Invalidity dossier
US 6061797
Outside access to computer resources through a firewall
Current assignee: Trend Micro Inc
Added 9/24/2026, 3:50:12 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for authoritative information on this specific patent, including any CAFC 2026 docket activity.
Let me verify litigation/docket activity and confirm the bibliographic details from additional sources.
US Patent 6,061,797 — Analyst Summary
Scope note on the "CAFC 2026 docket" request: I searched for Federal Circuit / CAFC 2026 docket activity tied to this specific number and found none. I want to be explicit rather than fabricate: I could not locate any 2026 (or other) Federal Circuit appeal, PTAB proceeding, or district-court litigation naming U.S. Patent No. 6,061,797 as the patent-in-suit. Search results for CAFC activity returned unrelated 2026 decisions and unrelated patents. Treat the absence of docket activity as "not found in my searches," not as a certified negative — a definitive check requires PACER/Docket Navigator and the CAFC's own docket, which I cannot query directly here.
Bibliographic Data (from Google Patents and cited USPTO/report sources)
| Field | Value |
|---|---|
| Patent number | US 6,061,797 A |
| Title | Outside access to computer resources through a firewall |
| Application number | US 09/132,915 |
| Filing date (this application) | 1998-08-12 |
| Priority date | 1996-10-21 |
| Issue/grant date | 2000-05-09 |
| Inventors | Prashanth Jade; Victor Stuart Moore; Arun Mohan Rao; Glen Robert Walters |
| Original assignee | International Business Machines Corporation |
| Current assignee | Trend Micro Incorporated (assignment recorded 2010-05-17; effective 2010-03-31; REEL/FRAME 024390/0164) |
| Legal status | Expired – Lifetime (anticipated expiration 2016-10-21) |
| Relationship | Continuation under 37 CFR 1.53(b) of US 08/731,800 (issued as US 5,944,823) |
| Classification | H04L63/02 (firewalls); H04L63/0272 (VPNs); H04L63/029 (firewall traversal/tunnelling); H04L9/40 |
Data discrepancy flagged (literal reading, not corrected): The Google Patents page lists the parent US 08/731,800 with a priority date of 1996-10-16 in its "Related Parent Applications" table, while the priority date elsewhere on the same page and the specification text both say Oct. 21, 1996. The Chinese family member CN1107400C shows the priority as 1996.10.21 (US 731800). I am reporting this as-is; I do not auto-correct it. The weight of the record indicates the operative priority date is 1996-10-21.
Abstract (as granted)
A firewall isolates computer/network resources inside the firewall from networks, computers, and applications outside it. Inside resources are typically private databases and LANs; outside objects typically reach them over public networks such as the Internet. Ordinarily a firewall lets inside objects originate connections outward but blocks connections generated from outside in. The invention provides a "tunneling" mechanism operating on both sides of the firewall to establish such "outside-in" connections when requested by certain "trusted" outsiders. The goal is to minimize resources needed for tunneled connections while minimizing the security risk. The mechanism includes tunneling applications on interface servers inside and outside the firewall, plus a table of "trusted sockets" created and maintained by the inside tunneling application. Table entries define inside objects by special inside port, a telecommunications protocol to be used at each port, and a host object associated with each port. Each entry is "trusted" in that it is supposedly known only by individuals authorized to have tunneling access through the firewall from outside.
Plain-Language Overview of the Claims
This patent has two claims total — one independent claim (claim 1) and one dependent claim (claim 2). Note the claim set is unusually narrow for the disclosure.
Claim 1 — Independent (a "tunneling software application" on computer-readable media)
Plain-language reading:
- The invention is a software product (stored on computer-readable media) that runs on two computers that sit on opposite sides of a firewall and connect the two networks the firewall separates (an inside/secure network and an outside network).
- Its job: keep the secure objects in the first network isolated from the second network, while still allowing data to pass through the firewall between the two networks without compromising the security of the secure objects.
- The application is split into two program segments, one per computer: the first segment interfaces the firewall to the inside network; the second interfaces the firewall to the outside network.
- The first (inside) segment must:
- Create and maintain a table of "trusted objects" (this corresponds to the specification's "trusted sockets" table), where the table's objects are associated with the secure objects on the inside network; and
- Operate the first computer, relative to the firewall and the second computer, to send a copy of that table to the second computer for use by the second (outside) program segment.
Key takeaway: the independent claim captures the two-segment tunneling application plus the trusted-object table and its replication from inside to outside. It does not, by itself, recite the control connection or the request-validation/forwarding behavior.
Claim 2 — Dependent on Claim 1 (adds the control connection and validation/forwarding)
Plain-language reading — everything in Claim 1, plus:
- The first (inside) program segment establishes, with the firewall and the second computer, a private control connection through the firewall between the two computers; this control connection is normally inaccessible to communications directed from the outside network into the inside network.
- The second (outside) program segment must:
- Receive a communication directed from the outside network toward the inside network;
- Verify that the received communication is addressed to a trusted object designated in its stored copy of the trusted-object table; and
- Forward the data from that received communication to the first program segment (inside computer) through the private control connection — in a form that lets the inside segment deliver the data to the secure object without exposing that secure object to access from the outside network.
Key takeaway: Claim 2 adds the core security mechanism described throughout the specification — the private inside-initiated control channel, validation against the replicated trusted table, and data forwarding that never exposes the inside object directly to the outside network.
Supporting Context from the Specification (consistent with the claims)
- Architecture: Firewall computer 1; interface server A inside, interface server B outside (FIG. 1). Server A maintains the trusted-socket table, opens a control connection to B, and passes a copy of the table to B (FIG. 2, items 10–12).
- Request handling: Outside requests to non-trusted sockets are ignored; valid requests cause B to spawn a task (e.g., B.1), connect to the requesting object, and forward the request plus the task identity to A over the control connection; A spawns a task (e.g., A.1) that builds the inside data-connection segments and instructs the firewall to extend the connection to B.1 (FIG. 3, items 20–25).
- Trusted-socket table format (FIG. 4): each entry = port number (inside address), protocol (examples given: NNTP and HTTP), and host-object identity.
- Optional inside re-validation and control-connection timeout/re-establishment are described (FIG. 5, items 46–51); these appear only in the specification/dependent-claim context, not as standalone independent-claim limitations.
Inventorship / Family Note (relevant if you are clearing rights)
- The parent patent US 5,944,823 lists the same four inventors (Jade, Moore, Rao, Walters) per Unified Patents' record for US-5944823-A.
- Foreign family members identified: EP 0932965 B1, WO 1998018248 A1, JP 3285882 B2, KR 100330619 B1, CN 1107400 C, CA 2269544 C, DE 69731965 T2, RU 2178583 C2, CZ 295858 B6, AT 285151 T1, ES 2231895 T3, MY 127656 A, TW 362177 B, HU P0000336, PL 332828 A1, BR 9712635 A.
- Because the patent expired 2016-10-21, any 2026 CAFC dispute over it would be unusual; none was found.
Uncertainty / Confidence Statement
- High confidence in: title, inventors, original assignee (IBM), current assignee (Trend Micro), application number, filing date 1998-08-12, issue date 2000-05-09, priority 1996-10-21, continuation-of-08/731,800 relationship, and claim text (these come from the authoritative full document you supplied plus corroborating PDF/hosted copies).
- High confidence in the import of both claims as explained above, which tracks the supplied claim language.
- Low/no confidence and explicitly not asserted: any CAFC 2026 (or other) docket, appeal, IPR, or litigation involving 6,061,797 — I found no evidence of any, and my tools cannot exhaustively confirm a negative across PACER/CAFC databases. If a 2026 docket is the premise of a specific question, please supply the case number and I will analyze it against the patent's literal text rather than infer one.
Generated 10/1/2026, 2:41:26 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 6061797. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US Patent 6061797. Let me search multiple sources.
Let me try more targeted litigation-specific searches.
Let me search more specific litigation databases and the patent's own litigation history.
Litigation Search Results: US Patent 6,061,797
Bottom line: I found no litigation involving US Patent 6,061,797 in any searchable source.
I searched for the patent by number across general web search, litigation-oriented indexing (Unified Patents portal references, PTAB/PTACTS filings, Lex Machina-derived reports, Docket Alarm, and Google Patents' own pages). None of the results identified any court case, ITC investigation, or PTAB proceeding asserting or challenging the '797 patent. I did not obtain a hit on the specific number from any case-list source.
What I checked and what came back
| Source type | Query | Result for '797 |
|---|---|---|
| General web | "6061797" patent litigation / lawsuit | No case hits — returned the patent document itself |
| Litigation aggregation | "6,061,797" patent case | No relevant case |
| Patent page | Google Patents US6061797 | No litigation/litigation-history section present |
| PTAB environment | Unified Patents / PTACTS / Docket Alarm | No proceeding referencing '797 |
Note on the Unified Patents angle: the searches surfaced Unified Patents' IPR case lists and its self-reported "PTAB Success" pages, but none of those lists contain patent 6,061,797. Unified's challenges shown were against other patents (e.g., 6,738,799; 7,197,662; 5,978,791; 10,311,073, etc.). So there is no evidence of a Unified Patents IPR against '797 either.
Important disambiguation (avoiding auto-correction errors)
Several results that look related involve different patents and should not be conflated with '797:
- US 5,623,600 ("the '600 patent") — Trend Micro's antivirus-gateway patent, litigated against McAfee (1997) and Fortinet (ITC Investigation, §337, ca. 2004–2006). This is not '797.
- US 5,944,823 — This is the parent of '797 (the '797 patent is a continuation of Ser. No. 08/731,800, which issued as 5,944,823). The '797 patent shares the same specification. My searches likewise returned no litigation naming 5,944,823, but note this is a distinct patent number.
- Webroot/OpenText v. Trend Micro and related 2022 W.D. Tex. suits — these involve Trend Micro patents like 8,201,243 / 8,719,932, not '797.
Assessment and caveats
- US 6,061,797 (IBM, filed 1998-08-12 as a continuation; priority 1996-10-21; granted 2000-05-09; now assigned to Trend Micro Incorporated; expired 2016-10-21) — no known litigation is recorded against this specific patent. Its expired status (anticipated expiration 2016-10-21) is consistent with it never having been a significant assertion vehicle.
- Confidence level: I have moderate-to-good confidence that no publicly indexed litigation exists for '797 as of the search date. However, I could not complete live queries against primary litigation databases (PACER, the Unified Patents litigation caselist at
portal.unifiedpatents.com/litigation/caselist, and Docket Navigator) because the tool returned no results for those specific queries. I am therefore not able to certify exhaustively that zero litigation exists — only that I found none.
Recommended verification steps (for a definitive answer)
To confirm a negative with certainty, check these primary sources directly by patent number:
- Unified Patents Litigation Caselist — https://portal.unifiedpatents.com/litigation/caselist (filter by patent 6061797)
- PACER / RPX / Docket Navigator — search "6,061,797"
- USPTO Patent Center "Litigation" tab and the PTAB/PTACTS proceeding search: https://ptacts.uspto.gov
- USITC EDIS (for any §337 investigation naming '797): https://edis.usitc.gov
If those return nothing, the conclusion that no litigation involves US 6,061,797 can be stated definitively.
Caveat on scope: I did not find or fabricate any case numbers, plaintiffs, defendants, or dates, because none were supported by the search results. If you need me to run the specific litigation-database queries above (if search access permits), I can attempt those next.
Generated 10/1/2026, 2:41:26 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the structured data with targeted searches before reporting.
Let me run a couple more targeted checks for any litigation-linked proceedings and the sibling patent.
One final verification pass on the patent-ownership and assertion history.
PTAB Proceedings on US 6,061,797 — Analyst Report
Patent: US 6,061,797 — Outside access to computer resources through a firewall
Patent Owner of record: Trend Micro Incorporated (assigned from IBM, effective 2010-03-31; recorded 2010-05-17)
Granted / Published: 2000-05-09 · Filing date: 1998-08-12 · Priority: 1996-10-21 · Expired: 2016-10-21
Continuation of: US 5,944,823 (Appl. 08/731,800), also expired
Proceedings overview
Total count: 0. The USPTO Open Data Portal structured block in this prompt returns no AIA trial proceedings on file (0 active, 0 claims invalidated, 0 claims sustained, 0 settled, 0 institution denials), and my independent web searches surfaced no IPR, PGR, or CBM petition against US 6,061,797 — or against its parent US 5,944,823 — under any petitioner.
Bottom-line defensive posture: this is not a "hardened patent" story — it is a no-contest story. US 6,061,797 was never tested at the Board, and it no longer needs to be: the patent expired 2016-10-21, all of its renewal fees lapsed with the term, and its entire universe of infringement exposure closed on that date. For a defendant receiving a demand letter today, the PTAB question is a red herring. The dispositive defense is statutory, not adjudicative: the patent is expired, and the 35 U.S.C. § 286 six-year damages lookback has run out. The last possible infringing act was 2016-10-21; more than six years have elapsed since (today being 2026-10-01), so there is no damages window left for any plaintiff to recover, whether or not a PTAB proceeding had ever been filed. Notably: no AIA proceedings exist, and none can realistically be brought now (see the Sony v. Iancu discussion below).
Confidence / search caveat: I could not query PTAB E2E, Docket Navigator, or Litigation Analytics directly. This finding rests on (a) the ODP structured block, and (b) targeted web searches for IPR/PGR/CBM petitions, litigation dockets, and Unified Patents portal entries tied to this patent number, its title, and its parent. No hits appeared. I rate this high confidence for "no IPR/PGR/CBM on file," moderate confidence that no proceeding exists under a number I was unable to surface. I did not find a Federal Circuit appeal — consistent with there being no FWD to appeal.
Per-proceeding detail
Not applicable — there are no proceedings to report. I am not populating the per-proceeding template with placeholder rows, because doing so would require inventing proceeding numbers, petitioner names, panels, and dispositions. Those would be fabrications, and the instructions are explicit that I must not invent proceeding numbers. There is nothing here to gloss — no institution decisions, no final written decisions, no settlements, no Rule 42.72 terminations, no IPR2016/2017/2018-era filings by Trend Micro, Cisco, or any defensive aggregator that I could locate.
Strategic summary
Claim status on US 6,061,797
The patent issued with exactly two claims — claim 1 (an independent "tunneling software application contained on computer-readable media," comprising first and second program segments, with the first segment creating and maintaining a "table of trusted objects" and providing a copy of that table to the second computer) and claim 2 (dependent, adding the private control connection through the firewall and the second computer's verification/forwarding function). Both claims remain UNTESTED — never canceled, never confirmed. "Untested" and "valid" are emphatically not the same thing here: the reason no one challenged these claims is almost certainly that the patent's useful life ended before the AIA trial regime had a realistic chance to reach it. From a defensive standpoint, a claim that was never adjudicated gives you no § 315(e) estoppel to lean on, but it also gives the plaintiff no favorable adjudication to wave at the court — and, critically, no live damages theory.
The more consequential target historically was the parent, US 5,944,823, whose claims were broader and covered the tunneling apparatus itself rather than the software-program-product framing of the continuation. That patent is also expired (2016-10-20 per the family data). Neither was litigated to judgment at the Board, to my knowledge.
Estoppel landscape — essentially moot, but here is the mechanics
Because no IPR, PGR, or CBM was ever instituted, there is no § 315(e)(2) estoppel attaching to anyone, and no privies barred from anything. In theory that means the entire prior-art universe — including Bellovin & Cheswick, Firewalls and Internet Security (Apr. 1994), the WO 97/16911 "Secured gateway interface" reference cited during prosecution, and US 5,826,014 (Network Engineering Software) — remains available as § 102/§ 103 grounds in a district court invalidity case, unencumbered by any petitioner estoppel. In practice this is cold comfort and largely academic: invalidity is not where this fight is won. A defendant facing assertion should lead with (1) expiration, (2) § 286's six-year bar (no actionable damages window survives), and (3) at most, a § 101/§ 112 challenge if the plaintiff somehow pleads a theory reaching pre-2016 conduct. Prior art is a fallback, not a strategy.
Pattern signals
- Same petitioner, multiple IPRs on this patent: No. No petitioner at all.
- Aggressive PTAB appeals by the patent owner: No. There is no FWD, hence no appeal to the Federal Circuit, hence nothing on CourtListener. (By contrast, the family's PTAB-adjacent history — as reflected in the "Families Citing this family" table — shows the references cited against this patent appearing in unrelated proceedings, not this patent appearing in its own.)
- Defensive aggregator involvement (Unified Patents, RPX, Open Invention Network): I found a Unified Patents portal page for US 5,944,823-A, the parent, but it reflects no challenge activity — no IPR, no district court assertion captured. This is a null signal, not evidence of a challenge.
- Assignee history: IBM → Trend Micro (2010-03-31). Trend Micro is an active PTAB petitioner (ranked among the most active petitioners in recent Patexia intelligence reporting), not an active PTAB patent owner on this asset. The 2010 acquisition post-dated the patent's productive assertion life and pre-dated its 2016 expiration; it appears the patent was acquired as part of a portfolio rather than for enforcement.
The timing problem for any would-be IPR
Two structural bars make a Sony-style institution denial the overwhelmingly likely outcome if anyone tried to file an IPR on US 6,061,797 today:
- Subject-matter availability. PGR is unavailable — it requires an effective filing date on or after 2013-03-16, and this patent's effective filing date is 1996-10-21. CBM review is unavailable — the transitional program sunset on 2020-09-16, and this is a network-security patent, not a covered business method on its face.
- The expired-patent / no-live-infringement doctrine. Under Sony Corp. v. Iancu, 924 F.3d 1235 (Fed. Cir. 2019), an IPR petitioner challenging an expired patent cannot satisfy § 311(b)'s "reasonable likelihood" threshold merely by asserting future infringement risk; it must show it could have infringed the claim while the patent was in force. A patent that expired 2016-10-21 — nearly a decade ago — makes that showing very hard to construct, and prior Board practice in this posture has been to deny institution.
Recommended next steps
If you are a defendant receiving an assertion or demand letter citing US 6,061,797:
- Say plainly: there is no PTAB activity on file for this patent. The structured ODP data returns zero AIA trial proceedings, and no IPR/PGR/CBM exists in the public record. Do not represent to a court or adversary that the patent "survived" or "was invalidated" at the Board — neither happened, and either claim would be a misrepresentation.
- Lead with expiration and § 286. The patent expired 2016-10-21. The last date on which damages could have accrued is 2016-10-21, and as of 2026-10-01 more than six years have passed. The § 286 lookback therefore excludes all remaining actionable conduct. Verify against the face of any complaint whether the plaintiff even pleads pre-expiration, pre-six-year activity; if it does not, the damages case is legally extinguished, not merely weak. (For the parent, US 5,944,823, the corresponding date is 2016-10-20.)
- Do not spend money on an IPR. An IPR on this patent would be an expensive nullity — Sony v. Iancu poses a near-insurmountable § 311(b) hurdle for an expired patent, and PGR/CBM are foreclosed by filing date and by program sunset respectively. Any budget is better spent on a Rule 12 motion or summary judgment on the expired-patent / no-damages theory.
- Preserve the invalidity card, but as a secondary. With no prosecution-history estoppel from any IPR, the classical firewall-art references remain fully available if the case somehow survives the timing defense. The prosecution history already shows the examiner relying on the Bellovin/Cheswick firewall literature and WO 97/16911, which gives you a well-documented starting point for a § 103 attack on the two claims of the '797 and the broader claims of the '823.
If you are evaluating this patent as a defensive-acquisition or prior-art target:
Its real value is as prior art, not as an assertion asset. With a 1996 priority date and a 2000 grant covering outside-initiated tunneling through a firewall via an inside-maintained trusted-socket table and a private control connection, US 6,061,797 (and its parent US 5,944,823) are strong § 102(b) references against later "reverse tunnel," "firewall traversal," and "outbound-initiated session" patents — a lineage visible in the 80–141 forward citations above. That is where the remaining value lies.
Where to verify all of this yourself (since the null result is the finding):
- PTAB E2E / Patent Trial and Appeal Board End-to-End: https://ptacts.uspto.gov/ptabweb/ — search by patent number 6061797 and cross-check 5944823
- USPTO Patent Public Search for the file wrapper and any certificate of correction: https://ppubs.uspto.gov/pubwebapp/
- Unified Patents portal entry for the parent: https://portal.unifiedpatents.com/patents/patent/US-5944823-A
- CourtListener / RECAP for any district court or Federal Circuit docket: https://www.courtlistener.com/?q=%226%2C061%2C797%22
- Google Patents family and status page (source of the authoritative text used here): https://patents.google.com/patent/US6061797/en
Verification-honesty note: I want to be explicit that the absence of PTAB activity is my finding, not a verified negative from a primary PTAB database query — I did not have direct E2E access in this session. Before relying on this in a filing, confirm the null result against PTAB E2E directly. What I can state without reservation is that nothing in the ODP structured data or in my searches supports the existence of any IPR, PGR, or CBM on this patent, and that the expiration dates and claim structure above are drawn from the authoritative patent text.
Generated 10/1/2026, 2:41:53 PM
Ownership chain (1)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2010-03-31 · recorded 2010-05-17 · reel 024390/0164 · Assignment
International Business Machines CorporationTrend Micro Incorporated
acquisition
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment record for US 6,061,797 across the available sources.
Let me try to access the assignment records directly.
Ownership & Assignment Reconstruction — US Patent 6,061,797
Method note / limitation up front (no fabrication): The authoritative assignment facts below come from the grant document and its Google Patents "Legal Events" table, which mirror the USPTO Assignment Center records. Live queries against assignmentcenter.uspto.gov and assignment.uspto.gov did not return page-level detail in my searches, so I could not retrieve the correspondent-of-record or the full reel/frame list beyond what the legal-events table exposes. I flag every field I could not verify rather than filling it in. Where the Assignment Center shows only one post-issuance record, that is itself the finding.
Inventors
| Inventor | Employer at filing (determinable?) |
|---|---|
| Prashanth Jade | Not expressly stated in the grant; original assignee is IBM, and the application was filed by/assigned to IBM — inferred IBM employee, not confirmed from a recorded assignment in my sources. |
| Victor Stuart Moore | Same as above — inferred IBM, not confirmed. |
| Arun Mohan Rao | Same as above — inferred IBM, not confirmed. |
| Glen Robert Walters | Same as above — inferred IBM, not confirmed. |
Pattern check: The four inventors appear together on the parent US 5,944,823 (same specification). I found no evidence of any inventor departing the original assignee within 12 months of filing, and no evidence of individual inventor-to-IBM assignments being recorded separately in the data I could retrieve. I am not asserting a departure pattern — that would require personnel/assignment documents I do not have. Do not read a fire-sale precursor into this record; none is evidenced.
Original assignee
- Entity on the issued patent: International Business Machines Corporation (IBM), Armonk, NY.
- Line of business: Diversified enterprise IT — hardware, software, and services; a very large, active patent licensor.
- Product embodying the claims: IBM marketed firewall / secure-gateway and VPN software in the relevant era (e.g., the IBM Firewall / SecureWay family). The claimed subject matter (firewall tunneling software with a "trusted socket" table) is consistent with a software product IBM could have shipped, but I have not verified a specific shipping SKU embodying claims 1–2. Treat "shipped an embodying product" as plausible, not confirmed.
- Current status: Operating company (IBM remains an active, publicly traded concern). The patent itself was sold away in 2010 (below). IBM did not enter bankruptcy — the fire-sale/bankruptcy hypothesis (Kodak/Nortel/Polaroid-style) does not apply here.
Assignment timeline
The USPTO record for this patent contains one recorded post-issuance conveyance (plus the original inventor→IBM assignment, whose reel/frame I could not retrieve). In chronological order:
2010-03-31 (executed) / recorded 2010-05-17 — Reel 024390/0164
- Conveyance: Assignment ("ASSIGNMENT OF ASSIGNOR'S INTEREST; SEE DOCUMENT FOR DETAILS")
- Assignor: International Business Machines Corporation
- Assignee: Trend Micro Incorporated (recorded owner name: "TREND MICRO INCORPORATED, JAPAN")
- Correspondent: Not retrieved. I could not obtain the correspondent-of-record from the sources available. I will not guess a name/firm.
- Context: Single-step portfolio acquisition — an operating company (IBM) transferring to another operating company (Trend Micro). Not an internal reorg (different corporate family), not a securitization, not a transfer to a licensing-only shell on the face of the record.
Original / pre-issuance: Inventors → IBM. Reel/frame not retrieved in the sources I could access. Standard for IBM-originated patents; not itemized here to avoid fabrication.
Fee-maintenance events (not ownership transfers), per legal events:
FPAYyear 4 (2003-09-25), year 8 (2007-09-19), year 12 (2011-11-09); grantSTCF2000-05-01;FEPPpayor/entity-status 2002-10-31. These confirm the patent was maintained to expiration, not abandoned.
Bottom line: The Assignment Center has records for this patent, but they reflect a single clean ownership transfer (IBM → Trend Micro). There is no chain of LLC transfers to reconstruct.
Timeline diagram
timeline
title Ownership of US 6061797
1996 : Priority date Oct 21
1998 : Continuation filed Aug 12
2000 : Patent issued to IBM
2010 : Assigned to Trend Micro
: Effective date Mar 31
: Recorded May 17
2016 : Patent expires Oct 21
NPE / troll-pattern signals
Shell-entity transfer — NOT PRESENT. The 2010-03-31 transfer (Reel 024390/0164) moved the patent from IBM to Trend Micro Incorporated, a large, publicly traded operating cybersecurity vendor — not a "IP/Licensing/Holdings/Ventures" LLC, not a registered-agent address, not a single-member Delaware/Texas shell. No shell-entity evidence exists in the record.
Known asserter in the chain — NOT PRESENT. Neither IBM nor Trend Micro appears on the named NPE lists supplied (Acacia, Marathon, Intellectual Ventures, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). Both are operating companies. (Note: Trend Micro has litigated patents as a plaintiff — e.g., the separate '600 antivirus patent against McAfee and in the Fortinet ITC matter — but that is operating-company assertion against product competitors, not NPE behavior, and does not involve '797.)
Repeat correspondent across the chain — UNCLEAR / NOT RETRIEVABLE. With only one recorded link and the correspondent-of-record not obtained, there is no basis to identify recurrence. Not a finding either way. This is the one field I most want to complete; it is not available from my sources.
Cascading transfers (<24 months through chained LLCs) — NOT PRESENT. One recorded transfer over the patent's 16-year life; no chained LLCs, no shared-address cluster.
Pre-litigation transfer — NOT PRESENT. No infringement suit naming '797 was found (consistent with the earlier litigation section). A 2010-03-31 assignment with no subsequent suit is not a pre-litigation standing transfer.
Bankruptcy fire-sale — NOT PRESENT. IBM never filed Chapter 7/11; this was an ordinary corporate portfolio sale of a maintained patent.
Privateering — NOT PRESENT. Privateering requires transfer to a non-practicing entity that asserts on the operating company's behalf. The assignee here (Trend Micro) is itself an operating cybersecurity vendor; there is no NPE conduit and no evidence of assertion on IBM's behalf.
Defensive aggregator (anti-NPE) — NOT PRESENT. The chain terminates at Trend Micro, an operating company — not RPX, AST, LOT Network, Unified Patents, or OIN. No neutralization signal.
Verdict
Operating-company assertion (selected, with an explicit caveat).
Justification: The sole recorded conveyance — executed 2010-03-31, recorded 2010-05-17, Reel 024390/0164, IBM → Trend Micro Incorporated — is a straight operating-company-to-operating-company portfolio transfer, and Trend Micro is a large, product-shipping cybersecurity vendor whose product lines (firewall/endpoint/VPN security) are technically aligned with the claimed subject matter. No NPE signal is present in the record. Caveat on the label: the "assertion" prong of this category (current assignee "suing actual competitors" over this patent) is not evidenced — no suit naming '797 was found, and the patent expired 2016-10-21. Read literally, the chain is best characterized as "operating-company ownership — not NPE," and the strict "operating-company assertion" definition is only partially met.
Verification links (restricted to primary sources):
- USPTO Assignment Search — https://assignmentcenter.uspto.gov/ (search patent 6061797; also https://assignment.uspto.gov/patent/index.html)
- Google Patents legal events (source of the Reel 024390/0164 entry) — https://patents.google.com/patent/US6061797/en
Residual uncertainty: (a) correspondent-of-record for Reel 024390/0164 not retrieved; (b) original inventor→IBM reel/frame not retrieved; (c) no litigation confirmed, but a true negative requires PACER/PTAB/EDIS queries that I could not complete. None of these gaps would change the NPE assessment, because the assignee is a known operating vendor rather than an anonymous licensing entity.
Generated 10/1/2026, 2:42:05 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll research the prior art references cited against US 6,061,797. Let me search for the patent and each cited reference.
I have good detail on several references. Let me research the remaining patent citations and the non-patent literature.
Prior-Art Analysis — US Patent 6,061,797
1. Patent identification (USPTO / Google Patents)
My search for the number 6,061,797 returned the correct document (Google Patents US6061797A; uspto.report/patent/grant/6061797), with a bibliographic record matching the authoritative text you supplied: "Outside access to computer resources through a firewall," App. 09/132,915, filed 1998-08-12, priority 1996-10-21, granted 2000-05-09, inventors Jade/Moore/Rao/Walters, original assignee IBM.
Disambiguation (do not conflate — literal ID handling):
- US 6,061,798 — a different patent (Cole,y et al., Network Engineering Software), also granted 2000-05-09. It is the continuation of US 5,826,014. It appears in the same CPC neighborhood and on the same issue date but is not 6,061,797.
- US 5,944,823 — the parent of 6,061,797 (Ser. No. 08/731,800). Same specification, distinct patent number.
I did not obtain a direct hit from patents.google.com's USPTO litigation tab or the Patent Center litigation view; the citation lists below are taken from the authoritative full text you supplied and are consistent with the mirrored copies.
2. Critical dates for the § 102 calculus (pre‑AIA)
Because the priority date predates March 16, 2013, pre‑AIA 35 U.S.C. § 102 governs. As a straight continuation of 08/731,800, the '797 application is entitled to the parent's 1996‑10‑21 filing date for its disclosure.
| Threshold | Date | Effect |
|---|---|---|
| § 102(b) one‑year bar | before 1995‑10‑21 | patents/printed publications more than one year before the effective filing date |
| § 102(a) | before 1996‑10‑21 | patents/publications before the invention |
| § 102(e) | any US patent whose application was filed before the invention | effective as of filing date, not issue date |
3. Cited prior-art PATENTS (the 6 references)
① US 5,283,828 A — Hughes Training, Inc.
- Full citation: "Architecture for utilizing coprocessing systems to increase performance in security adapted computer systems," U.S. Patent 5,283,828, filed/priority 1991‑03‑01, granted 1994‑02‑01.
- Description: A base computer paired with a separate "security computer" that reads/writes base-computer memory, controls an encryption unit, and enforces mandatory/discretionary access control over uniquely identified "objects," with a "trusted path" interface for user identification.
- § 102 status / mapping: § 102(b) art (granted 1994, >1 yr before 1996‑10‑21). Does not anticipate claim 1 or claim 2. It concerns intra-machine trusted-path/access-control architecture — no firewall, no two-sided interface computers, no replicated trusted-object table, no control connection. Relevant only as background to the "trusted object/subject" vocabulary.
② US 5,455,953 A — Wang Laboratories, Inc.
- Full citation: "Authorization system for obtaining in single step both identification and access rights of client to server directly from encrypted authorization ticket," filed 1993‑11‑03, granted 1995‑10‑03.
- Description: A credential ("authorization ticket") mechanism letting a client obtain both its identity and its access rights from a server in a single step.
- § 102 status / mapping: § 102(b) art (granted 1995‑10‑03, just inside the 1995‑10‑21 bar). Does not anticipate either claim. It may be tangentially relevant to claim 2's "verify … addressed to a trusted object" limitation (authorization/verification), but discloses no firewall traversal, no table replication, and no control connection.
③ US 5,481,715 A — Sun Microsystems, Inc.
- Full citation: "Method and apparatus for delegated communications in a computer system using trusted deputies," filed 1993‑12‑15, granted 1996‑01‑02 (Hamilton, Hagman, et al.).
- Description: A trusted "Deputy" application on a trusted machine acts on behalf of a client to invoke calls on servers and proves to those servers that it is trusted by the client — an intermediary ("deputy") that stands between a client and protected resources.
- § 102 status / mapping: § 102(e) art (filed 1993‑12‑15, before the invention); not § 102(b) (issued after 1995‑10‑21). Does not anticipate either claim. It is the closest conceptual antecedent to a "trusted intermediary," but there is no firewall, no table of trusted objects, no replication from inside to outside, and no control connection. Potentially citable for claim 2's "trusted" intermediary flavor only in an obviousness combination.
④ US 5,548,646 A — Sun Microsystems, Inc. (Aziz, Mulligan, Patterson, Scott)
- Full citation: "System for signatureless transmission and reception of data packets between computer networks," filed 1994‑09‑15, granted 1996‑08‑20 (reissued as US RE39,360 E1).
- Description: A "tunnelling bridge" at each private network's interface. Each bridge intercepts all packets, uses a memory-resident hosts/networks table to decide whether to encrypt, adds an encapsulation header, and sends the packet over the public internetwork; the receiving bridge reads its table, decrypts, and forwards to the destination host.
- § 102 status / mapping: § 102(e) art (filed 1994‑09‑15, before the invention); not § 102(b) (issued 1996‑08‑20, <1 yr before 1996‑10‑21). This is the closest single reference to claim 1's architecture and is the most likely § 102 primary reference. It discloses: two computers on opposite sides of the public network boundary, a table in each side's memory, and tunneling across the boundary. However, it does not disclose the claim‑1 requirement that the first segment create and maintain the table of trusted objects and provide a copy of that table to the second computer (Aziz configures each bridge's table locally). So it is not a full anticipation; under § 103 it would be the anchor combined with a table-replication teaching.
⑤ WO 97/16911 A1 — International Business Machines Corp.
- Full citation: "Secured gateway interface," PCT publication WO 97/16911 A1, filing/priority 1995‑10‑31, published 1997‑05‑09.
- Description: An IBM secured gateway interface for mediating access across a firewall.
- § 102 status / mapping — FLAG A DATE ANOMALY: The publication date (1997‑05‑09) is after the '797 priority date (1996‑10‑21), so as a printed publication it is facially not § 102(a)/(b) art. Its only route to prior-art status is § 102(e) via its 1995‑10‑31 filing, and the availability of pre‑AIA § 102(e) effect for PCT publications filed before Nov 29, 2000 is legally contested/limited. I am reporting the dates literally and not resolving this; it is a genuine § 102 date problem worth verifying against the file wrapper (§ 102(e) vs. § 102(a)). Subject-matter-wise it is closer to firewall mediation than ①② , but the disclosed record does not establish the claimed trusted-table-created-inside-and-copied-outside + control-connection combination.
⑥ US 5,826,014 A — Network Engineering Software, Inc. (Cole et al.)
- Full citation: "Firewall system for protecting network elements connected to a public network," filed 1996‑02‑06, granted 1998‑10‑20 (parent of US 6,061,798).
- Description: A firewall on a stand-alone computer between the public network and protected elements. Proxy agents are assigned to an incoming request according to the service protocol/port number in the request; the proxy verifies the request's authority to reach the indicated network element and then completes the connection to the protected element on behalf of the requester.
- § 102 status / mapping: § 102(e) art (filed 1996‑02‑06, before the invention); not § 102(b). The closest reference to claim 2's validation-and-connection mechanism. It discloses "receive request → verify authority → complete connection on behalf of requester," which maps to claim 2's "verify … addressed to a trusted object" + "have data delivered … without exposing the secure object." But it does not disclose the two-segment (inside/outside) application, the inside-created trusted-object table copied to the outside computer, or the private control connection through the firewall between two interface computers. Not a full anticipation of claim 2.
4. Cited prior-art NON-PATENT LITERATURE (the printed publications)
| # | Full citation | Date | § 102 class | Relevance |
|---|---|---|---|---|
| A | Bellovin, S.M. & Cheswick, W.R., "Network Firewalls," IEEE Communications Magazine, vol. 32, no. 9, pp. 50–57 | 1994‑09‑01 | § 102(b) | Foundational firewall overview; includes a "Tunnels — good or bad" discussion of tunneling through firewalls. Background/general-art anchor; not an anticipation of either claim. |
| B | Cheswick, W.R. & Bellovin, S.M., "Firewalls and Internet Security: Repelling the Wily Hacker," Addison-Wesley, pp. 86–106 | 1994‑04 | § 102(b) | Textbook treatment of firewall topologies/tunneling; background art. |
| C | Bryan, J., "Firewalls for Sale," BYTE, vol. 20, no. 4, pp. 99–100, 102, 104 | 1995‑04‑01 | § 102(b) | Marketplace survey of commercial firewalls; background art. |
| D | Demizu, N., et al., "DDT — A Versatile Tunneling Technology," Computer Networks and ISDN Systems, vol. 27, no. 3, pp. 493–502 | 1994‑12‑01 | § 102(b) | General tunneling technology; conceptual support for the claim‑1 "tunneling" term; not an anticipation. |
| E | Doty, T., "A Firewall Overview," CONNEXIONS, vol. 9, no. 7, pp. 20–23 | 1995‑07‑01 | § 102(b) | Firewall primer; background art (also cited in the EP 1 197 056 file). |
| F | Newman, D., et al., "Can Firewalls Take the Heat?," Data Communications, vol. 24, no. 16, pp. 71–78, 80 | 1995‑11‑21 | § 102(a) (after 1995‑10‑21) | Firewall performance discussion; marginal general art. |
| G | PCT International Preliminary Examination Report, Int'l App. No. PCT/GB97/02712 | 1997‑10‑02 | Not prior art | This is the prosecution document for the '797 family's own PCT (WO 98/18248). It is a prosecution/administrative paper, not § 102 prior art. |
(The Chinese family member CN 1107400 C independently lists WO 97/16911, Bryan "Fire-Walls for Sale," and Bellovin "Network Firewalls" as its "references cited," corroborating A, C, and ⑤ as the substantive references in the family.)
5. § 102 anticipation mapping (claim-by-claim)
Because claim 1 is the only independent claim and claim 2 depends from it, the anticipation question is whether one single reference discloses every limitation of claim 1 (and, for claim 2, the added control-connection/validation/forwarding limitations).
| Reference | vs. Claim 1 | vs. Claim 2 |
|---|---|---|
| ① US 5,283,828 | No — no firewall, no two-sided segments, no table copy | No |
| ② US 5,455,953 | No | No (touches "verify" conceptually only) |
| ③ US 5,481,715 | No | No (trusted-intermediary concept only) |
| ④ US 5,548,646 | Closest for claim 1 — two bridges + tables on opposite sides; but missing "create/maintain table inside + provide copy to second computer" → not a full anticipation | No |
| ⑤ WO 97/16911 | No (and § 102 date problem — see flag) | No |
| ⑥ US 5,826,014 | No | Closest for claim 2 — verify-then-complete-connection; but missing the two-segment app, table replication, and control connection → not a full anticipation |
| A–G (NPL) | Background only | Background only |
Anticipation conclusion: Under § 102, no cited reference, taken alone, discloses every limitation of claim 1 or claim 2. Each is at best a § 103 anchor:
- Claim 1 is most exposed to ④ US 5,548,646 (tunneling bridges + per-side tables), potentially combined with the "trusted socket table" teaching sourced elsewhere.
- Claim 2 is most exposed to ⑥ US 5,826,014 (request verification + connection completion through a firewall), potentially combined with a message/tunnel-forwarding teaching.
6. Bottom line — most relevant prior art
Ranked for the '797 subject matter ("outside-in" tunneling through a firewall using a replicated trusted-object table and a private control connection):
- ④ US 5,548,646 (Sun/Aziz) — the strongest structural prior art (dual tunneling bridges, per-network tables, cross-boundary tunneling).
- ⑥ US 5,826,014 (Network Engineering Software/Cole) — the strongest functional prior art (request validation against port/protocol and proxy completion of the connection to the protected element).
- A Bellovin & Cheswick "Network Firewalls" (and the B Cheswick/Bellovin book, D Demizu "DDT") — the earliest secure tunneling/firewall teaching, § 102(b).
- ③ US 5,481,715 and ② US 5,455,953 — secondary art for the "trusted intermediary / authorization-ticket" limitations.
- ① US 5,283,828 — marginal background (trusted-path/access control).
- ⑤ WO 97/16911 — potentially relevant but carries a § 102 date problem (published after the 1996‑10‑21 priority; relies on 1995‑10‑31 filing for § 102(e)).
7. Confidence and caveats (explicit)
- High confidence in the citation list itself, the reference titles/numbers, and the § 102(a)/(b)/(e) date classifications (they follow mechanically from the dates in the authoritative text).
- Moderate confidence in my characterizations of US 5,548,646 and US 5,826,014 (verified against their Google Patents abstracts/descriptions). I did not retrieve full descriptive text for US 5,283,828, US 5,455,953, US 5,481,715, or WO 97/16911 in this session; those descriptions are drawn from the patent abstracts/titles and my existing knowledge, and should be re-verified against the full documents before being relied on in a validity opinion.
- Flagged anomaly (not auto-corrected): WO 97/16911 A1 shows a 1995‑10‑31 filing/priority and a 1997‑05‑09 publication — later than the '797 priority date. Whether it qualifies as § 102 art, and under which subsection, depends on facts (English-language PCT publication, US designation, and the pre‑Nov‑29‑2000 § 102(e) rule) that I cannot resolve from the search results.
- No litigation/CAFC data is asserted here; consistent with the earlier sections, I found none, and this section does not change that.
- I am not certifying that these are the only relevant prior art — the six patent citations and NPL are the references of record; broader prior-art searching (e.g., Raptor Systems' US 5,828,846, Digital's US 5,781,550, and the Check Point US 5,606,668 art visible in the same technology neighborhood) may be more material to the actual claims than some examiner-cited items.
If you want, I can next build a limitation-by-limitation claim chart for claim 1 vs. US 5,548,646 and claim 2 vs. US 5,826,014, which is where any real § 102/§ 103 attack would be anchored.
Generated 10/1/2026, 2:42:27 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll ground this analysis in the prior art actually listed on the patent's page, checking a few key references before reasoning.
Let me verify the content of two key references whose disclosures matter to the mapping.
Obviousness Analysis — U.S. Patent No. 6,061,797 under 35 U.S.C. § 103
Analyst note / scope. This section builds on the previously generated summary and litigation sections and does not repeat them. Two cross-reference flags up front:
- No contradiction found with the prior sections. The prior section correctly observed that claim 1 "does not, by itself, recite the control connection or the request-validation/forwarding behavior." That is confirmed by the claim text and drives the two-tier analysis below (claim 1 falls on a thinner combination than claim 2).
- One caution on the "Prior Art section" itself: of the 13 listed Non-Patent Citations, one item — "PCT International Preliminary Examination Report, Oct. 2, 1997, International Application No. PCT/GB97/02712" — carries the application number of this family's own PCT (PCT/GB1997/002712, which published as WO1998018248A1 per the "Country Status"/family tables on the same page). That item is a file-history document, not third-party prior art, and I do not treat it as art below. (The date shown, Oct. 2, 1997, appears to be the international filing/priority date of the family rather than the report date; I flag the inconsistency rather than correct it.)
1. Legal framework
| Item | Determination |
|---|---|
| Governing law | Pre-AIA § 102/§ 103. The application was filed 1998-08-12 as a § 120 continuation of Ser. No. 08/731,800 (filed 1996-10-21); the AIA first-inventor-to-file provisions apply only to applications filed on/after 2013-03-16. |
| Effective filing date of the claims | 1996-10-21 (the parent's filing date). The Google Patents "Related Parent Applications" table shows 1996-10-16 for the parent; either date is well before every potential publication date that matters except one (discussed in §3). |
| Obviousness standard | Graham v. John Deere factors + KSR Int'l v. Teleflex (2007). Pre-AIA § 103(a): the claimed subject matter as a whole would have been obvious to a POSITA at the time of invention. No rigid teaching–suggestion–motivation requirement; a motivation may be found in the references themselves, in the nature of the problem, or in common sense / "obvious to try" over a finite set of predictable solutions. |
| Claim construction note | Both claims recite "means for operating said first computer…" / "said second program segment comprises means for operating said second computer…" → pre-AIA § 112 ¶ 6 means-plus-function constructions, with corresponding structure being the disclosed "tunneling application" segments and the algorithms of FIGS. 2, 3 and 5. This raises the bar slightly: the prior-art structure must perform the identical function, not a similar one. |
| Claim 1 character | A Beauregard-style "computer-readable media" product claim covering a two-segment tunneling application plus a trusted-object table and its replication to the outside computer. |
| Claim 2 character | Adds the inside-initiated private control connection and the outside-side validate-then-forward behavior. |
2. Person of ordinary skill in the art (POSITA)
A POSITA as of October 1996 would have: a B.S. in computer science or electrical engineering (or equivalent), plus roughly 2–4 years of experience in TCP/IP network engineering and firewall/proxy design, including familiarity with dual-homed gateways, application-level proxies (SOCKS-type), packet filtering, and the RFC literature. This is a crowded, fast-moving, well-documented art — a factor that weighs toward a finding of obviousness, because the references are all in the same field and largely cross-cite the same body of knowledge (e.g., Bellovin and Cheswick appear both as NPL on this patent's face and as background in the contemporaneous U.S. patent art).
3. Art-status audit (diligence before combining)
| Reference (as listed on the page) | Date basis | Pre-AIA status vs. 1996-10-21 | Usable in a § 103 combination? |
|---|---|---|---|
| WO 1997016911 A1 — IBM, "Secured gateway interface" | Published 1997-05-09 | Not § 102(a) and not § 102(b) — the publication postdates the effective filing date | No, not on its own face. Its only route into the art is via the corresponding U.S. Patent 5,826,029 (IBM, issued 1998-10-20; listed priority 1995-10-31) under § 102(e) (§ 363 international filing date), and then only if the PCT international filing date is on/before 1996-10-21. If the PCT was filed within 12 months after 1995-10-31 (i.e., late Oct. 1996), the § 102(e) date could fall after the critical date. I could not confirm the international filing date from the sources retrieved; this must be verified against the PCT front page / TW/EP family members before relying on the combination. |
| US 5,826,014 — Coley et al., Network Engineering Software, "Firewall system for protecting network elements connected to a public network" | Filed 1996-02-06; issued 1998-10-20 | § 102(e) (filing date precedes the critical date) | Yes. Non-IBM, so no § 103(c) common-ownership problem. |
| US 5,623,601 — Milkway Networks, "Apparatus and method for providing a secure gateway…" (family-cited) | Filed 1994-11-18; issued 1997-04-22 | § 102(e) (issue date postdates the critical date, so § 102(a)/(b) unavailable; the 1994 filing date supplies § 102(e)) | Yes. Non-IBM. |
| US 5,548,646 — Aziz et al., Sun Microsystems, "System for signatureless transmission and reception of data packets between computer networks" | Filed 1994-09-15; issued 1996-08-20 | § 102(a) (issued less than one year before the critical date) | Yes. Non-IBM. |
| US 5,481,715 — Sun, "delegated communications… using trusted deputies" | Filed 1993-12-15; issued 1996-01-02 | § 102(a) | Yes (secondary; trust-delegation concept). |
| US 5,455,953 — Wang, encrypted authorization ticket | Issued 1995-10-03 | § 102(b) | Yes (secondary; authentication only). |
| US 5,283,828 — Hughes Training | Issued 1994-02-01 | § 102(b) | Yes, but substantively poor (secure coprocessing architecture). |
| Bellovin & Cheswick, Firewalls and Internet Security, Apr. 1994, pp. 86–106 | Apr. 1994 | § 102(b) | Yes — primary printed-publication art. |
| Bellovin et al., "Network Firewalls," IEEE Comm. Mag., Sep. 1994, pp. 50–57 | Sep. 1994 | § 102(b) | Yes. |
| Demizu & Yamaguchi, "DDT — A Versatile Tunneling Technology," Computer Networks and ISDN Systems 27(3), Dec. 1, 1994, pp. 493–502 | Dec. 1994 | § 102(b) | Yes — primary tunneling art. |
| Bryan, "Firewalls for Sale," BYTE, Apr. 1995; Doty, "A Firewall Overview," CONNEXIONS, Jul. 1995; Newman et al., "Can Firewalls Take the Heat?" Data Comm., Nov. 21, 1995 | 1995 | § 102(b) (Newman: § 102(a)) | Yes (secondary; commercial state of the art / configurable rule tables). |
Additional § 103(c) wrinkle (important): the closest single reference, IBM's Secured Gateway Interface disclosure, is commonly owned with the '797 (both IBM at the time of invention). Under pre-AIA § 103(c), subject matter that qualifies as prior art only under § 102(e)/(f)/(g) and was commonly owned at the time the invention was made cannot be used in a § 103 rejection. So the SGI disclosure is available for anticipation purposes under § 102(e) but may be disqualified as a § 103 combination reference unless (i) it also qualifies under § 102(a)/(b) (it does not, given the 1997-05-09 publication date), or (ii) the common-ownership assumption fails. This is the single most consequential legal fact in the obviousness analysis, and it is why the analysis below is presented in two tracks.
4. Claim charts
4.1 Track A (merits-maximal): SGI + Coley + Bellovin/Cheswick + Aziz
| Claim element | Primary disclosure | Supporting disclosure |
|---|---|---|
| 1.1 Tunneling application on computer-readable media | US 5,826,029 / WO 1997016911 — expressly describes "a computer implemented method, a uniquely programmed computer system, and an article of manufacture embodying computer readable program means" | — |
| 1.2 First and second computers connecting directly to opposite sides of a firewall, each connecting its side to a network | SGI, Fig. 3: "External server 310 resides outside firewall 300, while internal server 320 resides inside firewall 300"; external server manages the external network (INTERNET), internal server manages the internal corporate network and database 330 | Coley, Fig. 2 (firewall 210 between internal network 214 and public network 202) |
| 1.3 Isolate secure objects in network 1 from network 2 while permitting data transfer through the firewall without compromising security | SGI: firewall 300 "prevents external transactions from passing through it to internal server 320," yet the invention lets an external user "validly initiate a transaction through a firewall to an internal network using internal resources" | SGI background expressly criticizes the alternative of "opening a specific port in firewall 6 to inbound traffic," which "leaves the internal network subject to external attack," and the alternative of copying databases to the external server, which "prohibits execution of internal transactions" / "may not have enough storage." These are the '797's own stated problems verbatim in substance. |
| 1.4 First and second program segments respectively on the first and second computers | SGI: outside daemon 312 on external server 310; inside daemon 322 on internal server 320, "thereby enabling communication across firewall 300" | Coley: proxy agents on the firewall box (single-segment analog) |
| 1.5 Segment 1 interfaces firewall↔network 1; segment 2 interfaces firewall↔network 2 | SGI, Fig. 3 (as above) | — |
| 1.6 Segment 1 creates/maintains a table of trusted objects associated with the secure objects | SGI limits requests to the enumerated set of available perl scripts and corresponding transaction programs residing in cgi-bin 415 (outside) and cgi-bin 426 (inside) — "the requests available to the customer are limited to the perl scripts and corresponding transactional programs" | Coley: proxy agent "assigned in accordance with a port number designation indicated in a request"; verification tests include matching the protocol of the request to the indicated port and checking source address against a list of authorized/unauthorized addresses or a range, with "the particular combination of tests [being] discretionary." Milkway (US 5,623,601): "checking a table to determine if a custom proxy process is bound to the destination port number" (claim 11) and "referencing a rule base… to determine whether the user identification/password at the source address is permitted to communicate with the destination address for a requested service" (claim 13). Bellovin & Cheswick pp. 86–106: proxy/bastion-host configurations organized by port and service. |
| 1.7 Segment 1 provides a copy of the table to the second computer for segment 2's use | SGI's outside cgi-bin 415 mirrors the inside cgi-bin 426 program set (the outside server must know which "services"/programs are available to present them) — a distribution of the service list to the outside host | Aziz (US 5,548,646): tunneling bridges "automatically determine[] from the tables whether each such packet should be encrypted," with the necessary table/key information obtained from a directory server — i.e., authorization/parameter data for a network-boundary function is replicated from a central trusted source to the boundary device. Also Bryan/Doty/Newman: commercial firewalls shipped with administratively distributed rule/policy sets. |
Claim 1 conclusion (Track A): every element is disclosed or would have been obvious. The only genuinely narrow feature is 1.7 — replicating the authorization table outward. That is a predictable, near-trivial variation of a known configuration-management practice, and the '797 specification itself offers only routine justifications ("when the table is created and/or altered, or at special times of day").
4.2 Track A — Claim 2 additions
Claim 2 is stronger for the challenger, because SGI discloses the private control connection almost element-for-element.
| Claim 2 element | Disclosure |
|---|---|
| 2.1 Segment 1 establishes a private control connection through the firewall between the two computers, normally inaccessible to communications directed from network 2 to network 1 | SGI, Fig. 3–4 (decisive): the system requires "securely authoriz[ing] a connection between an internal computer system and an external computer system before the external computer system receives transaction requests from users." The connection is opened from the inside: sgi_client routine 416 (inside) connects to outside daemon 312 on a designated "second port (daemon 312 communication port +1)," reading an 8-character password from a private client password file, followed by timestamp/crypt mutual authentication; outside daemon 312 forks a child that "returns to 430 to listen for another call from inside daemon 322." The internal-origin, password-gated, non-service port is precisely a private control connection that outside-network communications cannot address. |
| 2.2 Segment 2 receives a communication directed from network 2 toward network 1 | SGI: daemon 314 (e.g., an HTTPD) "listens for service requests from the external network," executing the outside "special" perl script that calls sgi_client/outside daemon 312 |
| 2.3 Verify the communication is addressed to a trusted object in the copied table | SGI: only the enumerated cgi-bin 415/426 program set is reachable; other requests cannot be mapped to a transaction program. Coley: port/protocol/source-address validation with "drop the packet" on failure ("If the source address is not on the list, the packet is discarded"). Milkway: "If the client is determined to have access rights to the requested service… the gateway station imitates the client to the host"; otherwise the session is cancelled. |
| 2.4 Forward the data through the private control connection to the first program segment | SGI: example.pl 462 builds a header string (SGIARG1, SGIARG2, SGICMD=example.pl, username) and transmits it, plus standard input, over the authenticated connection to outside daemon 312 → inside daemon 322 → service program 324 |
| 2.5 In a form enabling delivery to the secure object without exposing that secure object to access from network 2 | SGI: the actual transaction program resides inside the firewall (cgi-bin 426) and executes against internal database 330; the outside server only runs a decoy/stub ("example.pl 462 is not the actual transaction program"). Coley: the proxy "maintain[s] anonymity on each side of the firewall"; a tapping party "only 'sees' the elements on each side of the tap." Milkway: the gateway "transparently imitates a host" then "imitates the client to the host," using two distinct interdependent sessions. |
Claim 2 conclusion (Track A): obvious, and arguably anticipated by US 5,826,029 alone if (a) the service-list distribution to the outside cgi-bin is treated as "providing a copy of said table," and (b) § 102(e) status is established. The anticipation theory is aggressive; the obviousness theory is comfortable.
5. Motivation to combine (Track A)
- Same field, same problem, mutually cross-referencing art. SGI, Coley, Milkway, Bellovin/Cheswick and Demizu all address the identical problem — permitting legitimate external access to protected resources without opening inbound firewall holes. KSR: "if a technique has been used to improve one device, and a person of ordinary skill in the art would recognize that it would improve similar devices in the same way, using the technique is obvious."
- The problem statement is supplied by the reference itself. SGI's background expressly identifies and rejects the two prior solutions that the '797 also rejects (open a port; duplicate the resources outside the firewall). A POSITA presented with the '797's stated objective — avoid "unnecessary outside duplication of objects or resources inside the firewall" while enabling "telecommuting" — is directed to the SGI architecture.
- Tunneling as the known vehicle for inside-out reach. Demizu's DDT paper expressly solves the "insulating a network located in the depths of a private network from the Internet" problem by tunneling across the firewall gateway to a device deep inside, using encapsulated IP-over-IP / IP-over-TCP tunnels and virtual interfaces, and expressly notes that corporate access is "restricted to a small number of hosts near the firewall gateway." Demizu supplies both the technique (tunneling through/around a firewall gateway) and a motivation (reach resources not adjacent to the firewall) for the two-interface-server design.
- Pre-screening at the outer boundary is a recognized design goal with a predictable implementation. Coley and Milkway both validate by destination port + protocol + source/user identity against a rule base/list, and both drop non-conforming traffic. Placing an equivalent (or replicated) table on the outside interface server so it can reject non-trusted requests before consuming the scarce, private control channel is a design choice with only a finite, predictable set of options — squarely KSR "obvious to try."
- Least-privilege / minimization of risk is the express design driver. The '797 abstract states the intent to "minimize the security risk involved in permitting such connections to be made at all." Giving the outside server only a table of trusted objects (ports/protocols/hosts) — and nothing else — is the most direct way to achieve that, and the benefit is immediate and predictable.
- Replicating configuration/authorization data to a boundary device was routine. Aziz's directory-server distribution of tunnel-bridge tables, plus the ordinary administrative practice reflected in the 1995 firewall-product surveys (Bryan, Doty, Newman), establishes that distributing policy data to a network edge component was well known, with predictable results.
- Secondary indicia are weak or absent. No evidence located of unexpected results, licensing attributable to these two claims, copying, or long-felt need directed to the claimed combination; the patent expired 2016-10-21 and, consistent with the earlier litigation section, no litigation, PTAB proceeding, or 2026 CAFC docket naming US 6,061,797 was found. A 20-year dormancy and a two-claim, heavily narrowed claim set are consistent with a narrow claim scope rather than a commercially significant invention.
6. Track B (planned fallback if § 103(c) disqualifies SGI)
If the SGI disclosure is excluded from the § 103 combination by pre-AIA § 103(c) (common IBM ownership) — or if the § 102(e) date of US 5,826,029 fails because the PCT international filing date falls after 1996-10-21 — a rejection can still be assembled entirely from non-IBM art:
Combination B: Coley (US 5,826,014) + Milkway (US 5,623,601) + Bellovin & Cheswick pp. 86–106 (and Bellovin, IEEE Sep. 1994) + Demizu (DDT) + Aziz (US 5,548,646), optionally with Doty / Bryan / Newman for the state of the commercial art.
- Bastion-host/dual-homed proxy architecture (Bellovin & Cheswick; Milkway's own background classifies firewalls into "screening router, bastion host and dual homed gateway") supplies the two-computer, opposite-sides-of-the-firewall topology of element 1.2/1.5 when combined with the packet-filtering front end.
- Coley + Milkway supply the trusted/rule table (port, protocol, source/user) and validate-and-drop behavior (elements 1.6, 2.3).
- Demizu supplies tunneling across a firewall gateway (element 1.2/1.3 rationale; the inside-out connection concept).
- Aziz supplies the tunneling bridge that consults tables to decide treatment, with table/key data distributed from a directory server (elements 1.7, and the "private control connection" flavor of 2.1).
- Milkway supplies the two interdependent sessions in which the gateway "imitates" each endpoint in turn, directly teaching element 2.5 (neither endpoint is exposed to the other network).
Weakness of Track B: none of these references, taken individually or in combination, describes the explicit two-segment tunneling application with an inside-maintained table copied to a separate outside server. Track B therefore rests more heavily on "obvious to try" reasoning and on the argument that splitting a known single-box proxy/gateway function across a pair of servers straddling the firewall is a predictable architectural rearrangement. That is a defensible but materially weaker position than Track A. Track B is best pleaded as a secondary rejection, with the SGI combination as primary.
7. Counterarguments a patentee would raise (and my assessment)
| Patentee argument | Assessment |
|---|---|
| § 103(c) common ownership disqualifies the SGI reference | Strong for the patentee as to Track A. This is the best invalidity defense and should be tested early; it turns on the record of common ownership/assignment obligation at the time of invention, and on whether US 5,826,029 qualifies under § 102(e) only. |
| § 102(a)/(b) unavailability of WO 1997016911A1 | Correct as a matter of dates (published 1997-05-09 vs. 1996-10-21). Any reliance on the WO publication itself, rather than the US patent, is improper. |
| "Table of trusted objects" is not the same as a port/service rule base | Weak-moderate. The claim requires objects "associated with said secure objects," and the '797's own FIG. 4 defines entries as port + protocol + host object — a service/authorization table. Attack this by reference to the intrinsic record, not to labels. |
| "Copy of the table to the second computer" is not taught; the prior art keeps policy at the firewall | The strongest substantive (non-timing) defense. Rebut with (a) SGI's mirrored cgi-bin program set, (b) Aziz's directory-server table distribution, (c) predictability of replicating configuration data, and (d) the specification's own trivial rationale for when the copy is sent. |
| Means-plus-function: the prior art structures differ | Weak. Pre-AIA § 112 ¶ 6 maps to software performing the recited functions; both the SGI daemons and the Coley/Milkway proxies are programs on general-purpose computers performing pre-screening, table lookup, and forwarding. |
| Teaching away | Not available on this record. Nothing in SGI, Coley, Milkway or Demizu criticizes distributing validation data to an outside component; SGI's criticism is directed at opening firewall ports and at duplicating resources, both of which the '797 also rejects. |
8. Bottom line
- Claim 1 — Would have been obvious over the SGI disclosure (US 5,826,029 / WO 1997016911) in view of Coley (US 5,826,014) and Bellovin & Cheswick (pp. 86–106), further in view of Aziz (US 5,548,646) for the table-replication element. The only non-disclosed feature is the outward replication of the trusted-object table, and that replication is a predictable configuration-management step with a routine, recited rationale. Confidence in the merits: moderately high.
- Claim 2 — Would have been obvious, and is arguably anticipated, by the SGI disclosure alone (inside-initiated, password-authenticated connection opened before external requests are accepted; external daemon listening for requests; forwarding of request data across that connection to an inside daemon executing the real transaction program; decoy program outside so the internal database is never directly exposed), optionally combined with Coley/Milkway for the explicit table lookup. Confidence in the merits: high.
- Proof / procedural obstacles — the real battleground, not the technology:
- Establishing the § 102(e)/§ 363 date of US 5,826,029 (turn on the PCT international filing date for PCT/GB1997/002712-adjacent family documents — verify on the EP/JP family members).
- Defeating any § 103(c) common-ownership argument as to the IBM SGI subject matter.
- Falling back to Track B (non-IBM art) if either of the above fails.
- Explicit non-assertions: I found no litigation, IPR/PGR, or 2026 CAFC docket involving US 6,061,797 (consistent with the earlier sections); I did not confirm the international filing date of the PCT underlying US 5,826,029; and I did not verify the actual cited pages of the Bellovin & Cheswick and Demizu references beyond what the page's citation list states. Those three items should be verified against primary sources before any rejection is finalized.
Key URLs for the references relied on:
- WO 1997016911 A1 (SGI): https://patents.google.com/patent/WO1997016911A1
- US 5,826,029 (SGI, US counterpart): https://www.freepatentsonline.com/5826029.html
- US 5,826,014 (Coley): https://patents.google.com/patent/[US5826014A](/patent/US5826014A)
- US 5,623,601 (Milkway): https://patents.google.com/patent/[US5623601A](/patent/US5623601A)
- Demizu & Yamaguchi, "DDT": https://www.socolar.com/Article/Index?aid=100051200144&jid=100000020607
- Patent under analysis: https://patents.google.com/patent/US6061797/en
Generated 10/1/2026, 2:43:28 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 10019722I'll search for authoritative information on this specific patent number. Let me search for any 2026 CAFC docket activity and additional USPTO records. US Patent 10,019,722 — Verified Bibliographic Summary Search scope note: I searched for…
- US 10241643I'll search for the specific patent number and any litigation/docket activity. No litigation hits for this specific patent yet. Let me check for claim text and any court dockets. Let me try to retrieve the actual claim text. US Patent…
- US 8387155I'll search for authoritative records on this specific patent number before summarizing. Let me pull the actual claim text and check for any 2026 appellate activity. Let me try to retrieve the actual claim language and confirm the…
- US 8127345I'll verify the patent against live sources before summarizing. Now let me pull the actual claim language and check for any 2026 activity. Let me obtain the actual claim text rather than paraphrase from memory. US Patent 8,127,345 B2 —…
- US 11659381US 11,659,381 B2 — Verification Summary Sources used: the authoritative full text of US 11,659,381 B2 supplied in this matter (Google Patents, fetched 2026-10-01), plus live web results including Unified Patents, Docket Alarm/PACER-derived…
- US 8898260I'll search for authoritative information on this specific patent number and any 2026 CAFC activity. Let me dig deeper into the 2026 docket activity and the reexamination/PTAB status specifically for the '260 patent. One more targeted…
- US 8756336I'll search for authoritative information on this specific patent number. US Patent 8,756,336 B2 — Summary I searched for the specific number 8756336 (treated literally, no auto-correction). The authoritative full text (provided) is…
- US 7289772I'll search for authoritative information on this patent, including any 2026 litigation activity. US Patent 7,289,772 — Summary Note on identifiers: I interpreted "7289772" literally as US 7,289,772 B1. I did not find any CAFC 2026 docket…