Invalidity dossier
US 10659573
Correlating packets in communications networks
Current assignee: Centripetal Networks, Inc.
Added 8/30/2026, 12:47:09 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
Summary — U.S. Patent 10,659,573 (US10659573B2)
Note on sourcing: The bibliographic data below comes from the authoritative Google Patents record for US10659573B2 (fetched 2026-08-30) included in the task materials, corroborated by Unified Patents and Justia records. I could not retrieve the full granted-claims text (the provided patent text truncates before the claims section), so the claim overview below is based on the published application (US20190394310A1, which corresponds to application 16/554,293 that issued as US10659573B2) as shown on Justia. Treat the exact granted claim language as unverified.
Bibliographic data
- Title: Correlating packets in communications networks
- Patent number: US10659573B2 (application no. US16/554,293)
- Assignee (original): Centripetal Networks LLC (later assignments show Centripetal Networks, Inc., and a 2023 change of name back to Centripetal Networks, LLC)
- Inventors: David K. Ahn; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry
- Earliest priority date: 2015-02-10 (chain: 14/618,967 → US9,264,370; 14/714,207 → US9,560,176; 15/413,947; then this continuation, filed 2019-08-28)
- Issue date: 2020-05-19
- Status: Active; anticipated expiration 2035-02-10
- Classifications: H04L69/22 (header parsing); H04L43/02, 43/026 (flow-identification monitoring); H04L43/12 (probes); H04L45/745 (address lookup/filtering); H04L47/10, 47/24, 47/32 (flow control/discard); H04L61/2567 (NAT traversal); H04L63/0227 (filtering policies); H04L43/0852/087 (delay/jitter); H04L43/106 (timestamps)
Abstract (verbatim)
"A computing system may identify packets received by a network device from a host located in a first network and may generate log entries corresponding to the packets received by the network device. The computing system may identify packets transmitted by the network device to a host located in a second network and may generate log entries corresponding to the packets transmitted by the network device. Utilizing the log entries corresponding to the packets received by the network device and the log entries corresponding to the packets transmitted by the network device, the computing system may correlate the packets transmitted by the network device with the packets received by the network device."
What the patent is about (plain language)
Endpoint communications are "flows" of related packets. A middlebox-type network device (e.g., a NAT device, proxy, or VPN/tunneling gateway) can rewrite or encapsulate packets in ways that obscure which flow a packet belongs to when viewed from outside that device. The patent places tap/packet-filtering devices on both sides of such a network device, logs packets received by the device (from a host in a first network) and packets transmitted by the device (toward a host in a second network), and then correlates the transmitted packets back to the received packets using the log data (header fields, ports, timestamps, encapsulated payloads, etc.). This re-association lets a correlator figure out, for example, which internal host was actually communicating with an external (possibly malicious) destination, generate alerts, and provision rules to drop offending traffic.
Independent claims (plain-language overview; from published application US20190394310A1, pending verification of granted text)
The publication shows three independent claim sets — a method claim (claim 1), a computing-device/system claim (claim 9), and a computer-readable-media claim (claim 17) — each with the same core steps:
- Method claim (claim 1): Identify a plurality of packets received by a network device from a host in a first network; generate a first plurality of log entries for those received packets; identify a plurality of encrypted packets transmitted by the network device toward a host in a second network; generate a second plurality of log entries for those transmitted encrypted packets; and correlate the transmitted encrypted packets with the received packets based on both sets of log entries.
- Computing device claim (claim 9): A device (memory + processors) that performs the same identification, log-generation, and correlation functions; dependent claim 10 adds provisioning of a first tap and a second tap with rules to identify the received and transmitted packets respectively; claim 15 adds determining the second-network host is malicious and generating drop rules; claim 16 adds generating a message identifying the first-network host.
- Computer-readable media claim (claim 17): Non-transitory media with instructions causing a computing system to perform the same identify/log/correlate operations.
Dependent claims detail correlation techniques (comparing ports, network-interface identifiers, timestamps of receipt vs. transmission, and encapsulated/request data).
Caveat: I could not confirm whether the granted claims of the B2 patent are identical to the published application claims (e.g., the "encrypted packets" wording appears in the publication; amendment during prosecution is possible).
CAFC 2026 docket status (with uncertainty)
- The Google Patents family record lists CAFC appeals involving this patent family: 25-1167, 25-1168, and 26-1359 (the 26-xxxx number being a 2026 docket), plus district-court cases 2:21-cv-00137 and 1:21-cv-00313 (E.D. Va.), 1:22-cv-00001 and 2:22-cv-00002, and PTAB case IPR2021-01151 (petition not instituted on the merits).
- News coverage (Law360, April 2026) reports that a Federal Circuit panel heard argument on April 7, 2026 and, around April 29, 2026, affirmed a Virginia district court finding that Cisco did not infringe a trio of Centripetal cybersecurity patents (following vacatur of a multibillion-dollar judgment due to a judge's stock conflict). It is plausible 10659573 is among those three patents, but I could not verify the specific patent-to-docket mapping (the CAFC opinions/orders page I retrieved showed Centripetal decisions 24-1406 and 24-1416, which concern a different patent, US10,284,526, and an ITC matter).
- Other 2026 activity: a June 12, 2026 report that the PTAB again found a Centripetal Cisco-related patent invalid as obvious on remand — again, not confirmed to be 10659573 specifically.
If you need certainty on the granted claims or the exact CAFC docket (26-1359) scope, I'd recommend pulling the claims PDF from USPTO Patent Center (application 16/554,293) and the CAFC docket sheet directly.
Generated 8/31/2026, 12:48:24 AM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 10659573. The free-form analysis below may also discuss cases beyond this list.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10091246, 10567437, 10530903, 10567413, 10757126, 10542028, 10503899, 10735380, 10749906, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10749906, 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10735380, 10757126, 10785266, 10931797
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search for litigation involving US Patent 10659573 across multiple sources.
Let me search for the specific case numbers identified and verify which involve this patent.
Let me search for the Keysight cases and Federal Circuit appeals to confirm which involve this patent.
Based on my research across Google Patents (the authoritative patent record provided), Unified Patents, Docket Alarm, RPX, CourtListener, Casetext, and Keysight's SEC filings, here is the known litigation involving US Patent 10,659,573 ("Correlating packets in communications networks"). I found no results for a "10659573" that differ from this patent.
1. Centripetal Networks, LLC (now Centripetal Networks, Inc.) v. Palo Alto Networks, Inc.
- Case No.: 2:21-cv-00137 (EWH-LRL / earlier RCY-RJK)
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
- Filing date: March 12, 2021
- Plaintiff: Centripetal Networks, LLC (later Centripetal Networks, Inc.)
- Defendant: Palo Alto Networks, Inc.
- Patents-in-suit: 13 patents, including No. 10,659,573 (the "'573 patent"). Per PAN's pretrial brief, Centripetal asserted claims 1 and 9 of the '573 patent (one of the "Correlation Patents" sharing a family with the '903, '797, and '437 patents).
- Status/Outcome:
- Jury verdict for Centripetal in May 2023 ($151.1M award). Judge Elizabeth W. Hanes subsequently granted judgment as a matter of law of non-infringement on the '437 patent and reduced the award; the jury's infringement findings on the Correlation Patents (including the '573 patent) were upheld as to patent eligibility and damages.
- District court case closed as of October 17, 2024 (per Ex Parte/Unified Patents docket data).
- Appeals pending: Federal Circuit Nos. 25-1167 and 25-1168 (Centripetal Networks, LLC v. Palo Alto Networks, Inc.), both filed November 13, 2024, arising from 2:21-cv-00137; appeal 25-1167 was reactivated by CAFC order on December 22, 2025. Google Patents also lists a CAFC matter, 26-1359, in this patent's litigation history.
2. Centripetal Networks, Inc. v. Palo Alto Networks, Inc. (companion filing)
- Case No.: 1:21-cv-00313
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (Alexandria Division)
- Filing date: March 12, 2021 (same day as 2:21-cv-00137)
- Plaintiff: Centripetal Networks, Inc.
- Defendant: Palo Alto Networks, Inc.
- Status: Listed in Google Patents' litigation record for this patent. Docket records show it as a parallel/companion patent-infringement filing (complaint and exhibits cross-referenced with 2:21-cv-00137). I could not independently verify a separate final disposition; treat this as related to the Norfolk case above.
3. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (IPR)
- Case No.: IPR2021-01151 (PTAB)
- Jurisdiction: Patent Trial and Appeal Board
- Filing date: July 20, 2021
- Petitioner: Palo Alto Networks, Inc.
- Patent Owner: Centripetal Networks, Inc.
- Claims challenged: All claims 1–24 of the '573 patent.
- Status/Outcome: Institution denied (February 16, 2022); Google Patents characterizes it as "Not Instituted – Merits." A related appeal (2022-145) is noted in case summaries.
4. Centripetal Networks, Inc. v. Keysight Technologies, Inc., et al.
- Case Nos.: 1:22-cv-00001 and 2:22-cv-00002 (E.D. Va.)
- Jurisdiction: U.S. District Court for the Eastern District of Virginia
- Filing date: January 1, 2022 (docketed January 4, 2022)
- Plaintiff: Centripetal Networks, Inc.
- Defendants: Keysight Technologies, Inc. and related entities (Unified Patents' litigation data for this patent lists Keysight Technologies Singapore Sales Pte Ltd among involved parties).
- Status/Outcome: Per Keysight's SEC filings, the district court action is stayed pending resolution of Centripetal's appeals of the ITC Section 337 investigation (terminated in Keysight's favor, Dec. 5, 2023) and USPTO validity challenges (Keysight states most claims of the challenged patents were found invalid, with Centripetal appealing; in January 2026 the Federal Circuit affirmed invalidation of all claims of one challenged patent). Google Patents lists both 1:22-cv-00001 and 2:22-cv-00002 as litigation involving this patent.
Related administrative proceeding (not district-court litigation)
- Ex parte reexamination 90/019,563 (USPTO): A request filed July 1, 2024 was granted; the Office found a substantial new question of patentability affecting claims 1 and 9 of the '573 patent. This proceeding was cited in the Palo Alto Networks litigation record (Docket Alarm). This is an ongoing USPTO proceeding, not a court case.
Notes and caveats
- The well-known Cisco verdict (Centripetal Networks v. Cisco Systems, 2:18-cv-00394, E.D. Va.) involved different Centripetal patents; the '573 patent did not issue until May 19, 2020, and I found no verified indication that 10659573 was asserted in the Cisco case, so I have not listed it.
- Details on 1:21-cv-00313 are thin in the sources I could access; it appears to be a companion filing to 2:21-cv-00137 rather than an independent merits case.
- The CAFC appeal number 26-1359 appears in Google Patents' litigation feed for this patent, but I could not confirm its caption or originating case with certainty; it is likely a further appeal in the Palo Alto Networks or Keysight matter.
If you need, I can dig deeper into PACER/CAFC dockets for 25-1167/25-1168/26-1359 or the Keysight stay to pin down exact current statuses — but I've hit the search-step limit for this response.
Generated 8/31/2026, 12:48:32 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Centripetal Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
The structured block says no AIA proceedings are on file via ODP, but web search is already surfacing IPR2021-01151. Let me verify its details and look for any other proceedings on this patent.
I have solid confirmation of IPR2021-01151. Now let me verify the Federal Circuit mandamus outcome and check whether any other IPR was instituted on this patent (e.g., by Cisco/Keysight).
I've reached the search limit, but I have enough verified material to answer. One important flag up front: the structured "PTAB proceedings on file" block (ODP) shows zero AIA proceedings — but web search independently verifies one proceeding, IPR2021-01151, which the Google Patents litigation metadata for this patent also lists ("filed (Not Instituted - Merits)"). Treating the ODP ingest as incomplete on this point.
Proceedings overview
Total: 1 AIA trial proceeding surfaced for US 10659573 — IPR2021-01151, denied institution on the merits (never instituted, no Final Written Decision, no claims canceled, no settlement). All 24 claims remain in force, and because the proceeding ended at the institution stage, no § 315(e)(2) estoppel attaches and no claim-level validity findings were made — which cuts both ways: the patent has not been merits-hardened, but the one full-frontal IPR (all 24 claims, best-available art) failed to clear the "reasonable likelihood" bar, making a repeat IPR with the same art a poor bet for a defendant.
IPR2021-01151 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review
- Filed: 2021-07-20
- Status: Institution denied — PTAB metadata labels it "Not Instituted - Merits," i.e., the Board did not find a reasonable likelihood that petitioner would prevail on any challenged claim, and the proceeding was closed without trial.
- Judge panel: Administrative Patent Judges Aaron W. Moore, Bryan F. Moore, and Stacey G. White (secondary-source listings; Patexia attributes the institution decision to APJ Stacey G. White). Note: I could not retrieve the institution decision's own text to confirm the authoring judge — flagging as unverified.
- Petition grounds: Challenged claims 1–24 (the entire patent) under 35 U.S.C. § 103 only:
- Ground 1: Claims 1, 7–9, 15–17, 23–24 obvious over Paxton (US 2014/0280778) + Sutton (US 8,413,238) in view of Deschenes (US 2013/0262655).
- Ground 2: Claims 2, 10, 18 obvious over Paxton + Sutton + Deschenes + McDonald (EP 2482522).
- Ground 3: Claims 3–6, 11–14, 19–22 obvious over Paxton + Sutton + Deschenes + Ivershen.
- Petitioner's theory: Paxton taught correlating packets across a NAT boundary via log data (payload hashes, timestamps); Sutton supplied the responsive security-action limitations (malware identification, rule generation, administrator notification); Deschenes taught correlating encrypted traffic using unencrypted header/timestamp data; McDonald supplied rule-provisioned "taps"/packet selectors; Ivershen addressed the remaining dependent-claim limitations.
- Institution decision: Denied 2022-02-16. I could not pull the full decision text, so I will not paraphrase the panel's reasoning beyond the verified "denied" outcome and the "Merits" label indicating the denial was based on the merits rather than a discretionary (Fintiv-type) ground. The denial covered all 24 challenged claims; no ground was instituted.
- Final Written Decision: None. Institution was denied, so no trial and no FWD issued. No claims were canceled; all 24 claims of the '573 patent remain intact.
- Settlement / termination: No settlement. The proceeding terminated at institution denial (case closed 2022-02-16).
- Appeal: Palo Alto did not directly appeal the institution denial (institution decisions are final and non-appealable, 35 U.S.C. § 314(d)). Instead, PAN sought Director rehearing of the non-institution decision; the USPTO refused to accept such requests, and PAN petitioned the Federal Circuit for a writ of mandamus — In re Palo Alto Networks, Inc., No. 22-145 (Fed. Cir. 2022) (panel: Dyk, Chen; Reyna concurring), filed 2022-04-19, decision 2022-08-16 (CourtListener, opinion PDF). The Federal Circuit denied mandamus, holding (precedentially) that the Director's delegation of institution decisions to the PTAB and the USPTO's policy of refusing party-requested Director review of non-institution decisions do not violate the Appointments Clause. No further appellate relief resulted.
- Defensive value: Mixed but net-positive for the patent owner. A sophisticated petitioner (Palo Alto, with Ropes & Gray) threw its best § 103 combination at all 24 claims and did not clear the institution threshold — that is a meaningful signal that this patent is not an easy IPR target. But because there is no FWD, there is no estoppel and no claim-by-claim validity determination a defendant can point to; a defendant facing assertion today cannot cite IPR2021-01151 as having "validated" any claim.
Sources: Patexia docket summary, Ex Parte PTAB case summary, Finnegan PTAB Blog, Justia CAFC docket for 22-145.
Strategic summary
Claim status of US 10659573. All 24 claims (independent claims 1 and 15, plus dependents 2–14 and 16–24) are SUSTAINED — by default, not by merits finding. No claim has ever been canceled in an AIA trial because no AIA trial was ever instituted. The only AIA challenge on the '573 — IPR2021-01151 — was denied institution on the merits. So the correct characterization is: 0 claims canceled, 24 untested-by-FWD, with one failed institution attempt on the full claim set. That is a weaker statement than "hardened by a FWD," but it is still the outcome a defendant must live with: the Paxton/Sutton/Deschenes/McDonald/Ivershen art cluster has been vetted at the PTAB and lost at the threshold.
Estoppel landscape. Because IPR2021-01151 was denied institution and never reached a final written decision, no § 315(e)(2) estoppel attaches — to Palo Alto, its privies, or anyone else. A defendant is not barred from raising the Paxton/Sutton/Deschenes combination again in district court or in a new petition. In practical terms, though, the art is now battle-tested and known to be insufficient at the PTAB threshold; a rational defendant would bring different, stronger art (e.g., art that more directly teaches log-based correlation of encrypted packets with rule-driven taps and responsive security actions) rather than recycle the denied combination. Also note the current USPTO posture (Director Squires, effective 2025-10-20): institution decisions are Director-controlled, institution rates have collapsed, and proposed rules would categorically bar institution where claims have already been found valid or where parallel litigation would outpace the IPR — so new IPR filings on this patent face an unusually hostile institution environment.
Pattern signals. Only one petitioner (Palo Alto Networks) has challenged this patent at the PTAB, and it filed the companion PGR2021-00108 against the closely related continuation patent US 10,931,797 (also denied institution, also covered by the same 22-145 mandamus). Centripetal (now Centripetal Networks, LLC/Inc.) is an aggressive litigant — the patent's family docket shows multiple E.D. Va. cases (e.g., 2:21-cv-00137 v. Palo Alto; 1:21-cv-00313; 1:22-cv-00001; 2:22-cv-00002) and Federal Circuit dockets 25-1167, 25-1168, and 26-1359 whose specific subject matter I could not verify — and Centripetal has separately pursued ITC domestic-industry theories on family patents. Unified Patents appears in the Google Patents litigation metadata only as the data source for the IPR2021-01151 listing, not as petitioner — do not attribute the proceeding to Unified. There is no defensive-aggregator petition on this patent on the record I found.
Recommended next steps
- If you are a defendant considering an IPR on the '573: The prior-art combination from IPR2021-01151 is a known loser at institution. Do not refile Paxton/Sutton/Deschenes. You need new art plus a Sotera-style stipulation and a plan to survive the post-October-2025 Director-controlled institution regime (which now favors denial where parallel litigation will reach validity first). Pull the actual institution decision (Paper 8, IPR2021-01151, P.T.A.B. Feb. 16, 2022) from PTAB E2E before drafting anything — my search could not retrieve its full reasoning, and the panel's specific claim-construction or motivation-to-combine findings are exactly what a new petition must distinguish.
- If you are a defendant relying on this proceeding in district court: Be precise — there is no FWD to quote, and no claim was held patentable. The only citable artifacts are (a) the institution denial (persuasive only, and arguably protected from evidentiary use as a non-final agency action) and (b) the Federal Circuit's In re Palo Alto Networks, No. 22-145 decision, which is about the Appointments Clause and Director review, not about the merits of the '573. Frame any argument as "the strongest available § 103 combination failed to persuade the PTAB," not as "the claims were validated."
- Monitor the family dockets: The CAFC appeals 25-1167, 25-1168, and 26-1359 on the '573 family's litigation record, and the district-court cases (2:21-cv-00137, 1:21-cv-00313, 1:22-cv-00001, 2:22-cv-00002), may produce validity rulings or settlements that matter more than PTAB activity. Also watch whether any new IPR petition is filed against the '573 under the Squires regime — with institution effectively at ~4% since October 2025, the absence of new petitions is itself consistent with the current environment rather than proof of the patent's strength.
- On the ODP gap: The USPTO Open Data Portal ingest shows no AIA proceedings for this patent, which conflicts with the verified record of IPR2021-01151. If you are relying on ODP data in a filing, reconcile this discrepancy (e.g., cite the PTAB case directly) rather than asserting "no PTAB activity" — an opponent will find IPR2021-01151 in five minutes.
Generated 8/31/2026, 12:49:16 AM
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
All five named inventors on US 10659573B2 — David K. Ahn, Peter P. Geremia, Pierre Mallett III, Sean Moore, and Robert T. Perry — were employees/officers of Centripetal Networks, Inc. (the original assignee) at the time the underlying application (US 14/618,967, filed 2015-02-10) was filed. Sean Moore was Centripetal's CTO; David Ahn was a co-founder/VP-level engineer. The 2023-01-20 recorded assignment (see below) confirms all five executed an "assignment of assignors' interest" to Centripetal.
Unusual pattern check: not present. The inventors did not depart and trigger a portfolio fire-sale; Ahn and Moore in particular remained with Centripetal through its major assertion campaigns (Cisco, Palo Alto Networks) years after filing.
Original assignee
Centripetal Networks, Inc. (renamed Centripetal Networks, LLC, Portsmouth, New Hampshire; earlier Herndon, Virginia). The issued patent's Google Patents "original assignee" field reads "Centripetal Networks LLC" only because of the later Inc.→LLC name change; at filing and issuance the entity was Centripetal Networks, Inc.
- Products: Yes — Centripetal ships network-security appliances (RuleEngine, CleanINTERNET, CleanICS, packet-filtering/threat-intelligence gateways) that embody the packet-correlation/filtering technology of this family.
- Line of business: Cybersecurity / network security gateway vendor (also a high-frequency patent plaintiff against direct competitors).
- Current status: Operating. Centripetal Networks, LLC remains active and has asserted this patent in E.D. Va. litigation (e.g., Centripetal Networks, LLC v. Palo Alto Networks, Inc., 2:21-cv-00137, which names US10659573 among 14 asserted patents; IPR2021-01151 against the family was not instituted).
Assignment timeline
I could not pull correspondent-of-record data directly from the USPTO Assignment Center in this session; reel/frame entries below are sourced from the Google Patents legal-events data for this patent and its same-family sibling US10931797 (identical chain — US10659573 is a continuation of 15/413,947 → 14/714,207 → 14/618,967). Verify reel/frame and correspondent at https://assignmentcenter.uspto.gov/ before relying on this in a filing.
2013-03-12 (effective) / recorded per family record — Reel 034992/0949
- Conveyance: Assignment of Assignors' Interest
- Assignor: Sean Moore (inventor)
- Assignee: Centripetal Networks, Inc. (Virginia)
- Correspondent: not retrievable from available sources
- Context: Inventor-to-company assignment of family assets (partial; the other four inventors' assignment to Centripetal was recorded 2023-01-20 per the patent text).
2017-04-17 recorded — Reel 042056/0098
- Conveyance: Security Interest
- Assignor: Centripetal Networks, Inc.
- Assignee: Douglas A. Smith (Texas) — an individual taking a security interest in the portfolio
- Correspondent: not retrievable from available sources
- Context: Portfolio-level security interest, roughly two years before Centripetal's first large assertion campaign against Cisco — consistent with litigation funding/lending secured against the patents; no assignee-LLC change.
Reel 048492/0499 (date not fully retrievable from snippet)
- Conveyance: Release or related interest (Douglas A. Smith / Centripetal Networks, LLC, New Hampshire appear on the record)
- Context: Appears to be the release/termination of the 2017 Smith security interest after the Inc.→LLC conversion.
2022-10-17 executed / 2023-01-20 recorded — Reel 062446/0660
- Conveyance: Change of Name
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC (New Hampshire)
- Correspondent: not retrievable from available sources
- Context: Pure corporate name change / conversion; no change in beneficial ownership.
2023-01-20 recorded (reel/frame not shown in available data)
- Conveyance: Assignment of Assignors' Interest (confirmatory/re-recorded)
- Assignor: David K. Ahn, Peter P. Geremia, Pierre Mallett III, Sean Moore, Robert T. Perry
- Assignee: Centripetal Networks, Inc.
- Context: Re-recordation of the inventors' original assignment to the company (the underlying 2015-era assignment), coincident with the name-change recordation.
No assignment to any third-party LLC, holding company, or NPE appears anywhere in the chain. The patent has never left the operating company.
Timeline diagram
timeline
title Ownership of US 10659573
2015 : Filed by Centripetal Networks Inc
2017 : Security interest to Douglas Smith
2020 : Patent issued
2021 : First suit vs Palo Alto Networks
2022 : Name change executed
2023 : Name change recorded
: Inventor assignment re-recorded
NPE / troll-pattern signals
Shell-entity transfer — not present. The patent moved only via inventor→company assignment and an Inc.→LLC name change (reel 062446/0660; recorded 2023-01-20). No licensing-only LLC, registered-agent address, or single-purpose entity ever held it.
Known asserter in the chain — not present. Centripetal Networks is not on the Unified Patents / RPX NPE directories; it is an operating security vendor. It is a high-frequency plaintiff (Cisco, Palo Alto Networks), but against direct competitors with shipped products, which is operating-company assertion, not NPE licensing.
Repeat correspondent across the chain — unclear. Correspondent-of-record data was not retrievable from the sources available this session; I cannot confirm or exclude a recurring attorney. This is the one gap in the record and should be checked at the Assignment Center.
Cascading transfers — not present. Only four substantive events over eight years (2013 inventor assignment, 2017 security interest, 2022/2023 release + name change), all within the same operating company or with a single individual secured party.
Pre-litigation transfer — not present. The first suit asserting this patent (Palo Alto Networks, 2:21-cv-00137) was filed 2021-03-12, ~10 months after issuance and before any of the 2022/2023 recordings. The 2017 security interest to Douglas A. Smith predates the first family suit (Cisco, 2019) by two years and did not change ownership. No transfer occurred within six months of any filing.
Bankruptcy fire-sale — not present. Centripetal has not filed bankruptcy; no estate-sale conveyances exist.
Privateering — not present. No SEC or press evidence that Centripetal asserts on behalf of a third party; it sues its own competitors over its own product technology (e.g., its $2.75B Cisco verdict, later vacated on appeal, and its Palo Alto Networks actions).
Defensive aggregator (anti-NPE) — not present. The chain terminates at Centripetal Networks, LLC, an operating company — not RPX, AST, LOT, Unified, or OIN.
Verdict
Operating-company assertion.
The assignment record (reel 034992/0949; 042056/0098; 062446/0660; 2023-01-20 recordings) shows the patent never left the hands of Centripetal Networks, Inc./LLC — an active cybersecurity vendor that ships packet-filtering gateways embodying the claims and asserts this patent in E.D. Va. against direct competitors (Palo Alto Networks, Cisco). The only quasi-financial event is the 2017 security interest to individual Douglas A. Smith (reel 042056/0098), which is consistent with litigation funding rather than an ownership transfer and was later released. No shell LLC, no cascading chain, no pre-suit transfer to an NPE, and no defensive-aggregator terminus — the assertion pattern is a practicing competitor suing competitors.
Verify the full record (including correspondents) at the USPTO Assignment Center: https://assignmentcenter.uspto.gov/ (search by patent 10659573) or https://assignment.uspto.gov/patent/index.html.
Generated 8/31/2026, 12:49:32 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
Let me search for the specific citation list on the patent's Google Patents page.
I need the actual backward citations listed on the face of US10659573B2. Let me search for the citations section directly.
1. Patent Confirmation — US 10,659,573 B2
The search confirms the target patent without ambiguity:
- Patent No.: US10659573B2
- Title: "Correlating packets in communications networks"
- Assignee: Centripetal Networks LLC (later Centripetal Networks, Inc.)
- Application: US16/554,293, filed 2019-08-28
- Grant date: 2020-05-19 (pre-grant publication US20190394310A1, published 2019-12-26)
- Priority date: 2015-02-10 (continuation chain: US14/618,967 → US9,264,370 → US14/714,207 → US9,560,176 → US15/413,947 → US16/554,293)
- Inventor(s): David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert T. Perry
- Source: https://patents.google.com/patent/US10659573B2/en
Subject matter (from the abstract/specification): A computing system identifies packets received by a network device (e.g., a NAT device, proxy, or VPN/tunneling gateway) from a host in a first network, generates log entries for those received packets, identifies (e.g., via tap devices 124/126) packets transmitted by the network device to a host in a second network, generates log entries for the transmitted packets, and then correlates the transmitted packets with the received packets using the two log sets — even though the network device transformed/obfuscated the packets (NAT, proxying, encapsulation/encryption). The system can then generate rules to drop packets from a source host, generate alert messages identifying a host that communicated with a malicious entity, and provision packet-filtering devices with those rules.
2. Methodological caveat
I was able to retrieve a partial citation set for US10659573B2 from the Unified Patents patent page ("Patent Art" listing for US-10659573-B2, https://portal.unifiedpatents.com/patents/patent/10659573), but I could not retrieve the complete, examiner-endorsed "References Cited" page from USPTO Patent Center or the Google Patents "Citations" tab before hitting the search limit. The list below is therefore the most relevant subset I could confirm from the retrieved data, not necessarily the exhaustive face-of-patent citation list. I recommend verifying the complete list in USPTO Patent Center (U.S. Appl. No. 16/554,293) before relying on this for litigation or IPR work.
Also note: several documents appearing in the same aggregated listing (e.g., US20170359449A1, EP3257202A1/B1, US20190394310A1, US10530903B2, US10931797B2, US11683401B2, US11956338B2, US20210203761A1) are family members or later publications of the same invention and are not § 102 prior art against US10659573B2.
3. Most relevant prior art references (with § 102 anticipation assessment)
The independent claim (as published in US20190394310A1, the application that issued as US10659573B2) generally requires: (a) identifying packets received by a network device from a host in a first network; (b) generating first log entries for those packets; (c) identifying encrypted packets transmitted by the network device to a host in a second network; (d) generating second log entries; (e) correlating the transmitted packets with the received packets based on the log entries; (f) responsive to the correlating, generating rules to identify packets from the host in the first network; and (g) provisioning a packet-filtering device with those rules. Dependent claims add comparing ports, network-interface identifiers, times/timestamps, threshold-latency comparisons, message generation, and drop-rule generation. Anticipation assessments below are preliminary (bibliographic-level) and assume the published claim set tracks the granted claims.
A. US8219675B2 — "System and Method for Correlating IP Flows Across Network Address Translation Firewalls"
- Full citation: US 8,219,675 B2, NetScout Systems Texas, LLC (assignee per Unified Patents listing); filing date listed as 2009-12-10; grant ~2012-07-10.
- Description: Discloses correlating IP flows across NAT firewalls — i.e., matching pre-NAT and post-NAT flows belonging to the same end-to-end communication despite address/port translation, using flow records on both sides of the translating device.
- § 102 assessment: This is the single most on-point reference for the core correlation concept (elements (a)–(e)). However, it is directed at flow correlation across NAT, not specifically at log-entry-based correlation of encrypted/encapsulated packets, and it does not appear to disclose the responsive rule generation and packet-filtering-device provisioning of elements (f)–(g). It could anticipate a stripped-down independent claim that omits the encryption and responsive-rule limitations, but it likely does not fully anticipate the independent claim as published. Potential anticipation: independent claim (partial); most relevant as a § 103 combination anchor.
B. US7849502B1 — "Apparatus for Monitoring Network Traffic"
- Full citation: US 7,849,502 B1, Cisco IronPort Systems, Inc.; filing date listed as 2006-04-28; grant ~2010-12-07.
- Description: Discloses monitoring network traffic (tap/passive observation), generating traffic logs/records, and analyzing monitored traffic — relevant to elements (a)–(d) (identifying packets and generating log entries).
- § 102 assessment: Likely covers the identification/logging halves of the claim but not the cross-device correlation of transformed packets or the responsive rule-generation/provisioning. Potential anticipation: dependent claims directed to log generation/identification only (weak); more useful in § 103 combinations.
C. US8422391B2 — "Method, Media Gateway and Media Gateway Controller for Maintaining NAT Address Mapping Table"
- Full citation: US 8,422,391 B2, IP Edge LLC (per Unified Patents listing); filing date listed as 2008-04-02; grant ~2013-04-16.
- Description: Discloses maintaining NAT address-mapping tables across a gateway/media gateway controller — i.e., tracking the pre-/post-translation correspondence of sessions.
- § 102 assessment: Addresses the NAT-transformation problem but teaches table maintenance, not log-entry-based correlation with responsive rule generation. Potential anticipation: low for the independent claim; relevant to the NAT embodiment in the specification.
D. US20080201772A1 — "Method and Apparatus for Deep Packet Inspection for Network Intrusion Detection"
- Full citation: US 2008/0201772 A1, Marvell Israel (M.I.S.L.) Ltd.; filed 2007-02-14; published 2008-08-21.
- Description: Discloses deep-packet inspection for intrusion detection, including rule-based identification of packets and policy enforcement — relevant to the rule-generation and packet-filtering aspects (elements (f)–(g)).
- § 102 assessment: Covers inspection and rule enforcement but not the two-sided log-based correlation. Potential anticipation: dependent claims directed to rule/policy enforcement (partial); primarily § 103.
E. US20150128274A1 — "System and Method for Identifying Infected Networks and Systems from Unknown Attacks"
- Full citation: US 2015/0128274 A1, Crypteia Networks S.A.; filing date listed as 2013-11-03; published 2015-05-07.
- Description: Discloses identifying infected hosts/networks from attack traffic and taking responsive action — relevant to the specification's malware-detection/notification and drop-rule features.
- § 102 assessment: Relevant to the "responsive action" portion (elements (f)–(g) and the message/drop-rule dependent claims) but not to the packet-correlation core. Potential anticipation: dependent claims directed to responsive actions (partial).
F. US20060133377A1 — "System and Method for Integrated Header, State, Rate and Content Anomaly Prevention with Policy Enforcement"
- Full citation: US 2006/0133377 A1, Fortinet, Inc.; filed 2004-12-21; published 2006-06-22.
- Description: Discloses integrated header/state/rate/content anomaly prevention with policy enforcement and logging — relevant to multi-layer packet analysis and rule-based enforcement.
- § 102 assessment: Potential anticipation: dependent claims directed to multi-layer information comparison (weak); primarily § 103.
G. US20070056038A1 — "Fusion Intrusion Protection System"
- Full citation: US 2007/0056038 A1, Lok Technology, Inc.; filed 2005-09-05; published 2007-03-08.
- Description: Discloses a fusion intrusion-protection system combining monitoring and policy responses.
- § 102 assessment: Potential anticipation: dependent claims directed to threat detection/response (weak).
H. US20060048142A1 — "System and Method for Rapid Response Network Policy Implementation"
- Full citation: US 2006/0048142 A1, Enterasys Networks, Inc.; filed 2004-09-01; published 2006-03-02.
- Description: Discloses rapid deployment of network policy (rules) to enforcement devices — relevant to element (g) (provisioning packet-filtering devices with rules).
- § 102 assessment: Potential anticipation: element (g)/dependent claims on provisioning (partial); primarily § 103.
I. US20040093513A1 — "Active Network Defense System and Method"
- Full citation: US 2004/0093513 A1, Hewlett-Packard / Trend Micro (per Unified Patents listing); filed 2002-11-06; published 2004-05-13.
- Description: Discloses an active network-defense system that detects attacks and actively blocks them.
- § 102 assessment: Potential anticipation: dependent claims directed to blocking/dropping (weak); primarily § 103.
J. US20030154399A1 — "Multi-method Gateway-based Network Security Systems and Methods"
- Full citation: US 2003/0154399 A1, Juniper Networks, Inc.; filed 2002-02-07; published 2003-08-14.
- Description: Discloses gateway-based security combining multiple inspection methods — relevant to gateway/flow-transforming-device scenarios.
- § 102 assessment: Potential anticipation: gateway embodiment dependent claims (weak); primarily § 103.
K. US20100211678A1 — "External Processor for a Distributed Network Access System"
- Full citation: US 2010/0211678 A1, Verizon Patent and Licensing Inc. (per Unified Patents listing); priority/filing listed as 2000-11-27; published 2010-08-19.
- Description: Discloses external processing of network traffic in a distributed access system with monitoring/logging.
- § 102 assessment: Potential anticipation: log-generation elements (weak); primarily § 103.
L. US20120084866A1 — "Methods, Systems, and Media for Measuring Computer Security"
- Full citation: US 2012/0084866 A1, The Trustees of Columbia University in the City of New York; filing listed as 2007-06-11; published 2012-04-05.
- Description: Discloses measuring computer/network security posture — relevant to the security-analysis context but not the correlation mechanism.
- § 102 assessment: Potential anticipation: low; primarily contextual § 103.
M. US20060136987A1 — "Communication Apparatus"
- Full citation: US 2006/0136987 A1, Fujitsu Limited; filed 2004-12-19; published 2006-06-22.
- Description: Discloses a communication apparatus with monitoring/logging features.
- § 102 assessment: Potential anticipation: low; primarily § 103.
N. US20050251570A1 — "Intrusion Detection System"
- Full citation: US 2005/0251570 A1, Secerno Ltd.; filing listed as 2002-04-17; published 2005-11-10.
- Description: Discloses an intrusion-detection system with database-style query-based analysis of traffic.
- § 102 assessment: Potential anticipation: low; primarily § 103.
O. EP1864226B1 — "Methods, Systems, and Computer Program Products for Network Firewall Policy Optimization"
- Full citation: EP 1 864 226 B1, Wake Forest University; priority/filing listed as 2005-03-27; granted ~2013.
- Description: Discloses firewall-policy optimization with packet classification/rule management — relevant to rule generation and filtering.
- § 102 assessment: Potential anticipation: dependent claims on rule management (weak); primarily § 103 (as a foreign patent, it is § 102(a)(1) art only if it qualifies as a "patent" published before the critical date — it does, being granted/published pre-2015).
4. Bottom line
- The most relevant single prior-art reference for US10659573B2 is US8219675B2 (correlating IP flows across NAT firewalls), because it addresses the same core problem — matching packets/flows across a flow-transforming network device. Its chief gap relative to the published independent claim is the "encrypted packets transmitted" limitation and the responsive rule-generation + packet-filtering provisioning steps.
- US7849502B1, US8422391B2, and US20080201772A1 are the next most relevant, collectively covering tap-based logging, NAT transformation, and rule-based filtering.
- None of the retrieved references appears to anticipate the full published independent claim in a single reference; the strongest theories are § 103 combinations (e.g., US8219675B2 with US7849502B1/US20080201772A1 for the rule-generation/provisioning elements), and possibly § 102 anticipation of narrower dependent claims.
- Confidence caveat: This assessment is based on a partial, search-verified citation set and the published claim text (US20190394310A1), not the granted claim text of US10659573B2. For a definitive claim-by-claim chart, pull the issued claims from USPTO Patent Center for 16/554,293 and the full "References Cited" list, and obtain the full text of each reference above. I could not verify the complete examiner citation list within the search limits, so there may be additional cited references (e.g., US20110055916A1 (Ahn), US20140201123A1 (Ahn et al.), US20140283004A1/US20140283030A1 (Moore/Moore et al.), and others appearing in the family's prosecution) that I was unable to confirm for this specific grant.
Generated 8/31/2026, 12:49:35 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll research the prior art record for US10659573B2. The provided patent text truncates before the claims and citations sections, so I need to locate the prosecution's cited references and any IPR petition art.
The Unified Patents portal shows a "Patent Art (284)" list for US10659573B2, including US8219675B2 (Netscout — correlating IP flows across NAT firewalls) and US7721084B2 (firewall for filtering tunneled data packets). Let me dig deeper into that cited-art list and the IPR petition.
Excellent — I've found the key proceedings: IPR2021-01151 (Palo Alto Networks challenged all claims 1–24 with a detailed obviousness petition) and an ex parte reexamination (90/019,563) that was granted in 2024 raising a substantial new question of patentability on claims 1 and 9. Let me verify the identities of the primary references and get the reexamination's relied-upon art.
I have enough from the record to deliver the analysis. Note up front: the provided patent text truncated before the claims and the "Citations" (prior art) sections, so I pulled the prior-art record from the USPTO/PTAB and litigation record instead — specifically (a) the cited-art list for US10659573B2 on the Unified Patents portal, (b) the IPR2021-01151 petition (Palo Alto Networks v. Centripetal Networks), which challenged all 24 claims on §103 grounds and contains an element-by-element claim chart, and (c) the order granting ex parte reexamination 90/019,563 (July 2024 request) raising a substantial new question of patentability as to claims 1 and 9. Caveats on what I could not verify are flagged inline.
Obviousness Analysis — U.S. Patent 10,659,573 (US10659573B2) under 35 U.S.C. § 103
1. Legal frame and claim scope
The patent is AIA-governed (earliest priority date Feb. 10, 2015; the reexamination notice confirms AIA/FITF status), so § 103 as amended by the AIA applies. All references discussed below published/issued well before the priority date and are § 102(a)(1)/(2) prior art.
Based on the IPR2021-01151 petition's claim chart (which quotes the granted claims, unlike the published application I summarized earlier), independent claim 1 requires, in substance:
- identifying a plurality of packets received by a network device from a host in a first network;
- generating a first plurality of log entries corresponding to those received packets;
- identifying a plurality of encrypted packets transmitted by the network device toward a host in a second network;
- generating a second plurality of log entries for those transmitted encrypted packets;
- correlating the transmitted encrypted packets with the received packets based on the two sets of log entries; and
- responsive to the correlating, generating one or more rules configured to identify packets received from the first-network host, and provisioning a packet-filtering device with those rules.
System/media counterparts are claims 9 and 17. Dependent claims add: provisioning first/second taps with rules (claims 2, 10, 18); correlation techniques using ports/interface IDs/timestamps/encapsulated data (claims 3–6, 11–14, 19–22); determining the second-network host is malicious and generating messages identifying the first-network host (claims 15–16); etc.
2. Primary prior art references
Paxton (US 2014/0280778 A1) — A packet-correlation system that places "inside" and "outside" sensors on either side of a network boundary (e.g., a NAT or gateway), logs packets from both sides (payload hashes, timestamps, source addresses), and matches them to attribute packets to their true origin. The petition quotes: "The combination of identifiable inside and outside header data can serve as the identity of the packet" (¶22); matching MD5 payload hashes with inside/outside arrival times (¶23, Fig. 2); and "the ability to identify the true source of packet transmission through a boundary can provide significant benefits to network security… identify nodes that are infected with malicious content… attribution of malicious activity sensed at the edge of a network back to its original source" (¶30). Paxton expressly notes its system is "highly modular" and built on commodity hardware.
Sutton (US 8,413,238 B2) — A network-security system that monitors communications, identifies malicious activity (e.g., communications with darknet addresses), generates filtering/blocking rules, and provisions network devices to enforce them, with administrator/user notifications.
Deschenes (US 2013/0262655 A1) — Teaches analyzing/correlating encrypted traffic using unencrypted information (timestamps, TCP/IP-level header data) when payloads are unreadable — the gap-filler for the "encrypted packets" limitation of the independent claims.
Ivershen (US 8,219,675 B2, Netscout) — "System and Method for Correlating IP Flows Across Network Address Translation Firewalls"; correlates flows on both sides of a NAT firewall using flow records. (This is the same reference as US8219675B2 in the cited-art list; the petition identifies Ivershen = US 8,219,675.)
McDonald (EP 2 482 522 A1) — A correlation system using "packet selectors" (taps) on either side of a NAT, programmed with rules/selection criteria (e.g., TCP flags) to select a subset of packets for correlation — the gap-filler for the rule-provisioned tap limitations.
3. The IPR2021-01151 grounds — the primary § 103 combinations
The Palo Alto Networks petition (filed July 20, 2021; challenged claims 1–24) asserted three grounds, all under § 103:
| Ground | Claims | Combination |
|---|---|---|
| 1 | 1, 7–9, 15–17, 23–24 | Paxton + Sutton, in view of Deschenes |
| 2 | 2, 10, 18 | Paxton + Sutton, in view of Deschenes + McDonald |
| 3 | 3–6, 11–14, 19–22 | Paxton + Sutton, in view of Deschenes + Ivershen |
Ground 1 — Paxton + Sutton + Deschenes
Element mapping (summary):
- Received-packet identification and first log entries: Paxton's inside sensor identifies packets received at the boundary device and logs them (payload hash, timestamp, SrcAddr).
- Transmitted encrypted-packet identification and second log entries: Paxton's outside sensor logs the corresponding outbound packets; Deschenes supplies the explicit teaching that the outbound packets may be encrypted and can still be identified and correlated via unencrypted header/timestamp data.
- Correlation: Paxton's matching of inside/outside hashes, timestamps, and header data (¶¶22–25) is exactly the claimed log-based correlation; Paxton even describes multi-packet correlation (Fig. 3).
- Responsive rule generation and provisioning: Paxton identifies infected nodes and attributes malicious activity to the true source but "leaves specific usage and remedial steps to a POSITA." Sutton supplies those steps: generating rules to identify/block further traffic from the offending first-network host, provisioning filtering devices, and notifying users/admins.
Why a POSITA would combine them: The references are in the same field (network security and traffic attribution) and solve complementary parts of one problem. Paxton is expressly designed to be "highly modular" and to be a "stable foundation for building tiered enterprise network architectures with an inherent capability for attribution of malicious activity" (¶30) — an invitation to add standard response components. A POSITA who detected malicious activity via Paxton's correlation would naturally add Sutton's well-known remedial rule-generation/provisioning to complete the security workflow, and would apply Deschenes's known technique for handling encrypted traffic because encryption was the ordinary, predictable state of enterprise traffic by 2015 (TLS everywhere). The result is the combination of known elements, each performing its known function, with predictable results — the classic KSR v. Teleflex situation.
Ground 2 — + McDonald (claims 2, 10, 18)
Claims 2/10/18 add first and second tap devices provisioned with rules to identify the received and transmitted packets respectively. Paxton's inside/outside sensors act as taps, but the petition argued that to the extent Paxton doesn't explicitly disclose provisioning the taps with selection rules, McDonald does: McDonald's "packet selectors" on either side of a NAT are explicitly programmed with selection criteria (e.g., packets with certain TCP flags) to pick a subset for correlation.
Motivation: Both Paxton and McDonald recognize that capturing/analyzing all traffic on high-bandwidth links is resource-intensive; McDonald's rule-based pre-filtering is a known performance technique. A POSITA seeking to scale Paxton's correlation to high-throughput enterprise links would adopt McDonald's rule-programmed selectors as a predictable efficiency improvement. This is a textbook combination of a known monitoring system with a known filtering mechanism to solve a known performance problem.
Ground 3 — + Ivershen (claims 3–6, 11–14, 19–22)
The dependent claims in this group recite specific correlation features — comparing ports, network-interface identifiers, timestamps (receipt vs. transmission), and encapsulated/request payload data. Ivershen (Netscout) discloses correlating IP flows across a NAT firewall using flow records, including transport-layer data and timing, which the petition used to fill any gaps in Paxton's correlation detail.
Motivation: Ivershen and Paxton are both flow-correlation-across-NAT systems; combining them is combining analogous references in the same art to supply implementation detail (e.g., which header fields and timing data to compare). A POSITA would consult Ivershen as the standard reference for NAT-flow correlation and would expect success because both systems use the same underlying approach (matching inside/outside records by header and timing data).
4. Additional combinations supported by the cited-art record
Beyond the IPR grounds, the 284-reference cited-art list on the Unified Patents record provides further obviousness building blocks that a challenger could deploy for specific limitations:
- Ivershen (US8219675B2) as a primary reference with Paxton — both are "correlate flows across a NAT/firewall" systems; a § 103 challenge could run Ivershen as the primary reference for the correlation steps and Paxton for the malicious-attribution/response context. This is a particularly strong pairing because Ivershen is earlier (filed Dec. 2009; issued 2012) and squarely on point.
- US 7,721,084 B2 ("Firewall for Filtering Tunneled Data Packets") — teaches inspecting/filtering encapsulated (tunneled) packets, supporting the "encrypted packets transmitted" and "data encapsulated in packets" dependent limitations (claims corresponding to the VPN/tunneling-gateway embodiment in the specification).
- US 7,849,502 B1 (Cisco IronPort, "Apparatus for Monitoring Network Traffic") and US 2006/0133377 A1 (Fortinet, integrated header/state/content anomaly prevention) — both teach rule-based identification and logging of network traffic, supporting the tap-provisioning and log-generation steps.
- US 2015/0128274 A1 (Crypteia, "Identifying Infected Networks and Systems from Unknown Attacks") and US 2014/0259170 A1 (Raytheon, cyber-threat reporting) — support the malicious-host determination, message generation, and notification steps (claims 15–16).
- US 2004/0093513 A1 (HP/Trend Micro, "Active Network Defense") — teaches responsive rule generation and packet dropping upon detection, corroborating Sutton's role in Ground 1.
A challenger could, for example, reformulate Ground 1 as Ivershen (primary) + Paxton + Sutton + Deschenes, or Paxton + Ivershen + US7721084B2 for the tunneled/encrypted-packet claims. None of these combinations requires any non-obvious reordering; they all use the references for their same-field, same-purpose teachings.
5. Motivation-to-combine analysis under KSR (summary)
Under KSR, obviousness can be shown by combining prior-art elements according to known methods, with predictable results, where a POSITA has a reason to combine. Here, for each pairing:
- Same field / same problem: All primary references address network-traffic monitoring, flow/NAT correlation, or network security response. The patent's own Background concedes the problem (middleboxes obfuscating flow association) was a known one.
- Complementary teachings: Paxton/Ivershen/McDonald/Deschenes cover detection and correlation (including encrypted traffic); Sutton covers response (rule generation + provisioning); each reference expressly leaves room for or invites the others' contributions (Paxton ¶30's modularity and its silence on remedial steps; McDonald's and Paxton's shared concern about capture cost).
- Predictability: Correlating logs from two sides of a boundary device and then applying filtering rules to the attributed source were routine techniques. The "encrypted packets" limitation is not inventive — Deschenes shows it was known to correlate encrypted packets via timestamps/header data, and the specification's own embodiments (NAT, proxy, VPN gateway) are all standard middlebox functions.
- No teaching away / no unexpected results: Nothing in the record suggests any reference teaches away from combining; the petition's expert declaration (Ex. 1003, Dr. Akl) mapped every claim element to the combination.
6. Countervailing considerations (be fair to the patent)
- Institution was denied in IPR2021-01151 (decision Feb. 16, 2022). The Board did not find a reasonable likelihood that the petitioner would prevail. This is not a merits holding of validity, but it is the only PTAB merits-adjacent outcome on these exact grounds, and any serious § 103 analysis must acknowledge it. The denial could reflect the Board's view that the petition's Paxton/Sutton/Deschenes mapping was deficient on specific limitations (e.g., the "encrypted packets" or "provisioning a packet-filtering device" steps), not that the claims are non-obvious as a matter of law.
- Ex parte reexamination 90/019,563 was granted (request filed July 1, 2024; order granting reexamination issued thereafter, Art Unit 3992, examiner Roland G. Foster), with the Office finding a substantial new question of patentability affecting claims 1 and 9 based on new, non-cumulative art. That means the Office itself believed at least one reference (or a new combination) from the request raised a real § 102/103 question on the independent claims. I could not retrieve the reexamination order's specific reference list from my searches, so I cannot name the art it relied on — but the grant is itself significant objective evidence that the independent claims are vulnerable under § 103.
- Secondary considerations: Centripetal could argue commercial success/licensing (it asserted the patent against Cisco and Palo Alto Networks) and long-felt need. But based on the Federal Circuit's treatment of Centripetal's RuleGATE secondary-indicia evidence in the related 9,124,552/9,160,713 litigation (rejecting industry-praise/commercial-success arguments for lack of nexus), courts in this family have been skeptical of such evidence unless it maps specifically to the claimed features. The patent-in-suit claims only the correlation + rule-provisioning method, not the full product.
- Litigation backdrop: The patent was asserted in E.D. Va. cases 2:21-cv-00137 and 1:21-cv-00313 (and 2022 cases), with related CAFC appeals (25-1167, 25-1168, 26-1359). A 2026 Federal Circuit decision affirmed a finding that Cisco did not infringe a Centripetal patent trio; I could not verify whether '573 was among them. The 2026 PTAB finding that a Centripetal Cisco-related patent was obvious (on remand) is also not confirmed to be this patent.
7. Conclusion
The strongest § 103 case against US10659573B2 is the IPR2021-01151 combination set: Paxton + Sutton + Deschenes for the independent claims (1, 9, 17) and their security-response dependents, + McDonald for the rule-provisioned tap claims, and + Ivershen for the correlation-detail dependents. The motivation-to-combine story is strong under KSR because the references are same-field, complementary, and — per Paxton's own disclosure — explicitly modular and aimed at a complete attribution-and-response security solution, with Deschenes supplying the routine handling of encrypted traffic. Supporting combinations from the cited-art record (Ivershen as primary; US7721084B2 for tunneled packets; Sutton/HP-Trend Micro for responsive rules; Crypteia/Raytheon for alerting) reinforce the conclusion.
Two caveats govern the confidence level of any invalidity conclusion: (1) the PTAB declined to institute IPR2021-01151, so these exact grounds have never been adjudicated on the merits; and (2) the granted ex parte reexamination (90/019,563) — whose relied-upon references I could not retrieve — indicates the independent claims face an active, Office-recognized patentability question as of the 2024–2026 timeframe. If the reexamination ultimately confirms obviousness of claims 1 and 9 over its new art, that would be the most authoritative § 103 determination available. For a definitive element-by-element chart, pull the IPR petition exhibits (Ex. 1004 Paxton, 1007 Sutton, 1008 Deschenes, 1005 Ivershen, 1009 McDonald) and the reexamination order from USPTO Patent Center/PTAB.
Generated 8/31/2026, 12:49:50 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 6665293I'll search for authoritative information on US Patent 6,665,293 and any CAFC 2026 docket references. Both searches returned no results. Let me try broader queries to locate authoritative sources. I have confirmation from Google Patents…
- US 6424624I searched the USPTO/patent databases and CAFC docket sources for the specific patent number 6424624 (i.e., US 6,424,624 B1 / US6424624B1). Here is the summary, with notes on confidence. Verification note - Searches for "6424624" confirmed…
- US 10491646Summary of U.S. Patent No. 10,491,646 (US10491646B2) I searched for the specific patent number 10491646 (front-page form: US 10,491,646 B2) and did not rely on similar numbers (e.g., 8,166,892, IPR2025-01046/01047, etc., which appeared in…
- US 9338140US Patent 9,338,140 B2 — Summary Bibliographic data (verified against USPTO-adjacent sources and the issued patent PDF) | Field | Data | |---|---| | Patent number | US 9,338,140 B2 (application no. 13/468,383) | | Title | Secure data…
- US 9129376US Patent 9,129,376 B2 — Summary Searches performed I searched for the exact identifier 9129376 (and US9129376B2 / 9,129,376) in patent databases and litigation/CAFC sources, and searched the CAFC 2026 docket for this patent number. My…
- US 8825454US Patent 8,825,454 — Summary Note on sources: Bibliographic data below is corroborated by Google Patents (patents.google.com/patent/US8825454) and FreePatentsOnline. The full specification was supplied in your prompt; however, the claims…
- US 8818770I have confirmation of the key bibliographic data and relevant dockets. Let me retrieve the independent claims' full text to describe them accurately. US Patent 8,818,770 B2 — Summary Bibliographic data (verified against USPTO/Google…
- US 8170840The CAFC 2026 hits so far involve different EagleView patents (8,670,961 and 8,078,436) — not 8,170,840. Let me verify whether 8,170,840 itself appears in any 2026 CAFC activity and pull the actual claim set. I need the actual claim text…
This patent in court (2)
2 tracked lawsuits name US 10659573.