and applies packet-level actions. It was the anchor for the packet security gateway and rule-based packet filtering limitations.
  • Kapoor (US 2008/0229415 A1) — supplies the security policy management server side: centralized, dynamically communicated security policies distributed to filtering devices — the "dynamic security policy received from the security policy management server" limitation of claim 1 and the "plurality of gateways associated with a management server" limitation of claim 10.
  • Johnson (US 2004/0123220 A1) — supplies the monitoring-device feature: identifying selected traffic and routing/copying it to a monitoring device. This is the exact limitation the applicant added in amendment to overcome the Examiner's Narayanaswamy/Kapoor rejection, i.e., the very gap the IPR petition then filled with Johnson.
  • Kjendal (US 9,172,627 B2) — supplies the additional packet transformation functions (e.g., redirecting/forwarding selected packets to a different destination or processing path) needed to complete the "routing to a monitoring device in response to performing the packet transformation function" recitation.

Why a PHOSITA would combine them — motivation:

  1. Same field, complementary roles. All four references are in the network-security/packet-filtering art. Narayanaswamy (the filter) and Kapoor (the policy manager) were already combined by the Examiner — the combination of a rule-enforcing gateway with a centralized policy source was the conventional architecture for enterprise perimeter security.
  2. Obvious to add monitoring to a filtering gateway. Lawful intercept, network monitoring, and security auditing were well-known, standard functions of enterprise and ISP security gateways long before the priority date (2012). A PHOSITA adding a monitoring/redirection capability to the Narayanaswamy/Kapoor filtering system would naturally look to Johnson (a monitoring/redirect system) and Kjendal (packet transformation functions). The result is a "mere aggregation" or, at most, a predictable combination of known elements, each performing its known function — precisely the situation KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), holds to be obvious.
  3. The applicant itself identified the gaps. The amendment history proves the only features distinguishing the claims over Narayanaswamy/Kapoor were (i) routing to a monitoring device on a packet-by-packet basis and (ii) DSCP-selector criteria. The IPR petition supplied references that teach exactly those features. Where the "gap" between the prior art and the claim is small and precisely identified, the motivation to fill it with known art is strong.
  4. "Packet-by-packet" is not a patentable distinction. The Board's analysis (per the appeal record) treated packet-by-packet identification as the ordinary operation of a packet filter — Narayanaswamy and the cited art (e.g., Reumann's "Adaptive Packet Filters") process packets individually. No unexpected result flows from per-packet evaluation of header criteria.

Combination B — Claims 10–16: Combination A + Diffserv (RFC 2475)

What Diffserv adds: RFC 2475 ("An Architecture for Differentiated Services," Dec. 1998) is the foundational, well-known document defining the DSCP field in the IP header, packet classification based on DSCP, and per-hop behaviors implemented via queuing at different forwarding rates. That maps directly onto:

  • claim 10's "packet-identification criteria compris[ing] a Differentiated Service Code Point (DSCP) selector"; and
  • the dependent claims and specification's enqueueing service — packets placed in different forwarding queues serviced at different rates based on DSCP values (see the specification's DSCP discussion and the "first forwarding queue … serviced at a higher forwarding rate than the second forwarding queue" embodiment).

Why a PHOSITA would add Diffserv to the combination:

  1. Same packet-processing plane. DSCP-based classification and queuing are implemented in the same devices that do security filtering — routers, switches, and security gateways. Integrating security-policy matching with DSCP-based QoS is standard network engineering; the '213 specification itself describes the DSCP rule and the queueing service as optional features of the same dynamic security policy.
  2. Obvious to try with a finite set of known options. Once the security filter already parses IP headers for five-tuple criteria, adding the DSCP field as another selector is an obvious extension — the field is in the same IP header, and RFC 2475 had taught DSCP-based differentiated treatment since 1998. A PHOSITA would have had a reasonable expectation of success in combining rule-based filtering with DSCP-based queueing because both operate on the same packet at the same layer.
  3. No unexpected synergy. The Board (per the appeal record) found the DSCP-based queueing/digest-logging features to be well within the reach of the combined art; Centripetal's appeal challenged only the Board's construction of "dynamic security policy," "monitoring device," and "packet-by-packet" and its motivation findings — not the presence of the DSCP/queueing teachings in Diffserv.

4. Graham-factor assessment

  • Scope and content of the prior art: The art spans packet-filtering gateways (Narayanaswamy; examiner-cited Coss '172, Beebe '372, Kenworthy '837), centralized policy management (Kapoor), monitoring/redirect (Johnson), packet transformation (Kjendal), DSCP QoS (RFC 2475), and adaptive packet filters (Reumann). Collectively, every claim limitation is accounted for.
  • Differences between the claims and the prior art: The applicant's own amendments isolate the differences to (i) redirecting matched packets to a monitoring device and (ii) DSCP-selector criteria for a packet-digest logging function. Both are expressly taught by Johnson/Kjendal and RFC 2475, respectively.
  • Level of ordinary skill: A PHOSITA would be a network engineer or security architect familiar with IP header parsing, firewall/IPS rule engines, centralized policy distribution, and QoS/DSCP mechanisms — i.e., someone who would consider the combination routine.
  • Secondary considerations: The Board considered Centripetal's objective-indicia evidence (per the appeal record, "the Board's determination that the evidence of secondary considerations … was decided adversely" to Centripetal). No nexus-based evidence of commercial success, long-felt need, or copying sufficient to overcome the strong prima facie case was credited. (For context, in the parallel Centripetal/Cisco and Centripetal/Palo Alto IPRs on family members, the Federal Circuit affirmed PTAB unpatentability findings — e.g., Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2023-1654 (Fed. Cir. Oct. 31, 2024), affirming unpatentability of related network-security patents over the Sourcefire User Guide.)

5. Additional art supporting obviousness

Even apart from the IPR combination, the examiner-cited art standing alone supports a strong § 103 case for the broader claims:

  • Reumann et al., "Adaptive Packet Filters" (IEEE 2001) — teaches dynamic, rule-based packet filtering in which filter rules can be updated at runtime — undermining any argument that "dynamic security policies" were novel.
  • US 6,098,172 (Coss), 6,226,372 (Beebe), 6,317,837 (Kenworthy), 6,662,235 (Callis) — perimeter security/filtering systems predating the priority date by a decade or more, showing that policy-driven packet filtering at network boundaries was old and well-developed.
  • US 6,484,261 (Wiegel), 6,611,875 (Chopra) — further packet-filtering/security-policy art in the same space.

These references corroborate that the "invention" is a combination of long-known building blocks (filter + policy server + monitor + QoS) rather than a new technical contribution.


6. Confidence caveats

  • Verified: The exact IPR combination (Narayanaswamy + Kapoor + Johnson + Kjendal ± Diffserv), the claim groupings (1–9; 10–16), the FWD date, the examiner's prosecution rejections, and the claim amendments are all confirmed by the Notice of Appeal (IPR2018-01386, appeal 20-1634) and the file history.
  • Inferred: The specific teachings I attribute to Johnson (monitoring/redirect) and Kjendal (packet transformation) are inferred from their role in filling the exact limitations the applicant added to overcome the Examiner's rejection; I did not retrieve the full text of those patents in this session, so their internal disclosures should be confirmed against the IPR petition (Cisco Ex. 1003/1004) before relying on them in litigation.
  • Unverified: The grounds and outcome of IPR2018-01512; the Federal Circuit's disposition of appeal 20-1634.

7. Bottom line

The § 103 case against US 9,565,213 is unusually strong because the prosecution record self-identifies the only features that distinguished the claims over Narayanaswamy + Kapoor — (1) packet-by-packet routing to a monitoring device and (2) DSCP-selector criteria — and the IPR record supplies references (Johnson, Kjendal, Diffserv/RFC 2475) that teach precisely those features. The Board found all 16 claims unpatentable on those combinations, and the motivation to combine is textbook KSR: known elements (policy-managed filtering, monitoring/redirect, DSCP-based queueing) from the same field, combined in a predictable way to serve known functions, with no unexpected results. A PHOSITA of ordinary skill in network security would have had every reason — and a reasonable expectation of success — to make each of the claimed combinations.

Key sources: Centripetal Notice of Appeal, IPR2018-01386 (Paper 31 FWD, Jan. 23, 2020), https://insight.rpxcorp.com/federal_circuit/[836543](/patent/836543)/...; File History of '213 patent (Cisco Ex. 1002, IPR2018-01512), https://www.docketalarm.com/cases/PTAB/IPR2018-01512/...; Patexia IPR2018-01386 summary, https://services.patexia.com/lawsuits/Cisco-Systems-Inc-v-Centripetal-Networks-Inc-id-[116203](/patent/116203); patent record at https://patents.google.com/patent/US9565213/en; JDSupra summary of Centripetal v. Palo Alto (Fed. Cir. Oct. 31, 2024), https://www.jdsupra.com/post/contentViewerEmbed.aspx?fid=ffa49eac-c43c-4944-abfe-64f8e1e724d4.

Generated 8/30/2026, 12:46:48 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (5)

5 tracked lawsuits name US 9565213.