Invalidity dossier
US 10530903
Correlating packets in communications networks
Current assignee: Centripetal Networks, Inc.
Added 8/30/2026, 4:49:27 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for the specific patent and any CAFC docket activity involving it.
I have strong confirmation of the patent's core details. Now let me verify the full claim set (the patent has 18 claims; I need to identify all independent claims).
Let me retrieve the full text of the independent claims (claim 1 is confirmed; I need claims 10 and possibly 18).
Based on my searches, here is a concise summary of US Patent 10,530,903 (US10530903B2). Note: I was unable to pull the verbatim text of the non-claim-1 independent claims before hitting my search-step limit, so I flag that uncertainty below.
Patent identification
- Patent number: US 10,530,903 B2 (searched as "10530903" — no similar-number substitutions; all results below are for this exact patent)
- Title: Correlating packets in communications networks
- Application: No. 15/413,947, filed January 24, 2017
- Issue date: January 7, 2020
- Priority date: February 10, 2015 (continuation chain: 14/618,967 → US 9,264,370; 14/714,207 → US 9,560,176; 15/413,947 → 10,530,903)
- Inventors: David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH); Pierre Mallett, III (Herndon, VA); Sean Moore (Hollis, NH); Robert T. Perry (Ashburn, VA)
- Assignee: Original/current assignee per Google Patents: Centripetal Networks LLC (original assignee Centripetal Networks LLC; the patent front page lists applicant/assignee as Centripetal Networks, Inc., Portsmouth, NH; a Jan. 20, 2023 reassignment/name-change shows Centripetal Networks, Inc. → Centripetal Networks, LLC)
- Claim count: 18 claims, 7 drawing sheets; primary examiner Obaidul Huq; agent Banner & Witcoff, Ltd.
- Abstract: "A computing system may identify packets received by a network device from a host located in a first network and may generate log entries corresponding to the packets received by the network device. The computing system may identify packets transmitted by the network device to a host located in a second network and may generate log entries corresponding to the packets transmitted by the network device. Utilizing the log entries corresponding to the packets received by the network device and the log entries corresponding to the packets transmitted by the network device, the computing system may correlate the packets transmitted by the network device with the packets received by the network device."
Plain-language overview of independent claims
Claim 1 (method) — verbatim text confirmed via the CAFC opinion in Palo Alto Networks v. Centripetal Networks, No. 2023-1636 (Fed. Cir. Dec. 16, 2024):
- A method comprising:
- determining, by a computing system, that a network device has received, from a first host located in a first network, a plurality of first packets corresponding to first requests for content from a second host located in a second network, wherein the network device comprises a proxy;
- determining, by the computing system, that the network device has generated a plurality of second packets corresponding to second requests, wherein the second requests correspond to the first requests, and wherein the second requests are configured to cause the second host to transmit, to the network device, the content;
- generating, by the computing system, a first plurality of log entries corresponding to the plurality of first packets, wherein each of the first plurality of log entries comprises a receipt timestamp indicating a packet receipt time, and wherein the first plurality of log entries comprise first data from the first requests;
- generating, by the computing system, a second plurality of log entries corresponding to a plurality of second packets, wherein each of the second plurality of log entries comprises a transmission timestamp indicating a packet transmission time, and wherein the second plurality of log entries comprise second data from the second requests;
- determining, by the computing system and for each transmission timestamp, differences between at least one packet transmission time indicated by transmission timestamps and at least one packet receipt time indicated by receipt timestamps;
- correlating, based on the differences and by comparing the first data and the second data, at least a portion of the plurality of first packets and at least a portion of the plurality of second packets; and
- responsive to the correlating: generating, by the computing system, an indication of the first host; and transmitting, by the computing system, the indication of the first host.
Plain language: A computing system watches a proxy network device. It logs packets that come into the proxy from a first host (requests for content from a second host) and logs packets the proxy sends out (corresponding re-issued requests). Each log entry has a timestamp. The system computes the time differences between outbound and inbound packet timestamps and compares the request data on both sides to match outbound packets back to the inbound packets they came from. After matching, the system generates and transmits an indication of the identity of the first (source) host — used to de-obfuscate which host is actually communicating, e.g., to flag communication with a malicious entity.
Claim 10 (independent — likely a system/apparatus claim): I have not verified the verbatim text. Based on IPR2021-01150 briefing (Palo Alto Networks v. Centripetal), claim 10 independently recites the "determining differences" limitation (same as claim 1), and claims 5/14 (network-interface identifier comparison), 8–9/17–18 (generating data/rules for dropping packets), and 16 (generating second packets by encapsulating data from first requests) map in parallel onto claims 1 and 10. The patent's structure strongly suggests claim 10 is a system claim mirroring claim 1's method (a computing system with processor/memory/communication interface configured to perform the same correlation and host-indication steps), but I could not confirm its exact wording from the sources I retrieved.
Other independent claims: Based on the available IPR briefing, the independent claims appear to be claims 1 and 10 only, with dependent claims 2–9 (on claim 1) and 11–18 (on claim 10). I could not confirm whether an additional independent statutory-type claim (e.g., a computer-readable-medium claim) exists, so treat this as inferred rather than authoritative.
Litigation / CAFC 2026 docket status (as reported by Google Patents' litigation feed and news sources)
- IPR2021-01150 (Palo Alto Networks v. Centripetal Networks): challenged claims 1–18 for obviousness (Paxton + Sutton + Ivershen). PTAB final written decision upheld claims; CAFC appeal No. 2023-1636 decided Dec. 16, 2024 — the Federal Circuit vacated and remanded, holding the Board inadequately explained its motivation-to-combine analysis (precedential). Per Patexia, the PTAB issued a subsequent final written decision dated July 21, 2025.
- CAFC 2026 docket entries tied to this patent family per Google Patents' litigation metadata: cases 26-1359, 25-1168, 25-1167, 25-1993, and 23-1636 (Federal Circuit), plus Virginia Eastern District Court cases 2:21-cv-00137 and 1:21-cv-00313. I could not retrieve the specific subject matter of the 2025/2026 docket entries (25-1167, 25-1168, 25-1993, 26-1359) before hitting my search limit, so I cannot state what those appeals concern.
- A Law360 article dated July 21, 2026 reports a Federal Circuit panel affirming a PTAB decision declining to strike Centripetal claims — plausibly related to this patent family, but I could not confirm it concerns the '903 patent specifically.
Uncertainty notes
- Claim 1 text is authoritative (quoted in the CAFC slip opinion). The exact wording of claim 10 (and the existence of any third independent claim) is inferred from IPR briefing, not confirmed verbatim — I recommend pulling the claims from USPTO Patent Center or Google Patents to verify.
- The subject matter of the 2025/2026 CAFC docket numbers associated with this patent was not retrievable in my searches; the litigation entries are as listed on Google Patents' page for US10530903B2.
Sources: Google Patents (US10530903B2); CAFC opinion, Palo Alto Networks v. Centripetal Networks, No. 2023-1636 (Dec. 16, 2024) (via CourtListener); IPR2021-01150 Patent Owner's Response (DocketAlarm); Patexia IPR summary; A&O Shearman/JD Supra/Lexology case notes; Law360 (July 21, 2026).
Generated 8/30/2026, 6:48:25 PM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 10530903. The free-form analysis below may also discuss cases beyond this list.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10091246, 10567437, 10567413, 10659573, 10757126, 10542028, 10503899, 10735380, 10749906, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10749906, 10091246, 10503899, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10757126, 10785266, 10931797
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I have good initial results. Let me verify the remaining case numbers referenced for this patent family (CAFC appeals and the other Virginia case).
Litigation Involving U.S. Patent No. 10530903 (the "'903 patent," "Correlating Packets in Communications Networks")
Based on searches of the patent's Google Patents litigation record, Unified Patents/PTAB portals, DocketAlarm, Justia, CourtListener, PACER-derived dockets, and practitioner summaries, the known proceedings are as follows. Note that the '903 patent is part of Centripetal's "Correlation Patents" family (with the '573 and '797 patents), so it appears in multi-patent cases.
1. Centripetal Networks, Inc. v. Palo Alto Networks, Inc. — E.D. Va. (district court)
- Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
- Defendant: Palo Alto Networks, Inc.
- Jurisdiction / case numbers: U.S. District Court for the Eastern District of Virginia — initially filed in the Alexandria Division as 1:21-cv-00313, then transferred intradistrict to the Norfolk Division as 2:21-cv-00137 (2:21-cv-00137-RCY-RJK, later 2:21-cv-00137-EWH-LRL)
- Filing date: March 12, 2021
- Patents: Thirteen Centripetal patents, including US10530903 (the '903 patent was one of the "Correlation Patents" tried to the jury)
- Outcome / status: Jury returned a $151.1 million verdict for Centripetal. Post-trial, the court granted Palo Alto's Motion for Judgment as a Matter of Law in part and denied it in part, denied the new-trial motion (Memorandum Opinion filed under seal), with judgment entered around October 3, 2024; the case was closed on the docket October 17, 2024. Appeals are pending at the Federal Circuit (see items 4–6 below). Sources: DocketAlarm (docket 2:21-cv-00137 listing US10530903 among asserted patents), Justia docket for 1:21-cv-00313 (intradistrict transfer to 2:21cv137), RPX (verdict), PatSnap litigation summary.
2. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — PTAB IPR
- Case: IPR2021-01150 (U.S. Patent No. 10,530,903 — note: documents in this proceeding use the identifier "10,530,903," which is the same '903 patent; the PTAB case covers claims 1–18)
- Petitioner: Palo Alto Networks, Inc.
- Patent owner: Centripetal Networks, Inc.
- Filing date: July 20, 2021
- Institution: February 16, 2022
- Ground: Obviousness over Paxton (US 2014/0280778) and Sutton (US 8,413,238) in view of Ivershen (US 8,219,675)
- Outcome: Final Written Decision (Feb. 15, 2023) held Palo Alto failed to prove the claims unpatentable. Appealed to the Federal Circuit (see item 3). A further decision on remand is listed by Patexia with a July 21, 2025 decision date. Sources: Patexia summary; RPX Insight; DocketAlarm PTAB docket; Patent Owner's Response.
3. Palo Alto Networks, Inc. v. Centripetal Networks, LLC — CAFC (IPR appeal)
- Case: Appeal No. 23-1636 (Federal Circuit)
- Parties: Appellant Palo Alto Networks, Inc. v. Appellee Centripetal Networks, LLC (fka Centripetal Networks, Inc.)
- Subject: Appeal of IPR2021-01150 (the '903 patent)
- Outcome / status: On December 16, 2024, the Federal Circuit vacated and remanded the Board's Final Written Decision, holding the PTAB failed to adequately explain its reasoning on the motivation to combine Paxton and Sutton (and analyzing the references individually rather than in combination). Matter remanded to the PTAB; a subsequent PTAB decision on remand is reflected with a July 21, 2025 date in Patexia. Sources: CourtListener opinion (23-1636), Lexology and A&O Shearman summaries, California Lawyers Association New Matter article.
4–6. Federal Circuit appeals from the E.D. Va. case (and related appeals)
The patent's Google Patents litigation record lists additional CAFC dockets tied to this patent family:
- 25-1167 and 25-1168 — CAFC appeals relating to Centripetal Networks, LLC v. Palo Alto Networks, Inc. (2:21-cv-00137). Docket entries (e.g., DocketAlarm No. 1017 in 2:21-cv-00137) show the CAFC reactivating appeal 25-1167 on December 22, 2025 under FRAP 4(a)(4). Status: pending.
- 25-1993 and 26-1359 — also listed on the patent's litigation page as CAFC cases involving this patent/family, but I was unable to verify their specific subject matter or parties within the available search results, so I cannot state their details with confidence.
7. Related PTAB/administrative context
- The PTAB proceeding IPR2021-01150 is the principal validity challenge to the '903 patent. Earlier Cisco IPRs (e.g., IPR2018-01654/01655) cited in the '903 IPR record involved related Centripetal patents, not the '903 patent itself.
- The Google Patents page also flags "First worldwide family litigation filed" via Darts-ip for the patent family.
Caveats
- 1:21-cv-00313 and 2:21-cv-00137 are the same case (original filing, then intradistrict transfer to Norfolk); they should not be double-counted.
- I did not find any district-court case asserting the '903 patent against Cisco, Keysight, or others; those litigations (e.g., Centripetal v. Cisco, 2:18-cv-00094; Centripetal v. Keysight) involved other Centripetal patents. The '903 patent issued January 7, 2020, after those cases were filed.
- The July 21, 2025 PTAB decision date comes from Patexia's case summary and appears to reflect the remand decision; I could not independently verify its full text in the searches performed.
Generated 8/30/2026, 6:48:56 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Centripetal Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
The USPTO ODP block in this prompt reports zero AIA trial proceedings on file for US 10,530,903 — but that ingest is stale: web search confirms one IPR, IPR2021-01150 (Palo Alto Networks v. Centripetal Networks), which is also listed on the patent's own Google Patents page. That IPR has gone to a Final Written Decision twice — the 2023 FWD sustained all 18 claims, the Federal Circuit vacated it on analytical-error grounds, and the Board on remand again found all claims patentable (2025-07-21, per PTAB trackers), with a second appeal now pending. Bottom line for a defendant: zero claims canceled — all 18 claims of the '903 patent have now survived the same obviousness challenge twice at the Board, so the patent is hardened, not broken; any validity defense must be built on art and arguments other than the Paxton/Sutton/Ivershen combination, and Palo Alto's own estoppel is still in flux because the proceeding has not gone final.
IPR2021-01150 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review
- Filed: 2021-07-20 (Petition, Paper 2)
- Status: Not reflected in the ODP block (ODP shows no proceedings); Google Patents lists "PTAB case IPR2021-01150 filed (Final Written Decision)." PTAB trackers (Patexia, RPX, ai-lab.exparte) show: instituted 2022-02-16 → FWD 2023-02-16 → CAFC vacatur and remand → second FWD 2025-07-21 → "Final Written Decision – Appealed." Plain-English gloss: the IPR is alive on appeal; no claim has ever been canceled.
- Judge panel: FWD panel — Stacey G. White (authoring APJ), Jon M. Jurgovan, Aaron W. Moore. (A Panel Change Order was entered 2022-04-22; the FWD panel is as stated.) Oral hearing held 2022-10-31.
- Petition grounds: One ground — claims 1–18 alleged obvious under 35 U.S.C. § 103 over US 2014/0280778 ("Paxton") and US 8,413,238 ("Sutton") in view of US 8,219,675 ("Ivershen"). PAN relied on Paxton for all elements of independent claim 1 except the final "transmitting an indication of the first host responsive to the correlating" limitation, which it sourced to Sutton's teaching of notifying administrators about devices suspected of malicious activity. (No § 102, no § 112 grounds.)
- Institution decision: Instituted on all challenged claims (1–18) on the sole § 103 ground — Paper 9, 2022-02-16.
- Final Written Decision (first, 2023-02-16, Paper 37): "Determining No Challenged Claims Unpatentable." All claims 1–18 held patentable; the Board found PAN failed to prove, by a preponderance of the evidence, that the Paxton/Sutton/Ivershen combination taught the "responsive to the correlating" transmission limitation. The Board said it was left "with a correlation from Paxton with no specific actions taken post-correlation, and a transmission from Sutton unrelated to any correlation, but without the necessary bridge showing that one of ordinary skill in the art would have appreciated that the transmission would be responsive to the correlation." See FWD Paper 37 (P.T.A.B. Feb. 16, 2023) (DocketAlarm copy).
- Settlement / termination: None. No settlement; the parties litigated through FWD and appeal.
- Appeal (first): CAFC No. 2023-1636, Palo Alto Networks, Inc. v. Centripetal Networks, LLC, decided 2024-12-16 (precedential) — vacated and remanded. The court held the Board (1) never made a clear finding on whether a POSITA would have been motivated to modify Paxton with Sutton's notification step, and the unexplained "necessary bridge" language made its reasoning unreviewable ("If the Board meant to say that it found no motivation to combine—and we do not know whether it did—it certainly failed to explain why…"); and (2) erred by analyzing Paxton and Sutton individually rather than as the proposed combination ("Paxton and Sutton must be read together, not in isolation"). See CourtListener opinion 10293067; IPWatchdog coverage.
- Final Written Decision (on remand, 2025-07-21): Per PTAB trackers (Patexia decision date 2025-07-21; ai-lab.exparte "FWD 07/21/25," outcome "Patentable"), the Board again determined no challenged claim unpatentable. I could not pull the remand Paper itself to quote the claim-level reasoning — verify on PTAB E2E / USPTO before relying on the specifics.
- Appeal (second, pending): CAFC 25-1993, Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — PAN appealing the remand FWD (per Justia docket listing; exact filing date not verified). Disposition: pending.
- Defensive value: Mixed but net-positive for the patent owner. The only IPR on this patent produced zero canceled claims — PAN has now lost the same obviousness ground twice at the Board (2023 and 2025). A defendant facing assertion today cannot point to a single canceled claim, and an IPR-based defense re-running Paxton/Sutton/Ivershen is both unlikely to be instituted (cumulative) and, for PAN itself, estoppel-barred once the proceeding goes final.
Related, not-on-'903 dockets for context: Palo Alto filed IPRs/PGRs against other Centripetal patents in the same campaign (e.g., PGR2021-00108, where the '903 patent appears only as an exhibit; and an IPR on the '856 patent, CAFC No. 23-2027, decided 2025-10-22). The parallel E.D. Va. infringement case (Centripetal v. Palo Alto, No. 2:21-cv-00137), which was stayed pending IPR2021-01150, produced its own consolidated CAFC appeal, Nos. 25-1167 / 25-1168 (filed 2024-11-13, reactivated 2025-12-22, appellant's brief due 2026-02-20) — that is a district-court appeal, not a PTAB appeal. Google Patents also lists CAFC case 26-1359 involving this patent; I could not verify its subject matter and flag it as unconfirmed.
Strategic summary
Claims status — CANCELED vs. SUSTAINED vs. UNTESTED. Every claim of US 10,530,903 — claims 1–18 — was challenged in IPR2021-01150 and every one was SUSTAINED in the 2023 FWD and again on remand in 2025. No claim of the '903 patent has ever been canceled in an AIA trial proceeding. There are no untested claims (all 18 were challenged), so the "narrowed through IPR" scenario does not apply — the patent is full-strength. Independent claims 1 and 10 anchor dependent claims 2–9 and 11–18, all of which survived.
Estoppel landscape. Under 35 U.S.C. § 315(e)(2), once the IPR results in a final written decision, Palo Alto Networks — and its privies — is barred from asserting in the E.D. Va. case (2:21-cv-00137) any ground it raised or reasonably could have raised: i.e., § 103 over Paxton, Sutton, Ivershen, and combinations thereof. Note the caveat: because the 2023 FWD was vacated and the remand FWD is itself on appeal (CAFC 25-1993), the proceeding is not yet "final," so estoppel is not fully settled for PAN. Critically, estoppel binds only PAN and privies — a new defendant is free to raise any § 102/§ 103/§ 112 ground, including different art or different combinations of Paxton/Sutton with other references (the Paxton/Sutton combination itself is now battle-tested and twice rejected, so it is a weak centerpiece for any new petition).
Pattern signals. One petitioner (Palo Alto Networks) has run a coordinated multi-patent attack on Centripetal's portfolio — IPR2021-01150 on the '903, plus IPRs/PGRs on sibling Centripetal patents (e.g., the '856 patent, where the CAFC in 23-2027 vacated a Board invalidity finding on secondary-considerations grounds). Centripetal has defended aggressively and successfully: it won the '903 IPR twice and has twice obtained CAFC remands favorable to it in this dispute (2023-1636 on '903; 23-2027 on '856). There is no defensive aggregator in the chain — the "Unified Patents" attribution on Google Patents is just the litigation-data source license, not the petitioner; the petitioner is Palo Alto Networks directly. The absence of any second IPR on the '903 by other defendants is itself a signal: after two Board wins for Centripetal on the same ground, would-be petitioners have not found a credible alternative theory — a reality that should temper any defendant's expectations of killing this patent at the PTAB.
Recommended next steps
- Do not tell your client the patent is weakened — it is not. The only IPR produced no canceled claims: the 2023 FWD held "Petitioner has not shown by a preponderance of the evidence that claims 1–18 are unpatentable" (Paper 37, DocketAlarm), and the remand FWD (2025-07-21) again returned "Patentable." Pull the remand FWD from PTAB E2E (Unified Patents portal) and quote its disposition before filing anything, since the 2025 paper is the operative decision.
- Watch the two pending CAFC dockets. (a) 25-1993 — PAN's appeal of the 2025-07-21 remand FWD; a decision against Centripetal would put claims 1–18 back in play at the Board. (b) 25-1167 / 25-1168 — the E.D. Va. appeal (Centripetal's infringement case), reactivated effective 2025-12-22 with appellant's brief due 2026-02-20; this will drive any settlement pressure. Monitor both via CourtListener/PACER.
- If you are a new defendant (not PAN or a privy): § 315(e)(2) does not bind you. A fresh IPR remains available on different art or different combinations — but the Paxton/Sutton/Ivershen combination is now a twice-litigated loser and a poor foundation for a petition. Budget instead for a district-court validity defense on non-Paxton art, and expect the E.D. Va. litigation (where Centripetal has already won a stay-through-IPR and is pursuing the case) to be the main battleground.
- If you are PAN or a privy: understand that the vacatur/remand posture means estoppel timing is contested; brief the issue early in the district court if you intend to relitigate any Paxton/Sutton-based ground — you are likely barred from doing so once the remand FWD is affirmed or the appeal concludes.
Verification note: the ODP "no proceedings" default is contradicted by web sources (Patexia, RPX, CourtListener, USPTO-adjacent trackers, and the patent's own Google Patents litigation block all confirm IPR2021-01150). Treat the ODP ingest as incomplete. The 2025-07-21 remand FWD and the 25-1993 appeal are corroborated by secondary trackers but I could not verify the underlying PTAB/CAFC papers directly — confirm via PTAB E2E and PACER before relying on them in a filing.
Generated 8/30/2026, 6:49:30 PM
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment records for US 10530903 through USPTO sources and cross-references. Let me run several searches in parallel.
I've confirmed key facts about the patent and its litigation. Now I need the actual USPTO assignment records with reel/frame numbers. Let me search for those specifically.
I've hit my search budget for this session, so I'll now consolidate what I could verify from the available records (Google Patents legal-event data included in the patent text, court dockets, PTAB records, ITC notices, and trademark filings) and be explicit about what I could not retrieve (USPTO reel/frame and correspondent data).
Inventors
| Inventor | Residence on patent | Employer at filing (inferred) |
|---|---|---|
| David K. Ahn | Winston-Salem, NC | Centripetal Networks, Inc. |
| Peter P. Geremia | Portsmouth, NH | Centripetal Networks, Inc. |
| Pierre Mallett, III | Herndon, VA | Centripetal Networks, Inc. |
| Sean Moore | Hollis, NH | Centripetal Networks, Inc. |
| Robert T. Perry | Ashburn, VA | Centripetal Networks, Inc. |
All five inventors are named on numerous other Centripetal-family patents, and their listed cities track Centripetal's offices (Portsmouth NH / Herndon & Reston VA), so employer-at-filing is Centripetal Networks, Inc. (per the patent's own (71) Applicant: Centripetal Networks, Inc., Portsmouth, NH (US) field). I found no evidence of a mass inventor departure within 12 months of filing, or of any inventor-side portfolio fire-sale — the unusual item here is that the inventors' assignment appears to have been recorded only in January 2023 (see below), ~3 years after grant.
Original assignee
Centripetal Networks, Inc. (renamed Centripetal Networks, LLC after a Delaware statutory conversion effective 2022-12-30; see court notices in Centripetal Networks, LLC v. Cisco Systems, Inc., E.D. Va. 2:18-cv-00094, Dkt. 673, and Centripetal Networks, LLC v. Keysight Technologies, Inc., E.D. Va. 2:22-cv-00002, Dkt. 55). Google Patents normalizes the "Original Assignee" to the current LLC name.
- Products: Yes — an operating network-security vendor. USPTO trademark registrations for CENTRIPETAL (Reg. 6312115) and AI-ANALYST (Reg. 6585061) cover "computer hardware and downloadable computer software … for IP network filtering, and managing computer network security" and security services. Product lines include RuleGuard, CleanINTERNET, and AI-Analyst. The '903 claims (proxy-based packet correlation to de-obfuscate host identity) map directly onto this filtering/threat-detection product line.
- Primary line of business: Network security / cyber-threat detection / packet-filtering appliances.
- Current status: Operating. Still prosecuting patents (e.g., US 11,956,338 filed 2023; US 2025/0039284 filed 2024) and still litigating (CAFC appeals 23-1636, 25-1167, 25-1168, 25-1359, 25-1993; ITC 337-TA investigation instituted May 2022). No bankruptcy.
Assignment timeline
Important caveat: I could not complete a live USPTO Assignment Center lookup for reel/frame numbers or correspondent-of-record names within my search budget. The two post-grant events below are verified from the Google Patents legal-event feed (which mirrors USPTO assignment records) and from court/ITC filings confirming the name change. Reel/frame and correspondent fields are not retrieved and should be verified at https://assignmentcenter.uspto.gov/ before reliance.
Executed ~2015–2017 / recorded 2023-01-20 — Reel not retrieved
- Conveyance: Assignment of Assignors Interest (confirmatory inventor assignment)
- Assignor: David K. Ahn, Sean Moore, Pierre Mallett III, Peter P. Geremia, Robert T. Perry
- Assignee: Centripetal Networks, Inc.
- Correspondent: not retrieved
- Context: recordation of the inventors' assignment was deferred until January 2023 — three years after grant and in the middle of the Cisco / Palo Alto / Keysight / ITC assertion campaign — consistent with perfecting chain of title for litigation standing rather than a substantive transfer.
Executed 2022-12-30 (conversion) / recorded 2023-01-20 — Reel not retrieved
- Conveyance: Change of Name
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: not retrieved
- Context: Delaware statutory conversion of the corporation into a Delaware LLC under Del. Code Ann. tit. 6, § 18-214 (same entity by operation of law; address 1875 Explorer St., Suite 900, Reston, VA 20190); name change only, confirmed by the E.D. Va. notices and the 2023 ITC name-change order.
No other assignments (pre- or post-issuance) are reflected in the Google Patents legal-event feed for this patent. If the Assignment Center likewise shows only these two entries, the original operating assignee (Centripetal Networks, Inc., now LLC) still owns the patent.
Timeline diagram
timeline
title Ownership of US 10530903
2015 : Priority filed by Centripetal
2017 : Continuation application filed
2020 : Patent issued
2021 : Palo Alto suit filed
: Palo Alto IPR filed
2022 : Converted to Delaware LLC
2023 : Inventor assignment recorded
: Change of name recorded
2024 : Federal Circuit remand
NPE / troll-pattern signals
Shell-entity transfer — not present. The only post-grant LLC in the chain (Centripetal Networks, LLC) is the same operating entity created by Delaware statutory conversion (E.D. Va. Dkt. 673 in 2:18-cv-00094; Dkt. 55 in 2:22-cv-00002), not a licensing-only shell. The company ships products (trademark regs 6312115, 6585061) and its address is its actual Reston, VA HQ, not a registered-agent service.
Known asserter in the chain — not present. Neither Centripetal Networks, Inc. nor Centripetal Networks, LLC appears on the standard NPE lists (Acacia, Marathon, IV, Conversant, Spangenberg entities, etc.). It is a practicing network-security vendor that happens to be a repeat plaintiff against competitors — that alone is not an NPE-list match.
Repeat correspondent across the chain — unclear / not verifiable. I could not retrieve correspondent-of-record data for the two 2023 records. For context: prosecution attorney of record was Banner & Witcoff, Ltd. (patent front page), and E.D. Va. litigation counsel of record included Stephen E. Noona (Kaufman & Canoles). No evidence of a recurring NPE-side recording attorney, but also no data to rule one out.
Cascading transfers — not present. Only two same-day (2023-01-20) records: a confirmatory inventor assignment and a name change. No chained-LLC transfer sequence.
Pre-litigation transfer — not present. The '903 patent issued 2020-01-07 and was first asserted in Centripetal Networks, Inc. v. Palo Alto Networks, Inc., 2:21-cv-00137 (E.D. Va., filed 2021; '903 appears as an exhibit at Dkt. 652-1). The assignments recorded 2023-01-20 come two years after that suit, so they were not arranged to enable it.
Bankruptcy fire-sale — not present. No Chapter 7/11 proceedings involving the assignor; the original assignee remains operating.
Privateering — not present. Centripetal asserts the patent in its own name against direct competitors (Palo Alto Networks, Cisco, Keysight, and an ITC 337 investigation), which is the opposite of an operating company handing patents to a third-party NPE.
Defensive aggregator (anti-NPE) — not present. The chain terminates at Centripetal Networks, LLC (an operating company), not RPX, AST, LOT, Unified Patents, or OIN.
Verdict
Operating-company assertion.
The current assignee, Centripetal Networks, LLC (f/k/a Centripetal Networks, Inc.), ships network-security products embodying the claimed packet-correlation technology and is asserting the '903 patent against actual competitors (Palo Alto Networks in E.D. Va. 2:21-cv-00137, with related campaigns against Cisco, Keysight, and an ITC investigation). The only recorded assignments — a 2023-01-20 confirmatory inventors' assignment and the same-day Delaware Inc→LLC change of name — are routine title housekeeping tied to an ongoing assertion campaign, not NPE structuring; there are no shell transfers, no cascading LLCs, no pre-litigation transfers, and no known-asserter or defensive-aggregator terminus. Caveat: reel/frame and correspondent data could not be live-verified in this session, so a final confirmation at the USPTO Assignment Center is recommended.
Verify: https://assignmentcenter.uspto.gov/ (search patent 10530903) · https://assignment.uspto.gov/patent/index.html
Generated 8/30/2026, 6:49:59 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research US Patent 10530903 and its cited prior art. Let me start by locating the patent record and its citations.
I found key leads, including the PTAB/IPR records. Let me dig deeper into the patent's full citation list and the IPR prior art.
I now have the IPR context. Next, I need the complete "References Cited" list from the patent's front page. Let me retrieve it.
I have reached the search limit for this session, but I've gathered substantial verified information from the USPTO/PTAB record, the patent itself, and litigation materials. Below is my analysis, with clear confidence markers where verification is incomplete.
US Patent 10,530,903 B2 — Prior Art Analysis
1. Patent Identification (verified)
| Field | Value |
|---|---|
| Patent No. | US 10,530,903 B2 (also written US10530903B2) |
| Title | Correlating packets in communications networks |
| Inventors | David K. Ahn; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry |
| Assignee | Centripetal Networks LLC (now Centripetal Networks, Inc./LLC) |
| Application | US 15/413,947, filed 2017-01-24 (continuation) |
| Grant date | 2020-01-07 |
| Priority date / earliest effective filing date | 2015-02-10 (US 14/618,967 → US 9,264,370; then US 14/714,207 → US 9,560,176) |
| Claims | 18 claims (independent claims 1 and 10; dependent claims 2–9, 11–18) |
| Status | Active; anticipated expiration 2035-02-10 |
Applicable law: Because the earliest effective filing date (Feb. 10, 2015) is after March 16, 2013, the AIA version of § 102 applies. Prior art includes (a)(1) anything publicly available before Feb. 10, 2015, and (a)(2) US patent documents effectively filed before Feb. 10, 2015. Every reference on the face of the '903 patent predates this date, so each is § 102 prior art by date — but date qualification is only the threshold; the harder question is disclosure content.
Claim 1 (independent, method) — key limitations:
- Determining a network device (a proxy) received first packets from a first host (first network) = first requests for content from a second host (second network);
- Determining the network device generated second packets = second requests corresponding to the first requests, configured to cause the second host to send content to the network device;
- Generating first log entries (receipt timestamps; first data from first requests);
- Generating second log entries (transmission timestamps; second data from second requests);
- Determining differences between transmission times and receipt times;
- Correlating based on the differences and by comparing first/second data;
- Responsive to the correlating: generating an indication of the first host and transmitting the indication of the first host.
Dependent claims 2–6 add comparisons (ports, protocol types, application-layer data, network-interface identifiers, times); claim 8 adds generating data to cause the first network to drop the first host's packets; claim 9 adds generating/provisioning rules to a packet-filtering device and dropping identified packets. Claim 10 is the apparatus counterpart (claims 11–18 mirror 2–9).
2. Most Relevant Prior Art (verified via IPR2021-01150 record)
The definitive relevance ranking comes from Palo Alto Networks, Inc. v. Centripetal Networks, Inc., IPR2021-01150 (petition filed 2020-07-20/2021-07-20; institution decision 2022-02-16; final written decision 2025; Federal Circuit vacate-and-remand 2024-12-16, appeal 2023-1636). The petition challenged all claims 1–18 on a single ground: obviousness over Paxton + Sutton, in view of Ivershen (35 U.S.C. § 103). Notably, no ground of anticipation (§ 102) by any single reference was asserted, and the PTAB ultimately found the combination did not teach the final "transmitting an indication of the first host" limitation.
Reference 1 — "Paxton": US Patent Application Publication 2014/0280778 A1
- Full citation: Paxton et al., [title per USPTO record — not independently verified in this session], U.S. Patent Application Publication No. 2014/0280778 A1, published 2014 (pre-AIA/AIA § 102(a)(1) prior art; before the Feb. 10, 2015 effective filing date).
- Description (from IPR record): Paxton was the primary reference, relied on by the petitioner for the majority of claim 1's elements — detecting/identifying a host via packets, generating log entries, and correlating received vs. transmitted packets. Per the PTAB's final written decision, Paxton "expressly teaches creating a log and notifying a network administrator of the identified host," but the Board found Paxton's disclosure ends at "a correlation with no specific actions taken post-correlation."
- § 102 anticipation assessment: Paxton alone likely discloses limitations (a)–(f) of claim 1 (receipt/transmission determination, log generation with timestamps, difference computation, correlation). However, per the PTAB's finding, Paxton does not disclose the claim-1 final limitation — generating and transmitting an indication of the first host responsive to the correlating. Because every claim (1–18) incorporates that final limitation, Paxton alone does not anticipate any claim in full as found by the Board. It would be the strongest single-reference anticipation candidate for a partial/limitation-level mapping, but the Board's record contradicts full anticipation.
Reference 2 — "Sutton": US Patent 8,413,238 B2
- Full citation: Sutton, U.S. Patent No. 8,413,238 B2, granted 2013 (approximately Apr. 2, 2013 — verify exact date at USPTO; AIA § 102(a)(2) prior art).
- Description (from IPR record): Sutton supplies the final limitation of claim 1 — notification of network administrators about devices suspected of malicious activity (i.e., generating and transmitting an indication of a host). The Federal Circuit summarized: PAN argued a skilled artisan would be motivated to combine Paxton's packet-correlation technique with Sutton's administrator-notification feature "to improve network security."
- § 102 anticipation assessment: Sutton discloses the notification/indication-and-transmission element, but does not disclose Paxton's packet-correlation engine, proxy-based request mapping, timestamp-difference correlation, or log-entry structure. Sutton alone does not anticipate any claim in full.
Reference 3 — "Ivershen": US Patent 8,219,675 B2
- Full citation: Ivershen, U.S. Patent No. 8,219,675 B2, granted July 2012 (confirmed by the patent's own face-citation list: "7/2012 Ivershen"; AIA § 102(a)(2) prior art).
- Description (from IPR record): A secondary reference combined "in view of" the Paxton/Sutton pair to fill remaining gaps in the obviousness case (the petition's Ground 1: "Claims 1–18 are obvious over Paxton and Sutton in view of Ivershen").
- § 102 anticipation assessment: No anticipation assertion was made against Ivershen; it functions as a gap-filler in the § 103 combination. Ivershen alone does not anticipate any claim in full on the available record.
Bottom line on the "big three": The PTAB's final written decision (and the Federal Circuit's 2024 vacate-and-remand on the motivation-to-combine analysis) confirms that no single prior-art reference was found to teach all elements of claim 1 — in particular the post-correlation transmission of the host indication. On the current record, no cited reference anticipates claims 1–18 under § 102; the asserted invalidity theory is § 103 obviousness, and even that remains unresolved (remanded).
3. Other Prior Art Identified in the IPR/PGR Record (secondary relevance)
From the IPR2021-01150 exhibit list (Petitioner's Reply exhibit table), these additional references were proffered and are either face-cited or otherwise relevant:
| Exhibit | Reference | Notes |
|---|---|---|
| 1006 | US 7,185,368 B2 ("Copeland") — "Flow-based detection of network intrusions," granted 2007 (face citation: "2/2007 Copeland, III") | Flow-based intrusion detection; correlates flows; relevant to claims 1, 4, 6, 10, 13, 15 on flow/correlation concepts |
| 1008 | US 2013/0262655 A1 ("Deschenes") | Published 2013; § 102(a)(1) prior art |
| 1009 | EP 2,482,522 A1 ("McDonald") | European publication |
| 1010 | US 8,621,556 B2 ("Bharali") | Granted 2013 |
| 1011 | US 9,628,512 B2 ("Pronger") | Granted 2017 — note: granted after the 2015 effective filing date; only qualifies under § 102(a)(2) if effectively filed before 2015-02-10 |
| 1013 | US 2006/0048142 A1 ("Roese") | Published 2006 |
| 1014 | US 2008/0163333 A1 ("Kasralikar") | Published 2008 |
| 1015 | US 2012/0240185 A1 ("Kapoor") | Published 2012 |
| 1016 | WO 2014/001773 A1 ("Jarvis") | Published 2014 |
I could not verify the complete disclosure content of each of these in this session, so I will not fabricate per-claim anticipation mappings for them.
4. Citations on the Face of US 10,530,903 B2 (partial, as captured)
The front-page "References Cited" list was captured in part from PTAB Exhibit 1028 (DocketAlarm copy of the patent). The list was truncated in the available source, so the following is a partial reconstruction — I flag it as such rather than guess at the omitted entries.
U.S. Patents (partial — date + first inventor):
Beebe et al. (5/2001); Vaidya (8/2001); Kenworthy (11/2001); Wiegel (11/2002); Chopra et al. (8/2003); Callis et al. (12/2003); Dutta et al. (11/2004); Nagai et al. (8/2006); Ke et al. (8/2006); Chen et al. (9/2006); Coss et al. (11/2006); Green et al. (12/2006); Copeland, III (2/2007); Ferguson et al. (5/2007); Watanabe (5/2007); Ji et al. (6/2007); Rayes et al. (6/2007); Woo et al. (8/2007); Hill et al. (11/2007); Le Pennec et al. (11/2007); Ramsey et al. (2/2008); Lyon (1/2009); Matityahu et al. (3/2009); Aerrabotu et al. (5/2009); Turley et al. (10/2009); Govindarajan et al. (3/2010); Ilnicki et al. (5/2010); Salminen et al. (5/2010); Matsuda (9/2010); Malik (10/2010); Strayer et al. (10/2010); Wittman (10/2010); Bloch et al. (12/2010); Rouland et al. (3/2011); Aaron (5/2011); Darisi et al. (8/2011); Zuk et al. (8/2011); Fulp et al. (10/2011); Spielman (2/2012); Kiley et al. (4/2012); Hurst et al. (5/2012); Ivershen (7/2012); Rajan et al. (9/2012); Kenworthy (11/2012); Davis et al. (11/2012); Newton et al. (12/2012); Zhu (4/2013).
U.S. Patents (partial — number-only entries): 8,495,725 B2; 8,510,821 B1; 8,726,379 B1; 8,806,638 B1; 8,856,926 B2; 8,935,785 B2; 9,094,445 B2; 9,124,552 B2; 9,137,205 B2; 9,154,446 B2; 9,160,713 B2; 9,172,627 B2; 9,419,942 B1; 9,531,672 B1; 9,634,911 B2; 9,686,193 B2.
U.S. Published Applications (partial): 2001/0039579 A1; 2001/0039624 A1; 2002/0016858 A1; 2002/0038339 A1; 2002/0049899 A1; 2002/0083345 A1 ("Method and system for secure communication over unstable public connections" — title verified via search result); 2002/0112188 A1; 2002/0152209 A1; 2002/0164962 A1; 2002/0165949 A1; 2002/0186683 A1; 2002/0198981 A1; 2003/0005122 A1; 2003/0018591 A1; 2003/0035370 A1; … (list truncated in source).
Titles verified for a few face-cited publications (via search-result snippets): US 2003/0051026 A1 — "Network surveillance and security system"; US 2004/0098511 A1 — "Packet routing method and system that routes packets to one of at least two processes based on at least one routing rule"; US 2005/0249214 A1 — "System and process for managing network traffic." For the remainder, I do not have verified titles or disclosure content and will not speculate.
5. Claim-by-Claim § 102 Anticipation Assessment
| Claim(s) | Most relevant reference(s) | Anticipation (§ 102) assessment |
|---|---|---|
| 1 (independent) | Paxton; Sutton | Not anticipated by any single reference. Paxton covers the correlation/logging engine but (per PTAB) no post-correlation action; Sutton covers notification but not correlation. All elements must appear in one reference for § 102. |
| 2 (ports) | Paxton | Comparison-of-ports limitation is within Paxton's correlation teaching, but the claim inherits claim 1's full scope; no single-reference anticipation on the record. |
| 3 (protocol types) | Paxton | Same analysis as claim 2. |
| 4 (application-layer data) | Paxton; Copeland | Paxton's correlation of request data is the closest; Copeland's flow-based detection is relevant. Still no single-reference full anticipation. |
| 5 (network-interface IDs) | Paxton (environmental variables) | Same. |
| 6 (times) | Paxton; Ivershen | Timestamp-difference correlation is central to Paxton and Ivershen; still subsumed in claim 1's full scope. |
| 7 | (claim text not captured in this session — truncated in source) | Cannot assess without verified claim text. |
| 8 (drop packets) | Sutton / rule-based filtering refs | No single reference shown to combine correlation + responsive drop. |
| 9 (rules → packet-filtering device) | Sutton; Copeland; rule-based filtering refs | No single-reference anticipation shown on the record. |
| 10–18 (apparatus) | Mirrors 1–9 | Same conclusion; the apparatus claims track the method claims. |
Overall § 102 conclusion: On the verified IPR/PGR record, no prior-art reference — including Paxton, Sutton, and Ivershen — was established to anticipate any of claims 1–18. The only invalidity ground pursued against all claims was § 103 obviousness (Paxton + Sutton, in view of Ivershen), and the PTAB's final written decision found that combination insufficient as to the final "transmitting an indication of the first host" limitation; the Federal Circuit then vacated and remanded (Dec. 16, 2024) for the Board to better articulate its motivation-to-combine analysis. That remand was still pending as of the most recent litigation records reviewed.
6. Confidence & Verification Notes (candid)
- High confidence (verified this session): Patent number/title/inventors/assignee/dates; claim 1 text; the 18-claim structure; IPR2021-01150 ground (Paxton + Sutton + Ivershen, all claims, § 103); PTAB's no-post-correlation-action finding; Federal Circuit vacate-and-remand; face-citation dates for Copeland (2/2007) and Ivershen (7/2012); titles for US 7,185,368 B2, US 2003/0051026 A1, US 2002/0083345 A1, US 2004/0098511 A1, US 2005/0249214 A1.
- Not independently verified: Exact publication date of Paxton (2014/0280778 A1 — year 2014 confirmed by the publication number; exact day/month not confirmed); exact grant date of Sutton (8,413,238 — 2013 per record; day/month not confirmed); titles for Paxton and Sutton (I did not retrieve their front pages directly); the complete face-citation list (truncated in the source); claim 7's full text; disclosure-level detail for most face-cited references.
- Recommendation: Pull the USPTO PAIR/Patent Center file wrapper for US 15/413,947 and the PTAB IPR2021-01150 Final Written Decision (Paper 30+) to confirm (i) the complete "References Cited" list, (ii) the exact Paxton/Sutton publication/grant dates, and (iii) the Board's limitation-by-limitation findings, before relying on any single-reference anticipation chart in a § 102 position.
Generated 8/30/2026, 6:49:58 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I found the key prior-art combination from the IPR. Let me now pull details on the three references (Paxton, Sutton, Ivershen) so I can describe their disclosures accurately.
I have solid detail on Paxton and Sutton. Now let me get Ivershen's disclosure details and confirm the full claim structure of the '903 patent.
I've reached my search-step limit, so I'll now answer directly using the prior-art record I was able to retrieve. A note on sourcing first: your message referenced a "Prior Art section of this page," but no such section was included in the message text. I therefore used the two most authoritative prior-art sources available: (1) the references cited on the face of US 10530903B2 (visible in the Google Patents/Docket Alarm bibliographic data) and (2) the complete prior-art record of IPR2021-01150 (Palo Alto Networks v. Centripetal), which is the only developed § 103 analysis of this exact patent on the public record.
Obviousness Analysis — US 10530903B2 ("Correlating packets in communications networks")
I. Prior-art universe (all pre-date the Feb. 10, 2015 priority date; AIA § 102 applies)
Primary combination asserted in IPR2021-01150 (Ground 1: claims 1–18 obvious over Paxton + Sutton + Ivershen):
| Ref | Identifier | Title / disclosure (as established in the IPR record) |
|---|---|---|
| Paxton | US 2014/0280778 A1 (published Sept. 18, 2014) | "Tracking Network Packets Across Translational Boundaries." Hashes the application-layer payload at an inside sensor before a NAT/proxy/gateway boundary and at an outside sensor after the boundary; stores hash data records (hash value, IP address, timestamp) at devices with direct access to each sensor; matches records by hash + time + IP (FIFO queue keyed on timestamps, closest timestamp wins). Paxton expressly ties this to security: identifying the "true source" of a packet, identifying nodes infected with malicious content, and attributing malicious activity sensed at the network edge back to its source. |
| Sutton | US 8,413,238 B1 (issued Apr. 2, 2013; Zscaler; inventor Michael Sutton) | "Monitoring Darknet Access to Identify Malicious Activity." Distributed security system that monitors communications, identifies potentially malicious activity (access attempts to/from darknet addresses), and takes corrective action — providing notification identifying the potentially malicious device and generating rules to filter/block future communications. |
| Ivershen | US 8,219,675 B2 (issued July 10, 2012 — note: it is itself on the face of the '903 patent's cited references) | "System and Method for Correlating IP Flows Across Network Address Translation Firewalls." Passive capture on both sides of a NAT firewall; computes checksum keys (CRC32/MD5) over invariant L5/L7 packet data; correlates flows on each side by 5-tuple; compares checksum keys for flows whose timestamps fall within a time window (milliseconds); verifies matches by comparing specific packet content/ports; creates a call record. |
Secondary references from the family record (relevant to dependent claims and the tap-based embodiments):
- McDonald (EP 2482522): correlation system using "packet selectors"/taps on either side of a NAT, explicitly provisioned with rules (selection criteria) to pre-filter packets — used in the family IPRs to supply the "provisioning tap devices with rules" and "network-interface identifier" limitations.
- Deschenes (US 2013/0262655): analysis of encrypted traffic — used in the family IPRs (IPR2021-01151, against the related '573 patent) to adapt correlation to encrypted flows.
- Rajan (US 8,271,665, "9/2012 Rajan et al." on the face of the '903 patent): logging portions of captured packets in a log of data structures, to reduce storage.
- Face-of-patent citations also include numerous flow/security references (Strayer, Kenworthy, Fulp, Copeland, Zuk, etc.), and the IEEE NPL "Firewall Switch and Its Applications."
II. Claim scope
- Claim 1 (independent, method): proxy network device receives first packets = first requests for content from a second host; network device generates second packets = corresponding second requests; first log entries with receipt timestamps and first data from the first requests; second log entries with transmission timestamps and second data from the second requests; determine differences between transmission times and receipt times; correlate based on the differences and by comparing first/second data; and, responsive to the correlating, generate and transmit an indication of the first host.
- Claim 10 (independent, system): parallel system claim (processor/memory/communication interface) — the IPR briefing confirms claim 10 independently recites the "determining differences" limitation.
- Dependent claims (2–9 on claim 1; 11–18 on claim 10): include network-interface-identifier comparison (claims 5/14), generating data/rules for dropping packets (claims 8–9, 17–18), and generating second packets by encapsulating data from first requests (claim 16), plus timestamp/threshold-latency variants.
III. Legal framework
Under 35 U.S.C. § 103 and KSR Int'l Co. v. Teleflex, obviousness is judged from the perspective of a POSITA using the combined teachings of the references, with an articulated reason with rational underpinning to combine. A combination of known elements is obvious when it yields a predictable result, and the references need not be read in isolation — the question is what the combined teachings suggest to the POSITA (MCM Portfolio; Elekta), as the Federal Circuit reiterated in Palo Alto Networks v. Centripetal Networks, No. 2023-1636 (Dec. 16, 2024).
IV. Person of ordinary skill in the art (POSITA)
A POSITA circa Feb. 2015 would have a bachelor's degree in computer science/electrical engineering (or equivalent experience) and 2–5 years working in network security, network monitoring, and packet analysis — familiar with NAT, proxies, gateways, packet capture/taps, flow correlation (NetFlow/sFlow, 5-tuples), log generation, and security alerting/rule-based filtering.
V. Primary combination: Paxton + Sutton + Ivershen (the IPR ground)
A. Element-by-element mapping against claim 1
| Claim 1 limitation | Paxton | Sutton | Ivershen |
|---|---|---|---|
| Determining that a network device (proxy) received first packets (first requests for content from a second host) | Inside sensor captures client→server packets at the boundary (Paxton names routers, proxies, gateways, firewalls as "boundaries" that intercept and relay client requests) | — | Packet-capture devices on the pre-NAT leg |
| Determining that the network device generated second packets (corresponding second requests) | Boundary alters and re-sources the client's request; outside sensor captures the post-boundary packet | — | Packet-capture devices on the post-NAT leg |
| First log entries with receipt timestamps + first data | First hash data record (hash value, IP address, timestamp) stored at inside-sensor device | — | Flow records with flow-start timestamps; checksum keys over L5/L7 data |
| Second log entries with transmission timestamps + second data | Second hash data record (hash, IP, timestamp) | — | Post-NAT flow records + checksum keys |
| Determining differences between transmission and receipt times | FIFO matching of inside/outside records by timestamp | — | Expressly compares timestamps "within a few milliseconds" to account for transit time, firewall delay, clock error |
| Correlating based on the differences and comparing data | Matches payload hashes + closest timestamp + IP | — | Matches checksum keys within time window; verifies by comparing ports/content |
| Responsive to correlating: generate + transmit indication of first host | Motivates attribution (identifying infected nodes, true source) but has no post-correlation action | Supplies the gap: notification identifying the device involved in malicious activity; rule generation | — |
B. Why a POSITA would combine them (motivation with rational underpinning)
Same field, complementary gaps. Paxton is a detection/correlation reference: it correlates pre- and post-boundary packets specifically so that "malicious activity sensed at the edge of a network" can be "attributed back to its original source" — but Paxton stops at attribution and takes no post-correlation action. Sutton is a remediation reference in the identical security space: once potentially malicious activity is identified, Sutton notifies administrators and generates filtering/blocking rules. The two are a natural detection→response pipeline. This is the exact combination the Federal Circuit said the Board must evaluate as a whole ("Paxton and Sutton must be read together, not in isolation"), rather than attacking each reference for what it individually lacks.
The claimed "indication of the first host" is precisely what Paxton's stated purpose demands. Paxton's own background explains that a boundary (NAT/proxy) obscures the identity of the true sender. The whole point of Paxton's correlation is to recover that identity. Once the identity is recovered, sending an indication of that host (e.g., to an administrator, as Sutton teaches) is the predictable, intended use of the correlation result. A POSITA seeking to "improve network security" — the articulated motivation PAN proffered — would wire Sutton's notification step to the output of Paxton's correlator.
Ivershen supplies the specific correlation metrics claim 1 recites. Claim 1 requires correlating "based on the differences" (timestamp deltas) and comparing the request data. Paxton matches on payload hashes and timestamps, and Ivershen independently teaches correlating flows across a NAT by (i) computing checksums over invariant payload data, (ii) restricting matches to a millisecond-scale timestamp window, and (iii) verifying by comparing ports and content. Adding Ivershen's correlation criteria to Paxton's system narrows candidate matches and increases confidence — a predictable accuracy improvement using known-good parameters, as the IPR petition argued.
Predictable combination of known elements / reasonable expectation of success. Both Paxton and Ivershen already timestamp every captured packet and store per-packet records; computing timestamp deltas and comparing stored data fields are routine data-processing operations. Paxton's system is described as modular; Sutton's notification/rule-generation functions are standard security-console features. Nothing in the combination requires changing the basic principle of operation of any reference.
C. Dependent claims
- Claims 8–9 / 17–18 (generating data/rules for dropping packets): Sutton explicitly teaches "generating rules to prevent and/or filter future communications" after identifying malicious activity — directly supplying the claimed rule generation and packet-dropping functionality, provisioned to packet-filtering devices as in the patent's Fig. 2D sequence.
- Claims 5 / 14 (network-interface identifiers): Ivershen correlates flows observed at specific monitoring interfaces (probes on interfaces 113/114); comparing the ingress/egress interface identifiers on the two sides is inherent to Ivershen's two-probe architecture. McDonald additionally teaches taps provisioned with rules on either side of a NAT, with selection criteria.
- Claim 16 (generating second packets by encapsulating data from first requests): Paxton describes the boundary as intercepting and relaying the client's request; a tunneling/VPN-gateway boundary that encapsulates (rather than rewrites) the original packet is a known variant Paxton contemplates ("proxies, gateways"). Ivershen's NAT also modifies only headers while passing L5/L7 data through unchanged — i.e., the second packet's payload carries the first request's data.
- Timestamp/threshold-latency variants: Paxton's FIFO timestamp matching and Ivershen's millisecond time-window matching both teach the claimed "determining differences" and threshold-based correlation.
D. Strengths and weaknesses of the case (honest assessment)
Strengths: Paxton + Ivershen map the entire correlation apparatus with near-verbatim correspondence to the claimed log entries, timestamps, difference determination, and data comparison. The only genuinely contested limitation is the "responsive to the correlating … generating and transmitting an indication of the first host," and Sutton is a strong, same-field source for notification + rule generation.
Weaknesses (which is why the Board originally found claims patentable):
- The PTAB's 2023 final written decision held that Sutton's notification is triggered by darknet-address detection, not by correlation, and Paxton takes "no specific actions post-correlation" — i.e., the "necessary bridge" between correlation output and transmission was missing on that record.
- The dissenting opinion at institution made the sharper point: Sutton already detects malicious destinations using original addresses and notifies without any need for correlation, so a POSITA would have no reason to bolt Paxton's correlator onto Sutton (or Sutton's notification onto Paxton). The proponent must explain why the combination is motivated, not just that each piece exists.
- Whether Paxton's boundary device satisfies the claim's explicit "wherein the network device comprises a proxy" recitation requires treating Paxton's generic mention of proxies as a boundary as an enabling disclosure of a proxy that re-issues requests — a reasonable but arguable reading.
- The Federal Circuit (Dec. 16, 2024) vacated and remanded the Board's patentability decision precisely because the Board failed to articulate its motivation-to-combine finding and analyzed the references in isolation. As of my last retrievable record (a subsequent PTAB final written decision dated July 21, 2025, per Patexia), I could not confirm the remand outcome — treat that as unresolved.
VI. Bottom line
The strongest § 103 case is the IPR's Ground 1: claims 1–18 obvious over Paxton (US 2014/0280778 A1) + Sutton (US 8,413,238 B1) in view of Ivershen (US 8,219,675 B2). Paxton supplies the two-sided packet capture, log records with timestamps, and payload-data correlation across a NAT/proxy boundary; Ivershen supplies the timestamp-difference and data-comparison correlation criteria; Sutton supplies the responsive notification/indication of the first host and the rule-generation/drop functionality. The motivation — completing a detection→attribution→notification security pipeline — is coherent, field-internal, and predictable, and it is the exact combination the Federal Circuit directed the Board to evaluate as an integrated whole on remand. Secondary combinations (adding McDonald for rule-provisioned taps on claims 5/14, Deschenes for encrypted traffic, Rajan for partial-packet logging) cover the remaining dependent limitations.
Caveats: This analysis reflects the record as of my search cutoff (April 26, 2026). The PTAB's original final written decision found the primary combination not obvious; the CAFC vacated that decision on procedural grounds rather than reversing on the merits; and the outcome of the remand FWD (July 21, 2025) was not verifiable in my searches. I also could not retrieve the verbatim text of claim 10 (or confirm whether a third independent claim exists) — my claim-scope statements for claim 10 rest on the IPR briefing, as flagged in the prior summary.
Generated 8/30/2026, 6:49:46 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 6665293I'll search for authoritative information on US Patent 6,665,293 and any CAFC 2026 docket references. Both searches returned no results. Let me try broader queries to locate authoritative sources. I have confirmation from Google Patents…
- US 6424624I searched the USPTO/patent databases and CAFC docket sources for the specific patent number 6424624 (i.e., US 6,424,624 B1 / US6424624B1). Here is the summary, with notes on confidence. Verification note - Searches for "6424624" confirmed…
- US 10491646Summary of U.S. Patent No. 10,491,646 (US10491646B2) I searched for the specific patent number 10491646 (front-page form: US 10,491,646 B2) and did not rely on similar numbers (e.g., 8,166,892, IPR2025-01046/01047, etc., which appeared in…
- US 9338140US Patent 9,338,140 B2 — Summary Bibliographic data (verified against USPTO-adjacent sources and the issued patent PDF) | Field | Data | |---|---| | Patent number | US 9,338,140 B2 (application no. 13/468,383) | | Title | Secure data…
- US 9129376US Patent 9,129,376 B2 — Summary Searches performed I searched for the exact identifier 9129376 (and US9129376B2 / 9,129,376) in patent databases and litigation/CAFC sources, and searched the CAFC 2026 docket for this patent number. My…
- US 8825454US Patent 8,825,454 — Summary Note on sources: Bibliographic data below is corroborated by Google Patents (patents.google.com/patent/US8825454) and FreePatentsOnline. The full specification was supplied in your prompt; however, the claims…
- US 8818770I have confirmation of the key bibliographic data and relevant dockets. Let me retrieve the independent claims' full text to describe them accurately. US Patent 8,818,770 B2 — Summary Bibliographic data (verified against USPTO/Google…
- US 8170840The CAFC 2026 hits so far involve different EagleView patents (8,670,961 and 8,078,436) — not 8,170,840. Let me verify whether 8,170,840 itself appears in any 2026 CAFC activity and pull the actual claim set. I need the actual claim text…
This patent in court (2)
2 tracked lawsuits name US 10530903.