Invalidity dossier
US 10749906
Methods and systems for protecting a secured network
Current assignee: Palo Alto Networks, Inc.
Added 8/30/2026, 4:49:31 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I have gathered sufficient information from the searches. Here is my summary, with confidence levels noted per your instructions.
US Patent 10,749,906 B2 — Concise Summary
Bibliographic data (high confidence)
- Title: Methods and systems for protecting a secured network
- Patent number: US 10,749,906 B2 (application no. 16/448,969)
- Assignee: Centripetal Networks, Inc. (Portsmouth, NH) — later renamed Centripetal Networks, LLC (name-change recorded Jan. 20, 2023)
- Inventors: Steven Rogers (Leesburg, VA); Sean Moore (Hollis, NH); David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH)
- Filing date: June 21, 2019
- Issue date (grant): August 18, 2020
- Priority date: April 16, 2014 (chain: U.S. App. 14/253,992 → US 9,565,213 → App. 15/414,117 → US 10,142,372 → App. 16/158,868 → App. 16/448,969)
- Legal status: Active; anticipated expiration April 16, 2034
Abstract (verbatim)
"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets."
Classification (high confidence)
- CPC: H04L 63/20 (security policy management); H04L 63/02, H04L 63/0209, H04L 63/0218, H04L 63/0227, H04L 63/0236, H04L 63/0263, H04L 63/029, H04L 63/06, H04L 63/1408, H04L 63/1425, H04L 63/168; H04L 67/02; H04L 65/1069, etc.
Independent claims — plain-language overview
Caveat on claim text (important): The full claim text of US 10,749,906 was not reproduced in the provided patent text or surfaced verbatim in my searches. The claim language I verified comes from the closely related family member US 11,012,474 (a continuation-in-part of this patent), which shares the same title/inventors and the same claim architecture, and from the PTAB record (IPR2021-01157) confirming that claims 1–17 of 10,749,906 were challenged and invalidated. The four independent-claim structure described below is therefore highly probable but not 100% verbatim-verified for the '906 patent itself.
Claim 1 — Method (medium-high confidence on substance): A method of filtering packets at a packet security gateway protecting a network, where the gateway can receive multiple dynamic security policies and is associated with a security policy management server external to the network. The gateway (a) receives from the server a dynamic security policy containing packet filtering rules that were automatically created or altered based on malicious-traffic information from multiple malicious host tracker services, with at least two of those services managed by different organizations, and where rules were added/removed/altered based on a correlation between portions of that malicious-traffic information; each matching rule includes at least one packet-matching criterion, a corresponding packet transformation function, and an indication of a feed managed by one of the tracker services; and (b) performs packet filtering on individual packets by inspecting each packet and filtering it based on the content determined from that inspection.
Claim 9 — Apparatus (packet security gateway): A packet security gateway with at least one processor and memory storing instructions that cause the gateway to perform the same receive-and-filter functions as claim 1 (receiving the correlated, multi-tracker-service dynamic security policy from the external management server and filtering individual packets on a packet-by-packet, content-based basis).
Claim 17 — Computer-readable media: One or more non-transitory computer-readable media storing instructions that, when executed by the processor(s) of a packet security gateway, cause the gateway to perform the same dynamic-policy receipt and content-based per-packet filtering recited in claim 1.
Claim 25 — System (medium-high confidence on substance): A system combining (i) a security policy management server external to the protected network, which receives malicious-traffic information from multiple malicious host tracker services (at least two managed by different organizations), automatically creates the dynamic security policy/rules (each matching rule including criteria, a transformation function, and a feed indication), and adds/removes/alters rules based on correlating portions of the malicious-traffic information; and (ii) the packet security gateway, which receives that policy and filters individual packets based on inspection of each packet's content.
Dependent claims (e.g., 2–8, 10–16, 18–24, 26–33) add limitations such as: matching criteria comprising network addresses associated with malicious traffic; transformation functions being network-protection actions; differential forwarding queues with different rates; network-layer-transparent operation using an unaddressed link-layer interface; the gateway being a LAN switch; and a packet-digest logging function (identifying a subset of packet information, generating records, reformatting per a logging standard such as syslog, and routing packets to a monitoring device).
Litigation / PTAB / CAFC status (high confidence from live searches)
- IPR2021-01157 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (PTAB). Petition filed July 22, 2021; institution March 15, 2022; Final Written Decision March 10, 2023, holding claims 1–17 unpatentable. (Panel: APJs McNamara, Moore, Amundson.)
- CAFC Appeal No. 2023-1730 — Centripetal Networks, LLC v. Palo Alto Networks, Inc. Oral argument May 9, 2024; nonprecedential per curiam judgment (Taranto, Hughes, Stoll) entered May 13, 2024, AFFIRMING the PTAB decision.
- District litigation: Patent asserted in Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137 (E.D. Va., filed Mar. 12, 2021), along with numerous other Centripetal patents (e.g., 10091246, 10503899, 10785266, etc.).
CAFC 2026 dockets — what I did and did not find
- I found no CAFC docket dated in calendar year 2026 specifically captioned for patent 10,749,906 itself.
- The most recent related CAFC activity is Appeal No. 25-1167 — the Federal Circuit appeal arising from the E.D. Va. case (2:21-cv-00137), which was reactivated by order dated December 22, 2025 (per a Dec. 22, 2025 district-court docket entry referencing "ORDER of USCA reactivating appeal under FRAP 4(a)(4) [25-1167]"). That appeal involves the multi-patent district litigation of which '906 is one of the asserted patents, and is the closest item to a "2026 CAFC docket" I could verify. I could not confirm any 2026-dated CAFC filing or disposition on that docket from the available search results.
Uncertainty notes
- Exact verbatim claim text of the '906 patent (versus its CIP family member 11,012,474) was not independently verified; the independent-claim overview above is based on the family's shared claim architecture and the IPR record (claims 1–17), not on a direct image of the '906 claims page.
- The December 2025 "reactivation" order and appeal 25-1167 were found via a secondary source (DocketAlarm) and a district-court docket entry; I did not pull the CAFC docket itself.
- All other bibliographic data (title, assignee, inventors, dates, abstract, status) is corroborated across Google Patents, USPTO-related records, and court/PTAB databases.
Generated 8/30/2026, 12:46:05 PM
Cases on file (4)
Group view →Specific litigation cases in our database that name US patent 10749906. The free-form analysis below may also discuss cases beyond this list.
- Palo Alto Networks, Inc. v. Centripetal Networks, Inc.filed Jul 22, 2021IPR2021-01157Patent Trial and Appeal Board (PTAB)terminated Mar 10, 2023final written decision; appealed to Federal Circuit
Defendants: Centripetal Networks, Inc.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10091246, 10567437, 10530903, 10567413, 10659573, 10757126, 10542028, 10503899, 10735380, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10757126, 10785266, 10931797
- 25-1167U.S. Court of Appeals for the Federal Circuitrelated appeal; details not specified
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Based on searches of Unified Patents, Patexia, Docket Alarm, RPX Insight, and related sources, here is what I can report regarding litigation involving US Patent No. 10,749,906 ("Methods and systems for protecting a secured network," Centripetal Networks). Please note the "10749906" identifiers are interpreted literally, and where search results were ambiguous or truncated I flag it below.
1. Centripetal Networks, LLC v. Palo Alto Networks, Inc. — No. 2:21-cv-00137 (E.D. Va.)
- Plaintiff(s): Centripetal Networks, LLC (sued as Centripetal Networks, Inc.)
- Defendant(s): Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division), Judge Elizabeth W. Hanes; Magistrate Judge Lawrence R. Leonard
- Case number: 2:21-cv-00137 (EWH-LRL)
- Filing date: March 12, 2021
- Outcome/status: '49906 was one of 13 patents originally asserted in this case (including 10091246, 10503899, 10530903, 10542028, 10567343, 10567413, 10567437, 10659573, 10735380, 10749906, 10757126, 10785266, 10931797). A jury returned a verdict on January 31, 2024 awarding Centripetal approximately $151.1 million, but that verdict covered claims of the '437, '903, '573, and '797 patents — not '49906. Palo Alto's post-trial briefing represented that ten of the thirteen asserted patents were ultimately found invalid or not infringed, which appears to include '49906. Post-trial, the court granted PAN judgment as a matter of law of non-infringement on the '437 patent (Oct. 30, 2024) and reduced the award accordingly; post-judgment proceedings (attorneys' fees, prejudgment interest) continued into 2025. Centripetal appealed to the Federal Circuit (Case No. 25-1168, filed Nov. 13, 2024; related appeal No. 25-1167), and the appeal was reactivated per a Dec. 22, 2025 docket entry. Status as of now: post-judgment proceedings/appeal ongoing.
2. Centripetal Networks, Inc. v. Palo Alto Networks, Inc. — No. 1:21-cv-00313 (E.D. Va.)
- Plaintiff(s): Centripetal Networks, Inc.
- Defendant(s): Palo Alto Networks, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (per Google Patents/Unified Patents litigation data linking this case to the '49906 family)
- Case number: 1:21-cv-00313
- Filing date: March 12, 2021 (same day as the 2:21-cv-00137 action; the 2:21-cv-00137 docket confirms a complaint for patent infringement was filed in 1:21-cv-00313 by Centripetal)
- Outcome/status: I could not independently confirm from the search results whether '49906 is specifically asserted in this case, nor its current status/disposition. Caution: a search for "1:21-cv-00313" also surfaces an unrelated Delaware case (Pearl IP Licensing LLC v. Schneider Electric USA Inc., D. Del.) with the same number; the E.D. Va. case referenced in the patent's litigation data is the Centripetal v. Palo Alto action. I could not verify further details with the sources available.
3. Palo Alto Networks, Inc. v. Centripetal Networks, Inc. — IPR2021-01157 (PTAB)
- Petitioner: Palo Alto Networks, Inc.
- Patent Owner: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
- Jurisdiction: Patent Trial and Appeal Board (PTAB)
- Case number: IPR2021-01157
- Filing date: July 22, 2021
- Outcome/status: Petition challenged claims 1–17 of '49906. Institution decision: March 15, 2022. Final Written Decision: March 10, 2023 (Administrative Patent Judges Brian J. McNamara, Bryan F. Moore, and Steven M. Amundson; Judge McNamara wrote the final decision). The search results confirm the proceeding reached a "Final Written Decision" but truncated the "Claims Invalidated" field, so I cannot confirm with confidence whether all challenged claims were invalidated — I will not speculate. (The case is flagged in the patent's litigation data as having a "Final Written Decision.")
4. Appeal of IPR2021-01157 — No. 23-1730 (Fed. Cir.)
- Parties: Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (appeal of the IPR final written decision)
- Jurisdiction: U.S. Court of Appeals for the Federal Circuit
- Case number: 23-1730
- Filing date: 2023 (linked to the March 10, 2023 FWD)
- Outcome/status: The Federal Circuit appeal was docketed, but I could not confirm the outcome or current status from the sources retrieved.
Summary caveats
- The only litigation I could verify as specifically involving US 10,749,906 is: 2:21-cv-00137 (E.D. Va.), IPR2021-01157 (PTAB), and its Federal Circuit appeal 23-1730. The E.D. Va. companion case 1:21-cv-00313 is linked to the patent family in the patent's litigation data, but I could not confirm whether '49906 is asserted in it or its current disposition.
- I did not locate any litigation involving other defendants (e.g., Cisco, Fortinet, etc.) specifically tied to '49906 in these results, though the same family has been litigated broadly — do not assume other Centripetal suits involve this exact patent without confirming the asserted patent numbers.
- If you need the precise IPR outcome (which claims survived), I'd recommend pulling the Final Written Decision from PTAB (IPR2021-01157, Paper No.) or the Federal Circuit docket for 23-1730 directly.
Generated 8/30/2026, 12:45:56 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Palo Alto Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll research the PTAB proceedings on this patent. The structured ODP block reports no AIA trial proceedings, but prior litigation research surfaced IPR2021-01157 — I need to verify that and pin down the claim-level outcome from the Final Written Decision and the Federal Circuit appeal.
I've confirmed the key proceeding (IPR2021-01157) with a Final Written Decision finding all challenged claims unpatentable. Now I need the petition grounds/art, and the Federal Circuit appeal (23-1730) disposition. Let me dig deeper.
Proceedings overview
The USPTO Open Data Portal block in this prompt reports zero AIA trial proceedings on file — but that index is stale: web research confirms one Inter Partes Review was filed, fully litigated, and resulted in all 17 claims (the entire claim set) of US 10,749,906 being invalidated, a decision affirmed by the Federal Circuit and followed by a with-prejudice dismissal of every '49906 claim in the parallel E.D. Va. litigation. Defensive posture: this patent is dead on arrival — all claims are canceled; any demand letter or infringement theory built on US 10,749,906 is worthless and should be met with a motion to dismiss with prejudice.
IPR2021-01157 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review
- Filed: 2021-07-22
- Status: Final Written Decision — "Determining All Challenged Claims Unpatentable" (35 U.S.C. § 318(a)); proceeding terminated 2023-03-10. Plain-English gloss: the IPR ran its full course and the patent owner lost on every claim.
- Judge panel: Administrative Patent Judges Brian J. McNamara (author of the Final Written Decision), Bryan F. Moore, and Steven M. Amundson.
- Petition grounds: PAN challenged all 17 claims (claims 1–17). The petition asserted obviousness under 35 U.S.C. § 103 over combinations of prior art that included Centripetal's own earlier-filed family patents — US 9,565,213 (the '49906's parent), US 9,560,077, and US 9,137,205 (all Rogers et al.) — together with US 2008/0229415 (Kapoor), US 7,084,760 (Himberger), US 2003/0214913 (Kan), US 2015/0215329 (Singla), US 2004/0123220 (Johnson), US 2008/0282080 (Hyndman), and academic references (Granidt; Navrikuth). Caveat: the truncated search results did not show the Board's exact ground-by-ground chart from the Institution Decision (Paper 10); pull Paper 10 for the precise reference/claim mapping before citing it in a filing.
- Institution decision: Granted — 2022-03-15 (Paper 10, per docket: "Board Institution Decision: Grant"). The Board instituted review on the obviousness challenge to the challenged claims, finding PAN had shown a reasonable likelihood of prevailing.
- Final Written Decision (issued 2023-03-10, Paper 36, 52 pages): The Board determined all challenged claims — claims 1–17 — unpatentable as obvious. This is the entire claim set of the patent; no claim survived. The Board's decision was captioned "Final Written Decision Determining All Challenged Claims Unpatentable" under § 318(a). (The Patexia summary truncates the "Claims Instituted" and "Claims Invalidated" fields, but the FWD caption and the Justia file-history entry confirm the full-claim-set disposition.) Centripetal's own earlier-filed family patents were effective prior art against the later continuation claims.
- Settlement / termination: No settlement. The proceeding terminated by issuance of the Final Written Decision on 2023-03-10.
- Appeal: Yes — affirmed. Centripetal appealed to the Federal Circuit as No. 23-1730 (filed 2023-04-10; oral argument 2024-05-09). On 2024-05-13, the Federal Circuit entered a nonprecedential per curiam Rule 36 judgment AFFIRMING the Board (panel: Taranto, Hughes, and Stoll). See CourtListener opinion No. 9501691. I found no evidence of further rehearing or certiorari review.
- Defensive value: Maximum. Every claim of US 10,749,906 has been found unpatentable, and that finding is final and affirmed. In the parallel E.D. Va. case (Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137), the district court dismissed all claims related to the '906 Patent WITH PREJUDICE on 2024-10-03, expressly noting "the PTAB's invalidations of the '246 Patent and the '906 Patent have now been affirmed by the Federal Circuit." Any assertion of this patent today is sanction-bait.
Strategic summary
Claims CANCELED vs. SUSTAINED vs. UNTESTED. All 17 claims (claims 1–17) are CANCELED — the complete claim set of US 10,749,906 was found unpatentable in IPR2021-01157, and that determination was affirmed by the Federal Circuit (23-1730) on 2024-05-13. Zero claims sustained, zero claims untested. There is no claim of this patent left to assert. A USPTO certificate canceling the claims should have issued following the affirmed FWD — verify it on the USPTO's patent file (the patent remains listed as "Active" at the USPTO for administrative reasons, but that status flag is not a reflection of claim validity; all claims are gone).
Estoppel landscape. 35 U.S.C. § 315(e)(2) bars Palo Alto Networks — and its privies — from asserting in district court or ITC any ground it raised or reasonably could have raised in IPR2021-01157. That matters little here because the claims are already canceled. For a different defendant (not PAN or a privy), there is no IPR estoppel, but none is needed: the claims are dead, and the affirmed FWD plus the with-prejudice dismissal give you claim/issue-preclusion and collateral-estoppel arguments against any re-assertion of the same claims. A new defendant should not need to file its own IPR — the target is gone.
Pattern signals. PAN did not single this patent out: it filed a coordinated wave of IPRs (including IPR2021-01152 against the '246 patent, IPR2021-01153 against the '437 patent, IPR2021-01154 against the '266 patent, and IPR2021-01157 against the '906 patent) in July 2021 against the 13 patents Centripetal had asserted in 2:21-cv-00137. Six of those patents were invalidated at the PTAB (the '028, '126, '413, '246, '906, and '899); as of May 2024 the Federal Circuit had affirmed two of the six — the '246 and the '906. Centripetal has appealed aggressively (and won some PTAB reversals on other patents, e.g., the '903 vacated/remanded in December 2024 and the '856 vacated/remanded in October 2025), but the '906 affirmance stands. Notably, PAN deployed Centripetal's own earlier-filed family patents (US 9,565,213, US 9,560,077, US 9,137,205) as the primary obviousness ammunition against this continuation — a tactic worth remembering for other Centripetal continuations in the family (e.g., US 10,912,474, US 10,951,660, US 11,412,774, US 12,107,893). Unified Patents appears in the Google Patents litigation-data attribution only as the PTAB-data source; there is no evidence a defensive aggregator filed or funded this IPR.
Recommended next steps
- If you are a defendant or target of a demand letter citing US 10,749,906: respond by pointing to the Final Written Decision in IPR2021-01157 (Paper 36, 2023-03-10, "Determining All Challenged Claims Unpatentable") and the Federal Circuit's Rule 36 affirmance in No. 23-1730 (2024-05-13). If litigation is filed, move immediately to dismiss with prejudice — the E.D. Va. court already did exactly that for the '906 claims (Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2:21-cv-00137, E.D. Va., Order of 2024-10-03, dismissing '906 claims with prejudice).
- CAFC Rule 36 judgment: https://www.cafc.uscourts.gov/05-13-2024-23-1730-centripetal-networks-llc-v-palo-alto-networks-inc-rule-36-judgment-23-1730-rule_36_judgment-5-13-2024_2316666/
- CourtListener (opinion): https://www.courtlistener.com/opinion/9501691/centripetal-networks-llc-v-palo-alto-networks-inc/
- USPTO PTAB decision search (IPR2021-01157, Paper 36): https://developer.uspto.gov/ptab-web/#/search/decisions?query=IPR2021-01157
- Confirm the certificate of cancellation issued on the patent's file after the affirmed FWD, and pull IPR2021-01157 Paper 10 (Institution Decision) if you need the exact § 103 ground/reference mapping for a brief.
- No active proceedings are pending on this patent — the FWD issued 2023-03-10 (within the statutory 1-year trial period), the appeal concluded 2024-05-13, and the E.D. Va. claims were dismissed with prejudice 2024-10-03. There is nothing left to stay or defend. The absence of additional PTAB activity is not a signal of weakness in the patent — it is a signal that no one needed a second shot because the first one killed every claim.
Generated 8/30/2026, 12:47:11 PM
Ownership chain (2)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2019-07-09 · Assignment
David K. Ahn, Sean Moore, Steven Rogers, Peter P. GeremiaCentripetal Networks, Inc.
? · recorded 2023-01-20 · Change of Name
Centripetal Networks, Inc.Centripetal Networks, Inc.
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
All four named inventors are listed on the patent and on the family's priority application (US 14/253,992, filed 2014-04-16), and all four appear on later Centripetal family members through at least 2022 (e.g., US 11,477,237, issued Oct. 18, 2022), indicating they remained with the company long after filing — no mass-departure-then-fire-sale pattern.
| Inventor | Residence at filing | Employer at filing (determinable) |
|---|---|---|
| Steven Rogers | Leesburg, VA | Centripetal Networks, Inc. (applicant/assignee on the family's patents; first-named inventor) |
| Sean Moore | Hollis, NH | Centripetal Networks, Inc. (also a named inventor on many Centripetal patents) |
| David K. Ahn | Winston-Salem, NC | Centripetal Networks, Inc. (previously associated with Great Wall Systems per other patents) |
| Peter P. Geremia | Portsmouth, NH | Centripetal Networks, Inc. (Centripetal's home base; later Portsmouth address) |
Source: patent front pages of US 9,565,213 / US 11,477,237 (applicant "Centripetal Networks, Inc., Reston, VA (US)"), and the 2019-07-09 recorded assignment naming all four as assignors to Centripetal Networks, Inc. (Google Patents legal events).
Original assignee
- Entity named on the issued patent: Centripetal Networks, Inc. (the 2019-07-09 recorded assignment to CENTRIPETAL NETWORKS, INC. predates the Aug. 18, 2020 grant; the company later converted to Centripetal Networks, LLC, 1875 Explorer Street, Suite 900, Reston, VA 20190).
- Products: Yes — Centripetal is a network-security vendor that ships threat-protection / packet-filtering gateway products (marketed under names such as RuleGate / CleanINTERNET-type offerings, per its marketing and litigation record). The claimed "packet security gateway" technology is core to its product line, and the company asserted this patent against a direct competitor.
- Line of business: Commercial network security (packet filtering, threat detection/mitigation, managed security services).
- Current status: Operating — privately held, still prosecuting and granting patents under Centripetal Networks, LLC through 2023–2024 (e.g., US 11,729,144, US 11,824,875), no acquisition or bankruptcy found. Note: claims 1–17 of this specific patent were invalidated in IPR2021-01157 (FWD Mar. 10, 2023, affirmed by the CAFC May 13, 2024), so this patent is no longer assertable even though the company operates.
Assignment timeline
I was not able to retrieve reel/frame numbers or correspondent-of-record names from the USPTO Assignment Center in my searches (the Center's records are not reliably indexable via web search). The two recorded events below are taken from the Google Patents legal-events record for US 10,749,906, which mirrors USPTO assignment data. No further assignments (no security agreements, no transfers to third parties) surfaced in any search. Reel/frame: not retrievable in this analysis — verify at https://assignmentcenter.uspto.gov/ (patent number 10749906).
Execution date not shown / recorded 2019-07-09 — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest ("ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
- Assignor: David K. Ahn, Sean Moore, Steven Rogers, Peter P. Geremia (the four inventors)
- Assignee: Centripetal Networks, Inc.
- Correspondent: not retrieved (cannot assess recurrence)
- Context: Standard employee-inventor assignment into the operating company, recorded just after the June 21, 2019 continuation filing that matured into this patent. This is the normal assignment-to-original-assignee step, not a transfer to an outside party.
Effective 2022-12-30 / recorded 2023-01-20 — Reel/frame not retrieved
- Conveyance: Change of Name (confirmed by PTAB IPR2022-00182 "Modification of Notice of Real Party in Interest," filed Jan. 19, 2023, stating the RPI changed "due to a change of corporate name on December 30, 2022" from Centripetal Networks, Inc. to Centripetal Networks, LLC, same address)
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: not retrieved (cannot assess recurrence)
- Context: Corporate conversion only — same entity, same management, no change in ownership, no transfer to a shell or third party.
No other recorded assignments exist for this patent in the sources I could reach. The absence of any transfer to a licensing entity, lender, or aggregator is itself the key finding: the patent stayed with the operating company from inventors → Inc. → LLC.
Timeline diagram
timeline
title Ownership of US 10749906
2014 : Filed by Centripetal Networks Inc
2019 : Inventors assign rights to company
2020 : Patent issued
2021 : First suit filed vs Palo Alto
2023 : Corporate name change to LLC
: IPR invalidates claims 1 to 17
2024 : CAFC affirms the IPR decision
NPE / troll-pattern signals
Shell-entity transfer — not present. The only post-issuance event is a Change of Name (recorded 2023-01-20) from Centripetal Networks, Inc. to Centripetal Networks, LLC at the same Reston, VA address — a corporate conversion of the operating company, not a transfer to a licensing-only LLC. No "IP Holdings / Licensing / Ventures" entity, no registered-agent address, no single-purpose LLC appears anywhere in the chain.
Known asserter in the chain — not present. Neither Centripetal Networks, Inc. nor Centripetal Networks, LLC appears on public NPE lists (Acacia, Marathon, Intellectual Ventures, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Round Rock, Spangenberg entities, etc.). Unified Patents' own patent page lists "Centripetal Networks Inc" as original assignee and "Centripetal Networks LLC" as current assignee — an operating vendor, not a flagged NPE.
Repeat correspondent across the chain — unclear. I could not retrieve the correspondent-of-record names from USPTO Assignment Center records. The prosecution firm on the family is Banner & Witcoff, Ltd. (a mainstream large firm, per US 11,477,237 front page), which is not an NPE-correspondent tell. No recurrence evidence available; flagging as unverifiable rather than a finding.
Cascading transfers — not present. Exactly two recorded events, 3.5 years apart, the second being a name change of the same entity. No chained LLCs, no rapid successive assignments.
Pre-litigation transfer — not present. The last substantive recorded event (inventor assignment, recorded 2019-07-09) predates the first suit naming this patent (2:21-cv-00137, filed 2021-03-12) by ~20 months, and the name change (recorded 2023-01-20) came nearly two years after the suit was filed. Nothing was transferred to set up venue or standing for the assertion.
Bankruptcy fire-sale — not present. Centripetal Networks has not filed Chapter 7/11; no trustee or bankruptcy-court sale appears in the record.
Privateering — not present. Centripetal asserted the patent on its own behalf in 2:21-cv-00137 against Palo Alto Networks — a direct competitor in network security — with no operating-company-behind-the-curtain arrangement surfaced in any SEC, EFF, or Patent Progress source I found.
Defensive aggregator (anti-NPE) — not present. The chain terminates at Centripetal Networks, LLC (operating company). No RPX, AST, LOT, Unified Patents, or OIN involvement in ownership.
Verdict
Operating-company assertion.
The patent never left the hands of its developer: inventors → Centripetal Networks, Inc. (recorded 2019-07-09) → Centripetal Networks, LLC via name change only (recorded 2023-01-20), with no shell entity, no NPE, no lender security interest, and no aggregator anywhere in the chain. Centripetal is a shipping network-security vendor that asserted this patent against a direct competitor (Palo Alto Networks, E.D. Va. 2:21-cv-00137, filed 2021-03-12), which is the textbook operating-company pattern; the sole unusual feature is not ownership but outcome — the patent's claims were invalidated in IPR2021-01157 (FWD Mar. 10, 2023; affirmed May 13, 2024). Reel/frame and correspondent verification is pending against the USPTO Assignment Center at https://assignmentcenter.uspto.gov/ (search patent 10749906).
Generated 8/30/2026, 12:47:14 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
Prior Art Analysis — US Patent 10,749,906 B2
Scope note: I searched the USPTO/Google Patents records, the Unified Patents patent-art database (which indexes 299 "Patent Art" items for this patent), and the PTAB record for IPR2021-01157 (Palo Alto Networks v. Centripetal Networks, the proceeding that challenged claims 1–17 of 10,749,906). The PTAB's March 10, 2023 Final Written Decision (Paper 36) held all challenged claims (1–17) unpatentable, and that decision was affirmed by the Federal Circuit (Appeal No. 23-1730, judgment May 13, 2024). The references listed below are the most relevant because they either (a) appear in the patent's citation record, or (b) were the prior-art exhibits actually relied on in the IPR that invalidated claims 1–17. Where I could not verify a detail (e.g., exact claim mapping, or the title of an IPR exhibit), I flag it explicitly rather than guessing.
1. Prior art actually used in IPR2021-01157 (highest relevance — invalidated claims 1–17)
These are the petitioner's (Palo Alto Networks') prior-art exhibits from the IPR docket. The PTAB instituted on these grounds and ultimately invalidated all challenged claims (1–17). The FWD grounds were obviousness (35 U.S.C. § 103) rather than pure anticipation, so for each reference I note below where a single-reference § 102 anticipation case would be plausible versus where the reference was used in a combination.
| Ref. / Exhibit | Citation | Date | Brief description | Claims potentially affected |
|---|---|---|---|---|
| US 9,565,213 B2 (Ex. 1007) | Rogers et al., "Methods and systems for protecting a secured network," Centripetal Networks, Inc. | Filed Apr. 16, 2014; issued Feb. 7, 2017 | The parent patent of 10,749,906 (same title, inventors, and specification). Discloses a security policy management server that pushes dynamic security policies to packet security gateways that perform packet transformation functions (filtering, forwarding, dropping, routing to monitors) on a packet-by-packet basis. | Claims 1–17. This is the closest art because it shares the entire written description; the challenged claims were added to distinguish over the family (e.g., the multiple-malicious-host-tracker-service, correlation, and feed-indication limitations). A § 102 anticipation case would fail only if those added limitations are absent — which is exactly why the PTAB analyzed it as an obviousness ground with the references below rather than a single-reference anticipation. |
| US 9,560,077 B1 (Ex. 1005) | Rogers et al., related Centripetal family patent (same title/specification family) | Priority 2014-04-16 (family) | Another member of the same "protecting a secured network" family; discloses policy-driven packet filtering at network boundaries with dynamic rules from a management server. | Claims 1–17 (used as a primary reference in the IPR combination). |
| US 9,137,205 B1 (Ex. 1006) | Rogers et al., related Centripetal family patent | Priority 2014 (family) | Family member disclosing dynamic security policies communicated to packet security gateways, with rules specifying packet criteria and transformation functions (e.g., forwarding/dropping/queuing). | Claims 1–17 (used as a primary reference in the IPR combination). |
| US 2008/0229415 A1 (Ex. 1008) | Kapoor et al. | Published Sept. 25, 2008 | Describes a networked security architecture in which policies/rules are provisioned and updated across distributed enforcement points based on aggregated/feed-based threat information. I could not verify the exact title from my sources; it is confirmed only as the "Kapoor" reference in the IPR exhibit list. | Claims 1–17, particularly the limitations reciting automatic creation/alteration of rules based on malicious-traffic information from multiple sources/feeds (independent claims 1, 9, 17, 25). |
| US 7,084,760 B1 (Ex. 1009) | Himberger et al. | Filed ~2001–2002; issued Aug. 1, 2006 | Early firewall/gateway patent describing policy-based packet filtering at a network boundary with centrally managed rules (I could not verify the exact title from my sources; confirmed only as "Himberger" in the IPR exhibit list). | Claims 1–17; likely cited for the packet-security-gateway + policy-filtering framework. |
| US 2003/0214913 A1 (Ex. 1026) | Kan | Published Nov. 20, 2003 | Cited in the IPR combination; I could not verify the title or content with confidence from available sources. | Claims 1–17 (combination reference). |
| Granidt et al., "Towards Gigabit Rate Network Intrusion Detection" (Ex. 1027) | Academic paper | Late 1990s (paper) | Describes high-throughput network intrusion detection using packet classification to filter substantially all traffic at line rate — the "scalable high-resolution filtering" concept the specification discusses. | Claims 1–17, likely cited for per-packet content-based inspection/filtering and high-speed rule application. |
| Navrikuth, "A Dynamic Firewall Architecture" (Ex. 1028) | Academic paper | Pre-2004 (paper) | Describes dynamically reconfigurable firewall policies — likely cited for dynamically updated security policy rules. | Claims 1–17 (combination reference). |
| US 2015/0215329 A1 (Ex. 1029) | Singla | Published Aug. 6, 2015 | Cyber-threat defense publication; I could not verify the exact title with confidence. | Claims 1–17 (combination reference, likely for threat-intelligence/feed-based rule generation). |
| US 2004/0123220 A1 (Ex. 1030) | Johnson | Published June 24, 2004 | Cited in the IPR combination; I could not verify the title with confidence. | Claims 1–17 (combination reference). |
2. Patent-citation record (references cited on/against the '906 patent per Unified Patents "Patent Art")
The Unified Patents database lists 299 art items associated with 10,749,906. The most relevant of those I could capture (with dates as listed in that database) are:
| Citation | Priority/Publication date | Brief description | Potential § 102 relevance |
|---|---|---|---|
| US 9,686,193 B2 — "Filtering Network Data Transfers" (Centripetal Networks) | Priority 2013-03-11 | Rule-based filtering of network data transfers; same assignee's earlier filtering architecture. | Independent claims 1, 9, 17, 25 (packet filtering per rules) and dependent claims on filtering criteria/actions. |
| US 7,814,546 B1 — "Method and System for Integrated Computer Networking Attack Attribution" (Verizon) | Priority 2004-03-18 | Correlating attack information to attribute network attacks. | Claims reciting correlation of malicious-traffic information from multiple sources (independent claims). |
| US 2014/0082730 A1 — "System and Method for Correlating Historical Attacks with Diverse Indicators to Generate Indicator Profiles for Detecting and Predicting Future Network Attacks" (KDDI) | Filed 2012-09-17 | Correlating diverse threat indicators to generate profiles for future attack detection — highly relevant to the "correlation between portions of malicious-traffic information" limitation. | Independent claims 1, 9, 17, 25 (correlation/feed limitations). |
| US 2015/0373043 A1 — "Collaborative and Adaptive Threat Intelligence for Computer Security" (HPE) | Filed 2014-06-22 | Aggregating threat intelligence from multiple feeds to update security rules — relevant to the multiple-malicious-host-tracker-services limitation. | Independent claims 1, 9, 17, 25 (multi-feed rule generation). |
| US 2016/0191558 A1 — "Accelerated Threat Mitigation System" (Bricata) | Filed 2014-12-22 | High-speed threat detection/mitigation with rule-based packet processing. | Independent claims 1, 9, 17, 25 (content-based per-packet filtering). |
| US 2006/0070122 A1 — "Method and Apparatus for a Distributed Firewall" (listed owner: RPX Corp) | Priority 1999-06-29 | Distributed firewall architecture with centrally managed policy enforcement points — relevant to the "security policy management server + packet security gateways" architecture. | Claims 1, 9, 17, 25 (system/method architecture). |
| US 7,913,303 B1 — "Method and System for Dynamically Protecting a Computer System from Attack" (listed owner: Alibaba Group) | Priority 2003-01-20 | Dynamically updating protective rules in response to attack information. | Independent claims (dynamic policy updates) and dependent claims on rule alteration. |
| US 2007/0147380 A1 — "Systems and Methods for Implementing Protocol-aware Network Firewall" | Filed 2005-11-07 | Application/protocol-aware firewall filtering — relevant to application-layer (e.g., HTTP/SIP) header criteria in dependent claims. | Dependent claims reciting application-layer packet-header criteria (e.g., SIP URI, HTTP GET/PUT). |
| US 2002/0049899 A1 — "Network Attached Device with Dedicated Firewall Security" (Firenet) | Priority 1998-08-31 | Dedicated firewall appliance at a network boundary. | Claims 1, 9, 17, 25 (gateway/boundary filtering). |
| US 7,954,143 B2 — "…Dynamically Assigning Users to Firewall Policy Groups" (AT&T) | Filed 2006-11-12 | Dynamic assignment of users to firewall policy groups — relevant to dynamically altered policies. | Independent claims / dependent claims on policy alteration. |
| US 2008/0235755 A1 — "Firewall Propagation" (DigiCert) | Filed 2007-03-21 | Propagating firewall policy changes across enforcement points — relevant to management-server-to-gateway policy distribution. | Claims 1, 9, 17, 25 (policy distribution). |
| US 2005/0010765 A1 — "Method and Framework for Integrating a Plurality of Network Policies" | Filed 2003-06-05 | Integrating/merging multiple network policies — relevant to correlating/merging rules from multiple feeds. | Independent claims (multi-source rule correlation). |
| US 2014/0201123 A1 — "Rule Swapping in a Packet Network" | Filed 2013-01-10 | Dynamically swapping/rules in a packet network — relevant to dynamic policy updates. | Independent claims / dependent claims on dynamic policy receipt. |
| US 2002/0152209 A1 — "Method, System and Computer Program Product for Classifying Packet Flows with a Bit Mask" | Filed 2001-01-25 | High-speed packet flow classification — relevant to scalable per-packet filtering. | Claims 1, 9, 17, 25 (per-packet content-based filtering). |
| WO 2012/146265 A1 — "Correlation of Media Plane and Signaling Plane of Media Services in a Packet-switched Network" (Voipfuture) | Filed 2011-04-27 | Correlating SIP signaling with media — relevant to VoIP/SIP-based rule creation (VoIP firewall service). | Dependent claims reciting VoIP/SIP session-based rules and SIP URI parameters. |
| US 2004/0151155 A1 — "Method for Activating a Connection in a Communications System… and Packet Filter" (Nokia) | Filed 2001-03-13 | Packet filter for connection activation in a communications system. | Dependent claims on filtering criteria / connection-based rules. |
| US 2006/0104202 A1 — "Rule Creation for Computer Application Screening; Application Error Testing" (Telus) | Filed 2002-10-01 | Automated rule creation — relevant to "automatically created or altered" rules. | Independent claims (automatic rule creation/alteration). |
| US 2005/0114704 A1 — "Method for Indexing a Plurality of Policy Filters" | Filed 2003-11-25 | Indexing multiple policy filters for efficient lookup — relevant to scalable high-resolution filtering. | Claims 1, 9, 17, 25 (efficient per-packet rule application). |
| US 2016/0285706 A1 — "In-fabric Traffic Analysis" (Gigamon) | Filed 2015-03-24 | Traffic analysis in network fabrics — relevant to monitoring/logging services. | Dependent claims on packet-digest logging and monitoring-device routing. |
| US 2009/0240698 A1 — "Computing Environment Platform" | Filed 2008-03-19 | Platform for policy-based network services. | Independent claims (policy-based processing platform). |
| US 2002/0038339 A1 — "Systems and Methods for Packet Distribution" (Spontaneous Networks) | Filed 2000-09-07 | Packet distribution/switching — relevant to routing/queueing transformation functions. | Dependent claims on queueing/routing transformation functions. |
| US 2010/0107240 A1 — "Network Location Determination for Direct Access Networks" (Microsoft) | Filed 2008-10-23 | Network location determination — of lesser relevance; appears in the citation record but is not central. | Marginal. |
| US 2014/0215574 A1 — "Accessing Objects in Hosted Storage" (Google) | Filed 2013-01-30 | Storage object access — peripheral to the security claims. | Marginal. |
3. Which claims each reference most plausibly anticipates (§ 102)
A few important caveats before the mapping:
- I could not pull the verbatim text of claims 1–17 of the '906 patent in my searches (the claims page was not reproduced in the provided text or surfaced verbatim). The claim architecture below is based on (a) the family member US 11,012,474 (a continuation-in-part sharing this claim architecture) and (b) the PTAB record, which confirms claims 1–17 were challenged and invalidated. The claim-by-claim mapping is therefore medium-high confidence on substance, not verbatim-verified.
- The IPR invalidated claims 1–17 on obviousness (§ 103) grounds using combinations (e.g., Kapoor, Himberger, the Centripetal family patents, and the academic references), not on single-reference § 102 anticipation. So for the question "which claims does each reference potentially anticipate under § 102," the honest answer is: no single reference in the record was found by the PTAB to anticipate; the invalidation rested on combinations.
- The independent claims (1, 9, 17, 25) center on: (i) a packet security gateway; (ii) a dynamic security policy received from an external security policy management server; (iii) rules automatically created/altered based on malicious-traffic information from multiple malicious host tracker services, at least two managed by different organizations; (iv) rules added/removed/altered based on a correlation between portions of that information; (v) each matching rule including a packet-matching criterion, a transformation function, and a feed indication; and (vi) per-packet, content-based filtering. Dependent claims add: network-address criteria; network-protection transformation functions; differential forwarding queues; network-layer-transparent operation; LAN-switch implementation; and a packet-digest logging function.
With that framework, the most plausible single-reference § 102 anticipation candidates for the independent claims are:
- US 2014/0082730 A1 (KDDI) and US 2015/0373043 A1 (HPE) — the only cited references that squarely address correlating malicious-threat information from diverse/multiple feeds to generate security rules. These are the closest to the "multiple malicious host tracker services + correlation + feed indication" limitations of claims 1, 9, 17, and 25.
- US 7,814,546 B1 (Verizon) — correlating attack information for attribution; relevant to the correlation limitation.
- US 9,686,193 B2, US 9,137,205 B1, US 9,560,077 B1, US 9,565,213 B2 (Centripetal family) — disclose the gateway + management-server + dynamic-policy architecture but not (as issued, per the PTAB's analysis) the multi-tracker-service correlation/feed-indication limitations; hence the PTAB treated them as primary references in combination rather than as standalone anticipations.
- Kapoor (US 2008/0229415 A1) and Himberger (US 7,084,760 B1) — were the petitioner's principal non-family references in the IPR; they map to the management-server/gateway architecture and rule-update limitations, but again the PTAB's holding was one of obviousness over combinations.
- US 2005/0010765 A1 and US 2014/0201123 A1 — "integrating a plurality of network policies" / "rule swapping" map to the dynamic-policy and multi-rule correlation limitations.
- Dependent claims (2–8, 10–16, 17's sub-limitations) — the logging/monitoring limitations map best to US 2016/0285706 A1 (Gigamon); the SIP/VoIP limitations map to WO 2012/146265 A1 (Voipfuture) and US 2007/0147380 A1 (protocol-aware firewall); the queueing/rate limitations map to US 2002/0038339 A1 and the DSCP/queueing disclosure in the Centripetal family; the network-layer-transparent operation and LAN-switch limitations are best covered by the Centripetal family patents themselves and US 2006/0070122 A1 (distributed firewall).
4. Bottom line
- The most relevant prior art for US 10,749,906 is the prior-art set from IPR2021-01157 — principally Kapoor (US 2008/0229415 A1), Himberger (US 7,084,760 B1), the Centripetal family patents (US 9,565,213, US 9,560,077, US 9,137,205), and the Granidt and Navrikuth academic references — which the PTAB used to hold claims 1–17 unpatentable (affirmed by the Federal Circuit in Appeal No. 23-1730).
- Strictly speaking, no reference in the record was found to anticipate under § 102; the invalidation was on § 103 obviousness over combinations. If you need a single-reference § 102 argument, the strongest candidates from the citation record are the multi-feed correlation references (KDDI '730, HPE '043, Verizon '546), but I cannot confirm any of them discloses every limitation of claims 1, 9, 17, or 25 without seeing the full FWD claim chart.
- Unverified items (stated explicitly): the exact titles of the Kapoor, Himberger, Kan, Singla, and Johnson IPR exhibits; the verbatim text of claims 1–17 of the '906 patent; and the complete 299-item citation list from Unified Patents (I captured the most relevant subset). To close these gaps, pull (1) the PTAB FWD for IPR2021-01157 (Paper 36) and (2) the claims page of US 10,749,906 from USPTO Patent Center.
Generated 8/30/2026, 12:47:37 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll verify the IPR grounds and the key references before building the § 103 analysis, then construct the combinations.
Good — that confirms two of the flagged-unknown reference titles and surfaces a 2026 CAFC decision worth noting. Let me verify the secondary threat-intelligence references I'll use in the combinations.
One structural issue needs resolving before the § 103 analysis: the prior sections are internally inconsistent about whether the '906 has 17 claims or ~33. Let me check.
I have what I need. Before the analysis proper, two housekeeping corrections and two flagged contradictions.
Obviousness Analysis — US 10,749,906 B2 under 35 U.S.C. § 103
Prepared: April 26, 2026 · Sources: the Prior Art, PTAB-challenges, Litigation, and Strategic-summary sections of this page, plus live verification searches run this session.
0. Threshold matters before any § 103 analysis
0.1 New verifications this session (updating the Prior Art section's "unverified" flags)
| Item | Prior Art section status | Now verified |
|---|---|---|
| Himberger US 7,084,760 B1 | "could not verify the exact title" | "System, method, and program product for managing an intrusion detection system" — Kevin D. Himberger, Clark Debs Jeffries, David M. McMillen; issued 2006‑08‑01 (Patent Leaderboard / IBM inventor record) |
| Kapoor US 2008/0229415 A1 | "could not verify the exact title" | "Systems and methods for processing data flows" — Harsh Kapoor; filed 2005‑07‑01, published 2008‑09‑18; sibling publication US 2008/0133517 discloses the flow processing facility 102, security policy 414, management server 228, alert 442, and quarantine/drop actions (FreePatentsOnline; Google Patents citation record) |
| KDDI US 2014/0082730 A1 | listed, title inferred | Confirmed title; granted as US 9,386,030 B2 (2016‑07‑05); priority 2012‑09‑18; assignees KDDI Corp. and TT Government Solutions / Vencore Labs |
| HPE US 2015/0373043 A1 | listed, title inferred | Confirmed: "Collaborative and Adaptive Threat Intelligence for Computer Security" (Wang, Shen, Palkar, Ramachandran); filed 2015‑06‑18; granted as US 10,469,514 B2 (2019‑11‑05); express disclosure of external threat feeds 285 — "blacklisted domains, blacklisted IP addresses, blacklisted filenames and/or file hashes; as well as metadata related to that blacklisted data (e.g., threat types, botnet types, first‑…)" — feeding a centralized controller trained on data from multiple customer networks |
These are usable, title-level verified references now.
0.2 Two contradictions in the previously generated sections (flagged per instructions)
(a) IPR outcome — resolved, but the sections disagree. The Litigation summary said it "cannot confirm with confidence whether all challenged claims were invalidated — I will not speculate." The PTAB challenges, Prior Art, and Strategic summary sections all state affirmatively that all of claims 1–17 were held unpatentable (FWD 2023‑03‑10) and affirmed (CAFC No. 23‑1730, judgment 2024‑05‑13). I adopt the later, more specific statements as controlling. The Litigation summary's hedged sentence is superseded.
(b) Claim-set size — UNRESOLVED, and it matters. The Patent summary section reconstructs four independent claims (1, 9, 17, 25) with dependents running to at least claim 33. The PTAB challenges section says claims 1–17 were "the entire claim set" with "zero claims sustained, zero claims untested." These cannot both be true. Either:
- the '906 has exactly 17 claims (probable structure: independent 1 = method, 9 = apparatus/gateway, 17 = computer-readable media, with dependents 2–8 and 10–16), in which case all claims are canceled; or
- the '906 has ≥ 33 claims and the "claim 25 system" architecture came from the CIP family member US 11,012,474, in which case claims 18–33 were never challenged and are not canceled (they would still be exposed to the same art, but they are not adjudicated dead).
I could not resolve this from the provided text (the '906 claims page is absent), and my two attempts to search it this session were cut off by the step limit. Treat the "entire claim set is canceled" statement as unverified for claims numbered above 17. The substantive § 103 analysis below addresses claims 1–17, then addresses the subject matter of the higher-numbered dependents.
0.3 Posture note
Because all challenged claims were held unpatentable and affirmed, the analysis below is not a live freedom-to-operate exercise. It is (i) a reconstruction of the invalidity theory that succeeded, (ii) an audit of whether that theory holds up under a Graham/KSR framing applied from scratch rather than post hoc, and (iii) a template for the family's live continuations — US 10,912,474, US 11,012,474, US 11,412,774, US 12,107,893, US 12,563,103 — which share the specification and face the same art. Recent confirmation that the Federal Circuit keeps treating this family's "rules + per-packet filtering" claims as obvious: Centripetal Networks, LLC v. Keysight Technologies, Inc., No. 24‑1406 (Fed. Cir. Apr. 23, 2026) — affirming obviousness on 18 of 20 claims of US 10,193,917 over Sourcefire alone and Sourcefire + Macaulay, and reversing the Board's two non‑obviousness holdings, i.e., invalidating the remaining two claims too.
1. Legal framework applied
- § 103: A claimed invention is obvious if the differences between it and the prior art are such that the subject matter as a whole would have been obvious to a person having ordinary skill at the time of the invention. The inquiry is the four Graham v. John Deere factors: scope/content of the prior art; differences; level of ordinary skill; and objective evidence of nonobviousness.
- KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007): A combination is obvious where it "is nothing more than the predictable use of prior art elements according to their established functions." The rationale need not be the patent's own stated purpose; "any need or problem known in the field of endeavor at the time of invention and addressed by the patent can provide a reason for combining the elements." Design incentives, market forces, and "common sense" may supply the reason. A finite number of identified, predictable solutions → "obvious to try."
- MPEP § 2143 / § 2144: Enumerate the recognized rationales — (A) combining prior art elements according to known methods to yield predictable results; (B) simple substitution of one known element for another; (C) use of known technique to improve similar devices in the same way; (D) applying a known technique to a known device ready for improvement; (E) "obvious to try"; (F) design incentives/market forces; (G) predictable variation.
- Anticipation vs. obviousness: § 102 requires a single reference disclosing every limitation arranged as claimed. As I noted in the Prior Art section, no reference in the record anticipates — the FWD holdings were § 103 combinations. That matters analytically: each reference is missing something, and the analysis must state what and why a POSITA would supply it.
2. Level of ordinary skill in the art (POSITA)
A POSITA at the 2014–2019 window is someone with a B.S. in electrical engineering, computer engineering, or computer science (or equivalent experience) and about 2–5 years of experience in network security and packet processing, or an M.S. with 1–2 years. That person's working knowledge includes:
- TCP/IP stack, five-tuple/IPv4/IPv6 header fields, DSCP, layers 2–7, HTTP (GET/PUT/POST) and SIP/URI semantics;
- stateful firewall and packet-filter ACL design, rule-ordering/conflict resolution, trie/ACL-compilation and TCAM-based high-speed classification;
- threat-intelligence (CTI) feeds and subscription blocklists — a mature commercial market by 2014 (the '906 specification itself names a "malicious host tracker service 508" that supplies subscription updates);
- centralized policy management/provisioning across distributed enforcement points (firewall management consoles, distributed firewalls);
- inline "bump-in-the-wire" / network-layer-transparent appliance deployment, IPsec, syslog-style logging.
This level of skill is central: the more predictable and mature the art, the easier the § 103 case. Packet filtering was, by 2014, a textbook-predictable engineering discipline — a point the Federal Circuit made repeatedly against this patent family (Centripetal v. Cisco, No. 20‑1635 (Fed. Cir. Mar. 10, 2021), aff'g Sourcefire-based obviousness).
3. The claims as decomposed (work product for the chart)
Because the verbatim '906 claim text was not retrievable in either session, I decompose the independent-claim limitations as reconstructed in the Patent-summary and Prior-Art sections into elements A–G. The chart below uses those letters.
| El. | Limitation (as reconstructed) |
|---|---|
| A | Packet security gateway ("PSG") protecting a network; PSG associated with a security policy management server external to the protected network |
| B | PSG configured to receive a plurality of dynamic security policies from the server over time |
| C | The dynamic policy comprises packet-filtering rules automatically created or altered based on malicious-traffic information received from a plurality of malicious host tracker services |
| D | At least two of the tracker services are managed by different organizations |
| E | Rules added/removed/altered based on a correlation between portions of the malicious-traffic information |
| F | Each matching rule comprises (i) packet-matching criteria, (ii) a packet transformation function, (iii) an indication of a feed managed by one of the tracker services |
| G | Per-packet filtering: inspecting each packet and filtering it based on content determined from that inspection |
| +deps | network-address-based criteria; network-protection transformation functions; differential forwarding queues with different rates; network-layer-transparent operation with an unaddressed link-layer interface + addressed management interface; LAN-switch implementation; packet-digest logging function (subset-of-information records, syslog reformatting, routing to a monitoring device) |
The inventive kernel, such as it is, is C + D + E + F(iii) — the multi-feed, cross-organization, correlated, provenance-tagged rule generation. Elements A, B, F(i), F(ii), and G are admitted prior art on the face of the '906's own specification (see § 4.1).
4. The § 103 grounds
4.1 Preliminary point: the specification is an admission against interest
Three of the limitations are conceded as known in the '906 specification itself, which is usable as applicant-admitted prior art:
- A/B — "Many network protocols route packets dynamically… it may be advantageous to locate a packet security gateway at each boundary between a protected network and an unprotected network," with policies pushed from a management server (¶¶ describing FIG. 1/FIG. 5).
- G — FIG. 2/FIG. 10 describe per-packet filter-then-transform.
- The scalability problem itself — Background: "A significant challenge associated with building a scalable proactive solution is the need to filter substantially all network traffic at a high resolution… the time required to provide high resolution filtering has traditionally been thought to render a proactive solution infeasible." This is the articulated problem statement that KSR says may supply the motivation to combine.
- E's mechanical content — the spec's FIG. 13 material recites exactly the correlation mechanics: deduplicating network addresses, merging overlapping ranges into new ranges, and combining rules from "two or more services." A claim limitation that recites the union/dedupe/merge of address sets is, on this record, a predictable data-processing variation, not an invention.
4.2 Ground 1 — Kapoor + Himberger (+ Kan, Johnson)
References
- Kapoor, US 2008/0229415 A1, "Systems and methods for processing data flows" (filed 2005‑07‑01; pub. 2008‑09‑18).
- Himberger, US 7,084,760 B1, "System, method, and program product for managing an intrusion detection system" (issued 2006‑08‑01).
- Optionally Kan, US 2003/0214913 A1 (pub. 2003‑11‑20) and Johnson, US 2004/0123220 A1 (pub. 2004‑06‑24).
Mapping
| El. | Where disclosed |
|---|---|
| A | Kapoor: flow processing facility 102 enforces security policy 414 at the boundary; management server 228 is external to the protected resources; Himberger: management of an intrusion-detection system from a central manager |
| B | Kapoor: policy 414 is provisioned/updated and the facility "may issue an alert 442 … to a management server 228"; Himberger: central management push/config |
| C | Kapoor: policies updated in response to detected threats; Himberger: IDS rules managed/updated centrally as new threats are identified |
| D | Missing — neither reference expressly divides policy sources among organizations |
| E | Missing in the express "correlate two feeds" sense (Himberger is closer: it manages detection and coordinated blocking measures) |
| F(i) | Kapoor: five-tuple/flow-based criteria; Himberger: IDS rule criteria |
| F(ii) | Kapoor: forward / quarantine / drop all further packets / "directed to a security port for further analysis" |
| F(iii) | Missing |
| G | Kapoor: flows/packets processed and matched against the policy per packet; Himberger: per-event inspection |
Motivation (articulated): Both references are in the identical field (perimeter/flow security enforcement) and address the same problem — applying a centrally managed, updatable rule set to traffic at a boundary. KSR rationale (C)/(D): applying the known technique of centrally provisioned rule enforcement (Himberger) to a known flow-processing enforcement point with a rich policy engine (Kapoor) is the use of a known technique to improve a similar device in the same way, with a predictable result. Rationale (F): competitive/market pressure to update perimeter rules faster than manual console edits.
Weakness: Ground 1 alone does not reach C/D/E/F(iii). It is a base-architecture ground, not an invalidity ground for the independent claims.
4.3 Ground 2 — Kapoor + Himberger + KDDI '730 (correlation)
Added reference: US 2014/0082730 A1 / US 9,386,030 B2, KDDI Corp. + TT Government Solutions, "System and method for correlating historical attacks with diverse indicators to generate indicator profiles for detecting and predicting future network attacks" (priority 2012‑09‑18; published 2014‑03‑20).
What it supplies that Ground 1 lacks: literally the word correlate. KDDI discloses "correlating historical attacks with diverse indicators to generate indicator profiles and decision rules"; a supervised-learning engine that "automatically learn[s] a decision rule which examines the temporal patterns in the coded values of the set of indicators"; and — critically for element E — rules that "automatically evolve in response to new attacks as the system updates its rules periodically by analyzing new data and the feedback signal about attacks in that data." KDDI further states the output is for "filtering devices deployable at gateways, routers, home computers, etc." and that counter-measures are taken based on which indicator drove the decision.
| El. | KDDI contribution |
|---|---|
| C | Automatic generation/evolution of rules from historical attack data and feedback |
| E | Correlation of diverse indicators into profiles/decision rules |
| D | Partial — KDDI's inventors/assignees span two organizations (KDDI + TT Government Solutions), and its data sources are heterogeneous, but "different organizations" as a claim limitation still needs a separate rationale (see § 5.4) |
| F(iii) | Partial — the "explanation" of which indicator drove a decision is a provenance field in substance |
Motivation: KSR rationale (A) — combining Kapoor's enforcement architecture with KDDI's learned, auto-evolving rule generation yields the predictable result of a boundary filter whose rules track new attacks without human re-authoring. Both references address DDoS/attack detection and mitigation (same problem, same field). Rationale (G) — the further step of tagging each generated rule with the indicator/feed that produced it is a predictable variation, because KDDI already computes and exposes which indicator was responsible for the decision; making that identifier a field of the rule is a bookkeeping choice with no change in function.
4.4 Ground 3 — Kapoor + Himberger + HPE '043 (multi-source feeds from different organizations)
Added reference: US 2015/0373043 A1 / US 10,469,514 B2, Wang et al., HP, "Collaborative and Adaptive Threat Intelligence for Computer Security" (filed 2015‑06‑18).
What it supplies: (a) external, multi‑source threat feeds — "external threat feeds 285 may include blacklisted domains, blacklisted IP addresses, blacklisted filenames and/or file hashes; as well as metadata related to that blacklisted data (e.g., threat types, botnet types, first‑…)"; (b) a centralized controller aggregating data collected on multiple customer networks — i.e., sources under different organizations' control — and distributing result data back to local enforcement; (c) feed/indicator metadata travelling with the indicator, which is the substance of F(iii).
| El. | HPE '043 contribution |
|---|---|
| C | Rules generated/adjusted from aggregated malicious-traffic information |
| D | Multiple customer networks / multiple feeds → inherently different organizations |
| E | The controller's aggregation of multiple networks' data is a correlation operation |
| F(iii) | Metadata associated with each blacklist entry (threat type, botnet type, first-seen) = an indication of the feed/source for the rule |
Motivation: Rationale (F)/(E): the entire commercial premise of collaborative threat intelligence (and HP's own 2013 product announcement of "HP Threat Central," a "community-sourced security intelligence platform" that "automates open sharing of security data") is that no single organization sees enough attacks alone. Once an enterprise subscribes to multiple CTI feeds (which the '906 specification itself assumes — "updates (e.g. as part of a subscription) from malicious host tracker service 508"), it is a matter of engineering necessity, not invention, to (i) merge them, (ii) de-duplicate and reconcile overlaps, and (iii) retain per-rule provenance so that when a feed expires or is retracted the correct rules can be withdrawn. Rationale (D) — applying a known technique (feed ingestion + metadata) to a known device (a policy-driven packet filter) ready for improvement.
4.5 Ground 4 — the four-reference combination (closest to the independent claims)
Kapoor + Himberger + KDDI + HPE '043.
This is the combination that, element-for-element, comes closest to fully meeting reconstructed independent claim 1 (and, mutatis mutandis, the apparatus, CRM, and system claims that recite the same functional set):
| El. | Kapoor | Himberger | KDDI '730 | HPE '043 |
|---|---|---|---|---|
| A PSG + external management server | ✓ | ✓ | ||
| B plural dynamic policies pushed | ✓ | ✓ | ||
| C rules auto-created/altered from malicious-traffic info | ✓ (partial) | ✓ | ✓ | |
| D ≥2 tracker services, different organizations | partial | ✓ | ||
| E correlation between portions | ✓ | ✓ | ||
| F(i) matching criteria | ✓ | ✓ | ✓ | ✓ |
| F(ii) transformation function | ✓ | ✓ | ✓ | ✓ |
| F(iii) feed indication per rule | partial | ✓ | ||
| G per-packet content-based filtering | ✓ | ✓ |
Aggregate motivation for the four-way combination: Every reference sits in the same field (network traffic security enforcement) and is reasonably pertinent to the particular problem the '906 specification identifies — scalable, high-resolution, proactive filtering. The combination is the predictable assembly of (1) a boundary enforcement point with a centrally provisioned rule set, (2) automatic rule generation from attack data, and (3) multi-source, provenance-tagged threat feeds. KSR: "the combination of familiar elements according to known methods is likely to be obvious when it does no more than yield predictable results." There is no teaching away, no change in the principle of operation of any reference, and no unexpected result alleged or shown.
4.6 Ground 5 — Centripetal's own family patents as art (requires a priority ruling — see § 4.7)
The Prior Art section reports that PAN used US 9,565,213 B2, US 9,560,077 B1, and US 9,137,205 B1 (all Rogers et al., same family, same specification) as primary references against the '906's claims. Read as art, they supply A, B, F(i), F(ii), and G verbatim — plus, notably, the enqueueing/DSCP differentiated-queue and VoIP-firewall/SIP-URI dependent-claim subject matter. The obviousness theory is then: the family discloses the entire gateway-plus-management-server architecture and every transformation function; the only added limitations are multi-feed correlation and provenance-tagging, supplied by KDDI and HPE '043 for the reasons in §§ 4.3–4.5.
A POSITA would combine them because the '906's own specification frames the multi-service correlation as an improvement to the already-disclosed system ("Security policy management server 120 may be configured to add, remove, and/or alter one or more dynamic security policies… based on information received from two or more devices"; "The updates from the two or more services may be correlated"). Using the patentee's own disclosure as the roadmap to the improvement is the paradigm case for KSR rationale (D).
4.7 ⚠️ The timing gate that decides the whole case (flagged as inference)
This is the single most important analytical point, and I could not verify it directly (the FWD text was not retrievable this session).
If the '906 is a straight continuation of 16/158,868 → 15/414,117 (a divisional of 14/253,992), its specification contains no new matter relative to the 2014‑04‑16 filing, and any claim supported by that disclosure is entitled to April 16, 2014. Under that date:
- Kapoor '415 (2008) ✓ art
- Himberger '760 (2006) ✓ art
- KDDI '730 (2014‑03‑20) ✓ art, by 27 days
- Granidt (1990s) ✓, Navrikuth (pre‑2004) ✓, Verizon '546 ✓, US 2006/0070122 ✓, US 2002/0038339 ✓, WO 2012/146265 ✓, Telus '202 ✓, US 2005/0114704 ✓, US 2014/0201123 ✓ (effectively filed 2013‑01‑10)
- ❌ HPE '043 (pub. 2015‑12‑31) — not prior art
- ❌ Singla '329 (pub. 2015‑08‑06) — not prior art
- ❌ Gigamon '706 (pub. 2016‑09‑29) — not prior art
- ❌ Bricata '558 (pub. 2016‑06‑30) — not prior art
- ❌ '213 / '077 / '205 — same 2014 priority, therefore not § 102(a)(2) art
- ❌ KDDI's own US 9,386,030 grant (2016) — but its 2014‑03‑20 publication remains art
So either the Board (i) invalidated claims 1–17 using only pre‑2014‑04‑16 art, or (ii) found the challenged claims not entitled to the 2014 priority date, moving the effective filing date to 2018‑10‑12 or 2019‑06‑21 (which is what makes HPE '043, Singla, and Centripetal's own family patents available simultaneously). Given that PAN's exhibit list includes both the family patents and the 2015 publications, hypothesis (ii) — a successful written-description/priority attack on the challenged claims — is the far more probable explanation, and it is the mechanism by which a continuation gets invalidated over its own ancestors. Label: inference, not verified.
Consequence for anyone re-running this analysis: the § 103 case is conditional on the priority holding. Build it in two alternative postures:
- Posture 1 (2014 priority): Ground 4 minus HPE '043 — i.e., Kapoor + Himberger + KDDI '730 + the family patents as § 102(a)(1) art only if published before 2014 — which is thinner on element D ("different organizations"). Element D would then rest on general-market evidence (multiple competing CTI vendors existing before 2014) plus KDDI's cross-organizational authorship.
- Posture 2 (later effective filing date): the full Kapoor + Himberger + KDDI + HPE '043 (+ Centripetal family) combination, which is materially stronger and is the ground I would expect to find in the FWD.
4.8 Ground 6 — the scalability/high-throughput strand (supports motivation, not element coverage)
Granidt et al., "Towards Gigabit Rate Network Intrusion Detection" and Navrikuth, "A Dynamic Firewall Architecture" (both pre‑2004, both in the IPR exhibit list), together with the firewall-optimization literature already cited in the family's IDS (Fulp's trie-based policy representations, Al-Shaer's firewall policy modeling, Warkhede's fast packet classification, RFC 2474 DSCP definitions):
These references defeat any argument that "filter substantially all traffic at high resolution" was an unsolved problem requiring invention. They were available long before 2014 and teach line-rate classification and dynamic rule reconfiguration. Their role in the § 103 case is to close the "the problem was thought infeasible" argument that the '906's Background advances — and the Background's own concession that such filtering "has traditionally been thought to render a proactive solution infeasible" is an admission that the goal was known and pursued.
4.9 Dependent-claim subject matter (and claims 18–33, if they exist)
| Dependent subject matter | § 103 mapping |
|---|---|
| Network-address criteria; network-protection transformation functions | Kapoor (quarantine/drop/redirect), Himberger, family patents |
| Differential forwarding queues with different rates | The family patents themselves (enqueueing service, DSCP selector, "first forwarding queue … serviced at a higher forwarding rate"); QoS/priority-queue design is old and predictable |
| Network-layer-transparent inline operation; unaddressed link-layer interface; addressed + app-secured management interface | US 2006/0070122 A1 (distributed firewall) plus the ordinary "bump-in-the-wire" appliance deployment of Kapoor's facility; abstract/functional claim language ("operate in a network layer transparent manner") is the classic statement of an intended result, and the mechanism (MAC-level forwarding + separate management plane) was conventional |
| LAN-switch implementation | Design choice / obvious placement: the '906's own FIG. 9 describes embedding or associating the gateway with a LAN switch, and US 2006/0070122 teaches enforcement at an internal switch point |
| Packet-digest logging (identify subset of packet info, generate records, reformat per a logging standard such as syslog, forward to monitoring device) | US 2016/0285706 A1 (Gigamon), "In-fabric Traffic Analysis" — only if the later filing date is established (pub. 2016‑09‑29). If 2014 priority holds, the same subject matter is met by the '906 specification's own description (which recites syslog reformatting and a field list) combined with ordinary firewall logging (Himberger; the Hughes/Abraham-type "auditing — send a copy of the PDU to a third party" art in the record) |
| SIP-URI / VoIP-session-based rules | WO 2012/146265 A1 (Voipfuture) — correlating the signaling and media planes of packet-switched media services (filed 2011‑04‑27); plus US 2007/0147380 A1 (protocol-aware firewall) for application-layer criteria generally. The '906's own multi-dimensional routing/monitoring disclosure supplies the rest |
| Rule merging / removal of overlapping ranges | US 2005/0010765 A1 ("integrating a plurality of network policies") and US 2014/0201123 A1 ("rule swapping in a packet network"); also the family's own disclosure of merging rules with overlapping criteria |
Note: because the '906's dialog around claims 18–33 is unresolved (§ 0.2b), the correct framing is: if those claims exist, they were never challenged, but every one of them is drafted as a mechanical add-on to the independent claim's framework — and the add-ons are individually old. Their survival would be procedural, not substantive.
5. The motivation-to-combine argument, consolidated
A defendant or examiner should rest on five independent rationales, any one of which suffices:
5.1 The problem was identified in the art and in the patent itself. The '906's Background concedes the goal (scalable, high-resolution, proactive filtering of substantially all traffic). KSR: a known problem addressed by the patent supplies the reason to combine.
5.2 Predictable assembly of known elements. Kapoor/Himberger give the enforcement point + central provisioning; KDDI gives learned, auto-evolving rules; HPE '043 gives multi-source, metadata-tagged feeds. Each element performs exactly its established function; the aggregate is the "predictable use of prior art elements according to their established functions."
5.3 Market forces and competitive pressure. The CTI-feed subscription market existed and was consolidating (the '906 specification assumes a subscription "malicious host tracker service"); HP publicly launched a community threat-intelligence platform in September 2013. Enterprises facing DDoS attacks had every incentive to consume multiple feeds — and different organizations is a fact about the market, not an inventive contribution.
5.4 Engineering necessity for per-rule provenance (element F(iii)). Once multiple feeds are merged into one rule set, retaining an indication of which feed supplied each rule is required for feed lifecycle management (expiry, retraction, false-positive rollback, per-vendor trust weighting). A POSITA would not build a multi-feed rule compiler in which rules could not be attributed to their source. This is the strongest single rationale for the limitation that most likely separated the claims from the family patents, and HPE '043 expressly discloses carrying feed-derived metadata (threat type, botnet type, first-seen) with each indicator.
5.5 "Obvious to try" — a finite, predictable solution space. Given the disclosed and known mechanics, the only realistic ways to combine two feeds are union, intersection, weighting/voting, and precedence — and the '906's own specification names the union/dedupe/merge approach. KSR: where a finite number of identified, predictable solutions exist and one is selected with a reasonable expectation of success, the claim is obvious.
5.6 No teaching away, no unexpected result. Nothing in Kapoor, Himberger, KDDI, or HPE '043 disparages the combination; the combination uses each reference for its own purpose; and the '906 reports no data showing an unexpected result from correlating feeds (as opposed to from any filtering at all).
6. Objective indicia (Graham factor 4) — what Centripetal would argue, and why it likely fails
| Potential secondary consideration | Assessment |
|---|---|
| Commercial success / industry recognition — Centripetal's DHS SBIR case study ("How CNI Leveraged DHS S&T SBIR Funding to Launch a Successful Cyber Security Company," 2012) and its product line | Weak nexus. The evidence (if any) ties to the aggregate product, not to the claimed multi-feed-correlation-and-provenance feature. Nexus is "presumed only when the patented feature is the but-for cause of the commercial success." |
| Copying by Palo Alto | No evidence of copying the specific feed-tagging/correlation limitations; and the district court found the '906 claims invalid or not infringed, and dismissed the '906 claims with prejudice on 2024‑10‑03. |
| Licensing / settlement (Keysight) | The district court rejected the Keysight settlement as insufficiently comparable to the hypothetical license in post-trial briefing (PAN's JMOL brief, Centripetal v. PAN, No. 2:21‑cv‑00137) — so it is poor evidence of value attributable to these claims. |
| Long-felt need / failure of others | Explicitly rebutted by Ground 6: line-rate filtering was an active, published research and commercial field (Granidt; Fulp; Warkhede; Al-Shaer), and collaborative feed aggregation was commercially deployed (HP Threat Central, 2013). |
| The $151.1M verdict (Jan. 31, 2024) | Covers other patents — the '437, '903, '573, and '797 — not the '906. It cannot be offered as objective evidence of the '906's nonobviousness. |
| Industry praise / awards | Would fail the nexus test for the same reason as commercial success. |
Bottom line: objective indicia were available to Centripetal and did not carry the day — the FWD went against it on all challenged claims and was affirmed.
7. Conclusion
- No single reference anticipates claims 1–17. The invalidation was a § 103 holding over combinations, which is why the analysis must articulate element gaps and motivations rather than point to one document.
- The primary § 103 combination is Kapoor (US 2008/0229415) + Himberger (US 7,084,760) + KDDI (US 2014/0082730) + HPE (US 2015/0373043), optionally with Centripetal's own family patents ('213/'077/'205) and the academic/packet-classification references (Granidt, Navrikuth, Fulp, Warkhede) supplying the architecture and the scalability motivation. Each limitation of the reconstructed independent claims is met, and five independent KSR rationales support the combination.
- The strongest single rationale is engineering necessity for per-rule feed provenance (F(iii)) in a multi-feed rule compiler, reinforced by the patentee's own specification naming the union/dedupe/merge correlation operation.
- ⚠️ The case turns on a priority/§ 102 determination I could not verify. If the challenged claims are entitled to April 16, 2014, HPE '043, Singla '329, Gigamon '706, Bricata '558, and Centripetal's own family patents all fall out of the prior art, and the case must be rebuilt on the pre‑2014 subset. The fact that PAN's exhibit list contains both the family patents and the 2015 publications is strong circumstantial evidence that the Board moved the effective filing date forward — i.e., that the '906's own claims lacked written-description support in the 2014 priority application. This must be confirmed against the FWD (IPR2021‑01157, Paper 36) and Paper 10 before the analysis is relied on. My searches this session did not retrieve those documents.
- Practical value is forward-looking, not defensive on the '906. For the '906, the claims that were challenged are canceled and the E.D. Va. '906 claims were dismissed with prejudice; PAN is estopped under § 315(e)(2). The analysis above is what matters for the live continuations and siblings — US 10,912,474, US 11,012,474, US 11,412,774, US 12,107,893, US 12,563,103 — where the same specification, the same architecture, and the same "self-invalidating family patent + 2015 feed-art" structure are available, as the Federal Circuit's April 23, 2026 decision in Centripetal v. Keysight (No. 24‑1406) further illustrates.
Verification gaps carried forward (stated, not glossed)
- Verbatim claim text of US 10,749,906 — not retrieved; architecture is reconstructed from the family/CIP and the IPR record.
- IPR2021‑01157 Final Written Decision (Paper 36) ground-by-ground chart and the Institution Decision (Paper 10) — not retrieved this session; the ground construction above is my own, using the verified reference set reported in the Prior Art section.
- Claim-set size (17 vs. ≥33) — unresolved; see § 0.2(b).
- Whether the Board made an express effective-filing-date/priority finding — inferred, not verified; see § 4.7.
- Certificate of cancellation for the '906 — not retrieved.
Generated 9/21/2026, 8:24:30 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 12438978I'll search for this specific patent number across sources, including USPTO and CAFC 2026 docket references. Let me verify with additional targeted searches, including CAFC docket and any litigation references. Found litigation references…
- US 6594654I'll search for litigation and docket information on this specific patent number. Let me check for litigation involving the assignee and retrieve the full claim set. Let me try to retrieve the full claim set to identify all independent…
- US 7185358I'll search for authoritative information on US 7,185,358. Now let me check for litigation / CAFC docket activity and the USPTO assignment record. Let me check for any IPR/PTAB and Federal Circuit activity specifically involving 7,185,358…
- US 8131840I'll search for authoritative records on US 8131840, including any litigation/docket activity. Let me run a couple more targeted checks for any 2026 litigation or CAFC activity. Summary — US Patent 8,131,840 B1 Search transparency note: I…
- US 5652908I'll search for current information on this patent, including any litigation or docket activity. US Patent 5,652,908 — Analyst Summary Scope note: I searched for this specific number. The authoritative patent full text was supplied and is…
- US 11233777I'll search for this specific patent number and any litigation activity. Let me get the actual claim text and check for litigation specifically naming this patent. US Patent 11,233,777 — Analyst Summary Important caveat up front: I was…
- US 6873975I'll search for authoritative information on this specific patent number. Search results: US Patent 6,873,975 Note on scope of search I searched for the literal string "6873975" and combinations with USPTO/CAFC 2026 docket terms. I found…
- US 8610675I'll search for authoritative information on US 8610675, including any 2026 CAFC docket activity. Let me get the remaining independent claims and check for any 2025–2026 appellate activity on this specific patent. US 8,610,675 B2 —…
This patent in court (4)
4 tracked lawsuits name US 10749906.