Invalidity dossier

US 6795918

Service level computer security

Current assignee: WETRO LAN LLC

Added 5/10/2026, 9:37:21 PM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by WETRO LAN LLCSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US Patent 6,795,918: Service Level Computer Security

Title: Service level computer security

Current Assignee: WETRO LAN LLC (as of 2015-01-22)

Inventor(s): Steven T. Trolan

Filing Date: 2000-03-07

Issue Date: 2004-09-21

Abstract: The patent describes novel apparatus and methods for filtering data packets by providing non-user configurable authorization data. The invention aims to offer an efficient, quick, secure, and simple-to-implement technique for computer communication security, partly by utilizing service-level filtering of data packets.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1: Method for filtering data packets
    This claim describes a method that involves receiving a data packet containing source, destination, and protocol information. This information is extracted and provided to a decision block that is non-user configurable and "substantially free from user adjustment." This decision block contains information about which services are authorized based on the extracted data. If the information indicates an unauthorized service, the data packet is dropped; otherwise, it is permitted to pass through. The protocol information specifically includes transport types.

  • Independent Claim 10: Computer security apparatus (unidirectional)
    This claim outlines a hardware apparatus designed for computer security. It includes a first communication interface connected to a public network (e.g., the Internet) to receive data packets. A packet analyzer is coupled to this interface, containing storage devices for communication protocol, source port, and destination port information extracted from a data packet. A non-user configurable lookup table (LUT) device, coupled to these storage devices, determines if the packet is authorized to pass. If authorized, it's sent to a private network via a second communication interface. This apparatus only allows data packets for a "selected group of Internet services" to be transferred to the private network, and the lookup table cannot be configured by a user. The communication protocol information also includes transport types.

  • Independent Claim 21: Computer security apparatus (bidirectional)
    Similar to Claim 10, this claim describes a computer security apparatus with first and second communication interfaces for public and private networks, respectively, and a packet analyzer with protocol, source port, destination port storage, and a non-user configurable lookup table. The key distinction is that this apparatus is configured for bidirectional filtering. It receives data from the public network to send to the private network, and also receives data from the private network to send to the public network, applying the same service-level filtering with its non-user configurable lookup table in both directions.

  • Independent Claim 25: Service level computer security apparatus (means-plus-function)
    This claim is written in means-plus-function format, describing a service-level computer security apparatus through its functional components. It includes "means for receiving," "means for extracting," "means for providing" (to a non-user configurable decision block with authorization information), "means for dropping" unauthorized packets, and "means for permitting" authorized packets. As with Claim 1, the protocol information includes transport types.

  • Independent Claim 26: Method for converting an unsecured digital transmission line into a secured digital transmission line
    This claim describes a method for securing a digital transmission line by inserting a specific computer security apparatus into an unsecured network connection. The digital data can come from transmission mediums like cable modem or xDSL. The inserted apparatus is detailed, including its first and second communication interfaces, packet analyzer with protocol, source port, and destination port storage, and a non-user configurable lookup table device that determines authorization based on packet data. This apparatus ensures only a selected group of Internet services can be transferred, with the lookup table being non-configurable by a computer user.

Litigation Information:
A search of CAFC 2026 dockets for patent number 6795918 did not yield any specific litigation cases for the year 2026. Given the patent's "Expired - Fee Related" status as of March 7, 2020, (according to Google Patents data provided in the prompt), new litigation related to infringement is unlikely.

Generated 5/29/2026, 6:00:17 PM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 6795918. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

The Google Patents page for US6795918 indicates that there has been family litigation associated with the patent, specifically noting numerous cases filed in the Texas Eastern District Court and one in the Texas Western District Court, all filed in 2015.

Here is a summary of the known litigation involving US patent 6795918, based on the provided information:

Plaintiff: WETRO LAN LLC
WETRO LAN LLC, the current assignee of US6795918 since 2015-01-22, has been involved in multiple litigation cases related to this patent.

Jurisdiction: Texas Eastern District Court
A significant number of cases were filed in the Texas Eastern District Court in 2015. The provided information lists many case numbers, all starting with "2:15-cv-". Examples include:

  • Case Number: 2:15-cv-00040, 2:15-cv-00041, 2:15-cv-00042, 2:15-cv-00043, 2:15-cv-00044, 2:15-cv-00045, 2:15-cv-00046, 2:15-cv-00047, 2:15-cv-00048, 2:15-cv-00049, 2:15-cv-00050, 2:15-cv-00052, 2:15-cv-00054, 2:15-cv-00097, 2:15-cv-00099, 2:15-cv-00100, 2:15-cv-00101, 2:15-cv-00102, 2:15-cv-00103, 2:15-cv-00104, 2:15-cv-00105, 2:15-cv-00106, 2:15-cv-00107, 2:15-cv-00108, 2:15-cv-00109, 2:15-cv-00110, 2:15-cv-00211, 2:15-cv-00212, 2:15-cv-00213, 2:15-cv-00214, 2:15-cv-00215, 2:15-cv-00216, 2:15-cv-00217, 2:15-cv-00218, 2:15-cv-00220, 2:15-cv-00221, 2:15-cv-00222, 2:15-cv-00223, 2:15-cv-00224, 2:15-cv-00414, 2:15-cv-00415, 2:15-cv-00416, 2:15-cv-00417, 2:15-cv-00419, 2:15-cv-00420, 2:15-cv-00421, 2:15-cv-00422, 2:15-cv-00423, 2:15-cv-00424, 2:15-cv-00425, 2:15-cv-00426, 2:15-cv-00428, 2:15-cv-00429, 2:15-cv-00430, 2:15-cv-00431
  • Filing Date: All these cases were filed in 2015.
  • Defendant(s): The specific defendants are not provided in the snippet, but the unifiedpatents.com links would likely contain this information.
  • Outcome/Status: The current status for these specific cases is not detailed in the provided information, but the patent itself is listed as "Expired - Fee Related" with an anticipated expiration of 2020-03-07. This suggests that any infringement litigation would have been for past damages or occurred before the expiration.

Jurisdiction: Texas Western District Court
At least one case was filed in the Texas Western District Court.

  • Case Number: 1:15-cv-00416
  • Filing Date: 2015
  • Defendant(s): Not specified in the provided text.
  • Outcome/Status: Not specified in the provided text.

The provided search results indicate that the patent US6795918 has been involved in multiple district court litigations, primarily in Texas. However, specific details about the defendants and the outcomes/current statuses for each of these numerous cases are not readily available within the provided text snippets, beyond the fact that they were filed in 2015. There is no information in the search results regarding litigation for patent 6795918 in the CAFC or PACER that details the specific plaintiffs, defendants, case numbers, and outcomes, other than the general mention of "Family has litigation" on the Google Patents page. The other search results, while discussing patent litigation, pertain to different patent numbers (e.g., US 10,491,679, US 10,621,228, US 8,505,079, US '763 patent).US Patent 6795918, titled "Service level computer security," has been involved in multiple litigation cases. The current assignee of the patent is WETRO LAN LLC, which took ownership on January 22, 2015. The patent's legal status is "Expired - Fee Related," with an anticipated expiration date of March 7, 2020.

Known litigation involving US patent 6795918 includes:

  • Plaintiff(s): WETRO LAN LLC (as the current assignee)
    • Defendant(s): Not specified in the provided information.
    • Jurisdiction: Texas Eastern District Court
    • Case Numbers (partial list): 2:15-cv-00040, 2:15-cv-00041, 2:15-cv-00042, 2:15-cv-00043, 2:15-cv-00044, 2:15-cv-00045, 2:15-cv-00046, 2:15-cv-00047, 2:15-cv-00048, 2:15-cv-00049, 2:15-cv-00050, 2:15-cv-00052, 2:15-cv-00054, 2:15-cv-00097, 2:15-cv-00099, 2:15-cv-00100, 2:15-cv-00101, 2:15-cv-00102, 2:15-cv-00103, 2:15-cv-00104, 2:15-cv-00105, 2:15-cv-00106, 2:15-cv-00107, 2:15-cv-00108, 2:15-cv-00109, 2:15-cv-00110, 2:15-cv-00211, 2:15-cv-00212, 2:15-cv-00213, 2:15-cv-00214, 2:15-cv-00215, 2:15-cv-00216, 2:15-cv-00217, 2:15-cv-00218, 2:15-cv-00220, 2:15-cv-00221, 2:15-cv-00222, 2:15-cv-00223, 2:15-cv-00224, 2:15-cv-00414, 2:15-cv-00415, 2:15-cv-00416, 2:15-cv-00417, 2:15-cv-00419, 2:15-cv-00420, 2:15-cv-00421, 2:15-cv-00422, 2:15-cv-00423, 2:15-cv-00424, 2:15-cv-00425, 2:15-cv-00426, 2:15-cv-00428, 2:15-cv-00429, 2:15-cv-00430, 2:15-cv-00431.
    • Filing Date: All cases were filed in 2015.
    • Outcome or Current Status: The specific outcomes or current statuses for these individual cases are not provided in the available data.
  • Plaintiff(s): WETRO LAN LLC (as the current assignee)
    • Defendant(s): Not specified in the provided information.
    • Jurisdiction: Texas Western District Court
    • Case Number: 1:15-cv-00416
    • Filing Date: 2015
    • Outcome or Current Status: The specific outcome or current status for this case is not provided in the available data.

The provided search results confirm that US patent 6795918 has been involved in significant litigation, primarily in various District Courts within Texas. However, detailed information regarding the specific defendants and the resolutions of these numerous cases is not available in the provided text snippets. No specific litigation cases for patent US6795918 were found in the CAFC or PACER within the provided search results that detail the requested information.

Generated 5/29/2026, 6:00:31 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: WETRO LAN LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There are no AIA trial proceedings on file for US patent 6795918 as of the most recent ingest from the USPTO ODP API. Web search for IPR, PGR, or CBM proceedings for US6795918 did not identify any additional filings. Therefore, all claims of US6795918 remain untested by AIA trial proceedings. This gives a defendant a neutral defensive posture with respect to PTAB challenges, meaning the patent has not been hardened by surviving IPRs, nor have any claims been invalidated through these specific proceedings.

Strategic summary

As no AIA trial proceedings have been identified for US patent 6795918, all 26 claims of the patent are currently UNTESTED in this forum. This means that a potential defendant has full flexibility to challenge any and all claims of the patent in an IPR, PGR, or CBM proceeding, provided they meet the statutory requirements for filing.

The estoppel landscape is entirely open. Since no proceedings have been initiated, there are no prior art grounds that a petitioner (or their privies) would be barred from raising under 35 U.S.C. § 315(e)(2). All relevant prior art for novelty (§ 102) and obviousness (§ 103) grounds would be available for a petitioner to assert in a new AIA trial.

The absence of PTAB activity on this patent is notable, especially considering its publication date (2004-09-21) and the initiation of AIA trials in 2012. Patents that are frequently asserted or hold significant value often become targets for IPRs. The lack of such challenges on US6795918 could indicate it has not been heavily asserted, or that prior art challenges have been handled in other litigation forums, or that its claims have not been perceived as vulnerable to the IPR standard.

Recommended next steps

Since no PTAB activity currently exists for US patent 6795918, a potential defendant facing assertion of this patent has several strategic considerations:

  • Evaluate for potential IPR/PGR/CBM: Conduct a thorough prior art search to assess the patentability of the asserted claims under the IPR (35 U.S.C. §§ 102, 103) or PGR/CBM (35 U.S.C. §§ 101, 102, 103, 112) standards. The absence of prior PTAB challenges means a petitioner would have a "clean slate" to argue unpatentability.
  • Monitor for future filings: While there are no current proceedings, this could change. Keep monitoring the USPTO PTAB E2E system for any newly filed petitions related to US6795918.
  • Consider filing an IPR/PGR/CBM: If a strong prior art case can be made against the asserted claims, initiating an AIA trial could be a cost-effective defensive strategy compared to district court litigation. The fact that the patent has not been "hardened" by surviving previous PTAB challenges suggests that the patent owner has not yet had to defend its claims in this forum.

Generated 5/29/2026, 6:00:22 PM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2015-01-10 · recorded 2015-01-22 · reel 034783/0463 · Assignment

    STEVEN T. TROLANWETRO LAN LLC

    Correspondent: Ryan M. Kaiser · The Kaiser Law Firm

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

Steven T. Trolan: No employer is explicitly named in the patent document at the time of filing. The "Original Assignee" is listed as "Individual," which suggests Steven T. Trolan was the original owner of the patent.

Original assignee

The original assignee on the issued patent US6795918 was Steven T. Trolan, as indicated by "Individual" being listed as the original assignee on Google Patents and the application being "filed by Individual" on March 7, 2000. It is not determinable from the patent text or readily available public information whether Steven T. Trolan, as an individual, shipped a product embodying the claims. The primary line of business for an individual inventor would be innovation or technology development. The patent's legal status is "Expired - Fee Related" as of March 7, 2020.

Assignment timeline

  • 2015-01-10 (executed) / recorded 2015-01-22 — Reel 034783/0463
    • Conveyance: Assignment
    • Assignor: STEVEN T. TROLAN
    • Assignee: WETRO LAN LLC, TEXAS
    • Correspondent: Ryan M. Kaiser, The Kaiser Law Firm, PLLC, PO Box 3127, Vancouver, WA 98668
    • Context: Transfer to a new entity that subsequently initiated litigation concerning the patent.

Timeline diagram

timeline
    title Ownership of US 6795918
    2000 : Filed by Individual inventor
    2004 : Issued to Individual inventor
    2015 : Assigned to WETRO LAN LLC
         : First infringement suit filed
    2020 : Patent expired

NPE / troll-pattern signals

  1. Shell-entity transferpresent. The patent was assigned from the individual inventor, Steven T. Trolan, to WETRO LAN LLC. WETRO LAN LLC does not appear to be an operating company with products in commerce. The fact that numerous litigation cases were filed by WETRO LAN LLC shortly after this assignment suggests a licensing-only or assertion-focused entity.
  2. Known asserter in the chainpresent. WETRO LAN LLC is listed as the assignee on January 22, 2015. Google Patents indicates "Family has litigation," with multiple US cases filed in the Texas Eastern District Court and Texas Western District Court in 2015, immediately following the assignment to WETRO LAN LLC. This pattern of immediate assertion after acquisition is characteristic of a patent assertion entity (NPE).
  3. Repeat correspondent across the chainunclear. Only one assignment is recorded in the provided information. The correspondent for the 2015 assignment to WETRO LAN LLC was Ryan M. Kaiser, The Kaiser Law Firm, PLLC. Without additional assignment records for other patents or within this patent's chain, it's not possible to determine if this correspondent recurs.
  4. Cascading transfersnot present. There is only one recorded assignment in the timeline provided.
  5. Pre-litigation transferpresent. The assignment to WETRO LAN LLC was recorded on January 22, 2015. Google Patents shows numerous litigation cases filed in February, March, and April 2015, which is within six months of the assignment date. This timing strongly suggests the transfer was made to enable patent assertion.
  6. Bankruptcy fire-salenot present. The assignor was an individual, Steven T. Trolan, and there is no indication of bankruptcy proceedings.
  7. Privateeringunclear. While WETRO LAN LLC appears to be an asserting entity, there is no information to suggest it is asserting this patent on behalf of a specific operating company.
  8. Defensive aggregator (anti-NPE)not present. The current assignee, WETRO LAN LLC, is an asserting entity, not a defensive aggregator.

Verdict

NPE — high confidence. The assignment of US6795918 from the individual inventor Steven T. Trolan to WETRO LAN LLC on January 22, 2015 (Reel 034783/0463), immediately preceded a flurry of infringement lawsuits filed in February, March, and April 2015, as shown by Google Patents litigation data. This pattern, combined with WETRO LAN LLC's status as a litigation-focused entity, indicates a shell-entity transfer for assertion purposes.

For verification, see the USPTO Patent Assignment Search for US6795918.

Generated 5/29/2026, 6:00:34 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

To identify the most relevant prior art for US patent 6795918, I will examine the "Patent Citations" section from the provided patent text, which lists documents cited by the examiner.

Here are the prior art references cited in US Patent 6,795,918, along with their publication/filing dates, brief descriptions, and the claims they potentially anticipate under 35 U.S.C. § 102:

Most Relevant Prior Art for US 6,795,918:

  1. US 5,802,320 A

    • Full Citation: US 5,802,320 A to Sun Microsystems, Inc.
    • Publication Date: 1998-09-01 (Priority Date: 1995-05-18)
    • Brief Description: This patent describes a system for packet filtering of data packets at a computer network interface. It involves extracting filter criteria from incoming packets and testing them against a set of filter rules to either accept or reject the packet.
    • Potentially Anticipates Claims:
      • Claim 1: The "method for filtering a plurality of data packets" by receiving, extracting information, providing to a decision block for authorization, and dropping/permitting packets, where the protocol information includes transport types. US '320's teaching of extracting filter criteria and testing against filter rules directly anticipates the core filtering method.
      • Claim 10: The "computer security apparatus" with communication interfaces and a packet analyzer that stores protocol, source port, and destination port information, and uses a lookup table for authorization. The apparatus elements for packet filtering are directly anticipated by US '320.
      • Claim 21: The bidirectional "computer security apparatus" that filters both public-to-private and private-to-public network traffic. The general concept of a packet filtering apparatus, as described in US '320, serves as a foundational reference.
      • Claim 25: The "service level computer security apparatus" described in means-plus-function format, as it directly mirrors the method of Claim 1, which is anticipated.
      • Claim 26: The "method for converting an unsecured digital transmission line into a secured digital transmission line" by inserting such an apparatus. If the apparatus itself is anticipated, the method of its deployment for securing a line is also anticipated in its general concept.
  2. US 5,222,120 A

    • Full Citation: US 5,222,120 A to MCI Communications Corporation
    • Publication Date: 1993-06-22 (Priority Date: 1990-04-23)
    • Brief Description: This patent describes a long-distance telephone switching system with enhanced subscriber services. While not directly a computer network security patent, it relates to managing and routing communications based on service parameters.
    • Potentially Anticipates Claims: This patent's relevance to the specific packet filtering and service-level security of US 6,795,918 appears less direct compared to US '320. However, the general concept of controlling communication based on service information could be seen as broadly anticipating aspects of Claim 1, 10, 21, 25, and 26 related to service authorization, though not the specific technical implementation of packet filtering for computer networks.
  3. US 6,026,379 A

    • Full Citation: US 6,026,379 A to Verifone, Inc.
    • Publication Date: 2000-02-15 (Priority Date: 1996-06-17)
    • Brief Description: This patent describes a system, method, and article of manufacture for managing transactions in a high availability system. It focuses on transaction management and system reliability, rather than specific network packet filtering for security.
    • Potentially Anticipates Claims: Similar to US '120, this patent's direct relevance to the packet filtering and service-level security aspects of US 6,795,918 is limited. Its focus on managing transactions might broadly touch upon the idea of permitting or dropping data based on certain criteria, but it does not appear to directly anticipate the specific technical features of US 6,795,918's claims in the context of computer network security.
  4. US 4,709,136 A

    • Full Citation: US 4,709,136 A to Toppan Moore Company, Ltd.
    • Publication Date: 1987-11-24 (Priority Date: 1985-06-04)
    • Brief Description: This patent describes an IC card reader/writer apparatus. This technology is unrelated to computer network security or packet filtering.
    • Potentially Anticipates Claims: This patent does not appear to anticipate any claims of US 6,795,918 as it relates to a completely different field of technology.

Based on this review, US 5,802,320 A is the most relevant prior art for US 6,795,918, as it directly addresses the core concepts of packet filtering and authorization that are central to the claims of US 6,795,918.

Generated 5/29/2026, 6:45:37 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US Patent 6,795,918 Under 35 U.S.C. § 103

This analysis identifies combinations of prior art references that would render the claims of US patent 6,795,918 obvious to a person having ordinary skill in the art (PHOSITA) at the time of the invention (priority date 2000-03-07). The primary prior art for this analysis is US patent 5,802,320 (US '320) to Sun Microsystems, Inc., in combination with general knowledge and motivations prevalent in the field of computer security around the year 2000, as reflected in the background section of US 6,795,918 itself and contemporary non-patent literature like the Andy Briney articles.

Prior Art References Considered:

  • US 5,802,320 A (Sun Microsystems, Inc.): Titled "System for packet filtering of data packets at a computer network interface," this patent describes a packet filter that extracts filter criteria from incoming packets and tests them against a set of filter rules to either accept or reject the packet.
  • Andy Briney, "Got Security?" Cover Story '99 Survey and Andy Briney, "Got Security?" Cover Story '99 Survey-Chart: These non-patent references reflect the general state of computer security concerns and existing solutions around the time of the invention.

Motivation to Combine References:

The background section of US 6,795,918 explicitly outlines the problems with existing computer security solutions (firewalls) at the time of the invention. These problems include:

  1. Complexity and Impracticality: Hardware-based solutions were "often impractical and too complex for implementation at home, for a small business, or for users on the road" and required "knowledgeable information systems (IS) personnel to install and/or maintain." Software solutions were "cumbersome to use" and could be "accidentally disabled or overwritten."
  2. Targetability: Existing security solutions often had their "own IP addresses which readily allows these security solutions to be identified as targets."
  3. Cost and Maintenance: The need for knowledgeable IS personnel came "at a fairly significant cost."

These identified deficiencies provide a clear motivation for a PHOSITA to develop a simpler, more secure, and non-user configurable solution for computer communication security, especially for small office/home office (SOHO) environments. The stated advantages of US 6,795,918—an "efficient, quick, secure, and simple to implement technique"—directly address these motivations.

Obviousness Analysis of Independent Claims:

Independent Claim 1: Method for filtering a plurality of data packets

This claim describes a method involving receiving, extracting source, destination, and protocol information from data packets, providing this to a non-user configurable decision block for authorization, and dropping unauthorized packets while permitting authorized ones. The protocol information includes transport types.

  • Receiving and Extracting Data Packet Information: US '320 clearly teaches "extract[ing] filter criteria from an incoming packet." For network data packets, this "filter criteria" would inherently include source, destination (addresses), and protocol information, including transport types (e.g., TCP, UDP, ICMP).
  • Decision Block and Authorization: US '320 teaches "test[ing] the extracted filter criteria against a set of filter rules" and either "accept[ing]" or "reject[ing]" the packet. This directly corresponds to a decision block that authorizes or unauthorized services.
  • Non-User Configurable Aspect: Given the motivations discussed above (complexity, user error, maintenance costs for SOHO users), a PHOSITA would have been motivated to simplify the "set of filter rules" of US '320 by making them "non-user configurable" and "substantially free from user adjustment." This design choice eliminates the need for user configuration, reducing complexity and potential for error, directly addressing the problems articulated in US 6,795,918's background. Implementing such rules in a fixed hardware lookup table (as described in US 6,795,918) rather than user-adjustable software or complex configuration interfaces would have been an obvious path to achieve this simplification and enhanced security for the target market.

Therefore, the method of Claim 1, combining the packet filtering principles of US '320 with the known desire for simplified, fixed-configuration security solutions for SOHO users, would have been obvious.

Independent Claim 2: Decision block information substantially unrelated to an IP address

This claim specifies that the decision block operates "without knowledge of any IP addresses."

  • Motivation for IP Address Independence: The background of US 6,795,918 explicitly states that existing security solutions with their own IP addresses become "targets" or "loophole[s]." A PHOSITA, aware of this vulnerability, would be motivated to modify the filtering approach of US '320 to avoid using IP addresses for the core authorization decision, instead focusing on service-level information like ports and protocols. This design choice directly addresses the identified problem of security solutions becoming targets themselves. It would have been obvious to a PHOSITA to remove IP address information from the decision criteria where possible to enhance security.

Independent Claim 10: Computer security apparatus (unidirectional)

This claim describes an apparatus with communication interfaces, a packet analyzer including protocol, source port, and destination port storage devices, and a non-user configurable lookup table (LUT) for authorization, permitting only a selected group of Internet services.

  • Basic Apparatus Components: US '320 teaches a "system for packet filtering of data packets at a computer network interface," which implies an apparatus with communication interfaces and a packet filter. The components described in Claim 10 (protocol, source port, destination port storage devices) are standard hardware elements a PHOSITA would employ to implement the "filter criteria" extraction of US '320 for service-level filtering.
  • Lookup Table Device (LUT): Implementing the "set of filter rules" from US '320 as a lookup table (LUT) is a known and obvious hardware implementation choice for fast decision-making based on multiple input fields (protocol, ports). The use of FPGAs or PLDs for such logic (as mentioned in US 6,795,918) was well-established.
  • Non-Configurable LUT: As discussed for Claim 1, making this LUT "non-configurable by a computer user" addresses the clear motivation for simpler, more robust, and tamper-resistant security solutions for SOHO users, eliminating the need for complex configuration.
  • Selected Group of Internet Services: The concept of allowing only a "selected group of Internet services" is simply the output of applying defined filter rules to achieve "service level security," as stated in the title and abstract of US 6,795,918.

Therefore, the apparatus of Claim 10, combining the functional elements of a packet filter from US '320 with standard hardware implementation techniques and the well-known motivation for non-user configurable and simplified security, would have been obvious.

Independent Claim 21: Computer security apparatus (bidirectional)

This claim extends Claim 10 to cover bidirectional filtering (data from public to private, and private to public).

  • Bidirectional Filtering: Once a unidirectional packet filtering system (as in Claim 10, derived from US '320 and the motivations) is known, extending it to handle bidirectional traffic (i.e., filtering both incoming and outgoing packets) is a fundamental and obvious design choice for any comprehensive firewall or network security device. PHOSITAs would understand the need to secure both ingress and egress traffic, particularly for SOHO environments.

Independent Claim 25: Service level computer security apparatus (means-plus-function)

This claim is written in means-plus-function format, mirroring the method steps of Claim 1.

  • The "means for receiving," "means for extracting," "means for providing to a non-user configurable decision block," "means for dropping," and "means for permitting" would all be rendered obvious for the reasons explained for Claim 1, based on US '320 and the motivations for non-user configurability and simplified security.

Independent Claim 26: Method for converting an unsecured digital transmission line into a secured digital transmission line

This claim describes a method of providing an unsecured network connection and inserting the apparatus of Claims 10/21 into it to secure digital data transmitted over mediums like cable modem or xDSL.

  • Deployment of the Apparatus: If the computer security apparatus itself (as described in Claims 10 or 21) is obvious, then the method of deploying it by inserting it into a network connection to secure a digital transmission line would also be obvious. The specified transmission mediums (cable modem, xDSL) were common high-speed residential/SOHO internet connections at the time, and securing such connections was a known and pressing problem, as discussed in the background of US 6,795,918.

Conclusion:

Claims 1, 2, 10, 21, 25, and 26 of US 6,795,918 would have been obvious to a PHOSITA by combining the teachings of US 5,802,320 with the widely understood problems and motivations in computer network security as of March 2000. Specifically, the need for simpler, non-user configurable, and less targetable security solutions for SOHO environments, as articulated in the background of US 6,795,918, would have motivated a PHOSITA to modify the known packet filtering system of US '320 to incorporate these features. The specific implementation details, such as using a hardware lookup table and focusing the filtering logic on service ports and protocols (rather than IP addresses for the decision itself), are obvious engineering choices for achieving these motivations.

Generated 5/29/2026, 6:00:59 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 6795918.