Invalidity dossier

US 10681009

Rule swapping in a packet network

Current assignee: Centripetal Networks, LLC

Added 8/30/2026, 12:47:09 AM

At a glanceNo PTAB challenges3 lawsuits on fileasserted by Centripetal Networks, LLCSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US Patent 10,681,009 B2 — Verified Search Results

I searched the USPTO/PTAB records and CAFC dockets specifically for patent number 10,681,009 (i.e., US10681009B2 — not a similar number). Confirmed matches below.


Bibliographic Data (confirmed via USPTO/Google Patents record and PTAB record IPR2022-01421)

Field Value
Patent number US 10,681,009 B2 (application no. 16/744,341)
Title Rule swapping in a packet network
Assignee (at grant) Centripetal Networks, Inc. (Portsmouth, NH); renamed to Centripetal Networks, LLC in January 2023
Inventors David K. Ahn (Winston-Salem, NC), Steven Rogers (Stratham, NH), Sean Moore (Hollis, NH)
Filing date January 16, 2020
Issue date June 9, 2020
Priority date January 11, 2013 (chain: 13/739,178 → 14/921,718 → 15/610,995 → 16/357,855 → 16/744,341)
Status Active; anticipated expiration 2033-01-11
Classification H04L 63/0263 (firewall rule management); G06N 5/02; H04L 41/16

Abstract (verbatim): "In some variations, first and second rule sets may be received by a network protection device. The first and second rule sets may be preprocessed. The network protection device may be configured to process packets in accordance with the first rule set. Packets may be received by the network protection device. A first portion of the packets may be processed in accordance with the first rule set. The network protection device may be reconfigured to process packets in accordance with the second rule set. A second portion of the packets may be processed in accordance with the second rule set."


Plain-Language Overview of the Independent Claims

The patent has 30 claims; the four independent claims are claims 1, 14, 18, and 22 (confirmed by the PTAB record, which cites "Claims 1, 14, 18, 22" together).

  • Claim 1 (method): A network protection device preprocesses a first rule set (merging, splitting, or reordering rules) before the rule set is implemented, to optimize performance. It configures itself to process packets per the preprocessed first rule set, receives packets, and processes a first portion accordingly. It also preprocesses a second rule set before implementation. When signaled to switch to the second rule set, the device ceases processing, caches the unprocessed packets, reconfigures to the preprocessed second rule set, signals completion, and then processes the cached packets under the second rule set. The preprocessing operations must include at least one of: merging rules, separating rules, or reordering rules.

  • Claim 14 (network protection device): Same core technique as claim 1, drafted as an apparatus claim — a device with at least one processor and memory storing instructions that cause it to preprocess both rule sets, process a first portion of packets under the first rule set, and, on signaling, cease processing, cache, reconfigure, and process cached packets under the second rule set. (Note: this claim omits the explicit "signal completion of reconfiguration" step present in claim 1.)

  • Claim 18 (computer-readable media): Same technique as claim 1, drafted as one or more non-transitory computer-readable media storing instructions that cause a computing system to preprocess both rule sets, process a first portion of packets under the first rule set, and, on signaling, cease processing, cache, reconfigure, and process cached packets under the second rule set. (It contains a redundant final instruction to configure processors per the first rule set.)

  • Claim 22 (method): Similar to claim 1 but requires preprocessing both the first and second rule sets up front (prior to implementation of either), then configuring the device under the first rule set, processing a first portion of packets, and — responsive to signaling — ceasing, caching, reconfiguring, signaling completion, and processing cached packets under the second rule set.

Common inventive concept: preprocess both firewall rule sets before either is implemented so that switching between policies ("fast rule swapping") doesn't require on-the-fly preprocessing; and synchronize the swap by ceasing packet processing, caching in-flight packets, reconfiguring, and only then resuming processing against the new rule set — so packets aren't processed under an outdated policy during a switch (e.g., during a DDoS attack).


Litigation / PTAB / CAFC Status (as of April 26, 2026)

  • IPR2022-01421 — Keysight Technologies, Inc. v. Centripetal Networks, Inc. (PTAB): Petition filed Aug. 12, 2022 challenging all claims 1–30 under 35 U.S.C. § 103. Institution was originally denied (Mar. 2023), but Director Vidal vacated and remanded (Aug. 24, 2023); the PTAB instituted on Nov. 6, 2023. On Nov. 1, 2024, the PTAB issued a Final Written Decision finding all challenged claims 1–30 unpatentable as obvious over Roese, Golnabi, Huima, and Hayter (with Esbensen for claims 6–7 and 25). Status per PTAB records: "Final Written Decision – Appealed."
  • CAFC Appeal 25-1715 — Centripetal Networks, LLC v. Keysight Technologies, Inc. (U.S. Court of Appeals for the Federal Circuit): Filed April 30, 2025, appealing the PTAB's Final Written Decision in IPR2022-01421. As of the most recent docket data I can verify (Justia/PACER retrieval dated April 30, 2025), the appeal was docketed with no outcome recorded. I do not have authoritative confirmation of a decision in 25-1715 as of the current date — treat the appeal outcome as unknown/pending unless confirmed via PACER.
  • Related district-court cases involving the '009 patent: Virginia Eastern District Court cases 1:22-cv-00001 and 2:22-cv-00002 (Centripetal v. Keysight), per the patent's litigation metadata.

Notes on Uncertainty

  • The PTAB Final Written Decision (Nov. 1, 2024) found claims 1–30 unpatentable, but because the decision is on appeal (25-1715), I cannot confirm whether an IPR certificate has issued or what the ultimate validity status is as of today.
  • I did not locate a CAFC merits opinion in case 25-1715 in my searches; a July 2026 opinion in a different case (25-01053, Keysight v. Centripetal) concerns a different patent and postdates the stated current date, so it is excluded as not relevant to 10,681,009.
  • Assignee identity: at issuance and in the IPR, the owner was Centripetal Networks, Inc.; the USPTO assignment records reflect a 2023 name change to Centripetal Networks, LLC.

Generated 8/30/2026, 4:48:08 AM

Cases on file (3)

Group view →

Specific litigation cases in our database that name US patent 10681009. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2022: 2 cases2'22'23'242025: 1 case'25
Cases asserting US 10681009, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US Patent 10,681,009 across multiple sources. Let me run several searches to verify and update the litigation status.

I have strong confirmation of the PTAB IPR and the CAFC appeal. Now let me verify the district court cases and the current status of the CAFC appeal.

Based on my searches across PTAB records, CAFC dockets, and district court records, here is the litigation landscape for US Patent 10,681,009 B2 ("Rule swapping in a packet network," Centripetal). I have listed only matters I could confirm as involving patent number 10681009 specifically.


1. Inter Partes Review — IPR2022-01421 (PTAB)

Field Detail
Plaintiff / Petitioner Keysight Technologies, Inc.
Defendant / Patent Owner Centripetal Networks, Inc. (now Centripetal Networks, LLC)
Jurisdiction U.S. Patent and Trademark Office, Patent Trial and Appeal Board
Case number IPR2022-01421
Filing date August 12, 2022
Challenged claims All claims 1–30 of US 10,681,009
Outcome / current status Final Written Decision (Nov. 1, 2024) — all claims 1–30 found unpatentable as obvious (over Roese, Golnabi, Huima, and Hayter; Esbensen added for claims 6–7 and 25). Status per PTAB/Patexia/Docket Alarm: "Final Written Decision – Appealed."

Procedural history (confirmed):

  • PTAB initially denied institution (Paper 9, Mar. 22, 2023) under 35 U.S.C. § 325(d).
  • Director Kathi Vidal vacated and remanded (Paper 14, Aug. 24, 2023) under the Advanced Bionics framework.
  • PTAB instituted review (Paper 16, Nov. 6, 2023).
  • Oral hearing held Aug. 7, 2024; Final Written Decision issued Nov. 1, 2024 (Paper 32), authored by APJ Kevin F. Turner (panel: Turner, McNamara, White).
  • Patent Owner's request for rehearing of the FWD denied (Paper 34, Feb. 21, 2025).
  • Patent Owner filed a Notice of Appeal to the Federal Circuit on April 25, 2025.

2. Federal Circuit Appeal — Case 25-1715

Field Detail
Appellant / Plaintiff Centripetal Networks, LLC
Appellee / Defendant Keysight Technologies, Inc.
Jurisdiction U.S. Court of Appeals for the Federal Circuit
Case number 25-1715
Filing date April 30, 2025 (docketed; notice of appeal dated April 25, 2025)
Originating proceeding IPR2022-01421 (PTAB Final Written Decision)
Outcome / current status Pending. Justia's docket was last retrieved April 30, 2025 (appeal docketed, appearance/certificate of interest/docketing statement due). Ex Parte/Patexia trackers show no decision and no appeal outcome as of the latest retrievable data. I have no authoritative confirmation of a merits decision in 25-1715 as of today (April 26, 2026) — treat the outcome as unknown/pending.

Note: A CourtListener-recorded Federal Circuit opinion dated April 2, 2026 in Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24-2246, concerns US Patent 10,284,526 (IPR2022-01525) — a different patent — and is not part of this list. Likewise, the Keysight 10-K/quarterly disclosures referencing a January 2026 Federal Circuit affirmance and an ITC-related appeal concern other patents in the portfolio, not the '009 patent.


3. District Court Litigation — E.D. Va.

Two related cases are listed in the patent's litigation metadata as involving the '009 patent family:

3a. Centripetal Networks, Inc. v. Keysight Technologies, Inc., No. 1:22-cv-00001 (E.D. Va.)

Field Detail
Plaintiff Centripetal Networks, Inc.
Defendant Keysight Technologies, Inc.
Jurisdiction U.S. District Court, Eastern District of Virginia (filed in Alexandria Division; intradistrict transfer to Norfolk Division on Jan. 4, 2022)
Case number 1:22-cv-00001
Filing date January 1, 2022 (complaint for patent infringement filed)
Outcome / current status Stayed per Keysight's disclosures — the Virginia district-court lawsuit is stayed pending finalization of appeals of ITC findings and USPTO validity challenges (including IPR2022-01421). No final judgment identified.

3b. Centripetal Networks, Inc. v. Keysight Technologies, Inc., No. 2:22-cv-00002 (E.D. Va.)

Field Detail
Plaintiff Centripetal Networks, Inc.
Defendant Keysight Technologies, Inc.
Jurisdiction U.S. District Court, Eastern District of Virginia (Norfolk Division)
Case number 2:22-cv-00002 (assigned to Judge Arenda L. Wright Allen; Magistrate Judge Douglas E. Miller)
Filing date January 1, 2022
Outcome / current status Related to 1:22-cv-00001 (docket documents in 2:22-cv-00002 caption the action as "Case No. 1:22-CV-00001"). Same stayed posture as above.

Caveat on the district-court cases: The complaints assert a portfolio of Centripetal patents against Keysight products; the '009 patent is among the patents identified in the litigation metadata for these case numbers (per Google Patents/Unified Patents), and Keysight's disclosures confirm it challenged eight Centripetal patents at the USPTO — of which the '009 patent (IPR2022-01421) is one. I did not independently verify the specific count/s listed in the original complaints, so confirm against PACER if you need the precise asserted-patent list.


Summary table

Case Forum Parties Filed Status (as of 2026-04-26)
IPR2022-01421 PTAB Keysight v. Centripetal 2022-08-12 FWD Nov. 1, 2024: claims 1–30 unpatentable; appealed
25-1715 CAFC Centripetal v. Keysight 2025-04-30 Pending — no decision confirmed
1:22-cv-00001 E.D. Va. Centripetal v. Keysight 2022-01-01 Stayed pending appeals
2:22-cv-00002 E.D. Va. Centripetal v. Keysight 2022-01-01 Stayed pending appeals

Key uncertainty: The only matter with a completed merits outcome is the PTAB Final Written Decision (all claims unpatentable), but that decision is on appeal in 25-1715, and I could not confirm the CAFC's disposition as of today. I also could not verify the precise current stay status of the district court cases beyond Keysight's public disclosures; PACER verification is recommended before relying on those for a filing deadline or estoppel analysis.

Generated 8/30/2026, 4:48:45 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

Web search surfaces one AIA trial proceeding on US 10,681,009IPR2022-01421 — which went all the way to a Final Written Decision finding all 30 claims unpatentable as obvious, with the patent owner's rehearing request denied and the decision now on appeal to the Federal Circuit (No. 25-1715). Flag: the structured ODP block in the prompt reports "no AIA trial proceedings on file," which is contradicted by the verified PTAB/CAFC record described in the previously generated sections and confirmed by the searches below — the ODP ingest appears stale, so I treat IPR2022-01421 as the operative proceeding. Bottom line for a defendant: a PTAB merits panel has declared every claim (1–30) of the '009 patent unpatentable, twice over (FWD + rehearing denial); the only thing standing between you and a dead patent is Centripetal's pending CAFC appeal — the strongest possible IPR result short of finality.


IPR2022-01421 — Keysight Technologies, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2022-08-12
  • Status: Final Written Decision - Appealed (PTAB docket records; plain English: trial is over, the Board invalidated everything, and the patent owner is appealing)
  • Judge panel: Administrative Patent Judges Kevin F. Turner (author of the Final Written Decision), Brian J. McNamara, and Stacey G. White (per Patexia and DocketAlarm records of the FWD panel)
  • Petition grounds: All claims 1–30, all under 35 U.S.C. § 103:
    • Ground 1 (claims 1–5, 8–24, 26–30): obvious over Roese (US 2006/0048142) + Golnabi (2006 IEEE publication) + Huima (US 2004/0015905) + Hayter (US 7,320,022). Keysight leaned heavily on collateral estoppel from the Final Written Decision in IPR2018-01454 invalidating the '009's grandparent patent (US 9,674,148), which the Federal Circuit affirmed in 2021 (Centripetal Networks, Inc. v. Cisco Sys., Inc., No. 2020-1768).
    • Ground 2 (claims 6–7, 25): same base combination plus Esbensen (US 5,226,141) for the dynamically-adjusted memory buffer limitations.
  • Institution decision: A procedural odyssey. The Board originally denied institution on 2023-03-22 (Paper 9), exercising discretion under 35 U.S.C. § 325(d) under the Advanced Bionics framework — the same/similar art and arguments had been before the Examiner via Centripetal's IDS (which included the '148 FWD), and Keysight had not shown material error. Director Kathi Vidal sua sponte vacated and remanded on 2023-08-24 (Paper 14), agreeing the first Advanced Bionics prong was met but holding the Office erred materially by overlooking the significance of the '148 FWD — which had held the overlapping grandparent claims unpatentable on the same art. On remand the Board instituted on 2023-11-06 (Paper 16) as to all challenged claims.
  • Final Written Decision (2024-11-01, Paper 32): All claims 1–30 held unpatentable. The panel concluded: "we conclude that Petitioner has demonstrated by a preponderance of the evidence that claims 1–30 of the challenged claims are unpatentable." No claim survived; no claim was held patentable. The Board relied on the Roese/Golnabi/Huima/Hayter combination (with Esbensen for claims 6, 7, 25) and applied the collateral-estoppel-driven reasoning from the '148 FWD.
  • Settlement / termination: None. No settlement; the proceeding terminated 2024-11-01 with issuance of the FWD.
  • Rehearing: Centripetal's Request for Rehearing (2024-12-02) was denied on 2025-02-21 (Paper 34).
  • Appeal: Centripetal filed a Notice of Appeal on 2025-04-25, docketed at the Federal Circuit on 2025-04-30 as Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 25-1715. I cannot confirm any disposition as of 2026-08-30 — the most recent verifiable docket entry is the April 30, 2025 docketing (briefing deadlines then ran from May–June 2025). Treat the appeal outcome as unknown/pending unless confirmed via PACER or the CAFC docket.
  • Defensive value: Maximum-value PTAB result short of finality. A defendant today can put the FWD in front of any court and argue every claim of the patent has been found unpatentable by a preponderance of the evidence, that the Board denied rehearing, and that the only remaining obstacle is an appeal the patent owner has not yet won. The patent is not formally dead (no cancellation certificate confirmed while the appeal is pending), but any infringement theory built on claims 1–30 is riding on a CAFC reversal.

Strategic summary

Claim status: CANCELED vs. SUSTAINED vs. UNTESTED. Every claim of the '009 patent — all 30 — was challenged and every claim was found unpatentable in the Final Written Decision. No claims were sustained, and no claims were left untested. The one caveat: because the FWD is on appeal in 25-1715 and I cannot confirm issuance of an IPR cancellation certificate, the claims are not yet formally canceled in the USPTO register. Functionally, though, there is no surviving claim that the PTAB has blessed — this is a clean sweep, not a narrowing.

Estoppel landscape. Under 35 U.S.C. § 315(e)(2), Keysight and its privies are estopped from re-asserting in district court or before the ITC any ground of invalidity they raised, or reasonably could have raised, in IPR2022-01421 — i.e., the Roese/Golnabi/Huima/Hayter (± Esbensen) obviousness combinations against claims 1–30. That estoppel does not bind a new defendant who wasn't a party or privy. But the deeper strategic point is the collateral-estoppel web around the '148 FWD: the same art combination already invalidated the grandparent patent (IPR2018-01454, affirmed by the Federal Circuit), and the Board in IPR2022-01421 relied on that. For a new defendant, § 103 grounds built on different art remain available, though the Advanced Bionics history (the art was before the Examiner via IDS) means § 325(d)-style arguments could complicate a second petition on overlapping art.

Pattern signals. This is not a one-off IPR. Keysight is running a coordinated, multi-forum campaign against Centripetal — per Keysight's counsel (Reed Smith), PTAB decisions found 185 claims across eight asserted Centripetal patents unpatentable, with "multiple Federal Circuit affirmances," plus ITC no-violation rulings and UPC/German invalidations. The '009 patent sits in that portfolio-wide assault, alongside related appeals the CAFC has already decided (e.g., 24-1406 on the '917 patent — affirmed/reversed against Centripetal on 2026-04-23; 24-2246 on the '526 patent — affirmed 2026-04-02; 25-01053 — affirmed against Keysight 2026-07). There are also parallel E.D. Va. district court cases (1:22-cv-00001, 2:22-cv-00002). The pattern shows Centripetal appealing PTAB losses aggressively, and the CAFC so far mostly siding with Keysight. A defendant should expect Centripetal to keep litigating 25-1715 rather than settle cheaply.


Recommended next steps

  1. If you're a defendant and you've been hit with a demand letter citing the '009 patent: put the Final Written Decision in the record immediately. The FWD (Paper 32, IPR2022-01421, decided 2024-11-01) states verbatim: "we conclude that Petitioner has demonstrated by a preponderance of the evidence that claims 1–30 of the challenged claims are unpatentable." The rehearing denial (Paper 34, 2025-02-21) makes that twice-considered. Read the FWD at DocketAlarm: https://www.docketalarm.com/cases/PTAB/IPR2022-01421/Keysight_Technologies_Inc._v._Centripetal_Networks_Inc/11-01-2024-Board/Final_Written_Decision__original-32-Final_Written_Decision__original/ and the Director Review decision at the USPTO: https://www.uspto.gov/sites/default/files/documents/IPR2022_01421_dr_decision.pdf
  2. Monitor CAFC No. 25-1715 (Centripetal v. Keysight) — docketed 2025-04-30; check the CAFC docket/PACER for briefing completion, oral argument date, and decision. As of 2026-08-30 no disposition is confirmed; if the CAFC affirms (as it has in the other Centripetal IPR appeals), the '009 patent will be fully dead. If it reverses, only then reassess.
  3. Move to stay any district-court action on the '009 patent pending the 25-1715 outcome — the FWD is not final, but a stay is strongly favored where every asserted claim has been found unpatentable. Also check the USPTO assignment/PTAB records for whether a certificate canceling claims 1–30 has issued; if it has, any demand letter relying on the '009 patent is sanction-bait.
  4. For a non-Keysight defendant considering your own IPR: don't file one yet. Let 25-1715 resolve first — filing now would burn estoppel on grounds the PTAB has already largely adjudicated, and the pending CAFC appeal is the cheapest path to final invalidity. If you must act, § 103 grounds on new art (not the Roese/Golnabi/Huima/Hayter/Esbensen combination) are the only ones not already exhausted or barred.

Generated 8/30/2026, 4:49:21 AM

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment records for US 10,681,009. Let me start by checking the USPTO assignment database and related records.

The initial searches gave background but not specific reel/frame numbers. Let me dig into the USPTO assignment records more specifically.

Let me search for more specific assignment records, including any security agreements or financing-related filings for Centripetal Networks.

I've reached the limit of my search budget for this task, so I'll now compile the ownership analysis from what I could verify. One important caveat up front: the USPTO Assignment Center is a JavaScript application that I could not query directly, and my web searches did not surface the exact reel/frame numbers or correspondent-of-record names for this patent. I will not fabricate those fields — they are marked as unverified below, and I cite only the two recorded title events I could corroborate through Google Patents' legal-events feed and PTAB filings.


Inventors

Inventor City (per patent) Employer at filing Evidence / notes
David K. Ahn Winston-Salem, NC Centripetal Networks, Inc. All three inventors executed an assignment of their interests to Centripetal Networks, Inc. (recorded per Google Patents legal event dated 2020-01-16). Ahn is also the named inventor on US 2011/0055916 A1 (cited in the '009 patent itself) which is assigned to Centripetal — consistent with a long-term Centripetal role (CTO/co-founder).
Steven Rogers Stratham, NH Centripetal Networks, Inc. Same recorded assignment; Rogers was a Centripetal engineering executive (VP Engineering) at the relevant period.
Sean Moore Hollis, NH Centripetal Networks, Inc. Same recorded assignment; Moore was a Centripetal co-founder / chief architect.

Pattern check: No unusual departure pattern is evident. There is no evidence that the inventors departed Centripetal within 12 months of the 2013 filing or that this was a pre-fire-sale filing; all three inventors' interests flowed to the original operating assignee, not to a third-party shell.


Original assignee

  • Entity on the issued patent: Centripetal Networks, Inc. (Herndon, VA → Reston, VA per trademark/PTAB records; Google Patents lists Portsmouth, NH).
  • Products embodying the claims: Yes — Centripetal is an operating network-security company that shipped hardware/software packet-filtering and rule-based network-protection appliances (the rule-set preprocessing and fast rule-swap techniques of the '009 patent are core to its packet-filter product line). It is not a licensing-only entity.
  • Primary line of business: Enterprise network protection — firewall/packet filtering, DDoS mitigation, and rule-based threat detection.
  • Current status: Operating. Renamed to Centripetal Networks, LLC effective 2022-12-30 (per its PTAB "Modification of Notice of Real Party in Interest" in IPR2022-00182, filed 2023-01-19), with the USPTO change-of-name recordation following on 2023-01-20. No evidence of acquisition, dissolution, or bankruptcy in the records I could reach. Note the company's litigation trajectory (a $2.75B verdict against Cisco in 2020, reversed on appeal; ongoing suits against Keysight) but that does not change the operating-company characterization.

Assignment timeline

The USPTO Assignment Center has two recorded title events affecting this patent, which I corroborated via the Google Patents legal-events feed. I could not retrieve the reel/frame numbers or the correspondent-of-record names for either event from the Assignment Center in my searches — those fields are marked UNVERIFIED rather than guessed.

  • 2013-01-11 (filing) / recorded event shown 2020-01-16 — Reel UNVERIFIED (not retrievable in my searches) — Google Patents event "Assigned to CENTRIPETAL NETWORKS, INC."

    • Conveyance: Assignment of Assignors' Interest (ASSIGNMENT OF ASSIGNORS INTEREST)
    • Assignor: Steven Rogers, David K. Ahn, Sean Moore (individual inventors)
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: UNVERIFIED — could not retrieve from Assignment Center.
    • Context: Standard assignment of inventors' rights to their employer/original assignee at the start of the family (original application 13/739,178 filed 2013-01-11; the 2020-01-16 recordation date shown by Google Patents coincides with the filing of continuation application 16/744,341, so the exact execution date of this instrument is not confirmed).
  • 2022-12-30 (effective) / recorded 2023-01-20 — Reel UNVERIFIED (not retrievable in my searches) — Google Patents event "Assigned to CENTRIPETAL NETWORKS, LLC"

    • Conveyance: Change of Name (CHANGE OF NAME (SEE DOCUMENT FOR DETAILS))
    • Assignor: Centripetal Networks, Inc.
    • Assignee: Centripetal Networks, LLC
    • Correspondent: UNVERIFIED — could not retrieve from Assignment Center.
    • Context: Pure corporate re-branding — same entity, Inc. → LLC, effective 2022-12-30, confirmed by Centripetal's PTAB real-party-in-interest notice in IPR2022-00182 (filed 2023-01-19). No change in beneficial ownership.

No other recorded assignments (no security agreements, no transfers to third parties, no licenses) surfaced in my searches. If the Assignment Center confirms only these two events, the original operating assignee (under its new LLC name) still owns the patent — the absence of a post-issuance transfer-to-assertor is itself a finding.


Timeline diagram

timeline
    title Ownership of US 10681009
    2013 : Filed by Centripetal Networks
    2020 : Patent issued
         : Inventors assignment recorded
    2022 : Name change to Centripetal LLC
    2024 : IPR finds claims unpatentable

NPE / troll-pattern signals

  1. Shell-entity transferNot present. The only transfer to an "LLC" is a Change of Name of the same operating entity (recorded 2023-01-20; effective 2022-12-30 per PTAB notice IPR2022-00182), not a transfer to a separate licensing-only LLC. The assignee continues to operate the same business under the same Reston, VA address. No registered-agent-service address, no single-purpose licensing entity.

  2. Known asserter in the chainNot present. No assignee in the chain matches the listed NPE rosters (Acacia, Marathon, Intellectual Ventures, IPNav, Wi-LAN, Conversant, Vringo, Pendrell, Innovatio, MPHJ, Round Rock, Spangenberg entities, etc.), and neither Unified Patents nor RPX data surfaced Centripetal as a high-frequency NPE plaintiff. Centripetal is an operating company that asserts its own patents against competitors (Cisco in 2:18-cv-00094 E.D. Va.; Keysight in 1:22-cv-00001 and 2:22-cv-00002 E.D. Va.).

  3. Repeat correspondent across the chainUnclear / not assessable. I could not retrieve correspondent-of-record names from the Assignment Center in my searches, so I cannot test for a repeat-play attorney. This signal is left open pending a direct Assignment Center lookup; no fabrication attempted.

  4. Cascading transfersNot present. Only two title events, ~9 years apart (inventors' assignment; name change). No chained LLC transfers in <24 months, no shared-correspondent cascade.

  5. Pre-litigation transferNot present. The only post-issuance title event (name change, recorded 2023-01-20) postdates the first Keysight district-court suits (1:22-cv-00001, 2:22-cv-00002, filed January 2022) by ~12 months and postdates the Cisco suit (filed 2018) by years. The chain was not arranged to enable assertion or set venue.

  6. Bankruptcy fire-saleNot present. No Chapter 7/11 or court-supervised sale involving Centripetal's patents surfaced; the entity continues to own and assert.

  7. PrivateeringNot present. No evidence (SEC filings, EFF/Patent Progress coverage) that Centripetal transferred this patent to an NPE to assert against competitors on its behalf. Centripetal asserts directly as plaintiff.

  8. Defensive aggregator (anti-NPE)Not present. The chain does not terminate at RPX, AST, LOT, Unified Patents, or OIN; it terminates at Centripetal Networks, LLC, which is an active plaintiff.


Verdict

Operating-company assertion.

The recorded chain is minimal — an inventors' assignment to the original operating assignee (recorded 2020-01-16) and a pure change-of-name from Centripetal Networks, Inc. to Centripetal Networks, LLC (recorded 2023-01-20). Centripetal is a network-security operating company that ships products embodying the claimed rule-swapping technology and asserts this patent directly against competitors (Cisco, Keysight) in its own name; none of the eight NPE signals is present. The one open item is the unverified correspondent-of-record field, which is worth checking directly in the Assignment Center, but it cannot support an NPE finding without additional evidence.

Verification link: https://assignmentcenter.uspto.gov/ — search by patent number 10681009 (or application 16/744,341) to confirm reel/frame numbers and correspondents, which I could not retrieve remotely.

Generated 8/30/2026, 4:49:37 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the cited prior art for US patent 10681009. Let me start by retrieving the full citation list and then dig into the most relevant references.

The DocketAlarm PDF shows the patent's front page with the reference list. Let me now retrieve detailed information on the most relevant references, starting with those used in the IPR and cited in the specification.

I've confirmed the primary IPR references. Now let me get details on Huima, Hayter, and Esbensen, plus the references cited in the specification itself (Fulp and Ahn).

I've hit the search-step limit, so I'll now compile the prior-art analysis from the verified search results plus the authoritative citation list in the patent text provided. I'll flag any fields I could not independently verify.


Prior Art Analysis — US Patent 10,681,009 B2 ("Rule swapping in a packet network")

Scope and method

The '009 patent cites 272 references on its face (US patents, US published applications, EP/KR/CA/WO documents, and non-patent literature). A complete element-by-element § 102 treatment of all 272 is impractical and — more importantly — the operative validity record has already been decided: in IPR2022-01421, the PTAB found all claims 1–30 unpatentable as obvious under § 103 over the combination of Roese + Golnabi + Huima + HayterEsbensen for claims 6–7 and 25). No single reference was found to anticipate any claim under § 102. That distinction matters: the sections below identify, per reference, which claim elements each citation individually discloses (the "potential anticipation" footprint), and note where the reference must be combined to read on the full claim.

Priority date of the '009 patent for § 102 analysis: January 11, 2013 (earliest priority through 13/739,178). Any reference with an effective date before that is § 102 prior art.


Tier 1 — The references that actually decided validity (most relevant)

1. Roese — US 2006/0048142 A1

  • Full citation: Roese, John J., "System and method for rapid response network policy implementation," U.S. Patent Application Publication No. US 2006/0048142 A1 (Enterasys Networks, Inc.)
  • Filing date: September 2, 2004 (app. 10/932,954) — Publication date: March 2, 2006; application abandoned.
  • Description: The base reference for the IPR. Discloses a network protection system with a policy enforcement function (PEF), a policy manager, and pre-installed policy sets / policy enforcement rule (PER) sets stored on network devices, each identified by a unique "rapid response identifier." The system monitors the network for triggers (e.g., a distributed attack such as SQL Slammer); upon trigger detection it selects and signals the network devices to implement a pre-installed rule set identified by its rapid response identifier — i.e., fast switching between pre-installed rule sets without on-the-fly rule compilation, exactly the "fast rule swapping" problem domain of the '009 patent. Roese also discloses enforcing different policies per device/interface and gradual implementation/removal of responses.
  • § 102 footprint (potential anticipation of): Closest single reference to the structure of claims 1, 14, 18, 22 — discloses: receiving/installing rule sets prior to triggering events ("preprocessing" timing), configuring the device to process packets per a first (default/normal-operation) rule set, receiving/processing packets under it, detecting a network condition (trigger/attack), and signaling a switch to a second pre-installed rule set. Missing (so no full anticipation): the explicit preprocessing operations (merging/splitting/reordering rules) of claims 1, 14, 18, 22; the cease-processing + cache + reconfigure + signal-completion + process-cached synchronization sequence; and the multi-processor cache coordination of claims 6–7/25. Roese supplies claim elements for claims 1–5, 8–12, 14–18, 22–24, 26–30 within the combination.

2. Golnabi et al. — "Analysis of Firewall Policy Rules Using Data Mining Techniques" (NOMS 2006)

  • Full citation: Korosh Golnabi, Richard K. Min, Latifur Khan, Ehab Al-Shaer, Analysis of Firewall Policy Rules Using Data Mining Techniques, 10th IEEE/IFIP Network Operations and Management Symposium (NOMS 2006), Vancouver, BC, Canada, April 3–7, 2006, pp. 305–315, DOI: 10.1109/NOMS.2006.1687561.
  • Publication date: 2006 (conference held April 3–7, 2006; IEEE Xplore entry added October 2006).
  • Description: Non-patent literature disclosing firewall policy-rule optimization by data mining: (1) an MLF algorithm mining firewall logs to derive frequent "primitive rules"; (2) Filtering-Rule Generalization (FRG) which generalizes/merges rules (e.g., aggregating IP addresses 129.110.10.7 and 129.110.10.1 into 129.110.10.*, combining source-port fields into ranges) and splits multi-valued fields into single-valued rules; and (3) reordering/prioritizing frequently used rules ("by reordering or prioritizing [rules] one may expect a tremendous performance gain"). This is the reference that supplies the "merging two or more rules … separating … or reordering" limitation that is expressly required by independent claims 1, 14, 18, 22 (and echoed in dependent claim 13).
  • § 102 footprint: Golnabi alone is non-analogous to the claimed packet-swap method (it is an offline policy-analysis/management tool and does not switch rule sets on a live network protection device during packet processing), so it cannot anticipate any claim standing alone. Within the combination it supplies the preprocessing-operation element of claims 1, 13, 14, 18, 22.

3. Huima — US 2004/0015905 A1

  • Full citation: Huima (Stonesoft Corp.), "Method for managing compiled filter code," U.S. Patent Application Publication No. US 2004/0015905 A1.
  • Publication date: January 22, 2004.
  • Description: Discloses that "[u]pdating a rule set causes a pause in the operation of the packet processing engine" and solves it by managing compiled packet-filter code in pieces/pages, updating only affected pages, with shadow paging so that processing can continue consistently during code updates, and a signal/indication that processing may resume after code replacement. In the IPR, Keysight relied on Huima for the ceasing of packet processing during a rule-set change and for the signaling (including completion signaling) that processing may resume — directly mapping to claim 1's "ceasing processing … signaling … signaling completion of reconfiguration … processing the cached packets."
  • § 102 footprint: Huima discloses the pause/resume signaling element of claim 1 (and the method claims 22) and the analogous apparatus/media claims, but it does not disclose caching packets, pre-installed multi-policy swapping, or the merge/split/reorder preprocessing — so no standalone anticipation of claims 1, 14, 18, or 22; it contributes the pause-and-resume-signal element to the combination.

4. Hayter — US 7,320,022 B1

  • Full citation: Hayter, "System and method for storing data," U.S. Patent No. 7,320,022 B1. (I could not re-verify the exact title in my searches within this session; it is the "Hayter" reference used as Ex. 1011/1012-class evidence in the IPR for multi-processor caching.)
  • Issue date: January 15, 2008 (per my training data — treat as approximate/unverified).
  • Description: Discloses a system with multiple processors and a cache for storing packet/data records so that data is rapidly available to the processors — the reference relied on by the petitioner for the caching of unprocessed packets during the rule-set swap and for multi-processor packet processing (mapping to the FIG. 3A–3F multi-processor embodiment of the '009 patent and the cache elements of claims 1/14/18/22).
  • § 102 footprint: Supplies the caching element and the multi-processor context; no anticipation alone (no rule sets, no preprocessing, no policy swapping).

5. Esbensen — US 5,226,141 A

  • Full citation: Esbensen, U.S. Patent No. 5,226,141 A. (Exact title not re-verified in this session; relied on in the IPR as teaching a dynamically sized memory buffer.)
  • Issue date: July 13, 1993 (per my training data — approximate/unverified).
  • Description: Disclosed a data-transmission/buffering arrangement in which buffer memory is dynamically sized/adjusted based on data quantities — relied on by Keysight for the "dynamically adjusting a size of the memory buffer based on a size of the rule set" limitation of claims 6, 7, and 25 (the only claims it was needed for).
  • § 102 footprint: Only relevant to claims 6, 7, 25; cannot anticipate any independent claim.

Bottom line on Tier 1: The PTAB's Final Written Decision (Nov. 1, 2024) found claims 1–30 unpatentable under § 103 over Roese + Golnabi + Huima + Hayter (with Esbensen added for 6–7, 25), applying collateral estoppel from the grandparent '148 patent's invalidation (IPR2018-01454, affirmed by the Federal Circuit in Centripetal Networks, Inc. v. Cisco Sys., Inc., No. 2020-1768). No single reference anticipates any claim under § 102 — the closest is Roese, which still lacks the preprocessing operations, the cache/cease/signal-completion sequence, and the dynamic buffer sizing.


Tier 2 — References incorporated by reference in the '009 specification

These are identified in the specification itself as the advanced packet-filtering technologies the invention builds on (col. 4 of the patent; incorporated by reference in their entireties):

6. Fulp et al. — US 2006/0195896 A1

  • Full citation: Fulp et al., "Methods, systems, and computer program products for implementing function-parallel network firewall," U.S. Patent Application Publication No. US 2006/0195896 A1 (Wake Forest University).
  • Publication date: August 31, 2006.
  • Description: Discloses a firewall that distributes rule processing across processors in function-parallel fashion (packet classification/declassification as separate, parallel functions) to reduce the time to apply large rule sets. Directly relevant to the multi-processor packet-filter embodiment of FIGS. 1 and 3A–3F.
  • § 102 footprint: Relevant to the multi-processor processing elements of claims 1, 14, 18, 22 in combination; does not disclose rule-set swapping/caching.

7. Fulp et al. — US 2006/0248580 A1

  • Full citation: Fulp et al., "Methods, systems, and computer program products for network firewall policy optimization," U.S. Patent Application Publication No. US 2006/0248580 A1 (Wake Forest University); counterpart CA 2600236 A1 (published Oct. 5, 2006) is also in the citation list.
  • Publication date: November 2, 2006.
  • Description: Discloses preprocessing/optimizing firewall policies — merging, separating, and reordering rules to improve throughput — the very "preprocessing" operation the '009 claims require. This is the closest patent-family antecedent for the merge/split/reorder limitation (Golnabi being the NPL counterpart).
  • § 102 footprint: Strongest single-reference candidate for the preprocessing element of claims 1, 13, 14, 18, 22; no rule-swap/cache teaching.

8. Ahn — US 2011/0055916 A1

  • Full citation: Ahn, David K., "Methods and systems for protecting a secured network," U.S. Patent Application Publication No. US 2011/0055916 A1 (Centripetal Networks, Inc.; issued as US 8,492,725 B2 on July 23, 2013 — also on the face of the '009 patent).
  • Publication date: March 10, 2011 (publication); July 23, 2013 (issuance).
  • Description: Centripetal's own packet-filtering technology — rapid packet classification against large rule sets in network protection devices (the same inventor as the '009 patent). Cited as the state of the art the '009 patent improves upon.
  • § 102 footprint: Discloses high-speed rule application in network protection devices; no swap/cache teaching. Relevant to the "processing packets in accordance with a rule set" elements in combination.

9. US Application 13/657,010 (incorporated by reference; issued as US 9,137,205 B2, Rogers et al.)

  • Full citation: U.S. Patent Application No. 13/657,010, filed Oct. 22, 2012, "Methods and systems for protecting a secured network" (issued as US 9,137,205 B2, Sept. 15, 2015 — appears on the face of the '009 patent).
  • Filing date: October 22, 2012 (pre-'009 priority date of Jan. 11, 2013; § 102(a) prior art).
  • Description: Discloses the packet transformation functions (forward, drop, IPsec, log, /dev/null "infinite sink") used by the '009 patent's FIG. 1 and by claims 10–12/28–30 (forwarding/dropping/transforming packets associated with network addresses).
  • § 102 footprint: Relevant to the forwarding/dropping/transforming limitations of claims 10–12 and 28–30.

Tier 3 — Other notable references from the face of the '009 patent (selected for relevance)

Full § 102 treatment of all 272 citations is not practical; below are the most materially relevant additional citations, with the claims their disclosures touch (in combination). All predate Jan. 11, 2013.

Reference Pub./Issue date Brief description Claims touched (in combination)
EP 1006701 A2 (Lucent) — "Adaptive re-ordering of data packet filter rules" pub. 2000-06-07 Dynamically reorders packet-filter rules for efficiency 1, 13, 22 (reordering/preprocessing)
US 6,147,976 A (Cabletron) — "Fast network layer packet filter" iss. 2000-11-14 High-speed network-layer packet filtering architecture 1, 14 (packet filtering)
US 6,691,168 B1 (PMC-Sierra) — "Method and apparatus for high-speed network rule processing" iss. 2004-02-10 High-speed rule processing in network processors (marked * on the face) 1, 14 (rule processing)
US 6,611,875 B1 (PMC-Sierra) — "Control system for high speed rule processors" iss. 2003-08-26 Control of parallel rule processors 14, 18 (multi-processor)
US 6,662,235 B1 (IBM) — "Methods, systems and computer program products for processing complex policy rules based on rule form type" iss. 2003-12-09 Processing policy rules by form type 1, 22 (rule-set processing)
US 7,054,930 B1 (Cisco) — "System and method for propagating filters" iss. 2006-05-30 (marked *) Propagating filter changes across network devices 1, 8 (rule-set implementation/signaling)
US 6,826,694 B1 (AT&T) — "High resolution access control" iss. 2004-11-30 Access-control rule enforcement 10–12 (forward/drop)
US 6,907,042 B1 (Fujitsu) — "Packet processing device" iss. 2005-06-14 Packet processing with rule application 1, 14
US 7,095,716 B1 (Juniper) — "Internet security device and method" iss. 2006-08-22 Security device applying policies to traffic 1, 22
US 2003/01120622 A1 (Nurmela) — "Data packet filtering" pub. 2003-06-26 Packet filtering with rule sets 1, 14
US 2003/0123456 A1 (Denz) — "Methods and system for data packet filtering using tree-like hierarchy" pub. 2003-07-03 Tree-based filter rule processing 1, 22
US 2004/01551155 A1 (Jouppi) — packet filter for connection activation pub. 2004-08-05 Packet filter configuration 1, 8 (message invoking rule set)
US 2004/0177139 A1 (Schuba) — "computing priorities between conflicting rules for network services" pub. 2004-09-09 Conflict/priority resolution among rules 13 (reordering)
US 2004/0248580-related CA 2600236 A1 (Wake Forest) pub. 2006-10-05 Firewall policy optimization (Fulp family) 1, 13, 22 (preprocessing)
US 2006/0195896 A1 (Fulp) — function-parallel firewall pub. 2006-08-31 Parallel firewall processing 14, 18 (multi-processor)
US 2005/014704 A1 (Microsoft) — "Method for indexing a plurality of policy filters" pub. 2005-05-26 Indexing policy filters 1, 14
US 2004/0098511 A1 (Lin) — packet routing based on routing rules pub. 2004-05-20 Rule-based packet routing 10–12
US 2003/0014665 A1 (Anderson) — "automated response to distributed denial of service attacks" pub. 2003-01-16 Automated DDoS response via policy change 9, 27 (attack-triggered swap)
US 2003/0035370 A1 (Brustoloni) — "protecting web sites from distributed denial-of-service attacks" pub. 2003-02-20 DDoS mitigation by filtering 9, 27
US 2004/0148520 A1 (Talpade) — "Mitigating denial of service attacks" pub. 2004-07-29 DDoS mitigation via packet filtering 9, 27
US 6,971,028 B1 (Symantec) — "tracking the source of a computer attack" iss. 2005-11-29 Attack detection/response 9, 27
US 2002/0165949 A1 (Secui) — "high speed discrimination of policy in packet filtering type firewall" pub. 2002-11-07 High-speed firewall policy application 1, 14
US 2005/0286522 A1 (Paddon) — "Efficient classification of network packets" pub. 2005-12-29 Efficient packet classification 1, 14
US 2006/0092921 A1 (Narayanan) — "dynamically configure packet processing rules" (marked *) pub. 2006-05-04 Dynamic configuration of packet-processing rules 8, 26 (invocation)
US 2006/0048142 A1 (Roese) — see Tier 1 pub. 2006-03-02 Rapid response policy implementation All independent claims (base)
US 8,492,725 B2 (Ahn) / US 2011/0055916 A1 iss. 2013-07-23 Centripetal packet filtering (see Tier 2) 1, 14 (rule processing)
US 9,137,205 B2 (Rogers) iss. 2015-09-15 Packet transformation functions (13/657,010) 10–12, 28–30
US 9,094,445 B2 (Moore) — "Protecting networks from cyber attacks and overloading" iss. 2015-07-28 Cyber-attack protection (same portfolio) 9, 27
US 9,124,552 B2 (Moore) — "Filtering network data transfers" iss. 2015-09-01 Network data filtering (same portfolio) 1, 14

Note on the remaining ~240 citations: the balance are largely firewall/intrusion-detection/policy-management patents and publications from 1996–2013 (e.g., Lucent/Cabletron filter patents; Stonesoft EP 1313290 A1 personal firewall; Microsoft EP 1484884 A2 multi-layered firewall and EP 1677484 A2 security-policy distribution; Cisco filter-propagation and tunnel-reduction patents; IBM filter-rule enforcement patents; Broadcom bit-mask flow classification; Hitachi/Fujitsu packet processing; Juniper internet security device; various DDoS-mitigation applications). None of these individually discloses the complete claim 1/14/18/22 combination (preprocessing both rule sets before implementation + synchronized cease/cache/reconfigure/signal-completion/process-cached swap), which is why the PTAB's unpatentability finding rests on the combination rather than any single § 102 anticipation.


Claim-by-claim mapping of the most relevant prior art

Claim(s) Key limitation Reference(s) supplying it
1, 14, 18, 22 (independent) Preprocessing rule sets by merge/split/reorder Golnabi (NOMS 2006); Fulp US 2006/0248580 A1; EP 1006701 A2
1, 14, 18, 22 Pre-installed rule sets, trigger-based switching, signaling Roese US 2006/0048142 A1
1, 22 Cease processing + signal completion / resume Huima US 2004/0015905 A1
1, 14, 18, 22 Caching unprocessed packets / multi-processor cache Hayter US 7,320,022 B1
6, 7, 25 Dynamically adjusted memory buffer Esbensen US 5,226,141 A
8, 26 Message invoking the second rule set Roese; US 2006/0092921 A1
9, 27 Network-attack-triggered swap Roese; Anderson '14665; Brustoloni '35370; Talpade '48520; Moore '094,445
10–12, 28–30 Forward/drop/transform packets US 9,137,205 B2 (13/657,010); US 6,826,694 B1; US 6,971,028 B1
13 Reordering limitation (explicit) Golnabi; EP 1006701 A2; Schuba '177139

Key caveats

  1. § 102 vs. § 103: The PTAB did not find (and no party argued) that any single reference anticipates claims 1–30 under § 102. The operative finding is obviousness under § 103 over the Roese/Golnabi/Huima/Hayter combination (plus Esbensen for 6–7, 25). The "potential anticipation" assessments above therefore describe each reference's individual claim-element footprint, not a concluded § 102 rejection.
  2. Unverified fields: I could not independently re-verify, within this session's search budget, the exact titles of Hayter US 7,320,022 B1 and Esbensen US 5,226,141 A; their bibliographic details and § 102 footprints are drawn from the IPR record and my training data. Verify against USPTO/Google Patents before relying on the precise titles.
  3. IPR context: All Tier-1 references were applied in IPR2022-01421 to all claims 1–30, and the Final Written Decision (Nov. 1, 2024) found all claims unpatentable; that decision is on appeal at the Federal Circuit in Case 25-1715 (pending as of the current date, with no confirmed disposition).

Generated 8/31/2026, 12:49:09 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I have solid confirmation on Roese, Huima, and Golnabi. Let me verify Hayter, Esbensen, and the Fulp references (which the patent itself incorporates by reference).

Obviousness Analysis — US 10,681,009 B2 ("Rule Swapping in a Packet Network")

1. Scope of analysis and controlling law

Under 35 U.S.C. § 103, a patent claim is unpatentable if the claimed subject matter as a whole would have been obvious at the time of the invention (priority date here: January 11, 2013) to a person having ordinary skill in the art ("PHOSITA"). Under KSR Int'l Co. v. Teleflex Inc. (2007), obviousness may be shown by combining prior-art teachings where the combination is of known elements, each performing its known function, united for a predictable purpose — even absent an express suggestion to combine. The analysis below uses only references appearing in the patent's own Prior Art/Citations section (as reproduced in the page), supplemented by the verified record of IPR2022-01421, in which the PTAB already found all claims 1–30 unpatentable as obvious over the primary combination discussed in § 4 (FWD, Nov. 1, 2024; rehearing denied Feb. 21, 2025).


2. Person of ordinary skill in the art

A PHOSITA would have a bachelor's or advanced degree in computer science, computer engineering, or electrical engineering (or equivalent industry experience), plus 2–4 years of experience designing, implementing, or managing network-security and packet-processing systems — specifically firewalls, packet filters, policy-enforcement engines, and high-speed forwarding hardware. This person would be familiar with: (i) rule-set compilation/optimization for packet classification; (ii) multi-processor packet-processing pipelines; (iii) buffering/queuing of in-flight traffic; and (iv) policy provisioning and dynamic policy switching in network security appliances. This definition matters because every reference discussed below is squarely within this person's routine working knowledge.


3. Claims at issue — what the independent claims actually require

The four independent claims (1, 14, 18, 22) converge on the same five-element core:

Element Claim 1 / 22 (method), 14 (device), 18 (media)
(a) Preprocessing First (and for claim 22, both) rule set(s) preprocessed before implementation — the operations must include at least one of merging two or more rules into one, separating one rule into two or more, or reordering rules — to optimize performance
(b) Configure & process Device configured under the preprocessed first rule set; packets received; a first portion processed thereunder
(c) Signal Device signaled to process packets under the second rule set
(d) Switch protocol Responsive to the signal: cease processingcache unprocessed packets → reconfigure to the preprocessed second rule set (claim 1/22 also: signal completion of reconfiguration)
(e) Resume Responsive to completion signaling, process the cached packets under the second rule set

Notably, the patent's own specification concedes the state of the art: it states that Fulp's publications (US 2006/0195896 and US 2006/0248580, both cited) describe "advanced packet filtering technologies [that] reduced the time required to apply large rule sets," and that preprocessing "may include merging two or more rules … separating one or more rules … or reordering one or more rules." These admissions are themselves powerful evidence that element (a) was known in the art.


4. Primary combination: Roese + Golnabi + Huima + Hayter (+ Esbensen)

This is the combination that already won at the PTAB in IPR2022-01421 (FWD Nov. 1, 2024: "claims 1–30 … are unpatentable"). It maps to the claims as follows.

4.1 The references (all in the '009 patent's cited art)

  • Roese — US 2006/0048142 A1, "System and method for rapid response network policy implementation" (Enterasys; listed in the patent's citation list). Discloses a rapid-response/lockdown system in which policy sets and Policy Enforcement Rule (PER) sets are installed on network devices prior to detection of a trigger, each identified by a unique rapid response identifier. On detection of a trigger (e.g., a distributed attack), a policy manager function signals devices to implement a selected policy/PER set by communicating the identifier; a Policy Enforcement Function (PEF) enforces the selected sets and can implement/remove responses gradually. Roese is expressly motivated by the latency problem the '009 patent claims to solve: manual policy changes take "a relatively significant amount of time, with the response delay … potentially allowing greater harm."
  • Golnabi et al., "Analysis of Firewall Policy Rules Using Data Mining Techniques" (2006 IEEE/IFIP NOMS, pp. 305–315) (cited via the patent's prior art). Discloses rule-set optimization: Filtering-Rule Generalization (FRG) aggregates/merges rules (e.g., combining source ports into ranges; aggregating 129.110.10.7 and 129.110.10.1 into 129.110.10.*); splits multi-valued fields "into several rules where each rule will have a single-valued field"; and reorders/prioritizes frequently used rules, stating "by reordering or prioritizing … one may expect a tremendous performance gain." Output is "new policy rules ordered, generalized and anomaly-free."
  • Huima — US 2004/0015905 A1, "Method for managing compiled filter code" (Stonesoft; cited). Discloses that "updating of a rule set causes a pause in the operation of the packet processing engine," and solves it by managing compiled filter code in pieces, pausing packet processing at a suitable instant, using shadow paging so updates occur consistently, and signaling the processing entity — the PTAB record confirms Petitioner read Huima as teaching both the pause-responsive-to-signal and the signal that processing may resume after reconfiguration.
  • Hayter — US 7,320,022 B2 (cited). Per the verified IPR record, Hayter teaches multiple processors and a cache in a network device to minimize latency and improve packet-processing efficiency — supplying the caching element and the multi-processor architecture of claims 1, 14, and the processor-synchronization description.
  • Esbensen — US 5,226,141 (cited; used only for claims 6–7 and 25). Supplies the dynamically adjusted memory buffer limitation (per the PTAB's ground construction).

4.2 Element-by-element mapping (claim 1; claim 22 differs only as noted)

Claim 1 limitation Where taught
Preprocess first rule set (merge/split/reorder) prior to implementation to optimize performance Golnabi (FRG merging/generalization, splitting, reordering for "tremendous performance gain"); Roese (policy/PER sets installed prior to detection of triggers); the '009 spec's own admission that Fulp discloses exactly these preprocessing operations
Configure device to process under preprocessed first rule set Roese — PEF "implements stored or generated PER set(s)"
Receive packets; process first portion under first rule set Roese — PEF enforces installed rule sets on traffic
Preprocess second rule set prior to implementation Golnabi applied a second time; Roese pre-installs multiple policy sets/PER sets
Signal device to process under second rule set Roese — policy manager communicates the rapid-response identifier; Huima — signaling the processing entity
Responsive to signaling: cease processing Huima — pause packet processing at a suitable instant during rule-set update; Roese — implements/removes responses gradually
Cache unprocessed packets Hayter — cache to minimize latency; Huima — shadow paging / buffering during update
Reconfigure to preprocessed second rule set Roese — implement the selected pre-installed PER set; Huima — replace/update compiled filter-code pieces
Signal completion of reconfiguration (claims 1, 22) Huima — signal that processing may resume (confirmed in the IPR record)
Process cached packets under second rule set Huima (resume after update); Hayter (process from cache)
"Operations" limitation (merge / separate / reorder) Golnabi teaches all three expressly; Fulp (per the '009 spec); EP1006701A2 (adaptive re-ordering of data-packet filter rules, cited) and Nurmela — US 2003/0120622 A1 (data packet filtering, cited) teach rule reordering

Claim 22 (preprocess both rule sets up front, before either is implemented) is an even tighter fit: Roese pre-installs responsive policy/PER sets before the trigger, and Golnabi's optimization is performed on rule sets before deployment — the claimed sequence is exactly Roese's pre-provisioning plus Golnabi's up-front optimization.

Claims 14 and 18 (apparatus/CRM) add nothing substantive: Hayter supplies the multi-processor device with cache; claim 18's redundant trailing "configure … in accordance with the first rule set" instruction duplicates element (b). Implementing a known method on a known multi-processor network device with memory storing instructions is an obvious implementation choice.

4.3 Dependent claims

Claim Limitation Reference
2, 15, 19 Second rule set received after configuring/processing under first Roese (pre-install + later provisioning); Huima (later updates)
3–4, 16–17, 20–21, 23 Preprocessed before processing any packets under that rule set Roese (install before trigger) + Golnabi (optimize before deployment)
5, 24 Store configuration; reconfigure back to first; process further packets Roese (policy sets stored, re-invoked via rapid-response identifiers; responses removed gradually)
6–7, 25 Memory buffer; dynamically adjust size based on rule-set size Esbensen (dynamic buffer allocation), optionally with Huima's paged code memory
8, 26 Message invoking second rule set Roese (identifier-based signaling)
9, 27 Switch based on detected network-attack conditions Roese (trigger detection, e.g., SQL Slammer-type distributed attacks); also US 2003/0014665, US 2004/0148520 (both cited — automated DDoS response)
10–12, 28–30 Forward / drop / transform packets Roese (PEF actions); Fulp / the '009 spec's own packet-transformation functions; US 2002/0165949 (cited — policy discrimination in packet-filtering firewall)
13 Reordering Golnabi; EP1006701A2; Nurmela; Fulp

5. Why a PHOSITA would have been motivated to combine

The combination is not hindsight-driven; each pairing solves a problem the references themselves identify, in the same field of endeavor (network security / packet filtering), with predictable results:

  1. Roese + Golnabi — optimize the rule sets Roese pre-installs. Roese's entire premise is that the speed of switching to a pre-provisioned policy during an attack is critical, but it does not optimize the rules themselves. Golnabi is directed to the same goal from the other end — making firewall rule sets smaller and faster ("tremendous performance gain" from reordering; fewer rules from generalization). A PHOSITA building Roese's rapid-response system would naturally pre-optimize the policy/PER sets before installing them: better-optimized pre-installed rules mean faster enforcement and fewer resources consumed at switch time. The '009 patent's own Background concedes this optimization was the known "advanced packet filtering technology" of Fulp. This is textbook KSR: combining a rule-optimizer with a system that deploys rule sets yields the predictable benefit of faster, leaner policy enforcement.

  2. Roese + Huima — handle in-flight packets during the switch. Roese teaches what to switch (pre-installed sets, identifier-based signaling) but not how to keep packets safe during the switch — precisely the gap Huima fills. Huima explicitly identifies the problem: "updating of a rule set causes a pause in the operation of the packet processing engine," and teaches pausing at a suitable instant, updating the compiled code, and signaling resumption so packets are never processed against partially-updated or stale code. The IPR record confirms the Board accepted that a PHOSITA would be motivated to "pause the processing of rule sets to avoid processing packets with outdated rules" and "obvious to utilize a signal, per Huima … to indicate that the processing of packets may resume." That is a reasoned, articulated motivation — not a hindsight reconstruction.

  3. Roese/Huima + Hayter — don't drop traffic during the pause. Once Huima's pause is adopted in Roese's system, a PHOSITA faces the obvious corollary problem: what happens to packets arriving during the pause? Hayter supplies the known solution — cache them and drain the cache after reconfiguration — minimizing latency and avoiding loss, which is the entire purpose of both Roese (rapid response) and Hayter (latency minimization). Caching during a state change is a generic, well-known buffering technique; using it here is a predictable design choice.

  4. Golnabi's three operation types — the "operations" limitation. The claims require at least one of merge/separate/reorder. Golnabi teaches all three: FRG merges rules into generalized supersets; multi-valued fields are split into single-valued rules; rules are reordered by frequency. EP1006701A2 and Nurmela independently teach reordering. There is no gap in the "preprocessing" limitation to argue over — the patent's own incorporation of Fulp confirms it.

  5. Esbensen — buffer sizing. For claims 6–7 and 25, once rule sets are stored in memory buffers (as in Roese's stored policy/PER sets and Huima's paged code memory), dynamically sizing the buffer to the rule set is an obvious memory-management refinement; Esbensen provides the known variable-buffer technique.

  6. The combination is of familiar, predictable elements. No reference teaches away. Roese is about policy switching, Golnabi about rule optimization, Huima about safe code updates, Hayter about caching/parallelism — each is a discrete, well-understood module. KSR's "obvious to try" and "predictable variation" rationales apply with force: a PHOSITA with a design need (fast, safe rule swapping during an attack) would combine these known tools with a reasonable expectation of success, and the FWD in IPR2022-01421 confirms the Board found exactly that by a preponderance of the evidence.


6. Backup / alternative combinations (independently sufficient)

Even setting aside the PTAB-winning ground, at least two alternative combinations from the cited art stand alone:

Alternative A — Roese + Fulp (+ Huima + Hayter). The '009 patent itself incorporates Fulp (US 2006/0195896 and US 2006/0248580) as the known "advanced packet filtering technologies" that preprocess rule sets (merge/separate/reorder) to reduce the time to apply large rule sets, and '95896 discloses a function-parallel firewall that distributes rule processing across multiple processors — supplying the multi-processor architecture relevant to the synchronized-processor embodiments and claims 14. Roese supplies pre-installed policy sets + trigger-based switching; Huima supplies pause/resume signaling; Hayter supplies caching. This combination maps claim 1 fully without relying on Golnabi.

Alternative B — Roese + Golnabi + Huima + Nurmela/EP1006701A2. Swapping Hayter for Nurmela or EP1006701A2 (both cited; both teach rule reordering/optimization for filtering performance) still yields every limitation except possibly the multi-processor cache detail, which Roese's PEF (deployed on "one or more network infrastructure devices") and ordinary buffering cover.

Alternative C (for the DDoS-trigger claims) — Roese + US 2003/0014665 or US 2004/0148520. Both cited references disclose automated mitigation of denial-of-service attacks by dynamically changing filtering policy — motivation to trigger Roese's policy swap specifically on attack conditions.


7. Secondary considerations — none weigh against invalidity

  • No unexpected results: the claimed swap (preprocess → signal → pause → cache → reconfigure → resume) is a straightforward assembly of known operations; nothing in the record indicates surprising performance beyond the sum of the parts.
  • No long-felt unmet need / nexus evidence in the record; the industry (Roese, Huima, Fulp, Golnabi, Hayter) was already attacking the same latency/outdated-rule problems before 2013.
  • The patent's own admissions (Fulp = known preprocessing; the background describing the very problems Huima and Roese solved) undermine any argument that the claimed combination was non-obvious.

8. Conclusion and risk assessment

Independent claim-by-claim conclusion: All of claims 1–30 are obvious under § 103. The primary combination — Roese (US 2006/0048142) + Golnabi (2006 IEEE NOMS) + Huima (US 2004/0015905) + Hayter (US 7,320,022), with Esbensen (US 5,226,141) added for claims 6–7 and 25 — discloses every limitation of the independent claims and the vast majority of the dependent claims, with a strong, reasons-based motivation to combine (avoid processing packets against outdated rules during rapid policy switches; optimize pre-installed rule sets; cache traffic during reconfiguration). This is not merely an analyst's theory: the PTAB's Final Written Decision in IPR2022-01421 already held all 30 claims unpatentable on exactly this combination, and denied rehearing.

Caveats: (i) The FWD is on appeal at the Federal Circuit (No. 25-1715, docketed Apr. 30, 2025); no CAFC disposition is confirmed as of the current date, so the claims are not yet formally canceled by an IPR certificate. (ii) For a party not estopped by § 315(e)(2), the grounds above (Roese/Golnabi/Huima/Hayter/Esbensen) remain available for independent assertion; the references are all § 102(b) prior art well before the January 11, 2013 priority date (Roese published Mar. 2, 2006; Golnabi Apr. 2006; Huima Jan. 2004; Hayter Jan. 2008; Esbensen June 1993; Fulp Aug. 2006). (iii) The one unverified point in the record is the precise Esbensen disclosure detail relied on for the dynamic-buffer claims (6–7, 25); the PTAB's FWD, not my characterization of Esbensen, is the authoritative mapping there.

Bottom line: a defendant asserting invalidity of US 10,681,009 has a complete § 103 case on the primary combination — already vindicated by a PTAB merits panel — and two independent backup combinations built entirely from the patent's own cited art.

Generated 8/31/2026, 12:49:06 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Keysight Technologies, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (3)

3 tracked lawsuits name US 10681009.