Invalidity dossier

US 11663031

Techniques for securing virtual cloud assets at rest against cyber threats

Current assignee: Orca Security Ltd.

Added 9/29/2026, 10:07:11 AM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by Orca Security Ltd.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative information on this specific patent number, including any 2026 litigation activity.

Let me check for the PTAB final written decision and any Federal Circuit 2026 appeal activity.

Let me check specifically for any Federal Circuit appeal docket in 2026 involving this patent.

US Patent 11,663,031 B2 — Analyst Summary

Scope note: I searched for the exact number 11663031 / 11,663,031 only. No results for similar numbers are included below. All bibliographic data is drawn from the authoritative full text you provided (Google Patents, fetched 2026-09-29) plus corroborating USPTO/PTAB, district-court, and Unified Patents records. Where sources disagree, I flag it rather than auto-correct.


1. Bibliographic data

Field Value
Patent number US 11,663,031 B2
Title Techniques for securing virtual cloud assets at rest against cyber threats
Inventor Avi Shua (Tel Aviv, IL) — sole named inventor
Assignee Orca Security LTD., Tel Aviv (IL) — original and current assignee
Application no. 17/400,364
Filing date August 12, 2021
Issue/grant date May 30, 2023
Prior publication US 2021/0377287 A1 (Dec. 2, 2021)
Priority Provisional 62/797,718 filed Jan. 28, 2019
Continuity Continuation of Ser. No. 16/750,556 (filed Jan. 23, 2020; now abandoned)
Child Continuation Ser. No. 18/182,750 (filed Mar. 13, 2023; abandoned)
Examiner Syed A. Zaidi
Attorney/agent Finnegan, Henderson, Farabow, Garrett & Dunner, LLP
CPC H04L 63/1433 (vulnerability analysis); G06F 9/45558; G06F 11/1464; G06F 16/128
Status Active; anticipated expiration 2040-01-23 (Google Patents)

Flagged discrepancy (not corrected): the Unified Patents patent page for US-11663031-B2 lists priority "2019-01-27," application date "2021-08-11," grant date "2023-05-29," and expiration "2040-01-22" — each exactly one day earlier than Google Patents and the printed face of the patent. This is most likely a time-zone/UTC artifact, but I am reporting it literally as found. (https://portal.unifiedpatents.com/patents/patent/US-11663031-B2)


2. Abstract (verbatim)

"A method and system for securing virtual cloud assets at rest against cyber threats. The method comprises determining a location of a view of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is at rest and, when activated, instantiated in the cloud computing environment; accessing the view of the virtual disk based on the determined location; analyzing the view of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset, wherein the virtual cloud asset is inactive during the analysis; and alerting detected potential cyber threats based on a determined priority."

Note a real internal inconsistency worth citing: the abstract (and the SUMMARY section) is written in terms of a "view" of a virtual disk, whereas the granted claims are written in terms of a "snapshot." The specification treats these as related but distinct concepts (a view/materialized view at col. ~4, versus a snapshot of a running VM). This mismatch between the abstract/summary language and the claim language was directly litigated — see §5.


3. Plain-language overview of the independent claims

There are 16 claims total. Independent claims are 1 (system), 9 (method), and 16 (non-transitory computer-readable medium). Claims 2–8 depend from claim 1; claims 10–15 depend from claim 9.

Claim 1 — System

A system with at least one processor configured to:

  1. Establish an interface between a client environment and security components.
  2. Using that interface, call the cloud platform's own APIs to identify the virtual disks of a virtual machine in the client environment.
  3. Use the platform APIs to query where those virtual disks are located.
  4. Receive back the location identification for the VM's virtual disks.
  5. Take a snapshot, or request that one be taken, of the VM at rest — where the snapshot is a copy of the VM's virtual disks at a point in time.
  6. Analyze that snapshot to detect vulnerabilities, with the VM inactive during the detection.
  7. Report the detected vulnerabilities as alerts.

In plain terms: an agentless cloud security tool that asks the cloud provider's management/API layer where a powered-off VM's disks live, grabs (or asks for) a point-in-time snapshot of those disks, scans the snapshot for vulnerabilities while the VM stays off, and raises alerts.

Claim 9 — Computer-implemented method

The same sequence as claim 1, expressed as method steps, plus an additional step: "emulating the virtual disks for the virtual machine." This emulation step does not appear in claim 1.

Claim 16 — Non-transitory computer-readable medium

Stores instructions that, when executed, cause a computing device to perform the same steps as claim 9 — including the "emulate the virtual disks for the virtual machine" step. So claims 9 and 16 share the emulation limitation; claim 1 does not.

Dependent claims at a glance

  • 2 / 10: reporting alerts includes indicating priority levels for the detected vulnerabilities.
  • 3 / 11: implement a remedial action for a detected vulnerability.
  • 4 / 12: the location identification includes a virtual address of a virtual disk.
  • 5 / 13: the snapshot includes a change log of a virtual disk usable to restore the VM to a point in time.
  • 6 / 14: the snapshot includes a page file of VM memory, enabling deduction of running applications.
  • 7 / 15: multiple snapshots generated on a predetermined schedule.
  • 8: snapshot generated in response to a predetermined trigger event (note: there is no claim 15 counterpart to claim 8; claim 15 maps to claim 7, and claim 8 has no dependent pair, so the claim set is slightly asymmetric).

4. Litigation, PTAB, and appellate posture (as found)

District court: Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del., filed July 12, 2023). US 11,663,031 was one of six asserted Orca patents (alongside 11,663,032, 11,693,685, 11,726,809, 11,740,926, 11,775,326). Wiz counterclaimed on five of its own patents.

PTAB: Wiz, Inc. v. Orca Security Ltd., IPR2024-00863, petition filed May 24, 2024, challenging all claims 1–16. Instituted December 9, 2024 on three grounds of obviousness:

  • Ground 1: claims 1, 3–9, 11–16 over Veselov (US 11,216,563) + Price (US 2013/0247133)
  • Ground 2: claims 2, 10 further over Hufsmith (US 2020/0097662)
  • Ground 3: claims 6, 14 further over Huseinović

Outcome: On December 8, 2025, the PTAB issued a Final Written Decision in IPR2024-00863 holding all claims of the '031 patent unpatentable (per the parties' joint notice filed in the Delaware case, D.I. 235 / Dec. 15, 2025 filing). Same date, parallel decisions issued in IPR2024-00864 ('032) and IPR2024-00865 ('685). The parties stated the deadline for a Notice of Appeal to the Federal Circuit was February 9, 2026, and for rehearing/Director Review was January 7, 2026.

Case disposition: The Delaware case was stayed January 16, 2025 (D.I. 233) pending the IPRs, and was dismissed with prejudice by stipulation on January 13, 2026 (D.I. 238), each side bearing its own costs and fees — reported by CTech/Calcalist and BankInfoSecurity.

CAFC 2026 docket — uncertainty flagged: I found no authoritative record of a Federal Circuit appeal docketed for US 11,663,031 despite the February 9, 2026 notice-of-appeal window. Given the January 13, 2026 dismissal with prejudice and the intervening settlement wave (e.g., the parties jointly moved to terminate IPR2024-01190 on January 7, 2026), it appears Orca did not appeal as to this patent — but I cannot confirm that with high confidence from the sources retrieved, and I am explicitly not asserting the absence of an appeal as established fact. A direct CAFC docket query (or PACER/PTAB appeal tracker) would be needed for certainty.


5. Claim-construction dispute over the key limitation

This is the single most important interpretive issue and it was briefed in both fora. The disputed phrase in claims 1, 9, and 16:

"(i) taking at least one snapshot, and (ii) requesting taking at least one snapshot of the virtual machine at rest"

  • Orca's position: the "of the virtual machine at rest" clause applies to both romanettes (i) and (ii).
  • Wiz's position: plain reading; the clause applies only to romanette (ii) ("requesting taking").

Wiz's IPR theory turned on this: it argued Veselov + Price disclosed everything except snapshotting/reporting an at-rest VM, and used Price to supply the at-rest teaching — which only works if romanette (i) is unconstrained by "at rest." The PTAB nevertheless found all claims unpatentable. (Joint Claim Construction Chart, D. Del.; Orca's PO Response and Kaeli declaration, IPR2024-00863 Ex. 2001; Institution Decision, Paper on IPR2024-00863.)


6. Confidence and caveats

  • High confidence: title, inventor, assignee, application number, filing/issue dates, continuity chain, full claim text, and the PTAB institution/grounds — all directly from the authoritative patent text and PTAB/PTAB-mirror documents.
  • High confidence: the December 8, 2025 Final Written Decision invalidating all claims, and the January 13, 2026 dismissal with prejudice — sourced from the parties' joint court notice and multiple trade-press reports.
  • Low confidence / explicitly uncertain: whether any Federal Circuit appeal was filed or is pending in 2026 for this specific patent. I found no docket record; treat this as "not found," not "does not exist."
  • Minor flagged conflict: one-day discrepancies in priority/grant/expiration dates between Google Patents and the Unified Patents portal, reported literally without correction.
  • I did not retrieve the sealed Final Written Decision text itself, so I cannot quote the PTAB's precise reasoning from the primary document.

Generated 9/29/2026, 10:11:58 AM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 11663031. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search for litigation involving US patent 11663031 across patent litigation sources.

Let me dig deeper into the IPR outcome and any Federal Circuit appeal.

Let me check for any Federal Circuit appeal activity and confirm no other cases involve this patent.

Litigation Involving U.S. Patent No. 11,663,031

I searched patent-litigation aggregators (Unified Patents portal, Docket Alarm), PACER/RECAP-derived dockets (CourtListener), the PTAB (PTAB/Unified Patents), and news coverage. Based on those results, the only known litigation involving U.S. Patent No. 11,663,031 ("the '031 patent") is the Delaware action between Orca Security Ltd. and Wiz, Inc. No other district-court, ITC, or Federal Circuit case specifically asserting the '031 patent surfaced.


1. Orca Security Ltd. v. Wiz, Inc. — District Court

Item Detail
Plaintiff / Counter-Defendant Orca Security Ltd.
Defendant / Counter-Plaintiff Wiz, Inc.
Jurisdiction / Court [U.S. District Court for the District of Delaware (Wilmington Division)](/courts/district-of-delaware-wilmington)
Case No. 1:23-cv-00758 (JLH) (SRF) — also cited as C.A. No. 23-758-JLH-SRF
Filing Date July 12, 2023
Judges Judge Jennifer L. Hall (presiding); Judge Sherry R. Fallon (magistrate/referral)
Cause 35 U.S.C. § 271 — Patent Infringement

The '031 patent's role: Orca's original complaint asserted two patents, including the '031 patent (Docket entry #3 — "Report to the Commissioner of Patents and Trademarks for Patent/Trademark Number(s) 11,663,031 B2; and 11,663,032 B2"). Orca later filed a Second Amended Complaint (Oct. 10, 2023) asserting six patents — U.S. Patent Nos. 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,740,926; and 11,775,326. Wiz counterclaimed, asserting five of its own patents.

Procedural history / outcome:

  • June 2024 – Wiz answered and counterclaimed (D.I. 70).
  • May 24, 2024 – Wiz petitioned for inter partes review of the '031, '032, and '685 patents (IPR2024-00863/864/865).
  • Dec. 9, 2024 – PTAB instituted review of the '031 patent.
  • Jan. 16, 2025 – The court stayed the entire case pending the IPRs (D.I. 233).
  • Dec. 8, 2025 – PTAB issued Final Written Decisions in IPR2024-00863/864/865, holding all claims of the '031, '032, and '685 patents unpatentable (disclosed to the court by joint notice, D.I. 235, Dec. 15, 2025).
  • Jan. 6, 2026 – The parties filed a Stipulation of Dismissal With Prejudice (D.I. 237).
  • Jan. 13, 2026 – The court so-ordered the dismissal with prejudice and terminated the case (D.I. 238). All claims and counterclaims were dismissed; each party bears its own costs and attorney's fees. The dismissal is with prejudice, barring re-litigation.
  • Docket noted as CLOSED.

Sources: Docket Alarm docket for 1:23-cv-00758; CourtListener docket 67600951; Joint Notice (D.I. 235, filed 12/15/2025), available at archive.org/download/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf; Wiz's counterclaims and Orca's Second Amended Complaint (D.I. 80, 218, 220).


2. Related PTAB Proceeding (Wiz, Inc. v. Orca Security Ltd.)

This is an administrative validity proceeding, not civil litigation, but it directly involved the '031 patent and drove the outcome above:

Item Detail
Petitioner Wiz, Inc.
Patent Owner Orca Security Ltd.
Forum USPTO Patent Trial and Appeal Board
Proceeding No. IPR2024-00863 (Patent 11,663,031 B2)
Petition Filed May 24, 2024
Institution Dec. 9, 2024 (all claims 1–16)
Challenged Claims 1–16
Grounds §103 obviousness over Veselov (U.S. Pat. 11,216,563) + Price; + Hufsmith; + Huseinović
Outcome Final Written Decision Dec. 8, 2025 — all claims held unpatentable
Post-decision deadlines Request for rehearing / Director review: Jan. 7, 2026; Notice of Appeal to the Federal Circuit: Feb. 9, 2026

Panel: APJs Zecher, Baer, and Raevsky. Sources: Unified Patents PTAB portal (portal.unifiedpatents.com/ptab/case/IPR2024-00863); Joint Notice D.I. 235; Docket Alarm IPR2024-00863.


3. Federal Circuit Appeal — status uncertain

The Joint Notice stated the deadline to appeal the '031 FWD to the U.S. Court of Appeals for the Federal Circuit was February 9, 2026. I did not find any public record of an appeal being filed on the '031 patent, and the underlying district-court case was dismissed with prejudice on Jan. 13, 2026. Given that today's date (per your instruction) is after the appeal deadline, no Federal Circuit appeal appears to be pending — but I cannot confirm this with high confidence from the sources retrieved, and the PTAB appeal docket for IPR2024-00863 would be the authoritative check.


Caveats

  • I constrained the search to the exact patent number 11,663,031 / US11663031. The searches surfaced the Orca–Wiz family generally; the '031 patent is confirmed to have been asserted only in Orca Security Ltd. v. Wiz, Inc., 1:23-cv-00758 (D. Del.).
  • The parties' damages/valuation figures and settlement terms were not publicly disclosed.
  • If you need a PACER-certified confirmation of current docket status or verification of whether any notice of appeal was filed, that would require a live PACER/CM-ECF pull, which I could not perform here.

Generated 9/29/2026, 10:11:53 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Orca Security Ltd.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll research this. Note the patent text itself flags PTAB case IPR2024-00863 — let me verify that and any related proceedings.

Key finding already: the Google Patents litigation link mislabels the petitioner. Let me verify the petitioner, the FWD, and any appeal.

Now let me check for any Federal Circuit appeal and Director Review following the December 2025 FWD.

Proceedings overview

One AIA trial proceeding is on file for US 11,663,031 — IPR2024-00863 (Wiz, Inc. v. Orca Security Ltd.) — and it is not "no activity": the structured ODP block in the prompt is stale/incorrect, and Google Patents' own page for this patent already displayed the IPR2024-00863 litigation link.

Breakdown: 1 proceeding / 0 active institution-denials / 0 CBM / 0 PGR / 0 settlements / 1 in which all challenged claims were invalidated (Final Written Decision 2025-12-08 holding claims 1–16 unpatentable; statutory appeal window closed 2026-02-09 and I could not confirm whether an appeal was filed — see caveat below).

Bottom line for a defendant: every claim of the '031 patent — independents 1, 9 and 16 plus all thirteen dependents — has been held unpatentable by the PTAB. If a demand letter or complaint cites the '031 patent, the PTAB has already adjudicated it to death once; the only open question is whether Orca perfected a Federal Circuit appeal before the 2026-02-09 deadline. Treat it as a dead patent unless the patent owner produces proof of a live CAFC appeal — and even then, the FWD plus Wiz's district-court stipulation gives you a ready-made invalidity story.

Correction to the structured block: the ODP "no proceedings" result is wrong on the face of the patent page. Also, Google Patents' litigation table lists the "Petitioner" for IPR2024-00863 as Unified Patents — that is a mislabel. The petitioner is Wiz, Inc.; the unifiedpatents.com URL is merely Unified's public PTAB data portal, not a party. There is no defensive aggregator in this chain.


IPR2024-00863 — Wiz, Inc. v. Orca Security Ltd.

  • Type: Inter Partes Review (35 U.S.C. § 311; AIA § 102/§ 103 patent available — effective filing date no earlier than 2019-01-28)
  • Filed: 2024-05-24 (petition); PTAB Notice of Filing Date Accorded 2024-06-13
  • Status: Final Written Decision issued — all claims held unpatentable (verbatim from the parties' joint district-court notice: "on December 8, 2025, the Patent Trial and Appeal Board issued Final Written Decisions in IPR2024-00863, IPR2024-00864, and IPR2024-00865, finding all claims of Orca's Asserted U.S. Patent Nos. 11,663,031, 11,663,032, and 11,693,685 unpatentable.")
  • Judge panel: Michael R. Zecher, Garth D. Baer, and Scott Raevsky, Administrative Patent Judges. Institution opinion authored by APJ Baer. (The same panel presided over the consolidated -863/-864/-865 oral argument; in a related additional-discovery order, APJ Zecher filed a dissent — a split that matters if Orca appeals the discovery ruling's effect.)
  • Petition grounds — all three grounds are § 103(a) obviousness, targeting all 16 claims:
    • Ground 1 — claims 1, 3–9, 11–16 over Veselov (U.S. Pat. No. 11,216,563) + Price (U.S. Pub. 2013/0247133)
    • Ground 2 — claims 2, 10 over Veselov + Price + Hufsmith (U.S. Pub. 2020/0097662)
    • Ground 3 — claims 6, 14 over Veselov + Price + Hufsmith + Huseinović ("Virtual Machine Memory Forensics")
    • Petitioner's theory: Veselov (a security-assessment system using cloud APIs to snapshot a target resource and analyze the snapshot) teaches everything except the "at rest"/"inactive" limitations, which Price supplies via offline-VM image scanning.
  • Institution decision: Instituted 2024-12-09, as to all of claims 1–16. Verbatim from the decision: "we conclude that the information presented in the Petition establishes that there is a reasonable likelihood that Petitioner would prevail in demonstrating at least one of claims 1-16 of the '031 patent is unpatentable." Orca's preliminary response had urged § 314(a) discretionary denial under Fintiv (parallel Delaware litigation, no stay yet, same art) and argued the Veselov/Price combination was "classic hindsight bias" because Price's agent-based approach for active VMs "directly contradicts Veselov's goals." The Board was unpersuaded.
  • Final Written Decision: 2025-12-08 — all of claims 1–16 held unpatentable. Independent claims 1 (system), 9 (computer-implemented method), and 16 (non-transitory CRM) each fell, taking every dependent claim with them. ⚠️ I could not retrieve a verbatim quotation of the FWD's reasoning, and I will not invent one. The public docket shows the FWD was filed under seal in Delaware as Exhibit A to the Joint Notice because it "contain[s] certain confidential information of the Parties"; the redacted public FWD should be pulled from PTAB E2E before you quote any language. Do not cite the Google Patents "Definitions"-style summary language as if it were the panel's holding.
  • Settlement / termination: None. No adverse-judgment, no settlement, no termination — this went to a contested FWD on the merits after a consolidated, closed-to-the-public oral argument on 2025-09-15 (closed because the parties discussed business-confidential information).
  • Appeal: Unconfirmed. The district court record fixes Orca's deadlines precisely: "the deadline to file a Request for Rehearing or Request for Director Review is January 7, 2026 and the deadline to file a Notice of Appeal to the Court of Appeals for the Federal Circuit is February 9, 2026." As of today (2026-09-29) I could not confirm from available sources whether Orca filed a Request for Director Review or a CAFC notice of appeal, and I found no CAFC docket number. Treat the appeal status as an open item to verify on CourtListener/CAFC before relying on cancellation.
  • Defensive value: Maximal. Claims 1–16 are the entire patent, and all of them are dead at the PTAB. Any infringement theory built on claim 1, 9, or 16 is built on a claim the Board has already cancelled — and the same FWD simultaneously killed Orca's two sibling patents (see below). The only residual risk is appellate reversal.
  • Links: PTAB data portal — https://portal.unifiedpatents.com/ptab/case/IPR2024-00863 · PTAB docket (DocketAlarm) — https://www.docketalarm.com/cases/PTAB/IPR2024-00863/WIZ_Inc._v._Orca_Security_Ltd/ · Institution decision — https://www.docketalarm.com/cases/Delaware_District_Court/1--23-cv-00758/Orca_Security_Ltd._v._Wiz_Inc/docs/218/1.pdf · Joint Notice of FWDs (D. Del. D.I. 235) — https://storage.courtlistener.com/recap/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf · District docket — https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/ · PTAB decisions library — https://www.uspto.gov/patents/ptab/decisions

Related family proceedings (NOT on US 11,663,031 — do not confuse them)

These are the same family (ID 71731840, priority 2019-01-28) and the same petitioner, but they attack different patents. They are strategically relevant, not claim-level relevant to the '031.

Proceeding Patent Status
IPR2024-00864 11,664,032 Instituted 2024-12-09; FWD 2025-12-08 — all claims unpatentable
IPR2024-00865 11,693,685 Instituted 2024-12-09; FWD 2025-12-08 — all claims unpatentable
IPR2024-01109 11,726,809 Instituted 2025-01-16 (all claims); FWD statutory deadline 2026-01-16
IPR2024-01190 11,740,926 Institution pending as of the Dec-2024 report; FWD deadline 2026-01-22
IPR2024-01191 11,775,326 Institution pending as of the Dec-2024 report; FWD deadline 2026-01-22

All six Wiz petitions "rely on the same primary prior art reference" (Veselov). Delaware Judge Sherry R. Fallon stayed the entire case on 2025-01-16 pending the IPRs (D.I. 232–233).

Counter-current: Orca also filed IPRs against Wiz's asserted patents (Wiz asserted 11,722,554, 11,929,896, 11,936,693, 12,001,549, 12,003,529). At least one — IPR2025-01086 — was filed 2025-06-04, a year after service, prompting a Wiz Fintiv/dilatory-filing opposition ("Petitioner Orca Security Ltd. is misusing U.S. Patent and Trademark Office processes to delay parallel infringement proceedings"). Orca's rehearing/Director-Review deadline on those was 2026-01-14.


Strategic summary

Claim status on US 11,663,031. Canceled/held unpatentable: claims 1–16 — that is 100% of the patent. Independent claims 1, 9, and 16 fell, and every dependent claim (2–8, 10–15) fell with them as challenged. Sustained: none publicly reported. Untested: none — Wiz challenged every claim and the Board instituted on every claim. The only qualification is procedural, not substantive: PTAB "unpatentable" holdings become certificates of cancellation only after appeal rights are exhausted (37 C.F.R. § 90.2 / § 42.80), so the operating assumption should be "dead unless an appeal is live."

Estoppel landscape. Because a Final Written Decision issued, the statutory trigger for § 315(e)(2) estoppel has fired for Wiz: neither Wiz nor its privies may assert in district court, on claims 1–16, any ground it raised or reasonably could have raised in the IPR. Wiz independently papered this with a 2024-10-10 stipulation (Ex. 1083) promising not to pursue "the specific grounds advanced in the instituted IPR(s) or any ground that reasonably could have been raised in an IPR (i.e., any ground that could be raised under §§ 102 or 103 … only on the basis of prior art patents or printed publications)." For you, as a different, non-privy defendant, no § 315(e)(2) estoppel attaches to you — you are free to run any art you like. But § 315(b) matters: if Orca has served you with a complaint, your IPR petition is time-barred one year from service. And practically, the estoppel/claim-preclusion route is a dead end here anyway, because the claims are already invalid; a well-pled summary-judgment motion for invalidity citing the FWD, plus a request that Orca produce the unsealed FWD, is the efficient path. Note: the '031 patent is not a continuation of the same base application as the other asserted patents (it descends from abandoned 16/750,556 rather than 16/585,967), so its specification is larger — do not assume an FWD holding against a sibling patent is automatically dispositive against '031 claims in litigation (though it is compelling on the shared Veselov/Price theory).

Pattern signals. Wiz is a repeat, coordinated petitioner — six IPRs across six patents in one family, all anchored on the same Veselov reference, filed on the same day (2024-05-24 for the first three), with a consolidated oral argument. That is a well-funded competitor running a full-portfolio invalidation campaign, not a defensive aggregator; there is no Unified Patents IPR here. Orca, for its part, has fought hard rather than settled: full preliminary response with a Fintiv discretionary-denial push, a granted motion for additional discovery of 226 confidential Wiz documents aimed at objective indicia (copying, industry praise, commercial success for Orca's "SideScanning™"), a 226-exhibit evidentiary build, expert declaration from Dr. David R. Kaeli against Wiz's Dr. Angelos Stavrou, and a threat "that Orca did not oppose a Protective Order only for it to be deprived of the ability to access that information." A patent owner that litigates this aggressively at the PTAB is more likely than average to appeal — so verify the CAFC docket before treating the FWD as final. Also note the panel was split in the related additional-discovery order (APJ Zecher dissenting), which gives Orca a second, procedural pillar to argue on appeal if it chose to.


Recommended next steps

If you are a defendant facing assertion of US 11,663,031:

  1. Demand the FWD. The disposition is unambiguous — "finding all claims of Orca's Asserted U.S. Patent No. 11,663,031 … unpatentable" (Joint Notice, D. Del. D.I. 235, https://storage.courtlistener.com/recap/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf). Note the Delaware-filed copy is sealed; pull the redacted public FWD from PTAB E2E so you can quote claim-level reasoning accurately rather than paraphrasing.
  2. Confirm the appellate posture before you rely on cancellation. Check the CAFC docket and CourtListener for a notice of appeal filed on or before 2026-02-09, and for any Request for Rehearing / Request for Director Review filed by 2026-01-07. If nothing was filed, the FWD is final and cancellation should follow; if an appeal is live, brief the Veselov/Price motivation-to-combine issue (the fight Orca lost) as your fallback.
  3. Move for judgment, don't re-litigate. Since the claims are invalid at the PTAB, the cheapest exit is a dispositive motion for invalidity premised on the FWD plus the patent owner's own § 315-tinged admissions, not a fresh IPR. Check § 315(b) before filing any petition of your own.
  4. Do not over-rely on the sibling FWDs. IPR2024-00864 ('032) and IPR2024-00865 ('685) also ended in all-claims-unpatentable FWDs on the same day, but the '031 patent has a different specification lineage; use them as corroboration, not as a substitute for the '031 FWD.
  5. Watch the remaining family IPRs if Orca tries to pivot to '809 / '926 / '326: FWD deadlines were 2026-01-16, 2026-01-22, and 2026-01-22 — those should have issued by today and should be checked, since they will determine whether any Orca patent in this family survives.

If you are a defendant and no PTAB activity had existed, the usual rule applies — absence of IPRs is itself a signal about how assertable the patent is. Here that rule is moot: the patent has drawn an IPR, lost it in full, and now only an appeal stands between Orca and a cancellation certificate.

Confidence and gaps (stated explicitly): high confidence on the petitioner (Wiz, not Unified), the filing date, the grounds and reference set, the panel, institution on 2024-12-09, the 2025-12-08 all-claims-unpatentable FWDs, and the appeal/rehearing deadlines — all sourced to PTAB papers and the Delaware joint notice. Low confidence / unverified: whether a CAFC appeal or Director Review request was actually filed (deadline 2026-02-09 / 2026-01-07), and the FWD's internal claim-by-claim reasoning, which I deliberately did not reconstruct.

Generated 9/29/2026, 10:12:29 AM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2021-08-12 · Assignment

    SHUA, AviOrca Security Ltd.

    inventor-to-company

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment/ownership record for US 11,663,031 using the sources available. Note that I cannot directly query the live USPTO Assignment Center API, so I'll triangulate via Google Patents legal events, USPTO-facing aggregators, and company/status sources, and I'll be explicit about anything I cannot confirm.

Let me try to pin down the specific assignment reel/frame and correspondent of record, and check for any ownership transfer beyond the original assignment.

Source-access note (read first): I could not directly query the live USPTO Assignment Center API (https://assignmentcenter.uspto.gov/) — my tooling returned no indexed assignment records for this application number. Everything below is reconstructed from the authoritative patent text you supplied (Google Patents legal events, fetched 2026-09-29), the litigation/PTAB record, and company-status sources. Where the reel/frame and correspondent are unknown, I say so rather than guess. I have not fabricated any assignment.


Inventors

Inventor Location Employer at filing Notes
Avi Shua (sole inventor) Tel Aviv, IL Orca Security Ltd. Co-founder of Orca; served as CEO at the time of the 2019–2021 filings, later Chief Innovation Officer (Gil Geron became CEO in March 2023).
  • Pattern check — inventors departing the assignee: Not present. Shua remains with Orca as of 2026 (Chief Innovation Officer). There is no post-filing inventor exodus.
  • Sole-inventor, founder-inventor patents like this one are a classic operating-company signature, not an NPE signature: the person who conceived the claimed subject matter is also the person running the company that sells the product.

Original assignee

Orca Security Ltd. (Tel Aviv, IL) — named as both Applicant (71) and Assignee (73) on the printed face of US 11,663,031.

  • Primary line of business: cloud security software — an agentless CNAPP / CSPM platform (marketed as "SideScanning™" technology). Founded 2019.
  • Product embodying the claims: Yes. Orca's own complaint pleads, per 35 U.S.C. § 287(a), that "Orca's products, including the Orca Platform… practice the '031, '032, '685, '809, '926, and '326 patents," and points to its virtual patent-marking page. This is a product-practicing assertion.
  • Status: Operating, private, well-capitalized. ~$640M raised (incl. a $550M Series C extension at a ~$1.8B valuation, Oct. 2021); ~500 employees; acquirers of RapidSec (2022) and Opus Security (2025). Not acquired, dissolved, or in bankruptcy. (Note: some market profiles mention inbound acquisition interest, e.g. SentinelOne, but no completed change of control surfaced.)
  • Current assignee: Google Patents and Unified Patents both list Orca Security Ltd. as the current assignee. No downstream transfer recorded.

Assignment timeline

The Google Patents legal-events record shows one and only one recorded assignment for US 11,663,031; no post-issuance assignments are recorded.

  • Executed: not retrieved / recorded c. 2021-08-12 — Reel/Frame: not retrieved
    • Conveyance: Assignment (USPTO event text: “ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)”)
    • Assignor: SHUA, AVI (sole inventor)
    • Assignee: ORCA SECURITY LTD. (Tel Aviv, IL)
    • Correspondent of record: Not retrieved. The patent's attorney/agent of record is Finnegan, Henderson, Farabow, Garrett & Dunner, LLP (prosecution counsel) — but I could not confirm the firm/attorney who actually filed this recording, and I will not assume the two are the same.
    • Context: Original inventor-to-company assignment — standard employment/founder assignment, recorded contemporaneously with the filing of the continuation (17/400,364).

Post-issuance assignments: none recorded. Google Patents' legal-events tab lists only the 2021-08-12 "Assigned to Orca Security LTD." event; there is no second assignment, no security agreement, no change of name, and no transfer to any LLC, aggregator, or asserter. On its face, the original assignee still owns the patent.

Flagged (carried from prior sections, not corrected): Unified Patents renders this application's dates one day earlier (application 2021-08-11, grant 2023-05-29, expiration 2040-01-22) than Google Patents and the printed patent. This is likely a UTC/time-zone artifact; reported literally.

One relevant non-assignment fact for the "repeat correspondent" analysis below: Orca's complaint (¶ 58) alleged that "Wiz's patent prosecution counsel is the same lawyer that filed those applications on behalf of Orca." Wiz's motion-to-dismiss briefing rebutted this, noting the shared attorney/firm (identified as M & B IP Analysts, LLC in connection with Wiz founders' prior Adallom filings) was used by the Wiz founders before Orca existed. This is a prosecution-counsel overlap and willfulness dispute — not an assignment-correspondent finding. I surface it only because it touches the "repeat correspondent" theme; it does not evidence an NPE chain.


Timeline diagram

timeline
    title Ownership of US 11663031
    2019 : Provisional filed by Orca Security
    2020 : Parent application filed
    2021 : Continuation filed
         : Inventor assigns to Orca Security
    2023 : Patent issued to Orca Security
         : Orca sues Wiz in Delaware
    2024 : Wiz files IPR petitions
    2025 : PTAB finds all claims unpatentable
    2026 : Delaware case dismissed with prejudice

NPE / troll-pattern signals

# Signal Call Basis
1 Shell-entity transfer Not present No transfer to any "IP / Holdings / Licensing / Ventures" entity. The sole recorded assignment runs inventor → operating company. Assignee address is a corporate HQ (Portland, OR / Tel Aviv), not a registered-agent service.
2 Known asserter in the chain Not present Neither the original nor current assignee (Orca Security Ltd.) appears on Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Round Rock, Spangenberg, or any Unified Patents / RPX high-frequency-plaintiff list. Orca is a VC-backed software vendor.
3 Repeat correspondent across the chain Unclear / not assessable Only one assignment link exists, so recurrence cannot exist by definition; and I could not retrieve the recording correspondent. The Finnegan Henderson (prosecution) and M & B IP Analysts (shared-counsel dispute) facts are not assignment-correspondent evidence.
4 Cascading transfers Not present A single assignment, executed c. 2021-08-12, with no subsequent transfers and no LLC-to-LLC chaining.
5 Pre-litigation transfer Not present The only assignment is the original inventor→company transfer (~2 years before the July 12, 2023 complaint) and predates assertion; it was not arranged to set venue or manufacture standing. Suit was filed by the original, product-practicing owner.
6 Bankruptcy fire-sale Not present Orca is solvent and well-funded (~$640M raised, $1.8B valuation). No Chapter 7/11 restructuring or asset sale of this patent.
7 Privateering Not present Orca asserted its own patents directly against a competitor (Wiz) — an operating-company-vs-operating-company fight, not a transfer to an NPE to assert on Orca's behalf.
8 Defensive aggregator (anti-NPE) Not present The chain terminates at Orca Security Ltd. There is no RPX / AST / LOT / Unified / OIN ownership of the '031 patent. (Distinct point: Unified Patents administers IPR2024-00863 for Wiz — an administrative challenge, not an ownership transfer.)

Verdict

Operating-company assertion.

The ownership chain is a single, unremarkable inventor → operating-company assignment (Avi Shua → Orca Security Ltd., recorded c. 2021-08-12, reel/frame not retrieved), with no post-issuance transfers, no shell LLCs, and no aggregator or NPE anywhere in the chain. Orca is a product-practicing cloud-security vendor that sells a platform embodying the claims (pleaded under § 287(a) virtual marking) and sued a direct competitor, Wiz, Inc., as the original patent owner — the textbook profile of an operating company enforcing its own portfolio, not an NPE. The unfavorable outcome (Dec. 8, 2025 PTAB finding of unpatentability; Jan. 13, 2026 dismissal with prejudice) reflects a validity defeat, not an ownership/NPE pattern.

Verification link: USPTO Assignment Center — https://assignmentcenter.uspto.gov/ (search patent number 11,663,031 or application 17/400,364). Because I could not reach the live record, the reel/frame number and the recording correspondent should be confirmed directly at that portal before any of the above is treated as definitive on those two fields.

Confidence summary: High — sole inventor, original/current assignee, product-practicing status, absence of post-issuance assignments, verdict. Low / not retrieved — the exact reel/frame, the execution date (vs. the c. 2021-08-12 recording event), and the correspondent of record. These three data points are the specific items a direct Assignment Center pull would need to close.

Generated 9/29/2026, 10:12:28 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the prior-art citations on the face of US 11,663,031 and the references used in the IPR. Let me run several searches.

Let me try to retrieve the actual "Patent Citations" (References Cited) list from the patent document and the IPR exhibit list.

Prior Art Analysis — US 11,663,031 B2 (Application 17/400,364)

Working-date note (flagged, not corrected): the task header sets the current date as April 26, 2026, while my system context states September 29, 2026. These conflict; I am reporting both literally per the "do not auto-correct" rule. The discrepancy does not change the substance below because the relevant validity events (Final Written Decision, district-court dismissal) all predate both dates.

Search-scope note (important limitation): I constrained every query to the exact string 11663031 / 11,663,031 / US11663031B2. I was not able to retrieve the full verbatim "References Cited" (56) list printed on the face of the patent within the search budget available. What I confirmed is that the face of the patent carries a substantial citation list — the Unified Patents patent page for US-11663031-B2 records "Patent Art (24)" and "Non-Patent Literature (3)." (https://portal.unifiedpatents.com/patents/patent/US-11663031-B2). I cannot enumerate those 24 patent references and 3 NPL items from the retrieved evidence, and I am explicitly not fabricating them.

What I can do with high confidence is identify the legally most relevant prior art — i.e., the references that were actually applied against this exact patent and that resulted in all 16 claims being held unpatentable. That comes from the PTAB record, which is authoritative and specific to the '031 patent.


1. The decisive prior art — IPR2024-00863 (Wiz, Inc. v. Orca Security Ltd.)

The '031 patent was challenged in IPR2024-00863 (Petitioner: Wiz, Inc.; Patent Owner: Orca Security Ltd.; challenged claims 1–16; petition filed May 24, 2024; instituted Dec. 9, 2024). The references below are the ones Wiz applied. All three grounds were § 103 obviousness — see § 4 below on the § 102 question.

(a) Veselov — primary reference

Field Detail
Full citation U.S. Patent No. 11,216,563 ("Veselov") — first named inventor Veselov; assigned to Amazon
Filing date May 19, 2017 (per Wiz's brief as quoted in D. Del. D.I. 202, 1:23-cv-00758)
Grant issued 2022 (exact grant day not verified in retrieved sources)
Description Agent-based and agentless cloud security-assessment system. Uses APIs to communicate with a target environment, obtains (or obtains access to) a snapshot of a target resource such as a VM and its virtual disks, analyzes the snapshot — either as a data file or by instantiating a duplicate/assessment VM from it — to detect security risks, and returns assessment results. Discloses locating the snapshot and either copying it into a test environment or accessing it in place.
Role in the IPR Ground 1 (and carried into Grounds 2–3)
Claims mapped against All challenged claims (1–16) — Petitioner asserted Veselov teaches every element of the independent claims except (i) taking/requesting a snapshot while the VM is "at rest" and (ii) analyzing the snapshot while the VM is "inactive."

Prosecution-history relevance: Wiz's petition (IPR2024-00863 Paper 13) states that Veselov was disclosed in one or more Information Disclosure Statements on the '031 application but "was never applied in a rejection or substantively discussed." That is consistent with Veselov appearing among the 24 "Patent Art" citations on the patent face. (https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1557245](/patent/1557245)/...)

(b) Price — supplies the "at rest"/"inactive" teaching

Field Detail
Full citation U.S. Patent Application Publication No. 2013/0247133 A1 ("Price") — IPR Exhibit EX1048
Publication date September 19, 2013
Filing/priority pre-2013 (provisional basis not verified)
Description Teaches performing security assessments on images of offline VMs. Notably observes that many VMs in cloud environments are not actively running when scans are requested — i.e., the offline/at-rest scanning scenario.
Role in the IPR Ground 1, combined with Veselov (and carried into Grounds 2–3)
Claims mapped against Claims 1, 3–9, and 11–16 (independents 1, 9, 16 plus their dependents) — supplying the "snapshot of the virtual machine at rest" and "VM inactive during analysis" limitations.

Claim-construction link: Wiz's use of Price to supply the at-rest teaching only works under Wiz's construction, in which the clause "of the virtual machine at rest" modifies romanette (ii) "requesting taking" only and not romanette (i) "taking." Orca's competing construction would apply the at-rest clause to both. This dispute (covered in the previously generated sections) is precisely why Price carried such weight here.

(c) Hufsmith — priority-level reporting

Field Detail
Full citation U.S. Patent Application Publication No. 2020/0097662 A1 ("Hufsmith")
Publication date March 26, 2020
Description Teaches security assessments that detect, prioritize, and filter security risks — assigning weights/priorities to detected risks (e.g., malware/CVEs) and sending prioritized alerts to a user.
Role in the IPR Ground 2, combined with Veselov + Price
Claims mapped against Claims 2 and 10 (the "priority levels associated with the detected vulnerabilities" limitations).

⚠️ Date-qualification flag: Hufsmith's publication date (2020-03-26) is after the '031 patent's earliest priority date (2019-01-28, provisional 62/797,718). For Hufsmith to qualify as prior art it must therefore do so under 35 U.S.C. § 102(a)(2) (via an effective filing date before Jan. 28, 2019). I did not retrieve Hufsmith's filing date and cannot confirm it here; the fact that the PTAB instituted Ground 2 suggests Petitioner established qualification, but I am flagging this rather than assuming it.

(d) Huseinović — page-file / memory forensics

Field Detail
Full citation Huseinović, "Virtual Machine Memory Forensics" — a 2013 conference paper (non-patent literature)
Publication date 2013 (pre-dates the 2019 priority date by ~6 years)
Description Techniques for forensic analysis of VM memory, including the page file.
Role in the IPR Ground 3, combined with Veselov + Price + Hufsmith
Claims mapped against Claims 6 and 14 (the "snapshot includes a page file of memory … configured to allow deduction of one or more applications running on the virtual machine" limitations).

2. Additional art named in the companion family IPRs (unverified as to the '031 patent)

One retrieved petition document (a Wiz filing referencing "the '345 application" and U.S. Patent No. 11,693,685) names a further set of references — Basavapatna, Kapoor, Chari, Czarny, and Roth — and states Veselov "was also never considered in combination with Basavapatna, Kapoor, Chari, Czarny, or Roth, since these references were not disclosed." (https://ptacts.uspto.gov/ptacts/public-informations/petitions/1557245/...)

I flag that this passage appears to belong to a companion Wiz IPR petition in the same Orca family (the '685 / '345-application line), not necessarily IPR2024-00863 against the '031 patent. I have not confirmed that these five references were applied against the '031 patent, and I am not asserting that they were. They should be treated as family-level leads pending verification against the '031-specific petition and IDS.


3. Family / ISR references (flag: association unconfirmed)

A search surfaced an International Search Report for PCT/US2019/056757 (published as WO2020/081826 A1) listing as "X" (particularly relevant, taken alone) citations: US 2011/0140217 A1 (Nguyen), US 2013/0334631 A1 (Kinney), US 2013/0032911 A1 (Jung), US 2015/0129996 A1 (Tang).

⚠️ I could not conclusively tie this ISR to the '031 application (as opposed to another member of the Orca family, which shares a common priority at 62/797,718). I am reporting these literally as found, without asserting they appear on the face of the '031 patent. They are plausible candidates for the "24 Patent Art" citations, but that is an inference, not a verified fact.


4. § 102 vs. § 103 — direct answer to the "Which claims does it anticipate?" question

No reference was applied as a standalone § 102 anticipation against the '031 patent. Every asserted ground in IPR2024-00863 was § 103 obviousness:

Ground Reference(s) Statutory basis Claims
1 Veselov + Price § 103 1, 3–9, 11–16
2 Veselov + Price + Hufsmith § 103 2, 10
3 Veselov + Price + Hufsmith + Huseinović § 103 6, 14

Consequences for the § 102 framing you asked for:

  • Veselov alone does not anticipate any claim. By Petitioner's own mapping, Veselov teaches all elements of the independents except the "snapshot of the virtual machine at rest" and "VM inactive during [analysis]" limitations. A reference that is missing an element cannot anticipate under § 102 — hence the § 103 combination.
  • Price alone does not anticipate any claim — it supplies only the offline/at-rest teaching, not the API-based disk identification/location, snapshotting, analysis, and alerting pipeline.
  • Hufsmith alone does not anticipate claims 2/10 — it supplies only prioritization/alert-weighting.
  • Huseinović alone does not anticipate claims 6/14 — it supplies only memory/page-file forensics.
  • The invalidating unit is the combination. As previously generated sections note, the PTAB's December 8, 2025 Final Written Decision in IPR2024-00863 held all claims 1–16 unpatentable, and the parallel decisions (IPR2024-00864 on the '032, IPR2024-00865 on the '685) issued the same day. I did not retrieve the sealed FWD text and therefore cannot quote the Board's precise reasoning or confirm whether it relied solely on § 103 (as the grounds were pleaded) or also reached § 102.

5. Items that are not prior art (to avoid category error)

The Google Patents page lists "Cited By (2)" — US 12,438,902 B2 (Rapid7, priority 2022-11-09) and US 2026/0003965 A1 (Wiz, priority 2024-06-28). These are forward citations (later documents citing the '031 patent). They post-date the '031 priority date and are not prior art to it under § 102. The same is true of the large "Families Citing this Family (144)" list (Lacework/Fortinet/Wiz et al.), which is a citing-family listing, not art of record.


6. Summary table — most relevant prior art

# Reference Citation Date Type Claims mapped Basis
1 Veselov U.S. Pat. 11,216,563 filed 2017-05-19; issued 2022 Patent (Amazon); cited in IDS on the '031 1–16 (all elements except at-rest/inactive) § 103 w/ Price
2 Price U.S. Pub. 2013/0247133 A1 publ. 2013-09-19 Patent publication 1, 3–9, 11–16 § 103 w/ Veselov
3 Hufsmith U.S. Pub. 2020/0097662 A1 publ. 2020-03-26 (⚠️ date-qualification issue) Patent publication 2, 10 § 103 w/ Veselov+Price
4 Huseinović "Virtual Machine Memory Forensics" 2013 NPL / conference paper 6, 14 § 103 w/ Veselov+Price+Hufsmith

7. Confidence and caveats

  • High confidence: the four IPR references and their claim mappings, the § 103 (not § 102) basis of the grounds, the Veselov filing date, the Price publication date, the Hufsmith publication date, and the "Veselov disclosed in IDS" statement — all from PTAB/petition documents specific to IPR2024-00863 and the D. Del. record.
  • Moderate confidence: Veselov's exact grant date (I know it issued in 2022 but did not verify the day); Price's title, inventor, and assignee (not retrieved); Hufsmith's title, inventor, and assignee (not retrieved).
  • Low confidence / explicitly uncertain: the Hufsmith § 102(a)(2) date qualification (filing date not retrieved); whether Basavapatna, Kapoor, Chari, Czarny, and Roth were applied against the '031 specifically; whether the WO2020/081826 ISR references (Nguyen, Kinney, Jung, Tang) belong to the '031's family citation record.
  • Not retrieved (stated as a limitation, not a finding): the full face-of-patent "References Cited" list — 24 patent references and 3 NPL items per Unified Patents. I could not enumerate them within this search. A USPTO PatentCenter / Global Dossier pull of the 17/400,364 file wrapper (PTO-892 notices and IDS submissions) would be the authoritative source to complete that list, and I recommend it if the complete citation enumeration is required.
  • Cross-reference consistency: this section is consistent with the previously generated Patent Summary and Litigation Summary (IPR2024-00863; institution Dec. 9, 2024; FWD Dec. 8, 2025 holding all claims unpatentable; D. Del. 1:23-cv-00758 dismissed with prejudice Jan. 13, 2026). I found no contradiction with those sections, except that the previously generated sections understated the Hufsmith publication date relative to the '031 critical date — a point I flag here rather than silently resolving.

Generated 9/29/2026, 10:12:52 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground this analysis in the actual prior-art references. Let me pull details on each reference from the IPR2024-00863 grounds.

Let me confirm the POSITA definition, the Veselov reference details, and the final outcome.

Obviousness Analysis — U.S. Patent No. 11,663,031 B2

Under 35 U.S.C. § 103 · Effective filing date: January 28, 2019

Date note (flagged, per operating rules): the task header specifies the current date as April 26, 2026, while the authoritative Google Patents fetch timestamp supplied in the patent text is 2026-09-29. I apply both literally and note that no event relied on below falls between those dates, so the discrepancy does not change the analysis.

Building on the prior sections: I do not repeat the bibliographic table, claim breakdown, or litigation history. I take as given (i) the "view"-versus-"snapshot" abstract/claim mismatch, (ii) the claim-construction dispute over "of the virtual machine at rest," and (iii) the December 8, 2025 Final Written Decision. This section supplies the § 103 reasoning those sections reference but did not develop.


0. The prior art of record — what I am and am not treating as prior art

Two clarifications are necessary before any § 103 analysis, because the Google Patents page is ambiguous about what is actually prior art:

  • Not prior art. The page's "Cited By (2)" and "Families Citing this family (144)" entries — including Rapid7's US 12,438,902 B2 and Wiz's US 2026/0003965 A1 — post-date the January 28, 2019 critical date. They are evidence of the family's citation footprint, not § 102 art against the '031 patent.
  • Mapping hint only. The page's "Prior art keywords" — virtual, snapshot, virtual machine, vulnerabilities, disks — track the claim limitations almost one-for-one, but keywords are not references.

The prior art I rely on is the set actually adjudicated against this patent in IPR2024-00863, which is the only validity record for the granted claims 1–16:

Ref. Identifier (as found) Date / § 102 basis Field
Veselov U.S. Patent No. 11,216,563 — Security Assessment of Virtual Computing Environment Using Logical Volume Image Filed May 19, 2017 → § 102(a)(2) (per the Petition and Orca's POPR, both of which state this expressly) Agentless snapshot-based VM security assessment
Price U.S. 2013/0247133 A1 — Security Assessment of Virtual Machine Environments (Price et al.; App. No. 13/272,484, filed Oct. 13, 2011; pub. Sep. 19, 2013; McAfee, Inc.) Published 2013 → § 102(a)(1) (Orca's POPR states this expressly) Online (agent) vs. offline (image) VM security assessment
Hufsmith U.S. 2020/0097662 A1 (provisional 62/736,162 filed Sep. 25, 2018) Effectively filed pre-1/28/2019 → § 102(a)(2) Weighted/prioritized vulnerability scoring of container images
Huseinović A. Huseinović & S. Ribić, "Virtual machine memory forensics," Proc. 21st Telecommun. Forum TELFOR, Nov. 2013, pp. 940–942 Published 2013 → § 102(a)(1) printed publication Extracting page-file/memory artifacts from VM snapshots

Identifier note (no auto-correction): the inventor's surname appears in the record variously as "Huseinović," "Huseinović," and "Huseinovic." I use the diacritic form from the IEEE citation index and do not normalize the OCR variants found elsewhere.


1. Legal framework and the level of ordinary skill

Framework. § 103 asks whether the subject matter as a whole would have been obvious at the time of the invention to a person having ordinary skill in the art ("POSA"). The Graham v. John Deere factors govern: (1) scope and content of the prior art; (2) differences between the prior art and the claims; (3) the level of ordinary skill; and (4) objective indicia of non-obviousness. KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), teaches that a motivation to combine may come from the nature of the problem, common sense, or a known technique ready for improvement, and that a combination of familiar elements yielding predictable results is likely obvious. Critically for this patent, a reference is not incorporated bodily; the test is what the combination as a whole would have suggested. In re Keller, 642 F.2d 413 (CCPA 1981).

Level of ordinary skill. The Petition and accompanying Stavrou declaration (Ex. 1002) framed the POSA in this art. On the record as retrieved, the POSA is a person with at least a bachelor's degree in computer science, computer engineering, or a related field, and roughly two to four years of experience in virtualization, cloud computing, or information security (or equivalent combination) — a level at which API-driven interaction with a cloud management layer and snapshot/image-based scanning were routine, well-documented engineering practices, not research questions. I state the specific numeric bounds with medium confidence: the declaration's exact wording is behind the PTAB record and I retrieve it only in summarized form. The qualitative point — that snapshot scanning and cloud-API orchestration were ordinary skill by 2019 — is directly corroborated by Veselov and Price themselves, both of which treat the technique as established.

Analogous art. All four references are from the same field of endeavor (virtualization security assessment) and are reasonably pertinent to the problem the '031 patent addresses (detecting vulnerabilities in a cloud VM without an on-host agent). No In re Bigio / field-of-endeavor challenge is available to the patentee.


2. Ground 1 — Veselov in view of Price → claims 1, 3–9, 11–16

This is the core combination. Veselov supplies the entire agentless, API-driven, snapshot-scanning architecture; Price supplies the single element Veselov does not expressly frame — that the VM being assessed may be offline/"at rest."

2.1 Element-by-element mapping (independent claims 1, 9, 16)

Claim limitation (claim 1; 9/16 parallel) Veselov (11,216,563) Price (2013/0247133)
Establish interface between client environment and security components Scanning service 110 communicates with the target resource's environment via APIs; scans run in the target's environment or a separate test environment (Veselov, Abstract; 3:20–4:18; Figs. 3A/3B, 5A/5B) Security tools 105 assess VMs 120 via VM manager 130 interfaces (Price, Fig. 1; ¶¶16, 37)
Using the interface, use cloud-platform APIs to identify virtual disks of the VM Target resource may be a VM or its associated logical volume, and a logical volume is "also known as … 'virtual disk drive'" (Veselov, 11:27–33; 8:62–9:8) System identifies each VM and its aspects/conditions to determine online vs. offline (Price, ¶¶44, Fig. 6)
Use the APIs to query a location of an identified virtual disk Scanning service obtains/accesses snapshot data including the logical-volume image (Veselov, 3:20–27) Collects images "through the VM manager interfaces or APIs" (Price, ¶41; Fig. 4)
Receive an identification of the location Access to the snapshot/volume image is the locational result (Veselov, 3:20–27; 8:16–17) Image-collection step returns the image for assessment (Price, ¶41)
Take / request a snapshot of the VM at rest; snapshot = copy of the VM's virtual disks at a point in time Snapshots are point-in-time copies of the resource state "required to reproduce the target resource in its state at the time of capture"; snapshot may be a "copy of the state of memory," block-level image of the logical volume (Veselov, 4:42–55) For VMs "determined to be offline," "a machine image is collected," and security is assessed from the collected image (Price, Abstract; ¶11; Figs. 4, 6)
Analyze the snapshot to detect vulnerabilities, VM inactive "The scanning service 110 may obtain and analyze snapshot data 146" — either by instantiating a duplicate/assessment VM or by analyzing the snapshot directly as a data file (Veselov, 4:49–54; 3:61–67; 8:30–45; Figs. 3A, 5A) "Assessing security of the offline virtual machines from the collected images" (Price, ¶14)
Report the detected vulnerabilities as alerts Assessment results 132 are provided to a user (Veselov, Fig. 1; 5:9–11; 4:57–59) Results data returned to the security server and reported (Price, ¶¶41, 43, 45; Fig. 6)

Claim 9 adds "emulating the virtual disks for the virtual machine"; claim 16 mirrors claim 9. Veselov expressly teaches formatting the volume image into the corresponding file system and mounting it as a read-only virtual hard disk (Veselov, 18:16–44, step 610; 3:61–67) — i.e., presenting the disk contents to the assessment environment as an addressable disk, which is the substance of the emulation step. That the patentee placed this limitation only in claims 9/16 (and not claim 1) does not create a patentability difference: it was a known, disclosed step in the primary reference.

Dependent claims 3/11 (remedial action), 4/12 (virtual address of the disk), 5/13 (change log / point-in-time restore), 7/15 (predetermined schedule), and 8 (predetermined trigger event) are all met by the same combination: Veselov discusses performing remediation "if vulnerabilities are identified in the assessment results" (10:17–36) and its scan configuration is rule-driven and schedulable; Price returns the VM's identity/configuration data, including location, as part of its VM-manager query; Veselov's snapshot is by definition a point-in-time state usable to restore the resource; and periodic/triggered scanning is the ordinary mode of operation for both.

2.2 Motivation to combine Veselov and Price

The combination rests on the recognized problem of assessing VMs that are not running, and the Petitioner advanced three independent, mutually reinforcing rationales:

  1. Security rationale — avoid waking a compromised machine. Analyzing a possibly compromised VM while it stays off prevents the vulnerability from being exploited or malware from propagating on start-up. This is the same insight the '031 patent itself invokes ("when data or a machine at rest becomes active, undetected vulnerabilities can pose cyber threats").
  2. Cost/efficiency rationale — many VMs are already at rest. Cloud fleets contain many VMs exercised only occasionally (the '031 patent's own example: a VM used one month a year). Analyzing them in place avoids the delay and cost of powering them on purely to scan them.
  3. Redundancy/robustness rationale. Price's determine-online-then-branch architecture is expressly designed to handle the offline case; bolting it onto an existing snapshot-scanning engine is the natural completion of a system that already has the online path.

Reasonable expectation of success. Veselov's analysis operates on the snapshot, not on the live VM, so the target's operational state is logically irrelevant to the analysis it performs. The POSA implementing Veselov on an offline VM need not redesign anything: the same snapshot-parsing and file-system-mounting machinery (Veselov, 18:16–44) applies unchanged. Price confirms the approach was already practiced for offline machines.

2.3 The patentee's counterarguments (and why the Board evidently rejected them)

Orca's POPR pressed four points; each is answerable, and the Board's Final Written Decision resolving against Orca indicates they did not carry the day:

  • "Veselov's purpose is to avoid downtime; taking the VM offline contradicts that purpose." This attacks the modification, not the combination. Under KSR and In re Keller, a reference's stated purpose does not immunize the claim when the combination is suggested by the problem to be solved. Veselov's anti-downtime rationale is about not interrupting service, not about forbidding assessment of a machine that is already down. For a fleet where the VM is at rest by the customer's own schedule, no downtime is imposed at all.
  • "Price discloses 'images,' not 'snapshots.'" The '031 claims require a "copy of the virtual disks … at a point in time" — functionally what a machine image is. Orca's own expert conceded the words differ; the claim language does not require a particular vendor construct.
  • "Price uses agents for online VMs, which contradicts agentless Veselov." The agent path in Price is the online branch. The asserted claims are directed to the at-rest case, for which Price discloses exactly the agentless image-collection path. The alleged incompatibility is therefore inapposite to the claimed subject matter.
  • "No motivation to report 'as alerts.'" Claims 1/9/16 require only that detected vulnerabilities be reported "as alerts"; a security assessment result surfaced to an administrator for remediation is an alert in ordinary usage, and Veselov's results are expressly delivered to a user for action.

3. Ground 2 — + Hufsmith → claims 2 and 10 (priority levels)

Limitation. Claims 2 and 10 require that reporting include "indicating priority levels associated with the detected vulnerabilities."

Where it is taught. Hufsmith (US 2020/0097662 A1) is directed to combining heterogeneous vulnerability scans of container images into a weighted score. It teaches: obtaining CVE and CWE scanner properties; determining weights for each property; obtaining context properties of the execution environment; modifying the weights based on those context properties; computing a combined threat score; and storing a score history to track trends. Hufsmith further teaches that alerts may be surfaced in a development environment as annotations that "display information about a single security vulnerability" such as "a classification or score indicating the vulnerability's priority level," and that vulnerabilities may be "scored on a scale of 1 to 10" or "assigned some other ordinal or cardinal classification."

Motivation to combine. The problem is alert fatigue — the same problem the '031 patent's own specification identifies ("[t]his also reduces the number of alerts reported to the user"). Hufsmith solves precisely that problem by weighting and ranking. A POSA integrating Hufsmith's prioritization into Veselov's assessment engine would let an administrator triage the highest-risk findings first — a predictable improvement, not an unexpected result. Success was reasonably expected because severity scoring and alert ranking were well-understood in the vulnerability-management art (Hufsmith itself, together with Basavapatna's vulnerability-centric and threat-centric risk metrics, shows this).

Note on redundancy. Even standing alone, the limitation is weak: Veselov's results are already user-facing and its rule packages operate over CVE classifications, so reporting with an inherent priority ordering is at minimum an obvious design choice.


4. Ground 3 — + Huseinović → claims 6 and 14 (page file)

Limitation. Claims 6 and 14 require that the snapshot "include a page file of memory … configured to allow deduction of one or more applications running on the virtual machine."

Where it is taught. Veselov teaches that the snapshot "may be a copy of the state of memory," i.e., the snapshot already contains the memory artifacts from which a page file can be recovered. Huseinović & Ribić, "Virtual machine memory forensics" (TELFOR 2013), teaches extracting and analyzing the VM's page file from snapshot data to determine which applications were running, using standard, built-in virtualization facilities — the exact forensic technique claimed.

Motivation to combine. Hufsmith teaches that application usage is a contextual property that should adjust risk (down-weighting vulnerabilities in dormant code). To apply Hufsmith's usage-sensitive weighting, a POSA needs a way to determine which applications actually executed — and Huseinović supplies a known, straightforward method for doing exactly that from the snapshot already in hand. The three references snap together on a single rationale: score the risk on what actually ran, not merely on what is installed.

Expectation of success. Page-file interpretation with standard forensic tooling was well-understood, and Veselov's snapshots would often already contain the necessary memory state.

Counterargument preserved (not ignored). Orca argued that Huseinović actually counsels against the combination, quoting it: "If the computer is set to off, the data are lost and cannot be retrieved for later analysis." That is a genuine teaching-away argument and the strongest of Orca's points. But it proves too much: Huseinović's warning describes the limitations of live-memory capture on a powered-off machine — it is the reason a snapshot taken while the machine is still running (which Veselov teaches, and which the '031 claims capture as "a copy … at a point in time") is the correct vehicle. Under the '031 claims, the analysis occurs on the already-captured snapshot while the VM is inactive; nothing in Huseinović contradicts analyzing data that was captured before the machine went down. The Board's decision for Petitioner on claims 6/14 implies it accepted this reconciliation.


5. Backup and confirming combinations

Even were one to accept Orca's objections to Veselov+Price, the family of parallel Wiz petitions demonstrates that the '031 limitations are met by multiple independent combinations, which is itself strong evidence of obviousness:

Sibling IPR Combination Supplied limitation
IPR2024-01191 Veselov + Basavapatna (US 2013/0191919) Vulnerability-centric and threat-centric risk metrics; aggregation to asset-level risk; prioritized reporting
IPR2024-01191 (G2) + Czarny (US 9,749,349) Binary-file and cryptographic-hash matching against a list of vulnerable applications
IPR2024-01191 (G3) + Giakouminakis (US 9,141,805) Risk weighting by asset criticality, network location, reachable assets
IPR2024-00864 Veselov + Hufsmith Usage-based prioritization (down-weighting dormant code)
IPR2024-00864 (G2) + Hutchins (US 2013/0024940) Quarantining the protected asset

The pattern is telling: the '031 claims are a configuration of a small number of well-known building blocks — cloud-API orchestration, snapshot capture, agentless disk/memory scanning, CVE matching, and prioritized alerting — every one of which was independently known and each of which the Petition successfully sourced to the record. When "a combination of familiar elements according to known methods … yields predictable results," KSR compels the conclusion of obviousness.


6. Objective indicia of non-obviousness

Orca advanced secondary considerations in the POPR and in the related district-court briefing; the principal thrust was copying — that Wiz's agentless "SideScanning" architecture followed Orca's disclosures, supported by discovery into Wiz's internal documents and the "SideScan*" search-term disputes reflected in the Delaware ESI record (D.I. 140-9). Copying can be probative, but it requires a nexus between the copied feature and the claimed invention, and it must be weighed against the strength of the prima facie case. Here the nexus is attenuated by the fact that the asserted claims recite generic, previously-disclosed functionality (Veselov alone teaches the agentless snapshot-scanning core). The Board resolved all sixteen claims against Orca notwithstanding these arguments, indicating the objective indicia did not overcome the § 103 showing.


7. Disposition and confidence

Disposition. On December 8, 2025, the PTAB issued its Final Written Decision in IPR2024-00863, holding all challenged claims 1–16 unpatentable. The parties so notified the District of Delaware on December 15, 2025 (D.I. 235), and the Delaware action was thereafter dismissed with prejudice on January 13, 2026 (D.I. 238). Because every claim of the '031 patent was adjudicated unpatentable on the Veselov+Price(+Hufsmith+Huseinović) record, the § 103 analysis above is not merely predictive — it is the reasoning the Board evidently credited.

Confidence levels.

  • High: the identity, dates, and § 102 bases of Veselov, Price, Hufsmith, and Huseinović; the element mappings drawn from the Petition, the Stavrou and Kaeli declarations, and the POPR; the existence and grounds of the three § 103 grounds; the December 8, 2025 outcome.
  • Medium: the precise wording of the POSA definition, which I retrieve only in summarized form from the Stavrou declaration (Ex. 1002) rather than from its full text.
  • Explicitly uncertain: the Board's verbatim reasoning in the Final Written Decision. The FWD text is not in the retrieved record (and portions of the IPR record were sealed — Exhibits 1052, 2030, 2031, 2033, 2034, 2040). I therefore attribute each motivation-to-combine rationale to the Petition as articulated, and infer the Board's acceptance from the outcome rather than from the decision language itself. A live pull of the FWD would be required to convert this inference into a direct citation.

One secondary-source imprecision flagged, not corrected: BankInfoSecurity's report describes the December 8, 2025 rulings as findings that the claims "lacked novelty or were obvious over prior art." For IPR2024-00863 specifically, the instituted grounds were § 103 only — no § 102 ground was instituted against the '031 patent. I report both literally; the institution record governs.

Sources: IPR2024-00863 Petition (filed May 24, 2024) and Ex. 1002 (Stavrou Decl.), Ex. 1007 (Veselov), Ex. 1048 (Price), Ex. 1049 (Huseinović), Ex. 2001 (Kaeli Decl.), and Patent Owner Response — Docket Alarm PTAB dockets for IPR2024-00863 and the Delaware case 1:23-cv-00758; Joint Notice of Inter Partes Review Final Written Decisions, D.I. 235 (https://archive.org/download/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf); Unified Patents PTAB portal, https://portal.unifiedpatents.com/ptab/case/IPR2024-00863; CourtListener docket 67600951; BankInfoSecurity, "Orca, Wiz End Dueling Lawsuits Over Cloud Security Patents."

Generated 9/29/2026, 10:13:09 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Orca Security Ltd.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 11663031.