- Filed
- Sep 15, 2026
- Last modified
- Sep 15, 2026
- Petitioner
- Netskope, Inc.
- Inventor
- Matthew J. Little et al
Invalidity dossier
US 11449623
File access control based on analysis of user behavior patterns
Current assignee: Fortinet Inc
Added 9/15/2026, 6:00:09 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll verify the details and check for any litigation/docket references.
US 11,449,623 B2 — Verification Summary
Source of record: Google Patents full text supplied in this session (fetched 2026-09-15 from https://patents.google.com/patent/US11449623/en), corroborated against Espacenet bibliographic data (https://worldwide.espacenet.com/publicationDetails/biblio?CC=US&NR=[11449623B2](/patent/11449623B2)&KC=B2&FT=D) and uspto.report (https://uspto.report/patent/grant/[11,449,623](/patent/11449623)). The number was checked literally as 11449623; no similarly numbered patent was substituted.
Bibliographic data
| Field | Value |
|---|---|
| Title | File access control based on analysis of user behavior patterns |
| Patent number | US 11,449,623 B2 (application publication US 2020/0302074 A1) |
| Application number | US 16/362,167 |
| Assignee | Fortinet, Inc. (original assignee; assignment recorded 2019-04-15) |
| Inventors | Matthew J. Little; Jamie R. Graves; Carson Leonard |
| Filing date | 2019-03-22 |
| Priority date | 2019-03-22 (no foreign/earlier priority claimed) |
| Issue (grant) date | 2022-09-20 |
| Publication of application | 2020-09-24 |
| Legal status | Active; adjusted expiration 2041-02-02 (implies patent term adjustment) |
| Claims | 15 total |
| Classifications | G06F21/6218, G06F16/182, G06F21/316, G06F21/602, G06N20/00, H04L9/0819 / H04L9/0816 |
Abstract (as issued)
Systems and methods for a machine-learning driven fine-grained file access control approach are provided. According to one embodiment, a server associated with an enterprise network can obtain and store information regarding historical user behavior of users of the enterprise network by observing file access requests initiated by the users. The server receives a file access request initiated by a user, which relates to a file stored within the enterprise network in encrypted form. In response to receipt of the file access request, the server determines a risk score for the user based on multiple factors, including information regarding historical user behavior, the file access request and observed data determined based on the file access request so that based on the risk score, access to the file is permitted by returning a decryption key for the file or denied by withholding the decryption key.
Plain-language overview of claim 1 (the only independent claim whose full text is in the authoritative record I hold)
Claim 1 is a method covering:
- Learning phase — one or more servers in an enterprise network collect and store historical user-behavior information by observing file-access requests made by many users. (Notably, the training signal is the enterprise's own observed traffic, not a pre-authored policy.)
- Request phase — the server(s) receive a file-access request from a first user, where the target file is stored in the enterprise network in encrypted form.
- Scoring — in response to the request, the server(s) compute a risk score for that user from multiple factors: the historical behavior information, the request itself, and observed data derived from the request.
- Enforcement via key release — access is permitted or denied by returning or withholding the decryption key, and the grant/deny step is three-tiered:
- risk score < first threshold → return key, full access;
- risk score > second threshold → withhold key;
- risk score between the two thresholds → return key but grant limited access.
The claimed novelty point, as drafted, is the combination of cryptographic-wrapper/key-release enforcement with a machine-learning risk score that maps onto graduated access levels — this is what the specification frames as the improvement over static, policy-driven file access control (which it criticizes at length for requiring administrators to pre-model every access scenario and to manually add/revoke policies as employees join and leave).
Technical context from the specification (useful for claim construction)
- Architecture (FIG. 1): management server 102 (interface to the endpoint module), permission server 104 (holds/releases decryption keys), analytics server 106 (risk scoring); the last two may be integrated into the management server. Client machines 110 run a file-access control module that runs in kernel mode, hooks low-level OS/API calls, and performs on-access validation before allowing delete/open/read/write/rename.
- Behavioral factors: history of general file access (number/types of files, applications used over a period), current and historical location (from source IP), time of day of the request vs. the user's typical access times, trusted vs. untrusted connection (corporate network/VPN vs. public hotspot), and peer-group behavior (from a directory-services list or by measured similarity among users).
- Modeling: model of normal behavior built by unsupervised and/or supervised machine learning; may use a clustering algorithm with a modified outlier-detection scoring algorithm; may comprise multiple sub-models selected by identifier (user ID, file name/type, IP address, location, timeframe). Explicitly incorporated by reference: US Pub. Nos. 2018/0069881 and 2018/0351979.
- "Limited access" is described as directing access through a lower-risk channel, e.g. a VPN.
- Feedback loop: denials may generate administrator alerts; the administrator can reclassify false positives as normal behavior, modifying the model in a supervised manner (thresholds configurable via CLI/browser UI).
- Scope caveat in the specification: although the claims are directed to files and cryptographic wrappers, the description states the methodology is "thought to be applicable" to enterprise resources generally (network shares, directories, databases, applications, printers) — "albeit, without the use of a cryptographic wrapper as in the case of files."
Litigation / CAFC check
- A search of CAFC 2026 dockets and general litigation sources for this patent number returned no results. I found no verifiable US district court action or Federal Circuit appeal involving 11,449,623. I cannot confirm or refute the existence of any specific 2026 CAFC docket.
- One caveat: the Google Patents page for this patent carries a generic "Family has litigation — First worldwide family litigation filed" banner with a Darts-IP link (https://patents.darts-ip.com/?family=72513684). That banner is generated automatically for the patent family and does not, by itself, establish US litigation or a CAFC appeal; I was unable to open a corresponding case record.
Explicit uncertainties
- Claims 2–15: the authoritative record I hold shows "Claims (15)" but reproduces only claim 1 in full and truncates claim 2 mid-sentence ("wherein said determining…"). I therefore cannot quote or summarize the other independent claims (a system claim and/or a non-transitory machine-readable-medium claim are common in this format, but I will not assert that as fact here). My web searches for the claim set returned only unrelated patents (e.g., US 10,248,801 and US 2019/0052457 A1) and should not be confused with this patent.
- Inventor nationality: Espacenet lists all three inventors with a [GB] address indication; Google Patents lists names only. Treat the GB designation as bibliographic metadata, not a legal conclusion.
- Expiration/adjustment: the 2041-02-02 adjusted expiration shown by Google Patents reflects a PTA assumption and is flagged on the page as an assumption, not a legal conclusion.
Generated 9/15/2026, 6:01:31 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 11449623. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search litigation-specific sources for this exact patent number.
The general search returned only a Fortinet securities class action (unrelated to patent 11,449,623) and an empty result for the patent-litigation query. Let me try litigation-specific databases.
Litigation Search — US Patent 11,449,623 B2
Bottom line: I found no verifiable litigation — patent or otherwise — involving US Patent 11,449,623. No district court action, no CAFC appeal, no PTAB proceeding, and no ITC investigation naming this patent surfaced in any of the searches I ran.
What I searched and what came back
| Query | Source type | Result |
|---|---|---|
11449623 patent litigation |
general web / litigation pages | 0 results |
"11,449,623" Fortinet lawsuit |
general web | Hits only on Fortinet securities class actions (see below) — none reference the patent |
"11449623" patent case docket |
docket-oriented web | 0 results |
Unified Patents litigation "11449623" |
Unified Patents targeting | 0 results |
"US 11,449,623" OR "US11449623" lawsuit complaint |
general web | 0 results |
I was attempting to reach the Unified Patents case list (https://portal.unifiedpatents.com/litigation/caselist) and PACER/CAFC-oriented sources when I exhausted my search budget, so those specific portals were not directly loaded. My conclusion rests on the queries above, not on a page-by-page review of those databases.
The only Fortinet litigation that surfaced (expressly NOT this patent)
The searches did return a high-volume but technologically unrelated matter. Fortinet, Inc. is the current assignee of US 11,449,623, so a naive name search surfaces this; I list it only to rule it out:
- Case: In re Fortinet, Inc. Securities Litigation (lead case captioned Oklahoma Firefighters Pension and Retirement System v. Fortinet, Inc.; a parallel/related action State of Rhode Island Office of the General Treasurer … v. Fortinet, Inc., No. 25-cv-08888)
- Forum: U.S. District Court for the Northern District of California
- Case No.: 25-cv-08037 (lead)
- Filed: September 22–23, 2025
- Type: Securities fraud class action under §§10(b)/20(a) of the Exchange Act and Rule 10b-5
- Subject: Alleged misstatements about the FortiGate firewall "refresh cycle"
- Status: Consolidated Class Action Complaint filed April 24, 2026; motion to dismiss filed June 15, 2026, with opposition due August 7, 2026 (per Bleichmar Fonti & Auld, https://www.bfalaw.com/cases/oklahoma-firefighters-pension-and-retirement-system-v-fortinet-inc)
- Relevance to US 11,449,623: none. This is a securities matter; the patent is not asserted, cited, or mentioned.
Per your instruction to interpret identifiers literally, I want to be explicit: no case number, party name, or docket above corresponds to US 11,449,623, and I am not treating the Fortinet name match as a hit.
On the Google Patents "Family has litigation" banner
As noted in the previously generated summary, the Google Patents page for this patent displays a generic banner reading "Family has litigation — First worldwide family litigation filed," with a Darts-IP link (https://patents.darts-ip.com/?family=72513684). That banner is auto-generated at the patent-family level and:
- does not identify any party, court, case number, or date;
- does not establish that the litigation (if any) concerns US Patent 11,449,623 rather than a foreign family member; and
- was not resolvable to a case record in this session.
I cannot confirm what that banner refers to. It is the single strongest indicator that some family-level litigation may exist somewhere, and it directly conflicts with the absence of results from my litigation-database queries. I am flagging that contradiction rather than resolving it. If you need a definitive answer, the banner's Darts-IP family ID (72513684) is the specific lead to chase, along with a direct PACER docket search on the patent number.
Caveats and confidence
- Confidence that no US litigation is currently pending or was historically filed on this patent: moderate, not high. The patent issued only on 2022-09-20 (application published 2020-09-24), so the litigation window is short, which is consistent with a null result — but a null search result is not affirmative proof of non-litigation.
- Several of my search tool calls returned empty result sets, which may reflect source coverage rather than true absence of cases. Do not read the empty results as conclusive.
- Date discrepancy to note: this session's context is dated 2026-09-15, while the task instructions state the current date is 2026-04-26. Some retrieved material references events (e.g., a June 15, 2026 motion to dismiss, an August 7, 2026 opposition deadline) that post-date the April 26, 2026 instruction date. I fetched that material as-is and have not reconciled the two dates.
- I did not verify any of this against the actual PACER docket or the CAFC docket directly.
Recommended next steps to close the gap
- Query PACER (and the CAFC's CM/ECF) directly for "11,449,623" in the patent-number field of the docket search.
- Open the Darts-IP family record 72513684 to see whether the flagged first family litigation is US or foreign, and whether it names this specific patent.
- Check Unified Patents (portal.unifiedpatents.com/litigation/caselist), RPX, and PTAB (for IPR/PGR filed against 11,449,623), since a Fortinet-owned patent would more plausibly be attacked via PTAB than asserted in court.
- Run an assertion-side check: Fortinet is predominantly a patent defendant in its sector, so the more likely posture for this patent is defensive rather than offensive.
Generated 9/15/2026, 6:45:25 PM
Proceedings on file (1)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the proceeding record and look for any public filings or related activity.
I could not reach any public record of this proceeding beyond the USPTO Open Data Portal entry supplied in the structured block — consistent with a petition filed today. Below is what is verifiable, what is not, and how to read it.
Proceedings overview
There is exactly 1 AIA trial proceeding on file for US 11,449,623: IPR2026-00474 (Netskope, Inc. v. Fortinet, Inc.), status Pending — meaning 0 proceedings have canceled claims, 0 have sustained claims, 0 settled, and 0 were denied institution. The bottom-line defensive posture this gives a defendant is therefore "the patent is completely untested at the PTAB and no claim-level estoppel has attached — but a sophisticated, repeat competitor filed a petition on 2026-09-15, so the validity fight has just begun, not ended." Nothing in this record supports a statement that any claim of 11,449,623 is dead, and nothing supports a statement that the patent has been "hardened."
⚠️ Contradiction flag for the prior section: the earlier Patent Summary reported "no verifiable US district court action" involving 11,449,623, while the structured PTAB record shows Netskope, Inc. petitioning against it. A competitor does not ordinarily fund an IPR against a patent it is not accused of infringing, so the existence of IPR2026-00474 is evidence that the '623 patent is in play in the Netskope–Fortinet dispute — but I could not confirm the case number, the asserting party, or the service date. The Darts-IP "family has litigation" banner on the Google Patents page is consistent with this but is not proof of any specific action. Treat "which litigation asserts the '623" as an open item to confirm before relying on it.
IPR2026-00474 — Netskope, Inc. v. Fortinet, Inc.
- Type: Inter Partes Review (35 U.S.C. §§ 311–319). Not a PGR; not a CBM (the CBM transitional program sunset on 2020-09-16, and the '623 patent has a 2019-03-22 priority date, so CBM is unavailable regardless).
- Filed: 2026-09-15 (per USPTO Open Data Portal record; same-day "last modified" entry).
- Status: Pending (verbatim). Plain-English gloss: the petition exists on the docket; the Board has not yet issued a notice of filing date accorded, no Patent Owner Preliminary Response is due yet, and no institution decision has been made. There is no final written decision.
- Judge panel: Not public / not available. PTAB panels are ordinarily designated only when the institution decision issues, so no APJ names exist to report. (Do not infer a panel from the parties' other cases.)
- Petition grounds: Not available and not verifiable at this time. The structured record carries no claims-challenged, no art, and no statutory basis. I will not speculate. For completeness only: a defendant planning around this patent should expect any challenger to look first at the two references Fortinet itself incorporated by reference in the specification — US Pub. Nos. 2018/0069881 and 2018/0351979 — but I have no evidence either is asserted in IPR2026-00474.
- Institution decision: None issued. Statutory framework for what happens next:
- Patent Owner Preliminary Response due within 3 months of the notice of filing date accorded (37 C.F.R. § 42.107(b)); on a normal schedule the notice issues within days-to-weeks of 2026-09-15, putting the POPR around mid-to-late 2026-12.
- Institution determination due not later than 3 months after the POPR (or the last date it could be filed) — in practice ≈6 months from 2026-09-15, i.e., on or about 2027-03-15 (35 U.S.C. § 314(b)).
- If instituted, a Final Written Decision is due within 1 year of institution, extendable up to 6 months for good cause (35 U.S.C. § 316(a)(11)) → FWD on or about 2028-03 absent extension.
- Final Written Decision: None. No claim of 11,449,623 has been canceled or confirmed in any AIA proceeding. Claim 1 stands as issued; the 15 issued claims are all untested.
- Settlement / termination: None. No termination, no adverse judgment, no request for adverse judgment, no refund activity on the record.
- Appeal: None possible yet. There is no FWD to appeal. Nothing is at the Federal Circuit; no CAFC docket number exists for this patent.
- Defensive value: Marginal-to-cautious. For a defendant facing assertion of the '623 today, IPR2026-00474 provides no invalidity judgment to lean on and confers no estoppel — § 315(e)(1)/(2) estoppel attaches only after a final written decision, and even then it binds only the petitioner and its privies, not other defendants. What it does provide is (a) a free-riding roadmap if Netskope's petition, POPR, and institution decision become public, and (b) a signal that a well-funded competitor has independently concluded the '623 is vulnerable. It does not support a motion to dismiss, a Rule 12 argument, or an inequitable-conduct narrative.
Strategic summary
Claim status: all 15 claims UNTESTED. There is no cancellation, no confirmation, and no narrowing certificate. If a demand letter cites claims 1–15, every one of those claims is live and presumptively valid. Any statement to the contrary would be wrong on this record. Note also that my authoritative record reproduces only claim 1 in full (claim 2 is truncated mid-sentence), so I cannot state what the other independent claims recite, nor whether the 15 claims include a system or CRM claim — a gap to close before charting infringement.
Estoppel landscape: essentially empty, but with a closing window. No IPR has reached FWD on this patent, so no § 315(e) estoppel has attached to Netskope and none bars anyone else. For a different defendant, all § 102/§ 103 grounds based on patents and printed publications remain available in litigation today — but note the practical race: if the Board institutes and Netskope loses on a claim, that claim's validity has been adjudicated; if Netskope wins, that defendant benefits without paying for it. Two threshold issues worth checking immediately: (i) whether the petition is time-barred under § 315(b) because Netskope was served with a complaint alleging infringement of the '623 more than one year before 2026-09-15; and (ii) whether Fortinet will seek Director discretionary denial under Fintiv, which is a live and demonstrably successful tactic in this exact party pair (see below).
Pattern signals: this is a two-front war, and the direction of fire has reversed. The record I could verify shows:
- Netskope → Fortinet (2023): Netskope filed IPR2023-00457 and IPR2023-00458 against Fortinet's US 9,280,678 ("Secure Cloud Storage Distribution and Aggregation"). In IPR2023-00458 the Board's FWD of 2024-08-12 determined all challenged claims unpatentable; the patent owner noticed appeal on 2024-10-14, and a Federal Circuit mandate was entered 2025-01-30 — indicating a rapid resolution (consistent with dismissal or summary disposition; I could not verify the disposition). Consistent with this, Netskope's amended complaint in Netskope, Inc. v. Fortinet, Inc., No. 3:22-cv-01852 (N.D. Cal.) is reported to assert only surviving dependent claims of the '678 and '825 patents — i.e., Fortinet has already lost independent claims of its own patents to Netskope-filed IPRs. That is the single most important pattern signal here: Fortinet is not the only side with PTAB losses, and Netskope is an experienced, successful IPR petitioner.
- Fortinet → Netskope (2025–2026): Fortinet filed a volley of IPRs against Netskope's RPX-acquired portfolio — IPR2026-00025 ('639), -00026 ('426), -00027 ('936), -00031 ('697), -00040 ('336), -00041 ('282), -00042 ('710) — in parallel with Netskope, Inc. v. Fortinet, Inc., No. 4:25-cv-02360-HSG (N.D. Cal., Judge Haywood S. Gilliam). Fortinet filed Sotera-Plus stipulations (see the stipulation text at https://gaeflexstaging-dot-docketupdate.appspot.com/cases/PTAB/IPR2026-00031/Fortinet_Inc._v._Netskope_Inc/) to blunt Fintiv, and Netskope responded with discretionary-denial briefs leaning on settled expectations / RPX-as-defensive-aggregator arguments. The results appear to favor Netskope: IPR2026-00026 terminated on a discretionary denial (institution decision date 2026-01-27) and IPR2026-00031 terminated 2026-02-03 on a "Director Discretionary Decision: Deny," followed by refunds. IPR2026-00474 is best read as the counter-punch: Netskope now attacking a Fortinet patent. It is not a defensive-aggregator proceeding; no Unified Patents involvement is evidenced anywhere in this chain.
- Consequence for IPR2026-00474: given that the Board/Director has recently denied Fortinet's petitions against Netskope patents on discretionary grounds in a parallel N.D. Cal. case, expect a vigorous Fintiv/§ 325(d) discretionary-denial fight in the other direction here — including the mirror-image "settled expectations" argument, which cuts for Fortinet on the '623 (a patent Fortinet prosecuted itself, practices commercially, and which is only ~4 years old at issue) and against Netskope on its RPX-acquired patents.
Recommended next steps
- Pull the actual petition. It was filed 2026-09-15 and may not yet be indexed on third-party aggregators. Check PTAB E2E / P-TACTS (https://ptab.uspto.gov/, https://ptacts.uspto.gov/ptacts/) and the USPTO Open Data Portal for the petition, exhibits, and the Notice of Filing Date Accorded. Also search CourtListener (https://www.courtlistener.com/?q=%2211449623%22) for any opinion citing the patent.
- Establish the litigation anchor. Confirm in which case (candidate: No. 4:25-cv-02360-HSG or 3:22-cv-01852, N.D. Cal.) the '623 patent is asserted, and on what date Netskope was served with any complaint alleging infringement of it. That date controls the § 315(b) one-year bar and is the first thing a defendant should verify.
- If you are a defendant, do not cite IPR2026-00474 as an invalidity finding — there is none. It is useful only as (a) an early-warning source for prior art, and (b) evidence of a broader licensing/assertion campaign worth characterizing to the court.
- Diary the milestones once the notice of filing date issues: POPR due ≈3 months from the notice; institution decision ≈2027-03-15; if instituted, FWD ≈2028-03 (statutory 1-year trial clock from institution, extendable 6 months). Watch for a Sotera/Sotera-Plus stipulation or a stay motion in the parallel case — both are established moves in this party pair and are leading indicators of how the Board will treat discretionary denial.
- Re-verify claims 2–15. My authoritative full text reproduces only claim 1. Before drafting any invalidity or infringement position, obtain the complete issued claim set from the USPTO PatentCenter file wrapper for US 16/362,167.
Explicit non-findings (do not let anyone convert these into facts): no institution decision, no FWD, no claim cancellations, no settlement, no termination, no estoppel, no Federal Circuit appeal, and no named APJ panel exist for IPR2026-00474 as of 2026-09-15. The proceeding number was taken verbatim from the supplied structured record and was not independently corroborated by web search, which returned no hits for it.
Generated 9/15/2026, 6:45:48 PM
Ownership chain (1)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2019-03-22 · recorded 2019-04-15 · Assignment
GRAVES, JAMIE R.; LEONARD, Carson; LITTLE, MATTHEW J.FORTINET, INC.
acquisition
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment record for US 11,449,623 across the sources specified.
Let me dig deeper into the assignment record and NPE/litigation databases.
The EP record reveals the inventors' employer at filing was Inquisitive Systems Limited (Edinburgh). Let me investigate this acquisition and search the assignment databases.
Ownership & Assignment Reconstruction — US 11,449,623 B2
Method note / limitation (read first): I queried the sources described in the task, but this session hit its tool-call ceiling before I could open a live USPTO Assignment Center (https://assignmentcenter.uspto.gov/) result page for patent 11,449,623. I therefore could not retrieve reel/frame numbers or the correspondent of record directly. Everything below is limited to what the authoritative patent text (supplied in-session) and the indexed bibliographic sources actually showed. Where a field was not retrievable, I say so explicitly rather than invent it. Fields marked [NOT RETRIEVED] are genuine gaps, not "no record."
Inventors
| Inventor | Employer at time of filing |
|---|---|
| Matthew J. Little | Inquisitive Systems Limited, Codebase Argyle House, 3 Lady Lawson Street, Edinburgh EH3 9DR, GB |
| Jamie R. Graves | Inquisitive Systems Limited, same address |
| Carson Leonard | Inquisitive Systems Limited, same address |
Sourcing caveat: The issued US patent and the Google Patents record list the three inventors by name only — no employer. The employer attribution above comes from EP 3 272 097 (a different Fortinet application that shares three of the same named inventors: Graves, Little, Mandrychenko, Leonard), which lists each inventor's address as "Inquisitive Systems Limited, Codebase Argyle House, Edinburgh." That is corroborative evidence of the inventors' employer, not a direct read of the US 16/362,167 assignment document, which I could not open.
Pattern flags:
- All three named US inventors share a common GB employer (an Edinburgh software company) and all three appear as assignors to Fortinet on the same recorded assignment (Google Patents legal event, 2019-04-15). That is the signature of a company acquisition / employer-to-parent assignment, not an inventor-by-inventor fire-sale.
- I did not verify any inventor departures from Fortinet within 12 months of filing, and I have no evidence of one. Do not read a departure signal into this record.
- I was unable to complete verification of the corporate relationship between "Inquisitive Systems Limited" and Fortinet (the Edinburgh insider-threat vendor ZoneFox is widely associated with this inventor team, but I could not confirm in-session that Inquisitive Systems Limited is ZoneFox's legal entity). Treat the ZoneFox linkage as unverified.
Original assignee
- Entity on the issued patent: Fortinet, Inc. (original assignee; assignment recorded 2019-04-15 per Google Patents legal events).
- Primary line of business: Enterprise/network cybersecurity — firewalls, endpoint protection (FortiClient, FortiEDR), SIEM/SOC (FortiSOC), secure networking.
- Product embodying the claims: Fortinet is a large, operating, publicly traded security vendor. The specification itself names the FortiClient endpoint security solution (assignee's own product) as the file-access-control module host, and the FIG. 5 hardware discussion references "FortiSOC™ system on a chip processors." So there is direct in-patent evidence of a shipping product line rather than a licensing shell.
- Current status: Operating company. I have no evidence of dissolution, bankruptcy, or acquisition of Fortinet itself. (I did not re-verify current 10-K/8-K status in-session.)
Assignment timeline
Result of the search: only one assignment is reflected in the sources I could reach — the original inventor-to-assignee assignment. No post-issuance transfers appeared in the Google Patents legal-events record.
- 2019-03-22 (execution/filing context) / recorded 2019-04-15 — Reel [NOT RETRIEVED]/[NOT RETRIEVED]
- Conveyance: Assignment of assignors' interest (inventor-to-employer/parent assignment)
- Assignor: GRAVES, JAMIE R.; LEONARD, Carson; LITTLE, MATTHEW J. (all three jointly)
- Assignee: FORTINET, INC.
- Correspondent: [NOT RETRIEVED] — the Assignment Center record page was not opened, so I cannot state the attorney/firm of record. I am not flagging a repeat-correspondent signal, because I have no correspondent data at all; a missing field is not evidence.
- Context: Employer/parent acquisition assignment — the three inventors assigned their rights to Fortinet, consistent with Fortinet having acquired their Edinburgh employer.
Note on the "no records" question: The USPTO Assignment Center's coverage begins August 1980, so this 2019 patent is squarely inside the indexed window. The absence of any later chain in the sources I reached is a positive indication (not a database-coverage artifact) that Fortinet still owns the patent — but I flag this as not independently confirmed against the Assignment Center's live record, which I could not load.
Reel/frame and correspondent fields are explicitly marked [NOT RETRIEVED] rather than fabricated. To close these gaps, run a patent-number search at:
- https://assignmentcenter.uspto.gov/ (primary)
- https://assignment.uspto.gov/patent/index.html (mirror)
Timeline diagram
timeline
title Ownership of US 11449623
2019 : Application filed by Fortinet
: Inventors assign rights to Fortinet
2020 : Application published as 2020 0302074
2022 : Patent issued
2022 : No later assignment recorded
NPE / troll-pattern signals
| # | Signal | Call | Basis |
|---|---|---|---|
| 1 | Shell-entity transfer | Not present | The only recorded assignee is Fortinet, Inc., an operating cybersecurity vendor. No "IP / Holdings / Licensing / Ventures" LLC appears anywhere in the chain. |
| 2 | Known asserter in the chain | Not present | No assignee matches the Acacia / Marathon / IV / IPNav / Wi-LAN / Conversant / Vringo / Pendrell / MPHJ / Round Rock / Spangenberg set. Assignee is Fortinet throughout. |
| 3 | Repeat correspondent across the chain | Unclear | Correspondent of record was [NOT RETRIEVED]. With only one link in the chain, recurrence could not occur regardless; recorded as unclear, not as a finding. |
| 4 | Cascading transfers | Not present | No chain at all beyond the single inventors→Fortinet assignment dated 2019-04-15. |
| 5 | Pre-litigation transfer | Not present | No transfer, and no infringement suit naming this patent surfaced in searches of litigation/asserter sources. (The Google Patents "Family has litigation" Darts-IP banner is family-level and does not establish a US case — see prior section.) |
| 6 | Bankruptcy fire-sale | Not present | No bankruptcy event; original assignee is a solvent operating company; no Chapter 7/11 reference in any source reached. |
| 7 | Privateering | Not present | No NPE recipient exists to assert on Fortinet's behalf; the patent never left Fortinet. |
| 8 | Defensive aggregator | Not present | Chain does not terminate at RPX, AST, LOT, Unified, or OIN. (Absence of an anti-NPE endpoint is expected here and is not a negative signal.) |
Unified Patents / RPX check: searches across Unified Patents' news/insights index returned several NPE reexamination stories (Mimzi LLC, Edge Networking Systems, Gatekeeper Solutions), but none referenced US 11,449,623, Fortinet, or any Fortinet-divested entity as a patent owner/asserter.
Verdict
Insufficient data — specifically the "only the original assignment" variant.
Justification: The only ownership event surfaced across the authoritative patent text and indexed sources is the single 2019-04-15 assignment from inventors Graves, Leonard, and Little to Fortinet, Inc., with no subsequent recorded transfer and no litigation or NPE assertion tied to US 11,449,623. Under the rubric, a chain consisting solely of the original assignment must be scored "Insufficient data," and every one of the eight NPE signals resolves to not present (with signal #3 merely unclear because the correspondent field and reel/frame were not retrievable in this session). The practical read — that the patent remains with an operating cybersecurity vendor and shows no NPE pattern — is supported but should be confirmed by pulling the live Assignment Center record for the reel/frame and correspondent.
Verification link: https://assignmentcenter.uspto.gov/ (search by patent number 11449623; mirror at https://assignment.uspto.gov/patent/index.html).
Open items to close: (1) confirm the single-record finding and capture reel/frame; (2) capture the correspondent of record; (3) verify whether "Inquisitive Systems Limited" (Edinburgh) is the acquired entity behind the inventors' assignment.
Generated 9/15/2026, 6:45:36 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research this systematically, starting with the USPTO record and then the citation (prior art) references.
Attempted retrieval — what I could and could not verify
I searched for the specific number 11449623 (literal; no auto-correction, no substitution of similarly-numbered patents). Here is what the searches returned, and — importantly — what they did not.
Confirmed record (matches the earlier section):
- Espacenet bibliographic page: https://worldwide.espacenet.com/publicationDetails/biblio?CC=US&NR=[11449623B2](/patent/11449623B2)&KC=B2&FT=D — "FILE ACCESS CONTROL BASED ON ANALYSIS OF USER BEHAVIOR PATTERNS," applicant Fortinet, Inc., inventors Graves Jamie R [GB], Little Matthew J [GB], Leonard Carson [GB], application US201916362167 filed 2019-03-22.
- uspto.report record: https://uspto.report/patent/grant/11,449,623
Could NOT retrieve — and this is the crux of your request: the patent's own "References Cited" table. The authoritative Google Patents full text supplied in this session contains the specification, abstract, classifications and claim 1, but it does not contain the citations/cited-by tables. My follow-up searches for "US11449623" "Patent Citations" "Non-Patent Citations" and for the pre-grant publication US 2020/0302074 A1 did not surface that table; the search budget was exhausted before I could reach it.
Per the operating rule in this engagement, I will not fabricate a citation list. I cannot tell you "cited reference X anticipates claim Y" for references I have not actually seen in the record. Below I give (1) the prior-art references that are documented in the authoritative text I hold, and (2) an explicit list of what remains unverified.
A. Prior art documented in the authoritative record
A1. US 2018/0069881 A1 (published 2018-03-08) — not a "cited reference" in the ordinary sense; expressly incorporated by reference
| Field | Value |
|---|---|
| Publication | US 2018/0069881 A1, published Mar. 8, 2018 |
| Corresponding grant | US 10,652,255 B2 — "Forensic analysis," issued May 12, 2020 |
| Inventors | Jamie Robert Graves; Matthew John Little; Oleksii Mandrychenko; Carson Leonard (all Edinburgh, GB) |
| Assignee | Fortinet, Inc., Sunnyvale, CA |
| Priority/filing | PCT/GB2016/050659 filed Mar. 10, 2016; U.S. national stage under §371 |
| Source | US10652255B2 face page: https://patentimages.storage.googleapis.com/85/0d/bf/2e4e834b5b376c/US10652255.pdf |
Brief description. A forensic-analysis method on a distributed computing system (server + client machines). Data is collected at a client machine as a first data set consisting of a function call to a resource; a data-reduction model extracts a second data set comprising a user account identifier and a process and object identifier; the reduced set is processed at the server to provide for detection of suspect behaviour at the client machine.
Relevance to 11449623. This is the closest same-family antecedent. It supplies the collection/observation substrate (client-side interception of resource calls, user-account + process/object identifiers, server-side behavioral analysis) that 11449623's "obtaining and storing … information regarding historical user behavior … by observing file access requests" element builds on. The specification of 11449623 itself frames it as "further discussion regarding the collection of user behavior, although, from an endpoint device and in the context of identifying a user masquerading as another user."
§ 102 exposure. It cannot anticipate claim 1 as a whole — it discloses no decryption-key return/withhold enforcement, no risk score mapped to graduated access tiers, and no cryptographic wrapper. Its realistic role is (a) as a § 102 reference against narrower dependent claims (e.g., any claim reciting observation of file-access requests, user-account identifiers, or server-side abnormality detection standing alone), and (b) as § 103 art for the "obtaining and storing … by observing …" and "model of user behavior" limitations. Note the shared inventors/assignee: if it qualified only under § 102(a)(2) as a U.S. patent application publication, the § 102(b)(2)(C) common-ownership exception could remove it as prior art — but because it published 2018-03-08, more than one year before the 2019-03-22 effective filing date, it is § 102(a)(1) prior art (printed publication) and is not subject to the 102(b)(2) exceptions. That is the more likely posture.
A2. US 2018/0351979 A1 (published 2018-12-06) — also expressly incorporated by reference
The specification states: "…is described in US Pub. Nos. 2018/0069881 and 2018/0351979, both of which are hereby incorporated by reference for all purposes."
Verified: the publication number, and that it is a U.S. patent application publication that published before the 2019-03-22 priority date (2018/xxxxxxx series → Dec. 2018), making it § 102(a)(1) prior art on its face.
NOT verified: its title, assignee, inventors, and technical content. A search snippet contained the strings "2018/0351979 A1 … Berger et al. Graves et al." but I could not determine from that fragment which names attach to this publication. I am not asserting a title or assignee for US 2018/0351979 A1.
A3. Non-patent literature actually cited in the patent body
"See Kerr, Orin and Schneier, Bruce, Encryption Workarounds, 106 Georgetown L. J. 989 (2018)."
This is the sole NPL citation appearing in the authoritative text I hold (in the Description of the Related Art). It is cited to support the proposition that "encryption alone is insufficient" — data can be reached by "finding an existing copy of the decryption key or a password, passcode or passphrase used to create the decryption key."
§ 102 exposure: none. It is a law-review article addressing the general insufficiency of encryption; it discloses nothing about observing file access requests, ML risk scoring, or key-release gating. It is background/§ 103-context only, and legally it is arguably an admission about the state of the art rather than prior art that discloses claim elements. Do not mistake its presence for an anticipatory reference.
B. What I could NOT establish (explicit gaps)
- The "References Cited" table for US 11,449,623 is unverified. I have no list of the U.S. patents, foreign patent documents, or NPL that the examiner or applicants cited against this application.
- Claims 2–15 remain unseen in full. The authoritative record truncates mid-claim-2. Without independent claims' text (if any), a claim-by-claim § 102 map cannot be built.
- Forward citations are not prior art. One search result showed a "Cited By (13)" heading adjacent to a listing of US11449623B2 on the page for US 2020/0195672 A1, and mentioned sibling items such as "Analyzing user behavior patterns to detect compromised nodes in an enterprise network – US 2021/0344694 A1" and an SAP SE application on "Identifying security risks and fraud attacks using authentication f…". These are documents that cite 11449623 (i.e., later art / family landscape), not references cited by it. They post-date the 2019-03-22 priority date and therefore cannot be § 102 prior art against it. I flag this because such lists are frequently mistaken for the patent's own citation list.
- USPTO PatentCenter / Patent Public Search UI was not directly reachable with the tools available; my confirmation came from Espacenet, uspto.report and the Google Patents record, which agree with each other.
C. Date note (flagged per instruction)
Two different "today" values appear in this engagement: the current task states April 26, 2026, while the session/fetch metadata records 2026-09-15T18:00:09Z. I am surfacing the discrepancy rather than silently reconciling it. It does not affect the § 102 analysis, since all relevant dates (2016-03-10 PCT filing; 2018-03-08 and Dec. 2018 publication; 2019-03-22 filing; 2022-09-20 grant) are well before either date.
D. Recommended next step to close the gap
To complete the assignment as specified — one entry per cited reference with § 102 claim mapping — the following specific retrievals are needed:
- US 11,449,623 B2 face page and "References Cited" section via USPTO Patent Public Search (https://ppubs.uspto.gov) or PatentCenter (https://patentcenter.uspto.gov) for application 16/362,167, or the granted-PDF face page (INPADOC/patentimages).
- Full claim set (claims 1–15) from the same source, to identify any independent system/CRM claims and to name the affected claims precisely.
- US 2018/0351979 A1 full text, to state its title, assignee, inventors and content.
Until items 1–3 are retrieved, the honest answer to "identify the most relevant prior art and map it to claims under § 102" is: the only references I can cite with verified content are US 2018/0069881 A1 (US 10,652,255 B2) and US 2018/0351979 A1 — both same-family/incorporated-by-reference works rather than adverse third-party art — plus the Kerr & Schneier NPL citation; none of the three appears to anticipate claim 1, and the citation table that would name the examiner-cited art has not been obtained.
Generated 9/15/2026, 6:45:37 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll gather the prior-art record for this patent before analyzing. Let me search for the citation/prior-art listings.
Let me pull the actual citation lists (patent citations and cited-by) for this patent.
The citation tables aren't surfacing yet. Let me try the mirror sites that list "References Cited."
I've hit retrieval limits on the citation tables. Let me make targeted attempts at the two references the patent itself identifies as prior art, plus the closest analogous art.
Generated 9/15/2026, 6:45:28 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 11290527I'll search for authoritative information on this specific patent number. Let me run targeted checks for any litigation or appellate activity involving this patent. US 11,290,527 B2 — Automatic Tagging of Cloud Resources for Implementing…
- US 12244621I'll search for authoritative information on US 12244621, including any litigation activity. Let me search for the claim text and any litigation/docket activity. Important caveat up front My authoritative copy of US 12,244,621 (fetched…
- US 8073911I'll search for litigation and docket information on this specific patent, then compile the summary. Let me check for CAFC 2026 activity and the district court litigation. US Patent 8,073,911 — Summary Note on scope of this report: All…
- US 9110622I'll search for the authoritative details on this specific patent, including any 2026 CAFC activity. Let me check for any 2026 CAFC docket activity involving this patent. Summary of US Patent 9,110,622 B2 Identification & bibliographic…
- US 8332521I'll search for authoritative information on this patent number. US 8332521 — Concise Summary Search coverage / caveats up front: My searches did not return a CAFC (Federal Circuit) 2026 docket entry for patent 8332521. What I did find is…
- US 9069510I'll verify against live sources before summarizing. US Patent 9,069,510 B2 — Analyst Summary Verification status: Core bibliographic data below is grounded in the authoritative full text fetched from Google Patents…
- US RE42725I'll verify against live sources before summarizing. Let me check the claims and any 2026 Federal Circuit activity. Ground-truth check performed I could not reach USPTO PatentCenter or PACER/CAFC docket systems directly with the tools…
- US 10346114I'll search for authoritative information on this patent, including any CAFC 2026 docket activity. Let me search for the litigation/docket details and the actual claim text. US Patent 10,346,114 B2 — Analyst Summary Sourcing note: I worked…