Invalidity dossier

US 10567437

Methods and systems for protecting a secured network

Current assignee: Palo Alto Networks, Inc.

Added 8/30/2026, 4:49:27 AM

At a glanceNo PTAB challenges5 lawsuits on fileasserted by Palo Alto Networks, Inc.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for information on US Patent 10,567,437, including its claims and any CAFC 2026 docket activity.

Let me search specifically for the granted claims of US10567437B2 and the CAFC dockets 25-1167 and 25-1168 linked to this patent.

US Patent 10,567,437 B2 — Summary

Important scope note: The Google Patents page for this patent links it to CAFC dockets 25-1167 and 25-1168. Those are the relevant appellate dockets. I did not find any final CAFC merits decision in those dockets as of the current date — the appeal was consolidated in late 2024, deactivated pending post-judgment motions, and reactivated in late December 2025, so it is pending/active in 2026. The April 2026 Federal Circuit activity reported in the news (the Cisco non-infringement appeal and the ITC "domestic industry" appeal) involves different Centripetal patents/cases, not 10,567,437.


Bibliographic data (verified via search results)

  • Patent number: US 10,567,437 B2 (application no. 16/111,524; pre-grant publication US20190230128A1)
  • Title: "Methods and systems for protecting a secured network"
  • Inventors: Steven Rogers and Sean Moore
  • Original assignee / current assignee: Centripetal Networks LLC (recorded assignment on 2019-06-05 to Centripetal Networks, Inc.; name change to Centripetal Networks, LLC in 2023)
  • Filing date: August 24, 2018 (this application is a continuation)
  • Earliest priority date: October 22, 2012 (parent U.S. App. 13/657,010 → US 9,137,205)
  • Issue (grant) date: February 18, 2020
  • Status: Active; Google Patents lists anticipated expiration as 2032-10-22 (post-Term-Adjustment-type date, assuming maintenance fees are paid)
  • Continuation chain: 13/657,010 (US 9,137,205) → 14/698,560 (US 9,560,077) → 15/413,834 (US 10,091,246) → 16/111,524 (US 10,567,437)

Abstract (verbatim)

"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets. Performing the at least one of multiple packet transformation functions specified by the dynamic security policy on the packets may include performing at least one packet transformation function other than forwarding or dropping the packets."

Plain-language overview of the independent claims

The granted claim text was not included in the materials provided, and my searches returned the claims as published in the pre-grant publication US20190230128A1 (the application that became this patent). The claims below are therefore from that published application; the claims as granted may have been amended during prosecution — treat them as the best available but not fully authoritative. The published claim set has two independent claims (claims 2 and 9), with claim 1 canceled:

  • Claim 2 (method): A method of (a) provisioning a packet security gateway located at the boundary between a protected network and other networks with packet-filtering rules, where each rule pairs at least one packet-matching criterion tied to malicious network traffic with a corresponding packet-transformation function; and (b) configuring the gateway to receive packets through a communication interface that has no network-layer address, to drop any packets that match the criteria, and to modify a LAN switch's switching matrix so the switch also drops those matching packets. In plain terms: a stealthy (network-layer-invisible) inline security device that blocks malicious traffic and programs the adjacent LAN switch to do the same.

  • Claim 9 (system): A system (at least one processor plus memory storing instructions) that performs the same provisioning and configuring steps as claim 2 — i.e., the claim covers a security-policy-management server/controller that sets up such a gateway and switch.

  • Key dependent claims (for context): rules identifying spoofed source addresses (claim 3); rules based on subscription-service threat intelligence (claim 4); receiving rules over a network-layer-addressed management interface (claim 5); encapsulating matched packets with a header directing them to a different network address, e.g., a monitoring device (claim 6); Layer-2 VLAN-based rerouting (claim 7); and dynamically creating/altering criteria upon receipt of a policy information update (claim 8). Claims 10–15 mirror claims 3–8 for the system claim.

CAFC 2026 dockets (per Google Patents litigation metadata and Justia/RPX/DocketAlarm records)

  • 25-1167 and 25-1168 — Centripetal Networks, LLC (fka Centripetal Networks, Inc.) v. Palo Alto Networks, Inc., U.S. Court of Appeals for the Federal Circuit.
    • Filed: November 13, 2024; originating from E.D. Va. case 2:21-cv-00137 (Centripetal v. Palo Alto Networks).
    • On December 11, 2024, the CAFC consolidated 25-1167 (lead) and 25-1168 (member) as appeal and cross-appeal and deactivated them pending post-judgment motions; the docket was reactivated by CAFC order on December 22, 2025, so the appeal is live in 2026. No 2026 merits decision was identified in my searches.
    • Patent 10,567,437 is listed among the Centripetal patents asserted in the underlying E.D. Va. litigation (along with, e.g., 10,091,246, 10,542,028, 10,567,343, 10,567,413, 10,659,573, 10,749,906, 10,757,126, 10,785,266).

Additional litigation/PTAB context (for completeness)

  • IPR2021-01153 was filed against this patent; per the Google Patents metadata it was Not Instituted (Merits) — i.e., the PTAB declined to institute inter partes review on the merits.
  • Related E.D. Va. cases referencing the patent family include 3:21-cv-00597, 1:21-cv-01051, and 1:21-cv-00313.
  • Other reported 2026 Federal Circuit activity involving Centripetal (e.g., Centripetal Networks, LLC v. ITC, No. 24-1416, decided April 23, 2026, and the Cisco appeal argued April 2026) concerns different patents (e.g., the '370 patent and Cisco-asserted patents), not 10,567,437.

Uncertainties

  1. Granted claim text — I could not confirm the exact granted independent claims of the B2 patent from the available sources; the overview above reflects the published application US20190230128A1.
  2. Disposition of CAFC 25-1167/25-1168 — no 2026 outcome was located; the case was reactivated in December 2025 and remains pending per available docket data.
  3. Maintenance-fee status — Google Patents marks the patent "Active" with anticipated expiration in 2032, but I did not independently verify current USPTO maintenance-fee status.

Generated 8/30/2026, 6:49:31 PM

Cases on file (5)

Group view →

Specific litigation cases in our database that name US patent 10567437. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Litigation involving US Patent 10,567,437 ("the '437 patent")

Based on searches of PACER-derived dockets (Justia, Docket Alarm, RPX, UniCourt, Ex Parte), PTAB records, and contemporaneous press coverage (Reuters, IPWatchdog, Law360), the known litigation is set out below. All identifiers are reproduced literally.


A. District court litigation

1. Centripetal Networks, LLC (f/k/a Centripetal Networks, Inc.) v. Palo Alto Networks, Inc.

  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
  • Case No.: 2:21-cv-00137 (EWH-LRL) — Judge Elizabeth W. Hanes, Magistrate Judge Lawrence R. Leonard
  • Filing date: March 12, 2021
  • Plaintiff: Centripetal Networks, LLC
  • Defendant: Palo Alto Networks, Inc.
  • The '437 patent's role: Originally one of 13 patents asserted. By trial, only claim 8 of the '437 patent remained asserted, against PAN's Panorama (alone) and Panorama combined with Next-Generation Firewalls ("'437 Accused Products").
  • Outcome/status:
    • January 31, 2024 jury verdict: $151.5 million total for Centripetal across four patents. For the '437 patent specifically, the jury awarded $37,875,000, finding direct infringement of claim 8 (NGFWs combined with Panorama), and rejecting PAN's invalidity defenses (the verdict form also shows the jury did not find induced infringement or willfulness).
    • Post-trial (November 2024, E.D. Va. Doc. 989): Judge Hanes granted PAN's JMOL motion in part, holding there was legally insufficient evidence to support the jury's infringement finding on the '437 patent, and directed entry of judgment as a matter of law of non-infringement of the '437 patent, reducing the jury award accordingly. The Court denied PAN's motion for a new trial and upheld the jury verdicts on the "Correlation Patents" ('903, '573, '797).
    • Current status: Final judgment entered; both sides appealed (see CAFC dockets below). The CAFC appeal was reactivated effective December 22, 2025, with appellant's brief due February 20, 2026. As of April 26, 2026, the appeal is pending; no CAFC merits decision was located.

2. Centripetal Networks, Inc. v. LookingGlass Cyber Solutions, Inc. et al.

  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (filed in Alexandria Division as 1:21-cv-01051; transferred to Richmond Division)
  • Case No.: 3:21-cv-00597 — Judge David J. Novak
  • Filing date: September 14, 2021 (transferred in September 16, 2021)
  • Plaintiff: Centripetal Networks, Inc.
  • Defendants: LookingGlass Cyber Solutions, Inc.; Gilman Louie; Alsop Louie Management LLC; Alsop Louie Capital 2, L.P.; Alsop Louie Partners 2, LLC
  • The '437 patent's role: Asserted among five patents (also 10542028, 10757126, 10785266, 10735380). Causes of action included patent infringement, breach of contract, breach of fiduciary duty, and abetting breach of fiduciary duty.
  • Status: Docket was "open" as of late 2021, but I could not verify the current status or any disposition from the sources retrieved. Treat the outcome as unconfirmed.

B. Federal Circuit appeals

3. Centripetal Networks, LLC v. Palo Alto Networks, Inc.

  • Jurisdiction: U.S. Court of Appeals for the Federal Circuit
  • Case Nos.: 25-1167 (lead, appeal) and 25-1168 (member, cross-appeal)
  • Filing date: November 13, 2024 (appeal from E.D. Va. 2:21-cv-00137)
  • Parties: Centripetal Networks, LLC (f/k/a Centripetal Networks, Inc.), Plaintiff-Cross-Appellant; Palo Alto Networks, Inc., Defendant-Appellant
  • Status: Consolidated by CAFC order December 11, 2024 as appeal and cross-appeal; deactivated pending resolution of FRAP 4(a)(4) post-judgment motions; reactivated effective December 22, 2025 (appellant's brief due February 20, 2026). Pending as of April 26, 2026 — no merits decision located. This appeal encompasses the district court's post-trial rulings, including the JMOL of non-infringement of the '437 patent.

C. PTAB / IPR proceedings

4. Palo Alto Networks, Inc. v. Centripetal Networks, Inc., IPR2021-01153

  • Jurisdiction: Patent Trial and Appeal Board
  • Filing date: July 6, 2021
  • Petitioner: Palo Alto Networks, Inc.; Patent Owner: Centripetal Networks, Inc.
  • Claims challenged: 1–20 of the '437 patent
  • Outcome: Institution DENIED (decision January 24, 2022; panel: J. John Lee, Brian J. McNamara, John P. Pinkerton). Google Patents metadata likewise codes this IPR as "Not Instituted – Merits."

5. Keysight Technologies, Inc. IPR petition against the '437 patent (institution denied)

  • Per the parties' joint status report filed in 2:21-cv-00137 (E.D. Va. Doc. 329-8, filed March 29, 2023), Keysight Technologies, Inc. filed IPR petitions on patents asserted in that case and related patents; the row for 10,567,437 (challenging claims 1, 3, 5–8, 10, 12–15, and 17, 19–20) is listed as "Institution Denied." I did not locate the IPR case number for that particular petition in the sources retrieved, so the number is unverified. (The same filing identifies Keysight's IPR2023-00448 as a petition on related U.S. Patent No. 11,012,474, a grandchild of the '437 patent.)

D. Additional case number flagged in patent metadata (unverified)

  • 1:21-cv-00313 (E.D. Va.) — Appears in Google Patents' litigation metadata for this patent as a Virginia Eastern District Court case. I could not verify the parties, filing date, or status, and it may simply be the original docket number of a case later renumbered. Do not rely on this entry without PACER confirmation.

Key caveats

  • The biggest development affecting the '437 patent is the November 2024 JMOL: although the jury awarded $37.875M for claim 8, the district court entered JMOL of non-infringement of the '437 patent for insufficient evidence, and that ruling is now part of the pending CAFC appeal (25-1167/25-1168).
  • No CAFC merits decision on 25-1167/25-1168 was located as of April 26, 2026; the appeal was reactivated in December 2025 and briefing was underway in early 2026.
  • I did not verify current maintenance-fee status or whether the LookingGlass case (3:21-cv-00597) and the metadata-listed 1:21-cv-00313 have been resolved. PACER would be the authoritative source for those two items.

Generated 8/31/2026, 12:46:03 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Palo Alto Networks, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll research the PTAB proceedings on this patent. The structured data says the ODP returns no AIA trials, but the patent's own litigation metadata references IPR2021-01153 — so I need to verify that and check for any other proceedings via web search.

I found IPR2021-01153 (Palo Alto Networks v. Centripetal) — institution denied. Let me verify the panel, grounds, and check for any other proceedings against this patent or its direct parents.

I have solid confirmation of IPR2021-01153. Now let me get the actual institution decision reasoning and check for any other IPRs against this patent (or related family members that might cover the same claims).

Proceedings overview

There is one AIA trial proceeding on US 10,567,437 in the public record — IPR2021-01153 — and it was denied at institution (the only status that exists for it; no trial, no Final Written Decision). The bottom line for a defendant: zero claims have been canceled — all 20 claims survive, and the patent is arguably "hardened" in the sense that the only PTAB challenge (Palo Alto Networks' Jungck-based obviousness attack) failed at the threshold on 2022-01-24. But the claims have never been tested on the merits, no § 315(e) estoppel attaches (no FWD), and the co-pending E.D. Va. litigation (2:21-cv-00137) plus CAFC appeals 25-1167/25-1168 remain the live battlegrounds.


IPR2021-01153 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2021-07-06 (notice of filing date accorded 2021-07-23)
  • Status: Institution Denied — proceeding terminated 2022-01-24; petitioner's fee refund approved 2022-04-07 (per PTAB docket). Plain-English gloss: the Board never instituted trial, so there was no merits adjudication of any claim.
  • Judge panel: Kevin F. Turner (APJ), Bryan F. Moore (APJ), Lynne E. Pettigrew (APJ) — as shown on the Decision Denying Institution (Paper 10) itself ("Before KEVIN F. TURNER, BRYAN F. MOORE, and LYNNE E. …"). ⚠️ Discrepancy flagged: Patexia lists a different panel (J. John Lee, Brian J. McNamara, John P. Pinkerton); that appears to be a data error — APJ McNamara sat on a different Centripetal/Palo Alto IPR (the encrypted-threat-detection patent at issue in CAFC No. 2023-2027), not this one. I would trust the Paper 10 caption over the secondary aggregator.
  • Petition grounds (per Petition, Paper 2, and Paper 10):
    • Ground 1: claims 1–4, 6–11, 13–18, 20 — obvious under 35 U.S.C. § 103 over Jungck (US Patent Appl. Publ. No. 2007/0262741 A1);
    • Ground 2: claims 5, 12, 19 — obvious under § 103 over Jungck + RFC 2003 ("IP Encapsulation within IP," C. Perkins, IBM).
    • All 20 claims were challenged. Petitioner relied on a declaration of Dr. Vijay Madisetti (Ex. 1004) and, notably, a claim-comparison chart and the FWDs/institution decisions from Cisco's 2018 IPRs on Centripetal family members (Exs. 1012–1021).
  • Institution decision: Denied — 2022-01-24, Paper 10 (Decision Denying Institution of Inter Partes Review, 37 C.F.R. § 42.108). The decision concludes: "For the reasons explained below, we do not institute an inter partes review in this proceeding." I could not retrieve the full text of Paper 10 to quote the panel's precise rationale; Google Patents' litigation metadata characterizes it as "Not Instituted – Merits" (i.e., a failure to show reasonable likelihood under § 314(a) rather than a discretionary Fintiv/§ 325(d) denial). The petition itself devoted a section to arguing the Board should not exercise discretion to deny under § 314(a) and § 325(d), so those were contested issues — but the available record points to a merits-based denial.
  • Final Written Decision: None. Institution was denied, so no trial was conducted and no claim was canceled or confirmed.
  • Settlement / termination: No settlement. The proceeding was terminated by the denial itself on 2022-01-24 (docket shows "Terminated Jan. 24, 2022").
  • Appeal: Institution denials are not appealable under 35 U.S.C. § 314(d). Palo Alto nonetheless sought Director review of the denial; the USPTO refused (policy: no Director review of institution decisions), and PAN filed a mandamus petition in the Federal Circuit — In re Palo Alto Networks, Inc., No. 22-145 (Fed. Cir. 2022) (precedential). The CAFC denied mandamus, holding that the Director's delegation of institution authority to APJs and the policy of not accepting party requests for Director rehearing of non-institution decisions do not violate the Appointments Clause under United States v. Arthrex. The timing and docket entries are consistent with this mandamus arising from PAN's 2021–2022 Centripetal petitions (of which IPR2021-01153 is one), though the opinion addresses PAN's petitions collectively. No merits appeal exists because there is no FWD.
  • Defensive value: For someone facing assertion of the '437 patent today, this proceeding cuts against an IPR-based defense: Palo Alto Networks — the same defendant in the E.D. Va. case and CAFC appeals 25-1167/25-1168 — threw its best Jungck/RFC 2003 combination at all 20 claims and got denied at the threshold. No claim is dead; any infringement theory built on claims 1–20 stands. A new petitioner would need materially different art, and PAN itself is now time-barred under § 315(b) (complaint served in 2021, more than one year before any new petition).

Strategic summary

Claims CANCELED vs. SUSTAINED vs. UNTESTED. No claims of 10,567,437 have been canceled — IPR2021-01153 challenged all 20 claims and was denied institution, so no claim has been "sustained" on the merits either; all 20 claims (1–20) are untested by a Final Written Decision. The only PTAB signal is the institution-stage denial, which found (per the available metadata and decision conclusion) that PAN did not demonstrate a reasonable likelihood of prevailing on any ground. The patent is therefore structurally intact — every claim is enforceable and presumptively valid.

Estoppel landscape. Because no FWD issued, no § 315(e)(2) estoppel attaches to anyone. PAN is free to press Jungck and Jungck+RFC 2003 in the E.D. Va. litigation, subject only to the district court's own assessment (it will know the PTAB already rejected that combination at the institution threshold). For any defendant currently being asserted against: the § 315(b) one-year bar means PAN (and its privies) cannot file another IPR on this patent — the E.D. Va. complaint (2:21-cv-00137) was filed in 2021. A different, non-time-barred petitioner could still petition with new art (Jungck-based grounds would also face § 325(d) if the art was before the Office), but the practical read is that the obviousness art PAN assembled has been tested and found wanting at the PTAB.

Pattern signals. Only one IPR has ever been filed on this patent, and it failed at institution. There is no Unified Patents IPR in the chain — Unified Patents appears only as the litigation-data aggregator in the Google Patents metadata, not as a petitioner. The petitioner was Palo Alto Networks, which is the adverse party in the parallel E.D. Va. case and the CAFC appeals 25-1167/25-1168 (consolidated; reactivated 2025-12-22). Centripetal's broader PTAB history is aggressive: Cisco filed multiple 2018 IPRs on Centripetal family members (IPR2018-01513, -01443, -01444, -01505, -01506 — all cited as exhibits in PAN's petition), and Centripetal secured a CAFC affirmance in the Cisco litigation (847 F. App'x 929, May 11, 2021). Separately — and not on this patent — the CAFC recently vacated and remanded a PTAB FWD in Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2023-2027 (Fed. Cir. 2025-10-22), for the Board's failure to consider copying evidence, and rejected Centripetal's APJ-recusal challenge. That case involves a different Centripetal patent (encrypted network-threat detection) but confirms Centripetal's pattern of litigating PTAB outcomes aggressively.

Recommended next steps

  • Do not cite any FWD for cancellation — there is none. No claim of 10,567,437 has been invalidated. Any demand or complaint citing claims 1–20 of this patent is not vulnerable to a "canceled claim" attack.
  • For the record, the institution denial is Paper 10 in IPR2021-01153 (PTAB, 2022-01-24): available via the USPTO PTAB portal (search "IPR2021-01153") and mirrored at Docket Alarm (Paper 10 PDF; Petition PDF); the related mandamus ruling is In re Palo Alto Networks, Inc., No. 22-145, at CourtListener.
  • If you are the defendant (PAN or a privy): you are § 315(b) time-barred from a new IPR on this patent; the realistic validity fight is in E.D. Va. (2:21-cv-00137) and on appeal (CAFC 25-1167/25-1168, reactivated 2025-12-22 — no merits decision yet as of this writing). Weigh Jungck-based arguments there knowing the PTAB already rejected them at the threshold.
  • If you are a non-time-barred third party: a fresh petition would need new prior art; Jungck and RFC 2003 have been tried. Expect the Board to view repeat attacks on this patent skeptically, and expect Centripetal to litigate hard (see the 2023-2027 pattern).
  • Milestones: there are no pending PTAB trial-stage milestones (no institution, no oral hearing, no FWD due date) — the proceeding is closed. The only live deadlines are in the district court and CAFC appeals, not at the PTAB.

Caveats: I could not retrieve the full text of Paper 10 to quote the panel's institution rationale verbatim, and the ODP structured data shows no AIA trials (the proceeding above was surfaced via web sources, which are consistent with the Google Patents "IPR2021-01153 — Not Instituted (Merits)" litigation metadata). The panel composition reflects the Paper 10 caption; the Patexia panel listing is flagged as likely erroneous.

Generated 8/31/2026, 12:46:24 AM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2019-06-05 · Assignment of Assignors' Interest

    Steven Rogers; Sean MooreCentripetal Networks, Inc.

  2. 2023-01-20 · Change of Name

    Centripetal Networks, Inc.Centripetal Networks, Inc.

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I have good litigation context. Now I need the actual USPTO assignment records — reel/frame numbers, correspondents, and any security agreements (e.g., the Silver Point Finance financing referenced in litigation). Let me search for those.

The inventors' locations (Leesburg, VA; Hollis, NH) and the Portsmouth, NH assignee address are confirmed. Now let me dig for the specific reel/frame numbers of the recorded assignments.

Inventors

  • Steven Rogers — Leesburg, VA (per family-member cover pages, e.g., US 10,785,266 B2). Co-founder and CEO of Centripetal Networks at the time of filing (2012) and throughout the Cisco/Palo Alto litigations.
  • Sean Moore — Hollis, NH. Co-founder and CTO (later VP R&D / CTO) of Centripetal Networks at the time of filing.

Both inventors were employees/executives of the original assignee at filing and remained with it long after — no pattern of inventors departing within 12 months of filing (that NPE fire-sale precursor is not present here).

Original assignee

  • Centripetal Networks, Inc. (Portsmouth, NH), recorded on the patent and on the 2019-06-05 assignment of inventors' interest. Google Patents normalizes the current name (LLC) onto older events; the contemporaneous USPTO record is "CENTRIPETAL NETWORKS, INC."
  • Line of business: network-security appliances and software — RuleGATE (rule-based packet security gateway), CleanINTERNET, InfoSentry. The '437 claims (packet security gateways applying dynamic security policies) map directly onto the RuleGATE product line, so yes, the original assignee shipped products embodying the claims.
  • Current status: operating, privately held, still active and litigating through 2024–2026 (E.D. Va. 2:21-cv-00137; CAFC 25-1167/25-1168). No acquisition, dissolution, or bankruptcy.

Assignment timeline

I could not retrieve reel/frame numbers or correspondent names for either recorded event from the sources available to me (USPTO Assignment Center pages did not surface in search). The two events below are confirmed from Google Patents' legal-event feed (which mirrors USPTO assignment records) and from family-member cover pages. Verify reel/frame at the Assignment Center: https://assignmentcenter.uspto.gov/ (search "10567437") or https://assignment.uspto.gov/patent/index.html.

  • Executed ~2012–2013 (at filing) / recorded 2019-06-05 — Reel/frame: not retrieved — verify at Assignment Center

    • Conveyance: Assignment of Assignors' Interest
    • Assignor: Steven Rogers; Sean Moore
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not retrieved from available sources
    • Context: Original inventors-to-company assignment for the 2012 parent application, recorded ~6–7 years late (June 2019) — the standard "perfect title before issuance" housekeeping recording (the continuation was about to grant; patent issued 2020-02-18). This is the only substantive assignment in the chain.
  • Executed / recorded 2023-01-20 — Reel/frame: not retrieved — verify at Assignment Center

    • Conveyance: Change of Name
    • Assignor: Centripetal Networks, Inc.
    • Assignee: Centripetal Networks, LLC
    • Correspondent: not retrieved from available sources
    • Context: Corporate name change only — no change in beneficial ownership. Matches the recorded 2023 name change on the Google Patents event feed ("CHANGE OF NAME ... Assignors: CENTRIPETAL NETWORKS, INC.").

No security agreements, mergers, releases, or licenses appear in the available record. Note: litigation filings (RPX coverage of 2:21-cv-00137) reference a 2022 financing negotiation between Centripetal and Silver Point Finance (funds to pay for insurance on the Cisco judgment appeal); I found no recorded security agreement against this patent in the sources available, so any lien on the portfolio is unverified, not confirmed.

Timeline diagram

timeline
    title Ownership of US 10567437
    2012 : Filed by Centripetal Networks Inc
    2020 : Patent issued
    2021 : First infringement suit filed
    2023 : Name change to Centripetal Networks LLC

NPE / troll-pattern signals

  1. Shell-entity transfernot present. The only post-issuance event is a Change of Name (2023-01-20) from Centripetal Networks, Inc. to Centripetal Networks, LLC — the same operating company under a new entity name, not a transfer to a licensing-only LLC. No IP-holding LLC, no registered-agent address, no single-purpose Delaware/Texas shell in the chain.

  2. Known asserter in the chainunclear. The current assignee, Centripetal Networks LLC, is itself a high-frequency plaintiff tracked by RPX and Unified Patents (asserting against Cisco, Palo Alto Networks, Fortinet, Juniper, LookingGlass, and others; RPX covered its $151.1M E.D. Va. verdict in 2:21-cv-00137). But it is the original operating company, not an entity acquired into an NPE portfolio, and I could not confirm an independent public NPE-list classification (e.g., by Unified Patents or RPX) from the sources available. This is the strongest arguable signal in the file and it is genuinely borderline.

  3. Repeat correspondent across the chainunclear / not assessable. Correspondent names and reel/frame data were not retrievable from available sources; with only two recorded events (original assignment + name change) I cannot test for a recurring recording attorney. No finding either way.

  4. Cascading transfersnot present. Only two events, 3.5 years apart (2019-06-05 and 2023-01-20), no chained LLCs, no shared principals.

  5. Pre-litigation transfernot present. First suit naming this patent was filed 2021-03-12 (E.D. Va. 2:21-cv-00137). There is no assignment dated within six months before that filing — and the 2023 name change came after the suit was filed, so it cannot have been arranged to enable assertion or venue.

  6. Bankruptcy fire-salenot present. No Chapter 7/11 for Centripetal Networks; no bankruptcy-sale assignment.

  7. Privateeringnot present / unclear. No operating company transferred this patent to an NPE to assert against competitors; the operating company (Centripetal) asserts in its own name. The unverified Silver Point Finance financing arrangement (litigation funding, not an assignment) is the only privateering-adjacent fact, and it is unconfirmed in assignment records.

  8. Defensive aggregator (anti-NPE)not present. Chain terminates at Centripetal Networks LLC; no transfer to RPX, AST, LOT Network, Unified Patents, or OIN.

Verdict

Operating-company assertion.

The recorded chain is trivial — inventors → Centripetal Networks, Inc. (2019 recording of the original 2012 assignment) → Centripetal Networks, LLC (2023 change of name only) — so there is no shell transfer, no cascade, no aggregator, and no bankruptcy to support an NPE finding. The current assignee is the original operating company that ships RuleGATE products embodying the claims and is suing actual competitors (Palo Alto Networks in 2:21-cv-00137, plus Cisco, Fortinet, Juniper, LookingGlass). Caveat: Centripetal's business model is unusually litigation-dominant for an operating company (a $2.75B Cisco verdict later vacated; a $151.1M Palo Alto verdict), which is why RPX/Unified track it heavily and some observers treat it as NPE-like; if the unverified Silver Point Finance financing ever shows up as a recorded security interest against this patent, that would warrant revisiting this call. Verify the two events' reel/frame and correspondents at https://assignmentcenter.uspto.gov/ before relying on this analysis.

Generated 8/31/2026, 12:46:21 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

USPTO / Prior-Art Search Results for US Patent 10,567,437 (US10567437B2)

Method and sourcing caveats (read first)

I attempted to pull the examiner's "References Cited" section from USPTO PatentCenter/Public PAIR and the Google Patents "Citations" tab for US10567437B2. The full face-of-patent citation list was not fully retrievable through the available web-search tooling. What I did verify:

  1. US-6826694-B1 ("High Resolution Access Control") is linked as a citation to US10567437B2 in the Unified Patents patent record (search result: US-6826694-B1 - High Resolution Access Control - US-10567437-B2).
  2. US-20090262741-A1 ("Transparent Provisioning of Services Over a Network") appears on the US10567437B2 record (the Google Patents page for that reference lists US10567437B2 as citing it).
  3. The Unified Patents portal page for US-10567437-B2 contains a "Patent Art (291)" list — this is the prior-art set assembled for the IPR2021-01153 petition (which the PTAB declined to institute — "Not Instituted – Merits") and/or the E.D. Va. litigation (2:21-cv-00137, Centripetal v. Palo Alto Networks). This is challenger-generated art, not the examiner's citation list.
  4. I did not obtain the granted claim text of the B2 patent; claim mapping below uses the published-application claims (US20190230128A1) — independent method claim 2 and independent system claim 9 — which the earlier summary flagged as the best-available-but-not-authoritative version.

Per the operating rules, I flag this explicitly: I cannot assert with high confidence that the list below is the complete examiner-cited set. What follows is the verified relevant art from the searches, with confidence levels per item.


Verified prior-art references (with § 102 analysis)

Claim architecture used for mapping (published application):

  • Claim 2 (method): provisioning a packet security gateway at a protected-network boundary with packet-filtering rules (each rule pairs a packet-matching criterion tied to malicious traffic with a packet-transformation function); configuring the gateway to receive packets through a communication interface having no network-layer address, to drop matching packets, and to modify a LAN switch's switching matrix so the switch also drops matching packets.
  • Claim 9 (system): processor + memory configured to perform the same steps.
  • Key dependents: claim 3 (spoofed-source-address rules), claim 4 (subscription-service threat intelligence), claim 5 (network-layer-addressed management interface), claim 6 (encapsulation/rerouting to a different address, e.g., a monitoring device), claim 7 (Layer-2 VLAN rerouting), claim 8 (dynamic rule creation/alteration on policy update); claims 10–15 mirror claims 3–8.

1. US 6,826,694 B1 — "High Resolution Access Control" (verified citation)

  • Citation: US 6,826,694 B1; issue date January 12, 2004 (filed in the late-1990s/2000 timeframe per the record).
  • Description: Directed to high-resolution, granular access control / packet filtering — precisely the "filter substantially all traffic at high resolution" problem the '437 patent's Background calls out as the scalability challenge. This appears to be an earlier-generation design in the same technical lineage (same inventor field, Steven Rogers), i.e., a likely self-citation.
  • § 102 analysis: Potentially anticipates claims 2 and 9 (and the filtering-centric dependents 3 and 4) if it discloses: a gateway at a network boundary, criteria-based packet-filtering rules paired with transformation/deny functions, and high-resolution filtering. Gaps to check against granted text: whether it discloses the no-network-layer-address interface and the LAN-switch switching-matrix modification — I could not verify those disclosures from the available snippet.
  • Confidence: Citation itself verified; element-by-element mapping not fully verified — treat as high-priority art requiring full-text review.

2. US 2009/0262741 A1 — "Transparent Provisioning of Services Over a Network" (verified citation; assignee per record: Lookingglass Cyber Solutions LLC; priority date listed: 2000-06-22)

  • Citation: US 2009/0262741 A1; published October 22, 2009.
  • Description: Discloses provisioning network services (including security services) via inline devices that operate transparently — i.e., not addressed at the network layer while still processing traffic at higher layers. This maps almost directly onto the '437 patent's "network layer transparent" gateway features (spec: interfaces 206/208 not addressed at the network layer; PSG still performs network-layer transformation functions).
  • § 102 analysis: Strongest candidate against the transparency element of claims 2 and 9, and by extension the dependent-management-interface claims (claim 5). Whether it discloses the LAN-switch switching-matrix modification and the malicious-traffic-criteria limitation is unverified; if not, it may only partially anticipate or read as an obviousness reference rather than a full § 102 anticipation.
  • Confidence: Citation verified; substantive disclosure details from the abstract/body not fully retrieved — requires full-text confirmation.

3. US 2006/0070122 A1 — "Method and Apparatus for a Distributed Firewall" (verified in Patent Art list; priority date listed: 1999-06-29; current assignee listed: RPX Corp.)

  • Citation: US 2006/0070122 A1; published April 6, 2006.
  • Description: Discloses a distributed firewall architecture with centrally managed security policy pushed to enforcement points — analogous to the '437 security-policy-management-server → packet-security-gateways model.
  • § 102 analysis: Potentially anticipates claims 2 and 9 on the provisioning rules to a boundary gateway from a management server and drop-matching-packets elements. Unverified: the no-network-layer-address stealth interface and LAN-switch switching-matrix limitation.
  • Confidence: Listed in the IPR/litigation art set (verified); disclosure details not fully retrieved.

4. US 2007/0083924 A1 — "System and Method for Multi-stage Packet Filtering on a Network-Enabled Device" (verified in Patent Art list; filed 2005-10-07)

  • Citation: US 2007/0083924 A1; published April 12, 2007.
  • Description: Discloses multi-stage packet filtering on a network device — conceptually similar to the '437's packet filter → multiple packet-transformation-function pipeline.
  • § 102 analysis: Relevant to claims 2/9's rule-criteria → transformation-function pairing and to dependent claims specifying transformation functions (e.g., claims 6/7-style rerouting) if disclosed therein. Anticipation of the full independent claims is unlikely on its own unless it also discloses the stealth interface and LAN-switch programming — unverified.
  • Confidence: Listed in IPR/litigation art set (verified); disclosure details not retrieved.

5. US 2006/0133377 A1 — Fortinet — "System and Method for Integrated Header, State, Rate and Content Anomaly Prevention with Policy Enforcement" (verified in Patent Art list; filed 2004-12-21)

  • Citation: US 2006/0133377 A1; published June 22, 2006.
  • Description: Discloses integrated anomaly detection and policy enforcement — i.e., criteria-based classification of traffic with enforcement actions.
  • § 102 analysis: Relevant to the packet-matching criteria paired with transformation functions element of claims 2/9. Full anticipation depends on unverified disclosures (stealth interface, LAN-switch modification).
  • Confidence: Listed in IPR/litigation art set (verified); disclosure details not retrieved.

6. US 7,792,775 B2 — NEC — "Filtering Rule Analysis Method and System" (verified in Patent Art list; filed 2005-02-23)

  • Citation: US 7,792,775 B2; issued September 7, 2010.
  • Description: Discloses analysis/merging/transformation of filtering rules — relevant to the '437 specification's discussion of merging overlapping rules into non-overlapping rule sets (FIG. 3 discussion).
  • § 102 analysis: Not a standalone anticipator of claims 2/9 (it addresses rule analysis, not boundary-gateway provisioning with stealth interfaces); better suited to an obviousness combination or to dependent rule-structure claims.
  • Confidence: Listed in IPR/litigation art set (verified).

7. US 2005/0071650 A1 — ETRI — "Method and Apparatus for Security Engine Management in Network Nodes" (verified in Patent Art list; filed 2003-09-28)

  • Citation: US 2005/0071650 A1; published March 31, 2005.
  • Description: Discloses management of security engines in network nodes — policy distribution/management to network enforcement points.
  • § 102 analysis: Relevant to the management-server → gateway provisioning model of claims 2/9. Anticipation gap analysis as with items 3–5 (unverified stealth/switching-matrix elements).
  • Confidence: Listed in IPR/litigation art set (verified).

8. US 7,853,996 B1 — "Methodology, Measurements and Analysis of Performance and Scalability of Stateful Border Gateways" (verified in Patent Art list; filed 2003-10-02)

  • Citation: US 7,853,996 B1; issued December 14, 2010.
  • Description: Addresses stateful border-gateway scalability/performance — the exact "scalability of high-resolution filtering" problem motivating the '437 invention.
  • § 102 analysis: Diagnostic/analytical in nature; not a plausible single-reference anticipator of the structural method/system claims. Obviousness-combination relevance only.
  • Confidence: Listed in IPR/litigation art set (verified).

9. US 2001/0039579 A1 — "Network Security and Surveillance System" (verified in Patent Art list; filed 1996-11-05)

  • Citation: US 2001/0039579 A1; published November 8, 2001.
  • Description: Discloses network security monitoring/surveillance — relevant to the '437's monitoring-service embodiment (copy/reroute packets to a monitoring device, FIG. 6).
  • § 102 analysis: Relevant to dependent claims directed at rerouting/copying to a monitoring device (published claim 6 family). Not a standalone anticipator of claims 2/9.
  • Confidence: Listed in IPR/litigation art set (verified).

10. US 2015/0237012 A1 — "Filtering Network Data Transfers" (verified in Patent Art list; filed 2013-03-11)

  • Citation: US 2015/0237012 A1; published August 20, 2015. Note: filed after the '437's earliest priority date (Oct. 22, 2012), so it is not § 102 prior art against the '437 claims under pre-AIA § 102 (or under AIA § 102(a)(2) for the full claim scope) — relevant only for § 103 if at all.
  • Confidence: Listed in IPR/litigation art set (verified); prior-art status as to date is a red flag.

11. US 7,080,581 B1 — "Security System Design Supporting Method" (verified in Patent Art list; filed 1999-11-29)

  • Citation: US 7,080,581 B1; issued July 25, 2006.
  • Description: Design-support methodology for security systems; secondary relevance to rule/policy engineering.
  • § 102 analysis: Not a plausible single-reference anticipator of the independent claims.
  • Confidence: Listed in IPR/litigation art set (verified).

12. Lower-relevance items from the "Patent Art (291)" set (verified as listed, minimal analysis)

  • US 9,419,942 B1 (Palo Alto Networks, "Destination Domain Extraction for Secure Protocols," priority 2013-06-04) — post-priority-date filing; not § 102 prior art against the full claims; not claim-relevant on its face.
  • US 2015/0347246 A1 (Hitachi, "Automatic-Fault-Handling Cache System…," priority 2012-12-04) — post-priority-date filing; cache-fault handling, low claim relevance.
  • US 7,499,412 B2 (filed ~2005) — listed in the art set; I could not verify its title/disclosure from the available snippets; do not rely on my characterization — flagged as unverified.
  • US 7,080,581 / US 7,792,775 / US 7,853,996 — see above.

Bottom-line ranking of "most relevant" prior art

Rank Reference Best § 102 target Key unverified gap
1 US 2009/0262741 A1 (Transparent Provisioning…) Claims 2 & 9 (stealth/transparent gateway) LAN-switch switching-matrix modification; malicious-traffic criteria
2 US 6,826,694 B1 (High Resolution Access Control) Claims 2, 3, 4, 9 (high-res filtering rules) Stealth interface; LAN-switch programming
3 US 2006/0070122 A1 (Distributed Firewall) Claims 2 & 9 (managed distributed enforcement) Stealth interface; LAN-switch programming
4 US 2006/0133377 A1 (Fortinet) Claims 2 & 9 (criteria→enforcement pairing) Stealth interface; LAN-switch programming
5 US 2005/0071650 A1 (ETRI) Claims 2 & 9 (security-engine management) Stealth interface; LAN-switch programming
6 US 2007/0083924 A1 (Multi-stage filtering) Claims 2 & 9 (filter→transformation pipeline) Stealth interface; LAN-switch programming
7 US 2001/0039579 A1 (Surveillance) Monitoring dependents (claim 6 family)
8 US 7,792,775 B2 (NEC rule analysis) Rule-merging aspects (spec, FIG. 3) Not a standalone anticipator
9 US 7,853,996 B1 Scalability motivation only Not a standalone anticipator

Explicit uncertainty statement (per operating rules)

  • The complete examiner "References Cited" list on the face of US10567437B2 was not retrieved. The analysis above draws on (a) two confirmed citation links (US 6,826,694 B1; US 2009/0262741 A1) and (b) the Unified Patents "Patent Art (291)" list, which is petitioner/litigation art from IPR2021-01153 (not instituted) and E.D. Va. 2:21-cv-00137, not examiner citations. Those are different populations; do not conflate them.
  • Granted-claim text is unverified; mapping uses the published-application claims (claims 2 and 9 independent). If prosecution amendments narrowed the granted claims (e.g., added the LAN-switch limitation), the anticipation analysis shifts accordingly.
  • Element-by-element disclosure verification for each reference requires full-text review, which the search tooling did not permit; where a mapping element is unverified, I say so rather than infer it.
  • The fact that IPR2021-01153 was not instituted is relevant context: the PTAB did not find the petition's art sufficient to establish a reasonable likelihood of prevailing — a signal that none of the references above, as presented in that petition, cleanly reads on the claims.

Generated 8/31/2026, 12:46:27 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis — U.S. Patent 10,567,437 B2 ("Methods and systems for protecting a secured network")

1. Scope note and claim reconstruction

Before analyzing § 103, I must flag an evidentiary limitation that affects precision: I could not retrieve the exact granted claim text of the B2 patent from any source in this session. The earlier sections of this analysis relied on the pre-grant publication US20190230128A1 (claims 2 and 9 independent, claim 1 canceled). The IPR and PTAB records, however, confirm the granted patent has 20 claims with three independent claims — claims 1, 8, and 15 — and that the preambles of all three are limiting (Patent Owner's Preliminary Sur-Reply, IPR2021-01153; see ptacts.uspto.gov document and the IPR2021-01153 institution decision, Paper 10, Jan. 24, 2022). The IPR record also confirms a key preamble/limitation phrase: "a plurality of packet security gateways that collectively provide an entire interface across a boundary of a network protected." The granted claims therefore differ in form from the published claims 2/9, and my mapping below is necessarily based on (a) the IPR-confirmed claim structure, (b) the published-application claims, and (c) the specification (provided in full), which supports the recited features. Any conclusion should be re-validated against the actual granted claim text (USPTO Patent Center) before reliance in litigation or IPR.

The core limitations at issue, drawn from the specification and the record, are:

  • L1 (preamble): a plurality of packet security gateways that collectively provide an entire interface across a boundary of a protected network (per IPR record).
  • L2: a dynamic security policy received from a security policy management server, comprising rules pairing packet-matching criteria with packet-transformation functions.
  • L3: at least one packet-transformation function other than forwarding or dropping (e.g., rerouting/encapsulation to a monitoring device, IPsec-stack delivery, VLAN assignment, queueing).
  • L4: network-layer-transparent operation — traffic received/sent on interfaces not addressed at the network layer, while transformation occurs at the network layer; separate management interface with a network-layer address, secured at the application level (e.g., SSH).
  • L5: dropping packets matching criteria tied to malicious network traffic (blocklist/allowlist constructs).
  • L6: modifying a LAN switch's switching matrix so the switch also drops matching packets.
  • Dependent features: five-tuple rules; DSCP-based differentiated queueing; SIP-URI-based rerouting; VoIP-session-derived rules; subscription threat-intelligence feeds; IPsec security-association matching; phased restoration; series-configured gateways.

2. Prior art of record (the "Prior Art section" of the patent's family/records)

The examiner's References Cited (per PubChem's copy of the B2 bibliographic record) and the litigation/IPR record supply the following material references:

Ref. Identity Relevance
Jungck US 2009/0262741 A1, "Packet processing system and method therefor" (CloudShield; IPR Ex. 1051) Primary reference in IPR2021-01153; rule-based packet processing/transformation engine
RFC 2003 C. Perkins, "IP Encapsulation within IP," IETF, Oct. 1996 Encapsulation-based rerouting to a different address (used for claims 5, 12, 19 in the IPR)
AT&T '694 US 6,826,694 B1, "High Resolution Access Control" (priority Oct. 22, 1998) Payload/state-aware filtering rules; rules obtained from a node external to the firewall (dynamic policy provisioning)
Microsoft policy distribution US 2006/0129808 A1 / EP 1677484 A2, "Method and system for distributing security policies" (priority Nov. 19, 2004) Server distributes security policies to enforcement engines; each rule = condition + action; rule-type-based routing to the right enforcement point
Wood US 2007/0097976 A1 (IPR Ex. 1052) Additional packet-processing/filtering art in the IPR record (content not verified this session)
"Law" Unidentified reference argued in the IPR sur-reply re: the plurality-of-gateways preamble Cited by petitioner in preliminary reply; identity could not be verified — flagging as an open item
Sourcefire 3D System User Guide (Mar. 16, 2011) NPL of record Rule-based intrusion prevention with policy updates
Palo Alto Networks, "Designing a Zero Trust Network With Next-Generation Firewalls" (last viewed Oct. 21, 2012) NPL of record Boundary gateways enforcing centrally managed policy; date caveat below
Qiu et al. 2001; Fulp 2004; Warkhede 2001; Christiansen 2002 NPL of record High-resolution/ordered firewall rule sets and optimization — the scalability problem the patent addresses
Cisco "Control Plane Policing Best Practices" (Mar. 13, 2013) NPL of record Date caveat: post-dates the Oct. 22, 2012 priority date as archived; may not qualify unless an earlier version existed
IPR2021-01153 Palo Alto Networks v. Centripetal Networks (PTAB) Grounds: claims 1–4, 6–11, 13–18, 20 over Jungck; claims 5, 12, 19 over Jungck + RFC 2003. Institution denied Jan. 24, 2022

3. Primary § 103 combinations

Combination 1 — Jungck alone (claims 1–4, 6–11, 13–18, 20)

Asserted by the petitioner. Jungck discloses a high-speed, rule-based packet-processing system in which received packets are classified against rules and subjected to specified processing actions (forward, drop, and other transformations). For the preamble (L1), Jungck's architecture distributes processing across multiple packet-processing engines arranged to provide an interface between networks. For L2/L3, Jungck's rules pair matching criteria with configurable actions, including actions beyond simple pass/drop. For L5, block/drop rules tied to identified malicious traffic are routine. For the five-tuple, DSCP, queueing, and IPsec-stack dependent features, Jungck's programmable classification and action engine provides a natural home, combinable with the well-known DiffServ (RFC 2474/2475) and IPsec (RFC 4301) stacks.

Why the PTAB denied institution (important): the Board found the petitioner did not establish a reasonable likelihood on any independent claim (Paper 10). Based on the record, the likely gaps in Jungck alone are: the plurality-of-gateways-collectively-providing-an-entire-interface preamble (L1); the network-layer-transparent interface with an unaddressed data interface plus a separately addressed, application-secured management interface (L4); and the LAN-switch switching-matrix modification (L6). These are exactly the limitations a stronger combination must source from other references.

Combination 2 — Jungck + RFC 2003 (claims 5, 12, 19)

Asserted by the petitioner. Claims 5/12/19 (per the IPR) add rerouting of matched packets to a network address different from the destination — the monitoring-service embodiment of the specification (Fig. 6). RFC 2003 teaches precisely this: encapsulating an IP packet with an outer IP header so it is routed to an intermediate device, which can copy/inspect and then forward on. Motivation: the POSITA seeking to tap or mirror traffic at a security gateway — a routine lawful-intercept/IDS function — would use RFC 2003's encapsulation to redirect a copy to a monitoring device while preserving the original destination, exactly as the specification describes (col. 55–60 area: "encapsulate … with an IP header specifying a network address different from their respective destination addresses"). The combination is the textbook use of a standards-track encapsulation technique to implement a known function, with predictable results.

Combination 3 — Jungck + AT&T '694 (High Resolution Access Control)

AT&T '694 (claim 1 verbatim, from the record): "A method for filtering a packet … receiving a packet having at least one header parameter and a payload; selecting an access rule based upon the contents of the payload … implementing the access rule … selected based upon a combination of the contents of the packet … and the contents of at least one other packet." It also discloses rules "obtained from a node external to the firewall."

  • Fills L2 (dynamic policy provisioning): '694's external-node rule delivery is the management-server-to-gateway policy channel; combined with Jungck's rule engine, the POSITA would configure the gateway to receive updated rule sets from a policy server — the "dynamic security policy received from the security policy management server" limitation.
  • Fills the high-resolution-filtering problem the patent itself identifies as the reason proactive filtering was "deemed untenable": '694's payload/state-based rules and the Qiu/Fulp/Warkhede/Christiansen optimization literature (all of record) directly address the scalability concern that the specification concedes was the barrier.

Motivation: The patent's own Background frames high-resolution filtering as the core challenge; '694 is the canonical solution to that challenge and predates the '437 priority date by 14 years. A POSITA designing a scalable proactive filter would combine Jungck's high-speed engine with '694's high-resolution rule-selection and external provisioning as a matter of routine design.

Combination 4 — Jungck + Microsoft policy distribution (US 2006/0129808 / EP 1677484)

The Microsoft reference discloses a security-policy management server distributing policies to multiple enforcement engines at protected hosts, where each rule has a condition and an action and a rule type directing the rule to the correct enforcement engine.

  • Fills L1/L2: the plurality of enforcement points, the central server, and the rule = (criterion → action) structure are all present. The POSITA would substitute Jungck's packet gateways for the host-based enforcement engines (or combine both) to scale the Microsoft distribution model to boundary devices — a predictable substitution of one known enforcement point for another in the same field.
  • Motivation: centralized, dynamic policy management of distributed security devices was a well-documented trend by 2012 (also reflected in the Sourcefire and Palo Alto zero-trust literature of record). The POSITA would be motivated by operational efficiency (single-point policy updates, uniform enforcement at every boundary — the exact "uniform manner" goal of Figs. 7–8).

Combination 5 — Jungck + transparent/stealth-firewall prior art (L4)

The network-layer-transparent gateway (unaddressed link-layer data interfaces + addressed management interface secured at the application layer) was a well-known transparent firewall / "bump-in-the-wire" design long before 2012 (e.g., Cisco PIX/ASA transparent-mode and comparable products, which bridge at Layer 2 without IP addresses on data interfaces and are managed out-of-band/SSH).

  • Fills L4: a POSITA implementing Jungck's rule engine as an inline boundary device would routinely place it in transparent/L2 mode to avoid renumbering the protected network and to make it unaddressable (and thus less attackable — the specification's own stated rationale at Fig. 2: "attack packets cannot be routed to the network interfaces"), with an out-of-band management interface secured via SSH/TLS.
  • Motivation: non-disruptive deployment, stealth, and management security — all explicit in the specification — are standard design goals; the combination is the straightforward application of known transparent-firewall techniques to Jungck's engine.

Combination 6 — Jungck + switch-ACL/TCAM art (L6)

Programming a LAN switch's switching matrix/forwarding table (TCAM/ACL) to drop traffic matching a policy is standard switch security (port ACLs, VLAN ACLs, storm control, and switch-integrated security features).

  • Fills L6: once the gateway derives drop criteria from its dynamic policy, programming the adjacent LAN switch to enforce the same drop set is an obvious defense-in-depth step — the specification itself says the switch is modified "so the switch also drops those matching packets," i.e., to extend enforcement to traffic that may not physically traverse the gateway (LAN-to-LAN flows, Fig. 9).
  • Motivation: ensuring all traffic at the boundary is filtered (the patent's own scalability/full-coverage rationale); using the switch's hardware forwarding tables offloads enforcement from the gateway. The mechanism (writing filter entries into a switch's switching matrix) is a known, predictable use of switch ACL hardware.

Combination 7 — Jungck + subscription threat-intelligence feeds (dependent claim on malicious-address lists)

The "list of known network addresses associated with malicious network traffic … received from a subscription service" is precisely the DShield/Spamhaus/Emerging Threats model (aggregated malicious-IP feeds) that predates 2012.

  • Fills the dependent limitation: a POSITA would feed such a list into Jungck's rule engine to auto-generate drop rules — the specification's Fig. 5 "malicious host tracker service 508" is a direct description of this known model.
  • Motivation: automation of blocklist maintenance, reduction of human error, timeliness — all standard reasons to subscribe to threat feeds.

Combination 8 — Jungck + SIP-aware firewall/session-border-controller art + DiffServ (VoIP and DSCP dependents)

  • VoIP-session-derived rules: SIP-aware firewalls and session border controllers that open/close pinholes based on SIP signaling were mature by 2012. The POSITA would combine Jungck with a softswitch/SBC signaling feed (as in Fig. 6) to create and tear down per-session rules — the patent's VoIP firewall service.
  • DSCP-based differentiated queueing: RFC 2474/2475 DiffServ and DSCP-based scheduling/queuing in routers is foundational prior art; adding a DSCP selector to Jungck rules and mapping matched traffic to different forwarding queues with different rates is an obvious application of DiffServ to the gateway's egress queues (the specification's enqueueing service).

4. Why a POSITA would combine (general § 103 framework)

  1. Same field, same problem. Every reference above is in network security/packet processing — the exact field of the '437 patent. The patent's Background concedes the problem (scalable, high-resolution, proactive filtering) was known; the Qiu/Fulp/Warkhede/Christiansen papers of record show the POSITA community was actively working on ordered, high-resolution rule sets.
  2. Known elements, predictable combination. Each disputed limitation maps to a known technique: dynamic policy distribution (Microsoft; AT&T '694 external-node rules), transparent/stealth inline filtering (L2 firewall art), switch-ACL enforcement, RFC 2003 encapsulation, DiffServ queueing, SIP-pinhole firewalling, and threat feeds. § 103 does not require a reference to teach the combination; it requires the combination to be obvious, and here the specification itself describes each feature as a conventional "service" layered onto a rule engine.
  3. Design incentives. The specification's own stated benefits — uniform enforcement at every boundary (Figs. 7–8), non-disruptive deployment (transparency), scalability via series-configured gateways (Fig. 4), and centralized management (Fig. 5) — are precisely the incentives that would drive a POSITA to combine Jungck with the policy-distribution, transparency, and switch-enforcement references.
  4. Reasonable expectation of success. All components are off-the-shelf technologies with known interfaces; no new protocol or hardware is required. The series-gateway configuration (Fig. 4) is a straightforward application of the known "defense in depth"/chained-firewall model, and the two-policy decomposition (internal hosts / external hosts) is a standard rule-partitioning technique (cf. the rule-optimization NPL of record).

5. Countervailing factors and the record's cautionary signals

  • The PTAB declined to institute IPR2021-01153 on the Jungck and Jungck + RFC 2003 grounds. That decision is not a merits finding of patentability, but it is a meaningful signal that Jungck alone (and with RFC 2003) was not shown to disclose the full independent claims — most plausibly the plurality-of-gateways preamble, the network-layer-transparent interface/management-interface combination, and the switch-matrix modification. A robust § 103 case therefore requires the additional references (Combinations 3–6), not just the IPR grounds.
  • The "Law" reference relied on by the petitioner in the IPR reply for the plurality-of-gateways preamble could not be identified in this session; its strength is an open question.
  • Secondary considerations are likely to be contested (long-felt need for scalable proactive filtering; industry praise; licensing/settlement activity in the Centripetal litigation family). The CAFC appeals 25-1167/25-1168 (reactivated Dec. 22, 2025) may produce a merits decision that bears on claim construction and validity, but none was located as of this analysis.
  • § 101 exposure (raised in the Ixia/Keysight case, 2:17-cv-383) is outside the § 103 scope of this task but worth noting: the claims' emphasis on functional "services" could make eligibility an alternative invalidity path.

6. Bottom line

  • Most vulnerable claims: the dependent claims adding encapsulation-based monitoring (claims 5/12/19 over Jungck + RFC 2003, as the IPR alleged), the subscription-feed malicious-address limitation, and the DSCP/queueing and VoIP-session limitations — all map to mature, well-documented prior art.
  • Hardest limitations to reach under § 103: (i) the "plurality of packet security gateways that collectively provide an entire interface across a boundary" preamble; (ii) the combination of network-layer-transparent data interfaces plus a separately addressed, application-secured management interface; and (iii) the LAN-switch switching-matrix modification. Each requires a specific secondary reference (transparent-firewall art, switch-ACL art) rather than Jungck alone — which is consistent with the PTAB's institution denial.
  • Strongest overall combination: Jungck (rule engine) + AT&T '694 (high-resolution rules, external provisioning) + Microsoft EP 1677484/US20060129808 (policy-server distribution to multiple enforcement points) + transparent-firewall art (L4) + switch-ACL/TCAM art (L6) + RFC 2003 (monitoring reroute), with the threat-feed, DiffServ, and SIP-pinhole references filling the dependent features. Under KSR-style reasoning (known elements, predictable combination, same field, express design incentives), this composite has a realistic chance of rendering the independent claims obvious — provided the granted claim text does not contain undisclosed limitations beyond those confirmed in the IPR record.

Key caveat restated: the granted claim text was not fully verified this session; the mapping relies on the IPR-confirmed claim structure (independent claims 1, 8, 15; plurality-of-gateways preamble) and the published-application claims. Before relying on this analysis, pull the granted claims from USPTO PatentCenter and re-validate each limitation mapping, and verify the identity and dates of the "Law," Wood, and Palo Alto zero-trust references.

Generated 8/31/2026, 12:47:19 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (5)

5 tracked lawsuits name US 10567437.