Invalidity dossier

US 7372961

Method of public key generation

Current assignee: Malikie Innovations Ltd., Key Patent Innovations Ltd.

Added 9/28/2026, 7:32:32 PM

At a glanceNo PTAB challenges5 lawsuits on fileasserted by Malikie Innovations Ltd. +1Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll verify against live sources and check the litigation/docket angle.

Let me check for 2026 Federal Circuit activity and the recent reexamination event.

One more check for any 2026 Federal Circuit docket activity.

US Patent 7,372,961 — Summary

Note on sources & date: I was able to pull the patent's own front-matter/claim text plus live docket and USPTO-related material. One caveat: the instruction gives the current date as April 26, 2026, but several live results I retrieved are dated after that (e.g., a Unified Patents post dated Sept. 17, 2026, and a Law360 item dated July 17, 2026). I report those literally rather than discard them, and flag them where they affect the picture.


1. Bibliographic data (as printed on the patent face / Google Patents)

Field Value
Patent number US 7,372,961 B2 (application 10/025,924)
Title Method of Public Key Generation
Issue date May 13, 2008 (pre-grant pub. US 2002/0090085 A1, July 11, 2002)
Filing date December 26, 2001
Earliest priority December 27, 2000 (Canadian App. No. 2,329,590)
Inventors Scott A. Vanstone (Campbellville, CA); Ashok Vadekar (Rockwood, CA); Robert J. Lambert (Cambridge, CA); Robert P. Gallant (Mississauga, CA); Daniel R. Brown (Toronto, CA); Alfred Menezes (printed as "West Canada (CA)" on the face of the patent)
Original assignee Certicom Corp., Mississauga, Canada
Current assignee (recorded) Malikie Innovations Limited (Ireland), per assignment recorded 2025‑04‑10, effective 2025‑03‑28
Chain of title Certicom Corp. → BlackBerry Limited (recorded 2016‑07‑27) → Malikie Innovations Limited
Examiners / counsel Emmanuel L. Moise (Primary), Michael Pyzocha (Asst.); Blake, Cassels & Graydon LLP (John R. S. Orange; Brett J. Slaney)
Claims / sheets 30 claims, 7 drawing sheets; PTA disclaimer of 563 days
Classifications H04L 9/08, G06F 7/58 (CPC: H04L9/0861, H04L9/0869, H04L2209/26, H04L2209/46)
Legal status Expired – Lifetime; adjusted expiration July 12, 2023
Certificate of correction Recorded July 12, 2011 (per USPTO legal events)

Family: continuations US 12/119,248 → US 8,000,470 B2 (2011‑08‑16) and US 13/181,184 → US 8,466,944 B2 (2013‑06‑11), both claiming the same 2000‑12‑27 priority. Corresponding Canadian patent CA 2,329,590 C (2012‑06‑26).


2. Abstract (verbatim)

"A potential bias in the generation or a private key is avoided by selecting the key and comparing it against the system parameters. If a predetermined condition is attained it is accepted. If not it is rejected and a new key is generated."


3. Technical problem and thrust

The specification targets a specific known weakness in DSA/ECDSA ephemeral (per‑session) key generation. The NIST DSS (FIPS 186‑2) derivation, k = SHA‑1(seed) mod q (equivalently, subtract q if the hash output ≥ q), implicitly performs a modular reduction, which makes some values of k more likely than others. The patent cites Daniel Bleichenbacher's result that this bias is exploitable — "an examination of 2²² signatures could yield the private key d in 2⁶⁴ steps using 2⁴⁰ memory units" — and states the invention's object is "a key generation technique in which any bias is eliminated during the selection of the key" by rejection sampling: compare the hash output against the group order q before reducing mod q, and discard/retry rather than reduce.

The specification also describes further embodiments (FIGS. 3–7): deterministic re-hashing of an incremented seed; concatenating two hash outputs then taking an L-bit string; sliding an L-bit window over a combined/extended hash output; and low-Hamming-weight masking (additive with precomputed k′, or multiplicative with β = αᵘ) referencing Canadian application 2,217,925. Note: the quoted Canadian co-pending material maps to US 6,337,909 / EP 0 854 603, both of which appear in the "Family Cites Families" list.


4. Independent claims — plain language

The '961 patent has four independent claims: 1, 9, 15, and 23. Claims 1, 15 and 23 recite the same rejection-sampling method in three different statutory forms (method, computer-readable medium, and apparatus/unit). Claim 9 is the two-hash variant.

Claim 1 — Method (the core, and the claim asserted in litigation):

  • Generate a seed value SV from a random number generator;
  • Hash it: H(SV);
  • Determine whether H(SV) < q prior to reducing mod q — i.e., judge the raw hash output against the group order, not a reduced value;
  • If H(SV) < q → accept it as the key k, where k is exactly H(SV) (no reduction is applied);
  • If not → reject it and repeat (regenerate/rehash) until a value passes;
  • Then use k in the cryptographic function (claim 4: "used for generation of a public key" — hence the title).

Plain language: "Don't reduce mod q — roll the dice and throw away any roll that lands outside the allowed range, then roll again."

Claim 9 — Method, two-output variant:

  • Generate SV; hash it → first output H(SV);
  • Increment SV by a predetermined function f( ) and hash again → second output H(f(SV));
  • Combine the two outputs (specification: typically concatenation, e.g. 320 bits);
  • Test the combined output against q before any mod-q reduction; accept as k if less than q; otherwise reject and repeat.

Claim 15 — Computer-readable medium:

  • Identical functionality to claim 1 (RNG seed → hash → compare to q pre-reduction → accept k = H(SV) if less, else reject and repeat), packaged as computer-executable instructions.

Claim 23 — Cryptographic unit:

  • Identical functionality to claim 1, implemented in a unit having an arithmetic processor (the FIG. 1 unit: secure memory, arithmetic processor for finite-field operations, RNG, and hash function).

Dependent claims worth noting: claim 2 (fresh seed on rejection); claim 5–6 (q prime of length L; hash output of length L); claim 7–8 (on rejection, increment the output by a deterministic function — optionally by adding a constant — and re-hash); claim 12–14 (produce a bit string longer than L and select an L-bit string; reject excess bits so the new output is L bits).

Important scoping observation: the low-Hamming-weight masking embodiments (additive k′ masking, multiplicative β = αᵘ masking) described in the '961 specification's FIG. 7 discussion were not carried into the '961 independent claims. Those subject matters were pursued in the continuation US 8,000,470, whose independent claims (e.g. claim 2 of '470: "generating a low Hamming weight integer using a random number generator; combining said low Hamming weight integer with a first precomputed value to obtain a requisite Hamming weight; and providing the combination as said private key") are directed to the masking technique rather than the reject-if-≥-q technique. Do not conflate the two claim sets.


5. Litigation, PTAB, and reexamination posture (verified via live sources)

PTAB

  • IPR2019-00923 — Petitioners Facebook, Inc., Instagram, LLC and WhatsApp Inc. against BlackBerry; filed April 3, 2019; Not Instituted – Merits (terminated Nov. 5, 2019). Source: Unified Patents PTAB portal.
  • IPR2020-01741 — Petitioner MobileIron, Inc.; filed Oct. 2, 2020; terminated by settlement per the Google Patents litigation entry.

District courts

  • N.D. Tex. 3:16-cv-02185; C.D. Cal. 2:18-cv-01844 (BlackBerry v. Facebook/Instagram/WhatsApp — the '961 patent was one of seven patents-in-suit, per IPWatchdog, Mar. 24, 2018); N.D. Cal. 3:20-cv-02877 (MobileIron v. BlackBerry).
  • W.D. Tex. 7:25-cv-00222, Malikie Innovations Ltd. et al. v. MARA Holdings, Inc. (filed 2025‑07‑25; Midland‑Odessa Division). Six patents asserted: 8,788,827; 10,284,370; 8,666,062; 7,372,960; 7,372,961; 8,532,286. At least claim 1 of the '961 patent is asserted, with infringement alleged based on MARA's Bitcoin-protocol-compliant mining hardware/software/wallets.
  • Claim construction: Markman hearing March 4, 2026; Claim Construction Order entered March 12, 2026 (Judge Derek T. Gilliland). A live dispute concerns the terms "random number generator" and "seed value" in claim 1 — MARA argues "random" excludes pure deterministic PRNGs, and relies on prosecution-history statements distinguishing the DSS prior art. This directly implicates the scope of claim 1's "generating a seed value SV from a random number generator." Trial was set for March 1, 2027.
  • Ex parte reexamination of the '961 patent was granted March 10, 2026 (notice filed Mar. 11, 2026, Dkt. 79), finding a substantial new question of patentability — completing ex parte reexamination grants on all six asserted patents. Note that five of the six asserted patents (including the '961, which expired July 12, 2023) are expired, meaning claims cannot be amended — only cancelled or confirmed.
  • A § 290 report of record in 7:25-cv-00222 recites a "6/15/2026 Order Dismissing Case (Doc 99)." I flag this as ambiguous — I could not confirm from the sources retrieved whether this reflects disposition of the entire case, dismissal of particular patents/claims, or a docket-housekeeping entry. Treat it as an open item, not a settled fact.
  • Parallel campaign: Malikie/Key Patent Innovations v. Core Scientific & CoreWeave, E.D. Tex. 2:25-cv-519 (the '961 patent is not among the patents joined against CoreWeave in the motion to dismiss excerpt I reviewed; the '960, '062 and '286 patents are the § 101 targets there).

Federal Circuit

  • I located CAFC 20-1256 (2020) in the Unified Patents litigation feed associated with this family, but no 2026 CAFC docket for US 7,372,961. My searches for a 2026 Federal Circuit appeal naming the '961 patent or Malikie returned nothing on point. I cannot rule one out, but I have no authoritative basis to assert one exists — treat "no 2026 CAFC appeal found" as the accurate statement.

6. Uncertainty / verification notes

  1. Menezes's address is printed on the patent face as "West Canada (CA)," which is not a normal place name; other records list him at Waterloo, Canada. I report it as printed rather than correcting it.
  2. File-wrapper details (e.g., the exact date and scope of the 2011 certificate of correction) are not in the retrieved text beyond the legal-events entry.
  3. Reexamination outcome — as of the material retrieved, the '961 reexam had been granted; I did not retrieve a first Office Action on the merits, nor confirmation of whether the '961 patent was among the five reexams for which the PTO denied Malikie's summary-termination requests (that May 20, 2026 notice referenced five patents without enumerating them in the excerpt).
  4. I did not obtain direct USPTO Patent Center / Public PAIR output or a Federal Circuit docket query; the litigation and PTAB data above come from Google Patents' legal-events and litigation tables, Unified Patents' portals, CourtListener/RECAP filings, and an archived W.D. Tex. § 290 report.

Generated 9/28/2026, 7:44:20 PM

Cases on file (5)

Group view →

Specific litigation cases in our database that name US patent 7372961. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2016: 1 case1'16'172018: 1 case'18'19'20'21'22'23'242025: 1 case'25
Cases asserting US 7372961, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research this using the patent's own litigation records plus targeted searches.

Good initial leads. Let me verify each case and pull details.

Bottom line

US 7,372,961 is a real, litigated patent (Certicom/BlackBerry/now Malikie lineage), and it has been the subject of one Federal Circuit appeal entry, two PTAB proceedings, and several district court cases. Source quality varies: I could verify some details directly from court dockets/secondary databases, while a few items (notably the 2020 N.D. Cal. case caption/roles and the 2025 W.D. Tex. filing date) I could only partially confirm. I flag those explicitly below rather than filling gaps.

Note on identifiers, per your instruction: I am treating 7,372,961 and 7,372,960 as different patents. The whole-number identifier appearing as "737296" in some press coverage (e.g., ValueWalk, ITP.net) is not this patent as printed; those pieces describe "a method used to generate a cryptographic public key," which matches 7,372,961 — i.e., an apparent digit-drop typo in those outlets, not a separate patent. Ars Technica and CRN list 7,372,961 correctly.


1. District court litigation

# Caption Court / Case No. Filed Plaintiff(s) Defendant(s) '961 role Status
1 BlackBerry Limited et al. v. Avaya Inc. N.D. Tex. (Dallas), 3:16-cv-02185 2016-07-27 BlackBerry Limited; BlackBerry Corporation Avaya Inc. Asserted patent-in-suit (1 of 8) Outcome not verified; venue-transfer motion denied 2017-10-10
2 BlackBerry Limited v. Facebook, Inc., WhatsApp Inc., Instagram, LLC C.D. Cal., 2:18-cv-01844-GW-KSx 2018-03-06 BlackBerry Limited Facebook, Inc.; WhatsApp Inc.; Instagram, LLC Asserted (reported as 1 of 7 patents-in-suit) '961 not adjudicated; case dismissed with prejudice by stipulation 2021-02-16
3 MobileIron, Inc. v. BlackBerry Corporation et al. N.D. Cal., 3:20-cv-02877 2020 (exact date unverified) MobileIron, Inc. (per caption) BlackBerry Corporation (et al.) Asserted/at issue Not verified; parallel IPR settled 2021
4 Malikie Innovations Ltd. v. MARA Holdings Inc. W.D. Tex., 7:25-cv-00222 2025 (exact date unverified) Malikie Innovations Ltd. MARA Holdings Inc. Asserted — at least claim 1 (1 of 6 patents) Pending; amended complaint filed (Doc. 36)

Details and grounding

  1. Avaya (N.D. Tex. 3:16-cv-02185). Docket confirms plaintiffs BlackBerry Limited and BlackBerry Corporation v. Avaya Inc., filed July 27, 2016, Judge Barbara M.G. Lynn, Dallas Division; plaintiff's motion to transfer venue was denied by memorandum opinion and order (Doc. 59, Oct. 10, 2017) — https://dockets.justia.com/docket/texas/txndce/3:2016cv02185/[276894](/patent/276894). 7,372,961 was listed among the eight asserted patents, with the accused products described as those "includ[ing] OpenSSL and Open SSL elliptic curve cryptography" (Avaya CMS, conferencing systems) — https://arstechnica.com/tech-policy/2016/08/blackberry-enters-a-new-era-files-105-page-patent-lawsuit-against-avaya/ and https://www.crn.com.au/tools/print.aspx?ciid=[433124](/patent/433124). I did not find a verified final disposition (note Avaya's January 2017 bankruptcy, which would affect the case's trajectory). Treat outcome as unverified.

  2. Facebook/WhatsApp/Instagram (C.D. Cal. 2:18-cv-01844). Filed March 6, 2018 against Facebook, Inc., WhatsApp Inc., and Instagram, LLC; IPWatchdog's report on the complaint lists 7,372,961 among the asserted patents — https://ipwatchdog.com/2018/03/24/blackberry-sues-facebook-instagram-whatsapp-patent-infringement/. The court's Rule 54(b) final judgment of Nov. 26/27, 2019 entered judgment for the defendants only as to U.S. 8,296,351 and 8,676,929 under § 101, expressly leaving remaining claims (which would include any '961 count) on the existing schedule — https://docs.justia.com/cases/federal/district-courts/california/cacdce/2:2018cv01844/[703149/491](https://assignmentcenter.uspto.gov/search/patent/reelFrameDetail?reelFrame=703149-0491). All remaining claims and counterclaims were later dismissed with prejudice by stipulation (order of Feb. 16, 2021) — https://www.courtlistener.com/docket/[6325420](/patent/6325420)/blackberry-limited-v-facebook-inc/. No claim of '961 was held invalid or infringed on the merits.

  3. MobileIron (N.D. Cal. 3:20-cv-02877). The Stanford NPE Litigation Database lists this as the single district court case for patent 7,372,961 ("MobileIron, Inc. v. BlackBerry Corporation et al," N.D. Cal., 3:20-cv-02877) — https://npe.law.stanford.edu/patent/7372961. Google Patents' litigation record for the patent also links a "US case filed in California Northern District Court" at 3:20-cv-02877 (https://portal.unifiedpatents.com/litigation/California%20Northern%20District%20Court/case/3%3A20-cv-02877). The caption as indexed puts MobileIron as plaintiff (consistent with a declaratory-judgment posture), but I could not obtain the docket directly, so I cannot confirm the filing date, the precise party alignment, or the disposition. It is likely related to the settled IPR2020-01741 (see §2).

  4. Malikie v. MARA Holdings (W.D. Tex. 7:25-cv-00222). Malikie Innovations Limited is the current owner of record (assignment from BlackBerry Limited recorded 2025-04-10, reel/frame 070798/0381, per the patent's legal events). The amended complaint (Doc. 36) asserts six patents against MARA's bitcoin mining/node/wallet operations, expressly including "U.S. Patent No. 7,372,961 ('Ephemeral Key Generation Patent'), … 'Method of Public Key Generation,' issued May 13, 2008," with at least claim 1 alleged — https://ai-lab.exparte.com/case/dct/txwd/7:25-cv-00222/doc/36. This is a secondary/AI-generated case summary rather than the PACER docket, so the filing date and current status are unverified; the case number indicates a 2025 filing in the Western District of Texas. Google Patents likewise lists a "US case filed in Texas Western District Court" at 7:25-cv-00222. Practical note as counsel: the patent's record shows an adjusted expiration of 2023-07-12 (expired), so only pre-expiration damages would be in play.


2. PTAB (post-grant) proceedings

Proceeding Petitioner(s) Patent Owner Filed Status Source
IPR2019-00923 Facebook, Inc.; Instagram, LLC; WhatsApp Inc. BlackBerry Limited 2019-04-03 Not Instituted – Merits (terminated 2019-11-05) https://portal.unifiedpatents.com/ptab/caselist ; https://portal.unifiedpatents.com/ptab/case/IPR2019-00923
IPR2020-01741 MobileIron, Inc. BlackBerry Limited 2020-10-02 Terminated – Settled (2021-03-23) https://portal.unifiedpatents.com/ptab/case/IPR2020-01741 ; https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2020-01741
  • IPR2019-00923 challenged claim(s) of 7,372,961 and was denied institution on the merits. The Docket Alarm entry confirms petitioner Facebook, patent owner BlackBerry Limited, patent 7372961 (with Whatsapp also named) — https://www.docketalarm.com/search/PTAB/dockets/ (Facebook / IPR2019-00923).
  • IPR2020-01741 was filed by MobileIron against BlackBerry on the '961 patent (application 10/025,924, Tech Center 2100) and terminated as settled on March 23, 2021; petitioner counsel Parrish Freeman, respondent counsel Michael Hawkins — https://ipverse.greyb.com/ptab-web/cases/case-details/IPR2020-01741.

3. Federal Circuit


4. Related (non-litigation) USPTO activity worth noting

  • A request for reexamination appears in the patent's legal events with an effective date of 2025-01-06 (event recorded 2026-03-10) — i.e., a post-grant challenge at the USPTO, not litigation. Given the 2025 Malikie enforcement filings, this is likely a defensive response to that campaign; I have not verified the requester or the reexam's current posture.
  • Google Patents also links a Darts-IP "first worldwide family litigation" record for family ID 4167992: https://patents.darts-ip.com/?family=4167992 (external, licensed dataset; contents not retrieved).

5. Explicitly excluded / not attributable to 7,372,961


6. Confidence summary

  • High confidence: patent identity/number; Avaya case number, parties, filing date, and the 2017 venue order; Facebook case number, parties, filing date, and the 2019–2021 procedural history; both PTAB proceeding numbers, petitioners, filing dates, and statuses; current ownership chain.
  • Medium confidence: that 7,372,961 was asserted in the Facebook complaint (sourced to IPWatchdog's complaint summary, consistent with the patent record's link); that CAFC 20-1256 is the Facebook-case appeal.
  • Low confidence / unverified: the exact filing date and disposition of MobileIron v. BlackBerry (N.D. Cal. 3:20-cv-02877) and the precise party alignment in that caption; the filing date and current status of Malikie v. MARA Holdings (W.D. Tex. 7:25-cv-00222); the ultimate outcome of the Avaya case; and whether '961 was within the scope of CAFC No. 20-1256. If you need these locked down, pull the PACER dockets for 3:20-cv-02877 and 7:25-cv-00222 and the CAFC docket for 20-1256 (and its Rule 36/opinion disposition).

Generated 9/28/2026, 7:44:36 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Malikie Innovations Ltd., Key Patent Innovations Ltd.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll research the PTAB proceedings referenced in the patent record and verify their outcomes.

Let me dig into the institution denial details and the Federal Circuit appeal.

Let me pin down the petition grounds for IPR2019-00923 and the IPR2020-01741 disposition details.

Proceedings overview

Two AIA trial proceedings on file — both against the same patent, neither of which ever reached a Final Written Decision: one institution denied on the merits (IPR2019-00923, Facebook/Instagram/WhatsApp), one settled and terminated before institution (IPR2020-01741, MobileIron). Zero claims invalidated at the PTAB, zero claims sustained at the PTAB, zero active proceedings. (Note: the USPTO ODP block in this prompt returns no AIA trials, but the patent record itself and public PTAB dockets confirm the two proceedings below — flagging the discrepancy as instructed.) The bottom-line defensive posture is unusual: the '961 patent has never been tested at the PTAB on the merits, so there is no IPR-based estoppel and no Board invalidating roadmap to borrow — but the patent also carried no PTAB "hardening"; its real weaknesses surfaced in district court, not at the Board.


IPR2019-00923 — Facebook, Inc., Instagram, LLC & WhatsApp Inc. v. BlackBerry Limited

  • Type: Inter Partes Review
  • Filed: 2019-04-03
  • Status: Not Instituted - Merits (Decision denying institution entered 2019-11-05) — i.e., the Board found the petition failed the § 314(a) "reasonable likelihood" threshold on the merits; no trial was ever instituted.
  • Judge panel: Jacqueline T. Harlow (confirmed as a panel member in the Unified Patents PTAB case list for this proceeding, which shows panel judge Harlow and status "Not Instituted - Merits"). The remaining panel members are not confirmed in the sources I reviewed — I will not guess at them.
  • Petition grounds: Not confirmed at claim-by-claim granularity from the public documents I could retrieve. The petition ran parallel to BlackBerry Ltd. v. Facebook, Inc., No. 2:18-cv-01844-GW-KS (C.D. Cal.), where BlackBerry asserted only claim 2 of the '961 patent and where Facebook's final election of asserted prior art against the '961 patent was: (1) the Usenet post by Steven Brecher ("Brecher 1996"), (2) FIPS Pub 186-2 ("DSS 2000"), (3) OpenSSL 0.9.5, and (4) the Crypto++ Library v3.2. Whether the petition challenged those claims on § 102 and/or § 103 over those same references is not something I can state with confidence — treat the ground list as unverified.
  • Institution decision: Denied 2019-11-05 under 35 U.S.C. § 314(a). The Board held: "Having considered the evidence and arguments of record, for reasons discussed below, we deny the petition and do not institute inter partes review." The decision recites the § 314(a) standard — the petition must show "a reasonable likelihood that the petitioner would prevail with respect to at least 1 of the claims challenged." The "Not Instituted - Merits" classification indicates the denial rested on the merits rather than on discretionary factors, even though BlackBerry pressed discretionary denial in its Patent Owner Preliminary Response (arguing Facebook "dallied" a year to file, that its IPR grounds were "backup" grounds it "admit[ted]ly does not deem worthy of submitting to the jury," and invoking the Fintiv/E-One line of authority and General Plastic). BlackBerry's POPR and sur-reply are on file; the panel nevertheless resolved it on the merits.
  • Final Written Decision: None — no trial was instituted, so no FWD exists and no claim was canceled or held patentable by the Board.
  • Settlement / termination: N/A (institution denied; the proceeding ended at the institution stage on 2019-11-05).
  • Appeal: No appeal of this IPR (nothing appealable — no institution, no FWD). See the CAFC discussion below for the related district court appeal.
  • Defensive value: The denial is not a merits win for the patent on validity — it is a threshold failure of that particular petition on that particular record. For a defendant today it means (a) no § 315(e) estoppel attaches to Facebook/Instagram/WhatsApp (see Shaw Indus. Grp. v. Automated Creel Sys., 817 F.3d 1293 (Fed. Cir. 2016); HP Inc. v. MPHJ Tech. Inv., LLC, 817 F.3d 1339 (Fed. Cir. 2016) — non-instituted grounds do not become part of an IPR and cannot generate estoppel), and (b) you cannot simply copy this petition — you would need to find art and a theory the Board did not already reject.

IPR2020-01741 — MobileIron, Inc. v. BlackBerry Limited

  • Type: Inter Partes Review
  • Filed: 2020-10-02
  • Status: Terminated-Settled (termination date 2021-03-23) — terminated by joint motion shortly after the parties settled, with no institution decision reached.
  • Judge panel: None assigned publicly — the proceeding was terminated before an institution decision (no panel merits work).
  • Petition grounds: Not confirmed / not reached. Because the case terminated pre-institution, no ground was ever adjudicated. Petitioner counsel of record: Parrish Freeman; Patent Owner counsel: Michael Hawkins.
  • Institution decision: None — the Board never decided institution.
  • Final Written Decision: None.
  • Settlement / termination: The BlackBerry–MobileIron parties executed a settlement agreement dated 2021-02-22. In the parallel proceeding between the same parties, IPR2020-01519 (U.S. Patent No. 9,426,120), the parties filed a joint motion to terminate on 2021-03-05 representing that "[t]he parties have settled all disputes relating to the challenged patent," that the IPR was "in an early stage," that the Board "has not entered a final written decision," and that "if the Board terminates this IPR proceeding, no estoppel under 35 U.S.C. § 315(e) or 37 C.F.R. § 42.73(d)(1) will attach to Petitioner." The settlement agreement was filed under a request to be treated as business-confidential, so its terms are not public. The same settlement wave resolved the N.D. Cal. case MobileIron, Inc. v. BlackBerry Corporation, No. 3:20-cv-02877. IPR2020-01741 terminated on 2021-03-23 on the same terms.
  • Appeal: None — no appealable decision.
  • Defensive value: Zero estoppel and zero precedent. MobileIron bought its way out rather than litigate the validity of the '961 claims, and because no FWD issued, nothing here binds MobileIron (or its privies) under § 315(e)(2). It also means the Board never blessed the claims — a new defendant is free to bring fresh art.

CAFC 20-1256 — BlackBerry Limited v. Facebook, Inc. (related district court appeal, not a PTAB appeal)

  • Type: Federal Circuit appeal from the C.D. Cal. litigation (Consolidated Nos. 2:18-cv-01844-GW-KS and 2:18-cv-02693-GW-KS; consolidated on appeal with 20-1258).
  • Filed: 2019-12-17.
  • Disposition: Affirmed by Rule 36 judgment (nonprecedential) on 2020-12-10. Panel: Lourie, O'Malley, and Reyna, Circuit Judges (per curiam). Decided on the briefs without a precedential opinion.
  • Issues: The appeal arose from the district court's § 101 invalidity rulings and the Rule 54(b) final judgment entered 2019-11-26 on U.S. Patent Nos. 8,296,351 and 8,676,929. This appeal is not an appeal of any PTAB Final Written Decision on the '961 patent — none exists. The '961 patent was in the same district court case and was narrowed to asserted claim 2, which Facebook attacked under § 101 and on non-infringement; the sources I reviewed do not let me state the court's precise patent-by-patent disposition on the '961 patent with confidence, so I am not going to.
  • Defensive value: A Rule 36 affirmance of a district court § 101 judgment on other patents in the same campaign tells you BlackBerry's messaging patents fared poorly in court, but it does not invalidate any '961 claim.

Strategic summary

Claim status on the '961 patent (30 claims, 1–30 as granted): 30 UNTESTED at the PTAB. No claim was canceled and no claim was sustained, because neither IPR produced a Final Written Decision — IPR2019-00923 died at the institution stage and IPR2020-01741 died in settlement. So the correct statement is not "claims 1–5 were canceled" and not "the patent survived two IPRs and is hardened." Neither is true. The accurate framing is: two IPRs were filed, neither was tried, and the Board has never passed on the validity of any '961 claim. Any demand letter or complaint citing claims 1–30 faces the same claims the examiner issued; there is no PTAB cancellation to point to and no PTAB affirmance to overcome.

Estoppel landscape — essentially wide open. Because no IPR "result[ed] in a final written decision under section 318(a)," § 315(e)(1) and § 315(e)(2) estoppel never attached in either proceeding. Facebook/Instagram/WhatsApp are not estopped by the 2019 denial (Shaw; HP v. MPHJ), and MobileIron is expressly not estopped by its pre-institution settlement (the parties said so in their joint motion, which is correct law — § 315(e) requires a FWD). A defendant being asserted today therefore has the full universe of prior art available, including art that either petitioner used or could have used. If you want to challenge validity, your choices are: (i) file a fresh IPR/PGR within your § 315(b) one-year window of service of the complaint (be aware the patent is expired — see below — which may affect the remedy but not the Board's jurisdiction to review claims), and/or (ii) litigate § 101 in district court, which is where this patent family actually broke down.

Pattern signals. (1) No repeat petitioner on this patent — Facebook's group filed one IPR (2019-00923); MobileIron filed one (2020-01741) plus a separate IPR on a different BlackBerry patent (IPR2020-01519). (2) No defensive aggregator — Unified Patents appears only as the data source attributing the proceedings, not as petitioner; there is no RPX/Unified-funded IPR in this chain. (3) Patent owner posture: BlackBerry (now Malikie Innovations) had to fight off institution in 2019 with a discretionary-denial-heavy POPR and then settled the 2020 challenge; it has not had to defend any FWD on appeal for this patent. (4) The patent is expired — the record shows "Expired - Lifetime, adjusted expiration 2023-07-12" — yet there is a new W.D. Tex. suit filed in 2025 (7:25-cv-00222) and an earlier N.D. Tex. suit (3:16-cv-02185), plus a request for reexamination filed with an effective date of 2025-01-06 (docketed 2026-03-10) per the legal-events table. An expired patent still supports past-damages claims within the § 286 six-year lookback, and the pending reexam is a separate — and now potentially more important — validity front than any IPR.

Recommended next steps

  1. Do not tell the court or opposing counsel that any '961 claim has been invalidated at the PTAB. It hasn't. The only PTAB disposition here is a decision denying institution in IPR2019-00923 (2019-11-05) — publicly available via the PTAB decision (quoted above and reproduced in Docket Alarm's IPR2019-00923 file: https://www.docketalarm.com/cases/PTAB/IPR2019-00923/) and the Unified Patents PTAB case list (https://portal.unifiedpatents.com/ptab/caselist?judges.panel=Jacqueline+T.+Harlow). If you cite it, cite it for the right point: no estoppel attached, so your client keeps its full prior-art arsenal.
  2. Exploit the absence of estoppel immediately. Because neither proceeding reached a FWD, neither petitioner nor its privies is barred by § 315(e)(2). Confirm your client's relationship to Facebook/Instagram/WhatsApp and to MobileIron — if you are a privy of either, the analysis is different; if not, you are unconstrained.
  3. Watch the reexamination, not the PTAB, as the live invalidity track. A reexamination request with an effective date of 2025-01-06 (docketed 2026-03-10) is pending. Pull the reexam file from USPTO PatentCenter for the assignee's identity and the art, and consider whether the reexam's outcome will moot or narrow any IPR you file (a reexam FWD can cancel claims centrally and is not subject to § 315(b)).
  4. Calendar the litigation and the § 315(b) bar. The operative assertion appears to be W.D. Tex. 7:25-cv-00222. If your client is served, the IPR/PGR one-year bar runs from service; there is no active PTAB proceeding to join. If you file, PTAB's statutory clock is 1 year from institution (§ 316(a)(11)), extendable up to 6 months for good cause.
  5. Pressure-test § 101 and non-infringement in district court. The only real, tested weaknesses of this family — including the '961 patent's asserted claim 2 — surfaced in the C.D. Cal. litigation (Facebook's summary-judgment/motion-to-strike briefing arguing BlackBerry's "output H(SV)" theory collapsed on its own contentions) and the Rule 36 affirmance in BlackBerry Ltd. v. Facebook, Inc., No. 20-1256 (Fed. Cir. 2020-12-10, nonprecedential): https://www.courtlistener.com/opinion/[4837660](/patent/4837660)/blackberry-limited-v-facebook-inc/. Those are your best evidentiary leads, not the PTAB docket.

Verification caveats: I could not confirm the exact challenged-claim set or the art for IPR2019-00923 from the retrieved documents, and I did not attempt to guess the full panel composition beyond the confirmed member (APJ Harlow). Where I have not verified something — the '961 patent's precise district-court disposition, the contents of the sealed settlement agreement, the petitioner on the pending reexam — I've said so rather than filling the gap.

Generated 9/28/2026, 7:44:49 PM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2002-01-25 · recorded 2002-03-28 · reel 012725/0042 · Assignment

    Scott A. Vanstone; Ashok Vadekar; Robert J. Lambert; Daniel R. Brown; Robert P. Gallant; Alfred MenezesCerticom Corp.

    original inventor assignment

  2. ? · recorded 2016-07-27 · reel 039269/0856 · Assignment

    Certicom Corp.BLACKBERRY LIMITED

    internal reorg

  3. ? · recorded 2025-04-10 · reel 070798/0381 · Assignment

    BLACKBERRY LIMITEDMALIKIE INNOVATIONS LIMITED

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment record and the Malikie/Key Patent Innovations chain before writing up.

Assignment & Ownership Analysis — US 7,372,961 B2 ("Method of Public Key Generation")

Verification caveat up front. I did not obtain a direct, live response from USPTO Assignment Center (assignmentcenter.uspto.gov) — the queries returned no Assignment Center payload. The reel/frame numbers, assignors, assignees, conveyance type and effective dates below are taken from the recorded-assignment data mirrored into Google Patents' legal-events table for this patent, which reproduces the free-format text of each USPTO assignment record (including the REEL/FRAME string). What I could not retrieve is the correspondent of record field for any of the three recordings, and the exact signature/execution dates (as distinct from the USPTO-recorded "effective date"). Those gaps are flagged explicitly rather than filled in.


Inventors

# Inventor Address as printed on patent face Employer at filing (Dec. 26, 2001)
1 Scott A. Vanstone Campbellville, CA Certicom Corp. — founder and long-time chief cryptographer
2 Ashok Vadekar Rockwood, CA Certicom Corp.
3 Robert J. Lambert Cambridge, CA Certicom Corp.
4 Robert P. Gallant Mississauga, CA Certicom Corp.
5 Daniel R. Brown Toronto, CA Certicom Corp.
6 Alfred Menezes printed as "West Canada (CA)" University of Waterloo (academic) with a Certicom research affiliation

Employer determination. All six executed an assignment to Certicom Corp. (recorded reel 012725/0042, effective 2002-01-25, recorded 2002-03-28) covering their entire right, title and interest. For five of the six, Certicom was plainly the employer. Menezes is the outlier: he is a professor at the University of Waterloo and a co-author with Vanstone of the standard ECC reference works, and his affiliation with Certicom was research/consulting rather than salaried employment — hence his assignment to Certicom is consistent with a contractor/inventor agreement rather than an employment agreement. (I did not retrieve the underlying assignment instrument to confirm his capacity, so treat this as inference from public biography, not a record finding.)

Unusual-pattern check — no adverse signal.

  • No inventor departed Certicom within 12 months of filing that I could document. Certicom remained the owner of record until 2016, ~15 years after filing — the opposite of a pre-sale talent exodus.
  • The named-address "West Canada (CA)" for Menezes is anomalous on its face (not a real place name). I report it as printed. This is a USPTO data-entry artifact, not a legal finding.
  • One structural note worth recording: this is a six-inventor, single-assignee patent where the assignee is itself the R&D house. That is the classic profile of an operating-company-origin patent, which matters for the NPE analysis later — the chain begins clean.

Original assignee

Certicom Corp., Mississauga, Ontario, Canada (records for sibling Certicom/BlackBerry patents list the address as 4701 Tahoe Boulevard, 6th Floor, Mississauga, ON L4W 0B5).

  • Primary line of business. Certicom was a pure-play cryptographic technology company — one of the earliest and most aggressive commercializers of elliptic curve cryptography (ECC). It sold cryptographic toolkits and security products (SSL/TLS and ECC libraries, VPN clients, mobile security middleware) and ran a substantial patent licensing business (its ECC portfolio was licensed broadly, including to the U.S. National Security Agency).
  • Did it ship a product embodying the claims? Yes, in substance. Claim 1 is an ephemeral/nonce key-generation primitive for DSA/ECDSA. Certicom's ECC toolkits and ECDSA implementations practiced exactly this kind of key generation; the invention arose from Certicom's own implementation experience with the NIST DSS derivation. This is an operating company's patent, not a paper patent.
  • Current status. Acquired, not dissolved. Research In Motion (RIM) acquired Certicom on January 23, 2009 (consideration undisclosed in the public M&A records). RIM renamed itself BlackBerry Limited in 2013. Certicom Corp. continued for years as a wholly owned BlackBerry subsidiary carrying the patents on its books — which is why the 2016 assignment runs from Certicom Corp. to BlackBerry Limited rather than being swept up in the 2009 acquisition.

Assignment timeline

Three recorded assignments exist for this patent. Each is reproduced from the recorded assignment text mirrored in the patent's legal-events data.

1.

  • Executed 2002-01-25 / recorded 2002-03-28 — Reel 012725/0042
    • Conveyance: Assignment
    • Assignor: Scott A. Vanstone; Ashok Vadekar; Robert J. Lambert; Daniel R. Brown; Robert P. Gallant; Alfred Menezes (all individual inventors)
    • Assignee: Certicom Corp., Canada
    • Correspondent: ⚠️ Not exposed in the sources retrieved. The patent face lists Blake, Cassels & Graydon LLP (John R. S. Orange; Brett J. Slaney) as attorney of record for prosecution; that firm is a plausible but unconfirmed proxy for the recording correspondent. I cannot flag recurrence on this record.
    • Context: Original inventor assignment — the founding link in the chain, standard employment/consulting assignment to the operating company. Not a transfer-to-asserter.

2.

  • Effective 2016-07-27 / recorded 2016-07-27 — Reel 039269/0856
    • Conveyance: Assignment
    • Assignor: Certicom Corp.
    • Assignee: BlackBerry Limited, Ontario, Canada (2200 University Avenue East, Waterloo, ON N2K 0A7)
    • Correspondent: ⚠️ Not exposed in the sources retrieved. Because this is a purely intra-group transfer, the recording correspondent is very likely BlackBerry/Certicom in-house or outside Canadian counsel; I will not name a firm without the record.
    • Context: Internal reorganization only. Certicom had been a RIM/BlackBerry subsidiary since January 2009; this filing moved title from the subsidiary's name into the parent's. Seven years elapsed between acquisition and paper transfer — a book-consolidation pattern, not a monetization step.

3.

  • Effective 2025-03-28 / recorded 2025-04-10 — Reel 070798/0381
    • Conveyance: Assignment
    • Assignor: BlackBerry Limited
    • Assignee: Malikie Innovations Limited, Ireland (The Glasshouses GH2, 92 Georges Street Lower, Dun Laoghaire, Dublin A96 VR66)
    • Correspondent: ⚠️ Not exposed in the sources retrieved. This is the single most important correspondent to capture for the NPE analysis (see Signal 3) and I was unable to obtain it. It should be pulled directly from Assignment Center.
    • Context: Transfer-to-asserter. This is the link that carried the '961 patent out of an operating company into an Irish monetization vehicle — part of the ~32,000-asset BlackBerry "non-core" portfolio sale.

Timing anomaly worth noting. The commercial BlackBerry→Malikie deal was announced 2023-03-21 and closed May 2023; the UK/EP registry records a deed of assignment dated 11 May 2023 for sibling BlackBerry patents (e.g., EP 2,306,271; EP 2,703,778). The US record for this patent nonetheless carries an effective date of 2025-03-28, with recording on 2025-04-10. That is a ~22-month lag between the global deed and the US recordation/effective date. Explanations could include a separate or confirmatory US instrument, a delayed recordation, or a later-dated corrective assignment — I could not resolve which, and I flag it rather than guess.

Non-assignment records of note (not conveyances)

  • 2011-07-12 — Certificate of Correction (CC) against the granted patent.
  • 2023-07-12 — Adjusted expiration. The patent is expired — this matters because an expired patent's claims in the pending ex parte reexamination cannot be amended, only cancelled or confirmed.
  • 2026-03-10 — Request for reexamination filed (RR), effective date 2025-01-06. Not an assignment, but it confirms active third-party (Unified Patents) attack on the asset the NPE currently holds.

Timeline diagram

timeline
    title Ownership of US 7372961
    2000 : Priority date December 27
    2001 : US application filed
    2002 : Six inventors assign to Certicom Corp
    2008 : Patent issues May 13
    2009 : RIM acquires Certicom
    2016 : Certicom assigns title to BlackBerry
    2023 : Patent expires July 12
         : BlackBerry Malikie deal closes
    2025 : BlackBerry assigns to Malikie
         : Recorded Apr 10 reel 070798 0381
         : Malikie sues MARA Holdings

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT (with a naming nuance).
The substance is met: reel 070798/0381 moves the patent from BlackBerry Limited, an operating company that made and sold products, to Malikie Innovations Limited, a licensing-only entity with no products in commerce. The naming tells in the prompt (suffix "IP / Patents / Licensing / Holdings / Ventures"; single-member Delaware/Texas LLC; registered-agent address) do not match — Malikie is an Irish limited company at a Dublin office address, not a US LLC. The finding rests on function, not name: Malikie is described in its own litigation papers and by third parties as acquiring patents solely to license and litigate them, and it holds them in trust for Key Patent Innovations Ltd. That is a purpose-built holding vehicle regardless of the suffix.

2. Known asserter in the chain — PRESENT. The current assignee is not on the enumerated legacy NPE list (Acacia, Marathon, IV, Wi-LAN, Conversant, Vringo, Pendrell, etc.), but it squarely meets the prompt's broader criterion of an entity "surfaced by Unified Patents or RPX as a high-frequency plaintiff."

  • Unified Patents describes U.S. Patent 7,315,747 as "owned and asserted by Malikie Innovations Limited, an NPE and entity of New PP Licensing LLC," and has repeatedly challenged Malikie patents ex parte (Unified insights, 2025-06-17 and 2025-07-24; 2025-10-07 for US 10,779,156).
  • RPX maintains an assertion grid showing nearly 40 former BlackBerry patents asserted by this campaign (Mondaq, 2026-02-12, citing RPX Empower).
  • Corporate disclosure in Malikie's litigation identifies Malikie ← wholly owned by Key Patent Innovations Ltd. ← wholly owned by New PP Licensing LLC.
  • KPI's managing director, Angela Quinlan, previously held licensing roles at Atlantic IP Services and Solas OLED (one of Atlantic IP's plaintiffs) and at Longitude Licensing (an IPValue subsidiary) — a serial-monetization operator pedigree, reported in the Mondaq/IAM coverage of 2026-02-12.

3. Repeat correspondent across the chain — UNCLEAR / NOT DETERMINABLE ON THE RETRIEVED RECORD.
This is the signal I most wanted to score and cannot. None of the three recordings exposed a correspondent name in the material I could retrieve, so I have zero correspondent entries to compare for recurrence — neither within this chain nor against Unified/RPX assertion lists. I am expressly not treating the patent-face prosecution firm (Blake, Cassels & Graydon LLP) as the assignment correspondent, because prosecution counsel and assignment-recording counsel are frequently different and I have no record tying the firm to reels 012725/0042, 039269/0856, or 070798/0381. Action item: query Assignment Center for all three reel/frame entries and capture the correspondent of record on each. One adjacent, weaker fact does point the same direction but is not a correspondent finding: KPI itself has acknowledged hiring BlackBerry's outside prosecution counsel from Murgitroyd in Dublin — a personnel overlap between buyer and seller, not a recording-attorney overlap.

4. Cascading transfers — NOT PRESENT.
There is no rapid chained-LLC cascade. The chain is three links spread over 23 years: 2002 → 2016 (14-year gap) → 2025 (9-year gap). Two of the three links are intra-group or portfolio-level events, not serial flip-and-sue transfers. No evidence of shared correspondents or common principals across consecutive links (and see Signal 3: no correspondent data at all).

5. Pre-litigation transfer — PRESENT (moderate).
The assignment to Malikie carries an effective date of 2025-03-28 and was recorded 2025-04-10 (reel 070798/0381). Malikie's first suit asserting the '961 patent — Malikie Innovations Ltd. v. MARA Holdings, Inc., W.D. Tex. 7:25-cv-00222 — was filed 2025-07-25, roughly four months after the recorded assignment and within the six-month window. Caveat: the '961 patent had already been asserted before the transfer, by BlackBerry itself against Facebook/Instagram/WhatsApp (C.D. Cal. 2:18-cv-01844; N.D. Tex. 3:16-cv-02185), and the transfer was one of ~32,000 assets rather than a suit-specific conveyance. So the timing is suggestive of a planned assertion program, not of a bespoke last-minute venue-setup transfer.

6. Bankruptcy fire-sale — NOT PRESENT.
Neither Certicom (acquired by RIM in 2009) nor BlackBerry ever sought Chapter 7/11 protection in connection with this asset. The 2025 transfer was a strategic divestiture of ~32,000 non-core patents with an announced headline structure of $170M cash at closing, an additional $30M by the third anniversary, plus a profit share (reported as 8% of the first $500M, 15% of the next $250M, 30% of the next $250M, 50% thereafter, subject to a $700M cap). This is a monetization deal, not a distress liquidation.

7. Privateering — PRESENT.
This is the strongest signal and it is unusually well-documented. BlackBerry did not sell outright and walk away; it retained an economic upside in the litigation recoveries, i.e., it is monetizing its own portfolio through an NPE while sharing in what that NPE extracts. The Vantiva declaratory-judgment complaint (N.D. Ga., filed June 2025) pleads the deal terms at ¶11, including the share of future licensing profits; Malikie's own notices identify BlackBerry as a financially interested party on its supplemental interested-parties list; and KPI's public statements confirm ongoing engagement with licensees that BlackBerry had already approached. An operating company that sells to a litigating NPE while keeping a profit cut is the textbook privateering structure.

8. Defensive aggregator (anti-NPE) — NOT PRESENT.
The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. The opposite is true: Unified Patents is adverse to the current owner, having filed the ex parte reexamination request that was granted 2026-03-10 (RR, effective 2025-01-06). The patent is live in an assertion campaign, not neutralized.


Verdict

NPE — high confidence

The chain terminates in a purpose-built monetization vehicle with no products: Malikie Innovations Limited took title by assignment recorded 2025-04-10 at reel 070798/0381 (effective 2025-03-28) from BlackBerry Limited, and holds the asset in trust for Key Patent Innovations Ltd., itself owned by New PP Licensing LLC — a structure Malikie's own IPR mandatory notices describe as "KPI is the beneficiary of a trust pursuant to which Malikie owns and holds" the patents. The transfer is the tip of a ~32,000-patent divestiture in which the seller kept a share of future licensing profits, and within about four months the new owner asserted at least claim 1 of this patent against MARA Holdings in W.D. Tex. 7:25-cv-00222 — while Unified Patents, which expressly identifies Malikie as "an NPE," challenged the asset in an ex parte reexamination granted 2026-03-10.

That satisfies at least three strong signals independently (Signal 2 known asserter, Signal 7 privateering, Signal 1 operating-to-licensing-only transfer), with Signal 5 as reinforcement. Signal 3 — the repeat-correspondent check that would ordinarily let this be called very high confidence — is unresolved on my retrieved record, so I am not upgrading beyond high confidence.

Verify at: USPTO Assignment Center — https://assignmentcenter.uspto.gov/ (search patent 7372961; equivalently at https://assignment.uspto.gov/patent/index.html). Request the correspondent of record for reels 012725/0042, 039269/0856, and 070798/0381. Also cross-check USPTO Patent Center / ODP for any security agreement, license, or release recordings not reflected in the Google Patents event table, and confirm the execution date versus the recorded effective date on the Malikie link.


Cross-reference / contradiction flags vs. previously generated sections

  1. No contradiction on the assignment chain — reel 012725/0042 (2002), reel 039269/0856 (2016) and reel 070798/0381 (2025-04-10) match the prior summary's bibliographic and chain-of-title entries exactly.
  2. Date discrepancy to reconcile: the prior summary flags the stated "today" of April 26, 2026 while citing live items dated after that. The event most exposed to this is the 2026-03-10 reexamination request and the 2026-06-15 § 290 "Order Dismissing Case (Doc 99)" entry in 7:25-cv-00222, which the prior summary rightly marks ambiguous. If that dismissal disposed of the MARA case, Signal 5's "pre-litigation transfer" reading weakens (though the NPE verdict does not, because it rests on ownership structure and the portfolio-wide campaign rather than on that one suit). I could not resolve it.
  3. Prior-summary scoping note is confirmed and reinforced here: the low-Hamming-weight masking embodiments (FIG. 7) were pursued in continuation US 8,000,470, not in the '961 claims. For ownership purposes this matters — the '470 and '466,944 continuations also sit in the same Certicom→BlackBerry→Malikie chain and were part of the same 32,000-asset sale, so an assignment analysis of the '961 is not complete for the family until the '470 and '466,944 reel/frame records are pulled too.

Generated 9/28/2026, 7:45:11 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll verify the citation record and the two non-patent references before building the § 102 analysis.

Confirmed the two NPL references. Let me pin down the IPR grounds and the remaining cited references.

Valuable find — the IPR grounds. Let me identify the "Rose," "Rao," and "Floyd" references.

I've hit my research-step limit, so I'll deliver the analysis now, grounded in what the retrieval confirmed and flagging what it did not. One important scoping note up front: the tools available to me returned the patent's own front-matter citation record (mirrored on Google Patents and Justia), not a direct USPTO Patent Center / ODP "References Cited" query. I could not open a live USPTO database session. Where I mark something as unverified, I could not confirm it from the record retrieved.


Prior Art Analysis — US 7,372,961 B2 ("Method of Public Key Generation")

Record identification (literal, no auto-correction): The record retrieved is for 7,372,961 exactly. I explicitly did not return results for 7,372,960 (a separate BlackBerry patent, also asserted by Malikie in the same W.D. Tex. campaign), nor for the same-family continuations 8,000,470 and 8,466,944, nor for the "737296" digit-drop typo appearing in some press coverage.

Analytical frame. The '961 patent has a filing date of 2001-12-26 and an earliest priority date of 2000-12-27. It is therefore governed by pre-AIA 35 U.S.C. § 102 (2002 version), and the operative subdivisions for face-of-patent citations are:

  • § 102(a) — known/used/patented/published before the applicant's invention date;
  • § 102(b) — patented or described in a printed publication more than one year before the U.S. filing date (i.e., before 2000-12-26);
  • § 102(e) — described in a U.S. patent or published application by another, filed before the applicant's invention/priority date (for publications, only those filed on or after Nov. 29, 2000).

A literal-reading caveat that matters here: the file is expired (adjusted expiration 2023-07-12), and the asserted claim in the two district-court campaigns was claim 2, not claim 1. I flag that because anticipation mapping is claim-specific and the record I retrieved does not let me chart every dependent claim against every reference with confidence.


1. The eight patent documents cited on the face of the '961 patent

These are the U.S. Patent Documents listed under "Patent Citations (8)" / "Referenced Cited." I reproduce the number and identity literally as printed, including the discrepancy in the Shimbo/Assignee attribution. (Google Patents lists US 6,088,798 under "Kabushiki Kaisha Toshiba"; Justia lists the inventor surname as "Shimbo.")

# Full citation Filed / Priority Published / Issued Brief description Potentially anticipates under § 102?
1 US 5,073,935 — Pastor, Jose — Method for Secure Communication 1990-12-17 1991-12-17 Early secure-communication / key-establishment scheme. Predates the '961 priority by ~9 years. § 102(b) formally available. Anticipates no claim — does not disclose RNG-seeded hash output compared to a group order q prior to mod-q reduction. Background only.
2 US 6,088,798 — Shimbo (assignee of record: Kabushiki Kaisha Toshiba) — Digital Signature Method Using an Elliptic Curve, a Digital Signature System, and a Program Storage Medium… 1996-09-27 2000-07-11 ECDSA-family digital signature method on an elliptic curve; program-storage-medium claim format. § 102(b) (issued >1 yr before the '961 filing) and § 102(e). Anticipates no claim. Its relevance is to claim 1/9's context (the spec's ECDSA discussion) and to the computer-readable-medium form of claim 15 — but it does not disclose the pre-mod-q comparison. § 103 material at most.
3 US 6,219,421 B1 — Backal, Shaul O. — Virtual Matrix Encryption (VME) and Virtual Key Cryptographic Method and Apparatus 1997-10-24 2001-04-17 Symmetric/private-key encryption using a "virtual matrix" and a virtual key. Issued ~8 months before the '961 filing. § 102(e) (U.S. filing 1997-10-24 predates 2000-12-27). Anticipates no claim. Facially directed to a different cryptographic paradigm (matrix/stream keying), not DSA/ECDSA ephemeral-key derivation. Cumulative at best.
4 US 6,195,433 B1 — Vanstone et al. (assignee Certicom Corp.) — Private Key Validity and Validation 1998-05-08 (CA 2,330,749 priority 1999-05-10 per related record) 2001-02-27 The substantively closest same-family reference. Discloses a canonical private-key generation function: an RNG or PRNG produces a SEED; the SEED is hashed by SHA-1; the hash output is "shaped" to the correct size for a private key; a key test processor applies statistical criteria (monobit, poker, runs, long-run tests) and rejects failing candidates; a counter value (X'01', X'02', …) is concatenated to the SEED to produce successive 160-bit values. § 102(e) (U.S. filing 1998-05-08). Critical distinction: the '433 reference's "shape function used is modulo n" — i.e., it performs the modular reduction first and then statistically tests. Claim 1 requires the comparison "prior to reducing mod q." So the '433 reference teaches the inverse ordering to claim 1 and is best characterized as § 103 art that the specification would have to be argued around, not § 102 anticipation. Relevant to claims 1–3, 5–8, 15–17, 23–25 as a § 103 primary reference.
5 US 6,307,938 B1 — Matyas et al. (assignee International Business Machines Corp.) — Method, System and Apparatus for Generating Self-Validating Prime Numbers 1998-07-10 2001-10-23 Generation of self-validating prime numbers — i.e., generating a candidate and testing it against validity criteria before acceptance. § 102(e) (U.S. filing 1998-07-10). Anticipates no claim — the subject matter is prime-number generation for RSA-type systems, not ephemeral-key rejection sampling against a group order q. Its only relevance is the general "generate-and-validate" concept, which is exactly the abstraction claim 1 must be distinguished from.
6 US 6,327,660 B1 — Patel (assignee Intel Corporation) — Method for Securing Communications in a Pre-Boot Environment 1998-09-18 2001-12-04 Securing communications during pre-boot; cryptographic operations in a constrained/embedded environment. § 102(e) (U.S. filing 1998-09-18). Anticipates no claim. Relevant, if at all, to the cryptographic-unit apparatus form of claim 23 (a processor performing cryptographic operations) — but the reference does not disclose the claim-1 RNG→hash→pre-mod-q-compare sequence.
7 US 2002/0116527 A1 — Chen et al. — Lookup Engine for Network Devices 2000-12-21 2002-08-22 Network-device lookup engine (hashing/lookup hardware). § 102(e) technically available (U.S. filing 2000-12-21 predates the 2000-12-27 priority; filed after Nov. 29, 2000, so the publication qualifies). ⚠️ I cannot explain this citation on the merits. On its face the subject matter is not cryptographic key generation, and I could not retrieve the prosecution rationale tying it to any claim. Treat as a formal/ancillary § 102(e) citation, not substantive art. Anticipates no claim.
8 US 2003/0084332 A1 — Krasinski et al. (assignee Koninklijke Philips Electronics N.V.) — Method for Binding a Software Data Domain to Specific Hardware 2001-10-26 2003-05-01 Binding software to specific hardware (possibly via cryptographic binding). § 102(e) is the only possible basis: its 2001-10-26 filing is after the '961 priority date (2000-12-27), so it cannot be § 102(a) or § 102(b) art; it predates the '961's filing date (2001-12-26) by only two months. Anticipates no claim. Its technical relevance to key generation is not apparent on the face of the record. ⚠️ Flagged as an anomaly — a two-month-margin § 102(e) citation of apparently unrelated subject matter, which I could not corroborate from the file wrapper.

Net on the eight patent citations: None of them, on the record retrieved, anticipates any of claims 1, 9, 15, or 23 under § 102. Their aggregate role is to establish the general backdrop (RNG-seeded keying, hash-then-validate generation, ECDSA signature context, embedded cryptographic units). Reference US 6,195,433 is the only one that comes close on the elements, and it teaches the opposite ordering (mod reduction then testing) — making it a § 103 reference that the applicant had to distinguish, and arguably a teaching-away datum.


2. The two non-patent citations — the substantively important art

Both carry the "cited by examiner" asterisk in the record retrieved, i.e., they were examiner citations, not applicant submissions. Both were confirmed in live sources.

2.1 Nel et al. — the primary NPL reference

  • Full citation (as printed on the patent face): Nel et al., "Generation of Keys for use with the Digital Signature Standard (DSS)," 1993, IEEE, pp. 6-10.
  • ⚠️ Pagination discrepancy — do not auto-correct: Live bibliographic records give the correct span as pp. 6–11 (Semantic Scholar; the ISC/regional-index record lists Firstpage 6, Lastpage 11). The patent prints "pp. 6-10." I report the patent's version literally and flag the difference. Full record: *J. J. Nel & G. J. Kühn, "Generation of keys for use with the digital signature standard (DSS)," 1993 IEEE South African Symposium on Communications and Signal Processing (COMSIG '93), pp. 6–11, DOI 10.1109/COMSIG.1993.365882.* Affiliation: Dept. of Electrical & Electronic Engineering, University of Pretoria, South Africa.
  • Date: 1993 — well before the 2000-12-27 priority → § 102(b) prior art (printed publication).
  • Brief description (from the publisher abstract): "The comments received by the National Institutes of Standards and Technology (NIST) on their proposed digital signature standard (DSS) included criticisms of the generation of keys. The problems concerning key generation can be avoided by using effective techniques. The paper discusses the effective generation of keys for the DSA, based on algorithms which can run on a personal computer." Keywords: DSS, key generation, public key cryptography, NIST.
  • Why it is the most relevant reference: it is directly on point to the problem the '961 patent states it is solving — namely, how to generate the DSS/DSA key properly. It is the reference any invalidity theory would lead with, because it is the only cited item framed around DSS key generation as such.
  • § 102 mapping: Potentially anticipates or renders obvious claims 1, 2, 5, 6, 9, 12, 14, 15, 19, 20, 23, 27, 28 — but only to the extent it discloses comparing the hash output against the order q before any mod-q reduction and rejecting rather than reducing. Notably, the record confirms a second petitioner (MobileIron, IPR2020-01741) charted Nel as teaching that "the output from said hash function is a bit string of predetermined length L" and as teaching "rejecting excess bits such that said new output is a bit string of length L" (Docket Alarm, IPR2020-01741 Ex. 1003-2). That is a direct mapping to claims 6, 12 and 14. If Nel in fact discloses generating candidate keys by hashing and discarding out-of-range bit strings, Nel is the single most dangerous § 102/§ 103 reference on the face of this patent. I could not read Nel's full text to verify that it does so — treat the petitioner's characterization as a lead, not a finding.

2.2 Schneier, Applied Cryptography (2nd ed.)

  • Full citation (as printed): Schneier, Bruce, "Applied Cryptography," 1996, John Wiley & Sons, Inc., 2nd editiion, pp. 483–490. (Note: the patent prints "editiion" — reproduced literally, not corrected.)
  • Date: 1996 → § 102(b) printed publication.
  • Brief description: Standard practitioner reference. The cited span (pp. 483–490, 2nd ed.) is the DSA/DSS treatment — DSA key generation, the per-message/ephemeral key k, and the signature equations — i.e., the same subject matter the '961 specification recites in its Background (the k = SHA-1(seed) mod q derivation and the s = k⁻¹(H(m)+dr) mod q signature component).
  • § 102 mapping: Anticipates no claim in isolation. It is a § 103 secondary/background reference establishing that the DSA/DSS algorithm, the ephemeral key k, and the hash-to-integer step were well known. It supplies the "prior art DSA" predicate that a § 103 combination would modify. Relevant to the preamble of claims 1, 9, 15, 23 ("a cryptographic function performed over a group of order q") and to the spec's own admitted background.

3. Family-cited references that the specification actually leans on (worth flagging)

The '961 specification's FIG. 7 discussion expressly states the low-Hamming-weight masking procedure "is disclosed in copending Canadian application 2,217,925." That application maps to two references appearing in the "Family Cites Families" list — both Certicom's own:

Reference Dates Description Relevance
EP 0 854 603 B1 — Certicom Corp. — Generation of Session Parameters for El Gamal-like Protocols priority 1996-10-10; granted 2009-05-06 El Gamal-like session-parameter/key generation § 102(b)/§ 102(a) art. The source of the masking concept the '961 describes but does not claim. Relevant to the '470 continuation's claims, not to '961 claims 1–30.
US 6,337,909 B1 — Certicom Corp. — Generation of Session Keys for El Gamal-like Protocols from Low Hamming Weight Integers priority 1996-10-10; issued 2002-01-08 Deriving El Gamal-like keys from low Hamming weight integers Same point: supports the FIG. 7 embodiment. Confirms that low-Hamming-weight masking was Certicom's own earlier work, not novel to '961.
CA 2,257,907 A1 — M'Raihi, David — Public Key Cryptography Method priority 1996-06-05 Public-key method § 102(b) background; Certicom-family citation.
US 5,987,131 — PictureTel Corp. — Cryptographic Key Exchange Using Pre-Computation priority 1997-08-18; issued 1999-11-16 Precomputation for key exchange § 102(b) art bearing on the spec's concern with efficiently computing α^k (relevant to claim 4's public-key generation step, but not to the novelty of claim 1).

Important cross-reference: consistent with the prior sections of this analysis, none of the masking references (EP 0 854 603 / US 6,337,909) is a claim limitation of '961 claims 1–30 — those went into the '470 continuation. Treating them as anticipating '961's claims would be a category error.


4. Prior art asserted in the PTAB proceedings (not on the patent face)

This is the art that third parties actually briefed against the '961 claims, and it materially extends the list above. It is confirmed from BlackBerry's Preliminary Response in IPR2019-00923 (quoted at length in Petitioner's Ex. 1029 in IPR2020-01741, Docket Alarm).

IPR2019-00923 (Facebook / Instagram / WhatsApp) — four grounds:

  • Ground 1: DSS (FIPS 186-2) in view of Schneier and Rose — BlackBerry's POPR section heading: "GROUND 1 BASED ON DSS IN VIEW OF SCHNEIER AND ROSE IS DEFICIENT."
  • Ground 2: DSS in view of Schneier and Menezes — POPR: "GROUND 2 BASED ON DSS IN VIEW OF SCHNEIER AND MENEZES IS DEFICIENT."
  • Grounds 3 and 4: combinations "CITING RAO AND FLOYD."
Reference Status Relevance
DSS / FIPS Pub. 186-2 (NIST) Primary reference in Grounds 1–3 The '961 patent's own admitted prior art — the k = SHA-1(seed) mod q reduction the invention purports to improve. Not itself anticipatory of the claims (it does the very mod reduction claim 1 disclaims), but the natural § 103 starting point.
Schneier, Applied Cryptography (EX1008 in the IPR) Secondary, Grounds 1–2 Same volume cited on the patent face. Establishes DSA/DSS as known.
"Rose" Secondary, Grounds 1 and 3 (motivation-to-modify) ⚠️ I could not identify which "Rose" reference this is (author/title/date). BlackBerry's POPR indicates Rose was offered as supplying the motivation to modify DSS to address the modulo-bias vulnerability, and that Rose "fails to disclose multiple features from the solution claimed in the '961 patent." I decline to guess at its identity.
"Menezes" Secondary, Grounds 2 and 4 Presumably Menezes, van Oorschot & Vanstone, Handbook of Applied Cryptography (CRC, 1996) — but I could not confirm this from the record retrieved, and I note the awkward fact that two of the named inventors (Menezes and Vanstone) are its authors. Do not assert the identity without checking the petition's Exhibit 1000-series list.
"Rao" and "Floyd" Grounds 3 and 4 ⚠️ Not identified. I have no basis to state what these are.

Outcome: institution denied on the merits, 2019-11-05 (Unified Patents PTAB case list confirms: patent 7372961, filed 2019-04-03, terminated 2019-11-05, "Not Instituted – Merits"; panel includes APJ Jacqueline T. Harlow). No claim was adjudicated. As developed in the earlier PTAB section of this analysis: no § 315(e) estoppel attached, so this art — and any art the petitioners could have used — remains fully available to a current challenger.

IPR2020-01741 (MobileIron): terminated by settlement (2021-03-23) before institution. The petitioner's Ex. 1003-2 nonetheless charted Nel against the "bit string of predetermined length L" and "rejecting excess bits" limitations — the most concrete § 103 mapping of Nel that I retrieved.


5. Bottom line on anticipation vs. obviousness

  1. No reference cited on the face of US 7,372,961 anticipates claim 1 — or independent claims 9, 15, or 23 — on the record retrieved. None of the eight patent documents discloses the full sequence of (a) RNG seed → (b) hash → (c) compare H(SV) against q prior to reducing mod q → (d) accept k = H(SV) if less, else reject and repeat.
  2. The two NPL references are the substantive art, and both are § 102(b) printed publications: Nel et al. (1993) is the strongest — squarely about DSS key generation, and characterized by at least one petitioner as teaching hash-derived L-bit strings with excess-bit rejection (→ claims 6, 12, 14); Schneier (1996) is background establishing DSA/DSS as known.
  3. US 6,195,433 (Certicom/Vanstone, § 102(e)) is the closest patent reference on elements but performs modular reduction before testing — the inverse of claim 1's required ordering. It is a § 103 reference and arguably a teaching-away datum, not an anticipation reference.
  4. The real-world challenge was, and remains, a § 103 challenge — DSS in view of Schneier and Rose/Menezes (IPR2019-00923, denied institution) — not a § 102 challenge. The '961 claims have never been tested on the merits at the PTAB.
  5. Do not conflate the low-Hamming-weight masking art (EP 0 854 603 / US 6,337,909 / CA 2,217,925) with the '961 claims; those went to the '470 continuation.

Sources: the patent's own front matter as mirrored at https://patents.google.com/patent/[US7372961B2](/patent/US7372961B2)/en and https://patents.justia.com/patent/7372961; Nel et al. bibliographic record at https://www.semanticscholar.org/paper/b40310e78b0d24fd37d8d9ff0f415f21a726b454 and the ISC index record (DOI 10.1109/COMSIG.1993.365882); US 6,195,433 text at https://patents.google.com/patent/[US6195433B1](/patent/US6195433B1)/en; the BlackBerry POPR grounds quoted in IPR2020-01741 Ex. 1029 and the IPR2020-01741 Ex. 1003-2 Nel chart (both via https://www.docketalarm.com); and the Unified Patents PTAB case list at https://portal.unifiedpatents.com/ptab/caselist?judges.panel=Jacqueline+T.+Harlow.


6. Cross-reference and contradiction flags against the earlier sections

  1. No contradiction with the earlier patent-summary's claim mapping (four independents 1/9/15/23; claim 2 the asserted claim in the district court cases; masking embodiments carved out to the '470). This section reinforces that scoping.
  2. New fact not in the earlier sections (additive, not contradictory): the IPR2019-00923 ground structure — DSS + Schneier + Rose (Grounds 1, 3) and DSS + Schneier + Menezes (Grounds 2, 4), with Rao and Floyd in Grounds 3–4. The earlier "PTAB challenges" section correctly said the grounds were "not confirmed at claim-by-claim granularity"; I can now confirm the reference identities at ground level, though still not the claim-by-claim charts.
  3. Two references I could not resolve and will not guess: "Rose" and the "Rao"/"Floyd" pair, plus the uncertain identity of "Menezes." If these matter for a validity opinion, pull the Exhibit 1000-series index from IPR2019-00923 and IPR2020-01741.
  4. Carry-over caution from the earlier PTAB section, restated: the 2019 denial is not a validity win. No claim of the '961 patent has been cancelled, confirmed, or construed by the Board. A current challenger has the full prior-art universe available, including everything in the tables above plus the pre-expiration art the petitioners never reached.
  5. Live-track reminder: the pending ex parte reexamination (request effective 2025-01-06, docketed 2026-03-10) is now the more consequential validity front than any IPR, and because the patent is expired, claim amendments are unavailable — the claims can only be confirmed or cancelled. Any prior-art theory you develop should be sequenced with that reexam.

Generated 9/28/2026, 7:54:35 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground the obviousness combinations in the record before drafting, particularly the two gaps flagged as unresolved in the Prior Art section ("Rose" and "Menezes") and the Nel content.

Strong finds. Let me try to close the two open reference identities and locate the actual 2019 petition grounds.

Obviousness Analysis — US 7,372,961 B2 under 35 U.S.C. § 103

Builds on, and does not repeat, the four prior sections (Patent Summary, Litigation Summary, PTAB Challenges, Assignment History, Prior Art). Where this section adds new facts, I say so; where prior sections were uncertain, I flag the resolution.

Scope and verification. Pre-AIA § 103(a) governs (priority 2000‑12‑27; filed 2001‑12‑26). I located the actual IPR2019‑00923 petition ground structure and exhibit list and identified the two references the Prior Art section had left unresolved ("Rose" and "Menezes"), plus "Rao" and "Floyd." Those are new facts. Two things I could not verify: the full text of Nel & Kühn (1993) and whether Menezes et al., Handbook of Applied Cryptography (1997) discloses rejection-of-out-of-range-draws in terms. I flag both rather than assume.


1. Legal framework and the claim-construction overlay

Governing standard. Pre-AIA § 103(a); Graham v. John Deere Co., 383 U.S. 1 (1966) (scope/content of art; differences; PHOSITA; secondary considerations); KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007) ("a court must ask whether the improvement is more than the predictable use of prior art elements according to their established functions"; "if a technique has been used to improve one device, and a person of ordinary skill in the art would recognize that it would improve similar devices in the same way, using the technique is obvious"; "when there is a design need or market pressure to solve a problem and there are a finite number of identified, predictable solutions, a person of ordinary skill has good reason to pursue the known options"); MPEP § 2143 rationales (A) known-method combination, (C) known technique to improve similar devices, (D) applying known technique to a known device "ready for improvement," (E) obvious to try, (F) design incentives, (G) predictable variation.

Two construction rulings materially shape the § 103 case — and neither is in the prior sections:

  1. "reducing mod q" was construed by the C.D. Cal. court in a Tentative Claim Construction Ruling dated April 1, 2019 (Ex. 1035 at 041). Facebook's IPR petition was filed April 3, 2019 — expressly, per its own preliminary reply, because it "enabled Petitioner to account for the court's construction of the disputed term 'reducing mod q'." (Petitioner's Preliminary Reply, IPR2019‑00923, Sept. 17, 2019.) A second declaration, Aviel Rubin, Ph.D., addressed '961 claim construction in the same case (IPR2019‑00923 Ex. 1012, Feb. 28, 2019).
  2. The pending W.D. Tex. Markman fight over "random number generator" and "seed value" (prior section) is the validity-risk mirror image: if "random number generator" is construed to exclude purely deterministic generators, several of the combinations below weaken — but the same construction collapses the patent owner's own infringement theory, because the accused OpenSSL/FIPS-family implementations use deterministic PRNGs (G(t,c)). This is a genuine squeeze, not a one-way ratchet.

Statutory/enforcement overlay. (i) The patent is expired (2023‑07‑12), so a reexamination can only confirm or cancel claims — no amendment. (ii) That does not bar IPR: the Board may review claims of an expired patent, though the patent owner cannot amend. (iii) § 315(b) runs one year from service of a complaint; § 315(e) estoppel never attached in either prior IPR (neither reached a FWD), so a new challenger has the full art universe. (iv) § 325(d) risk is high for the best art, because DSS, Schneier, Nel, US 6,195,433, US 6,307,938, US 6,088,798 and US 6,327,660 were all before the Examiner — a new petition should present them in a materially new way, not re-run them.


2. Person of ordinary skill in the art (POSITA)

The contemporaneous record gives an unusually concrete answer, because both sides filed expert declarations: Jonathan Katz, Ph.D. (IPR2019‑00923 Ex. 1002, petitioner's declarant) and Michael Goodrich, Ph.D. (declarant in a later petition against the '961 patent), plus Rubin for construction. On that record a POSITA is a person with a graduate degree in computer science, electrical engineering, or mathematics and at least two to three years' experience implementing public-key cryptography (DSA/ECDSA), or equivalent practical experience — someone who reads NIST FIPS publications, ANSI X9.62/X9.63, and standard references (Schneier; Menezes/van Oorschot/Vanstone; Knuth). That skill level matters: converting a mod q key derivation to a reject-if-≥-q derivation is, for this person, a textbook exercise in uniform sampling, not a research problem.


3. The limitation that decides the case

Independent claims 1, 15 and 23 all require:

"determining whether said output H(SV) is less than said order q prior to reducing mod q … accepting said output H(SV) … if … less than said order q … rejecting … if said value is not less than said order q … if said output H(SV) is rejected, repeating said method … wherein said key k is equal to said output H(SV)."

Three elements, in order: (i) seed → hash → raw H(SV); (ii) test the raw output against q and reject out-of-range draws (rejection sampling); (iii) the ordering — no modular reduction is applied to the accepted value ("k is equal to said output H(SV)").

Claim 9 substitutes a two-hash variant: increment SV by f( ), hash again, combine the two outputs, then the same pre-reduction test.

Why this is a classic § 103 case. The negative limitation is functionally significant — the ordering is what eliminates the bias (the specification says so: "any bias is eliminated"). But significance cuts toward obviousness, not away from it: the very same reason the ordering matters is why a POSITA seeking an unbiased k would select it. The patent owner cannot simultaneously argue the ordering is critical and that it is an unpredictable design choice. Compare MPEP § 2144.04 / In re Kuhle line of reasoning: where the function served is the known goal, rearranging steps to achieve it is within the ordinary artisan's skill.


4. The reference universe, and what each reference does and does not supply

Ref. Identity (literal) Status Supplies Does not supply
DSS / FIPS 186‑2 (Jan. 27, 2000) NIST DSS, App. 3.1/3.2 § 102(b) (published >1 yr before 2001‑12‑26); the patent's own admitted prior art Seed-key XKEY; one-way hash G(t,c) (SHA‑1-based, 160-bit output); x_j = G(t, XVAL) mod q and k = G(t, ω_kkey) mod q; iteration/feedback XKEY = (1 + XKEY + x_j) mod 2^b, ω_kkey = (1 + ω_kkey + k); DSA group of order q; public-key usage r = (g^k mod p) mod q Any rejection; teaches the opposite ordering (reduce first)
Schneier, Applied Cryptography, 2d ed. (1996), pp. 483–490 patent face (examiner‑cited) § 102(b) DSA/DSS as known; per-message k; key-generation practice Rejection sampling in terms; the bias fix
Nel & Kühn (1993), pp. 6–11 patent face (examiner‑cited) § 102(b) Expressly: "The comments received by NIST on their proposed DSS included criticisms of the generation of keys. The problems concerning key generation can be avoided by using effective techniques" — i.e., motivation + the L‑bit/hash-output context (petitioner charted it to claims 6, 12, 14) Verified disclosure of excess-bit rejection (petitioner charted it; I could not read Nel's text — see §7.3)
Menezes, van Oorschot & Vanstone, Handbook of Applied Cryptography (1997) — this is the "Menezes" reference (IPR2019‑00923 Ex. 1011) IPR2019‑00923 / IPR2020‑01741 § 102(b) printed publication Standard treatise: DSA, PRNGs, uniform random-integer generation Not verified that it teaches discard-rather-than-reduce; verify before relying
"Rose," Re: "Card‑shuffling" algorithms, USENET, sci.crypt (~1993) (Facebook Ex. 1006) IPR2019‑00923 Grounds 1, 3 § 102(b) printed publication (if publicly accessible and dated 1993 — verify) Rejection of out-of-range draws when mapping a random value into a range ("card shuffling" is the canonical modulus-bias problem) Per the Board's Nov. 5, 2019 Decision: Rose does not (1) disclose hashing the random number, (2) contemplate application to a cryptographic key-generation algorithm, (3) contemplate avoiding bias in a hash output, or (4) contemplate iteratively repeating selection + hashing
US 6,195,433 B1 (Vanstone et al., Certicom) patent face § 102(e) RNG/PRNG → SEED → SHA‑1 → shaping → statistical test and reject; counter concatenation X'01', X'02'… to produce successive 160-bit values; store/validate private key Reduces mod n first ("the shape function used is modulo n") — teaches inversion of claim 1's ordering
US 6,307,938 B1 (Matyas et al., IBM) patent face § 102(e) Generate-and-validate-then-reject-otherwise paradigm for candidates Not key generation vs. order q
US 6,088,798 (Toshiba) patent face § 102(b)/§ 102(e) ECDSA-family signature method; program storage medium claim format Rejection sampling
US 6,327,660 B1 (Patel, Intel) patent face § 102(e) Cryptography in a constrained/embedded processor unit Key-generation algorithm
Rao, Error Coding for Arithmetic Processors (1974) (Ex. 1018) IPR2019‑00923 Grounds 3–4 § 102(b) Arithmetic-processing hardware context Anything about keys
Floyd, Essentials of Data Processing (1987) (Ex. 1019) IPR2019‑00923 Grounds 3–4 § 102(b) Digital data-processing unit context Anything about keys
Bellare (quoting: "SECRECY OF THE NONCE … If any nonce k ever becomes revealed … one can immediately recover the secret key x") cited in the Goodrich declaration supporting a later petition on the '961 § 102(b) (verify edition/date) Motivation — quantifies why a biased/short-entropy k is catastrophic Rejection sampling
NIST FIPS 186‑2 Change Notice #1 (Oct. 5, 2001) and NIST SP 800‑XX draft (Oct. 2001) — the k = (z₁×2¹⁶⁰ + z₂) mod q fix not on patent face ⚠️ NOT prior art — postdates the 2000‑12‑27 priority (Distractor.) Must be excluded as art; usable only as § 103 context/objective-indicia evidence with care

5. The combinations

Each combination is stated with the claim limitations it maps, the KSR/MPEP motivation, and the weakest link. Grounds I–III are the combinations actually briefed in IPR2019‑00923; Grounds IV–VII are combinations I have constructed from the face-of-patent art that were never briefed and are therefore § 325(d)-cleaner or § 325(d)-dirtier as noted.

Ground I — FIPS 186‑2 (DSS) + Schneier + Rose

Targets claims 1, 2, 5, 15, 16, 19 (the actual ground).

Limitation Where met
"seed value SV from a random number generator" DSS App. 3 "Choose a new, secret value for the seed-key, XKEY"; G(t,c) PRNG
"hash function H( ) on said seed value … output H(SV)" DSS: one-way function G constructed via SHA‑1, 160-bit output
"less than q prior to reducing mod q" Rose — discard the out-of-range draw rather than fold it; the whole point of a shuffling algorithm's rejection step is to avoid the modulo bias
"if rejected, repeating" Rose's repeated re-draw; DSS's for j = 0 to m-1 loop
"key k equal to H(SV)" Consequence of not reducing
claims 5/6 (q prime, L bits; output L bits) DSS: 160-bit q, 160-bit G output
claims 15/16/19 (CRM form) Schneier/US 6,088,798 (program storage medium)

Motivation (MPEP 2143 (A), (C), (E); KSR "finite number of identified, predictable solutions"). DSS's own algorithm makes k fall in (0, 2¹⁶⁰−q−1) with twice the probability of (2¹⁶⁰−q, q−1) — a mathematical property visible on the face of G(t,KVAL) mod q. The objective of the DSA key-generation algorithm is a uniform k in [1, q−1] (DSS itself requires k to be "random or pseudorandom integer with 0 < k < q"). Rose teaches the established technique for obtaining a uniform draw in a range from a larger uniform source: discard and redraw. Substituting the discard step for the modulo step yields the predictable result (uniformity) with no change in the surrounding apparatus. That is the paradigmatic "known technique to improve a similar device in the same way."

Weakest link. Rose is a USENET post about card shuffling, not cryptography. The Board's four reasons (no hashing; not cryptographic; not about hash-output bias; no iteration) are really one reason: Rose supplies only the abstract statistical idea, and the petition had to import the cryptographic context from DSS. The patent owner's winning framing in 2019 was hindsight: "the Petition Uses the '961 Claims As A Roadmap To Rewrite Rose's Algorithm Without Justification."

Ground II — FIPS 186‑2 (DSS) + Schneier + Menezes (HAC)

Targets the same claim set.

Same mapping, with HAC substituted for Rose as the motivation/uniformity teaching. Motivation: treatises of record are the ordinary artisan's first stop; HAC's treatment of DSA and of uniform random-integer generation supplies the same "avoid the bias" impetus with far greater technical authority than a USENET post. Weakest link: identical to Ground I unless HAC's actual text discloses discarding out-of-range values (unverified).

Ground III — Ground I (or II) + Rao + Floyd

Targets claims 23, 24, 27 (the apparatus/"cryptographic unit" claims).

Claims 23/24/27 are functionally identical to claim 1 but recited as a unit with an arithmetic processor. Rao (arithmetic processing) and Floyd (data processing) supply the conventional hardware context; US 6,327,660 (Patel/Intel) independently supplies a cryptographic processor in a constrained environment. Motivation: MPEP 2143 (A) — implementing a known algorithm on a known processor yields predictable results; the Federal Circuit routinely holds apparatus claims obvious where they add only conventional hardware to an obvious method. Strength: this is the strongest of the briefed grounds, because the apparatus limitations are the only additional features and they are indisputably conventional. It was still denied institution — but the denial is a § 314(a) threshold ruling, not a merits adjudication.

Ground IV — Nel & Kühn (primary) + FIPS 186‑2 + Schneier + Rose

Never briefed. The theory I would lead with.

Step Source
Problem identified: DSS key generation criticized; "can be avoided by using effective techniques" Nel & Kühn 1993 — on the patent face, examiner-cited
The specific flawed derivation k = G(t,KVAL) mod q and its doubled-probability interval FIPS 186‑2 App. 3 (and independently documented in the CRYPTREC DSA evaluation)
The fix: reject rather than fold Rose
Background that DSA/k are known Schneier

Motivation: Nel is the only reference in the record that is expressly about DSS key generation and expressly states the problem is avoidable with "effective techniques." Combined with a reference teaching rejection sampling, the case is a textbook KSR design-incentive case: a known, narrowly defined defect (mod q folding) in a known algorithm, with a known remedy (discard out-of-range draws) drawn from the general art of uniform random sampling. Risk: Nel is examiner-cited → § 325(d); the ground must be presented as materially new (Nel as the articulated motivation rather than as an element, combined with Rose as new art).

Ground V — US 6,195,433 (Certicom's own) + FIPS 186‑2 + Rose

Never briefed; strategically potent because it is the patent owner's own prior art.

US 6,195,433 supplies almost the entire architecture: RNG/PRNG → SEED → SHA‑1 → shaped key of correct size → test the candidate and reject failures → store and use. Its counter mechanism (concatenate X'01', X'02'… to the SEED and re-hash) supplies claim 9's increment-and-rehash and claims 7/8's deterministic increment, and supplies the "repeat on rejection" loop.

The gap is exactly one thing: '433 reduces mod n first and then statistically tests. Claim 1 forbids that ordering. Why the gap is bridgeable:

  • '433's statistical tests (monobit, poker, runs, long-run) test distributional quality of the bit string, not range uniformity. The two references are not in conflict — different defects, different remedies.
  • '433 does not disparage rejection sampling and would not lead away from it. In re Gurley/DePuy Spine teaching-away requires the art to criticize, discredit, or otherwise discourage the claimed route — silence plus an alternative is insufficient.
  • A POSITA combining '433 (generate-test-reject) with Rose (discard out-of-range) arrives at claim 1 by substituting the test criterion (range instead of statistical quality) and applying the test at the right point in the pipeline. MPEP 2143 (C)/(D).

This is the single best motivation story: the patent owner's own earlier patent already teaches "generate a candidate key, test it, throw it away if it fails, generate another" — the '961's only asserted contribution is which test and when. Patent-owner rebuttal: "criticality of the ordering — '433 teaches reduction is part of shaping the key, and the '961's contribution is the discovery that shaping must not precede the test." That is a real argument, but it is an argument about an order of conventional steps chosen to achieve a known goal, which KSR treats as predictable variation.

Ground VI — Ground I + US 6,307,938 (Matyas) / Nel

Targets claims 3, 17, 25 (store the key) and reinforces the "reject and retry" element. Matyas supplies the self-validating candidate paradigm (generate → validate → accept/reject). Claims 3/17/25 (storing the accepted key in a register) are met by the FIG. 1 memory 22/registers 30/32 architecture and by '433's own store-and-validate step. These dependent claims are the most vulnerable of all — they add nothing functional.

Ground VII — US 6,195,433 + Nel + FIPS 186‑2 for claim 9 (two-hash variant)

Claim 9 was never challenged in either IPR. Claim 9 requires: incremental function f( ) applied to SV, second hash H(f(SV)), combination of the two outputs, then the pre-reduction test.

  • Increment + re-hash: FIPS 186‑2 App. 3's XKEY = (1 + XKEY + x_j) mod 2^b (feedback, increment, re-hash) and '433's counter concatenation.
  • Combination: '433's counter-concatenation produces successive values from a seed; the specification's "typically by concatenation" is the obvious way to enlarge the entropy pool (claims 12/14's "bit string greater than L" and "rejecting excess bits").
  • Pre-reduction test: Rose / Nel as above.

⚠️ Critical asymmetry I want to flag. The art that most closely matches claim 9's combination step is NIST's Oct. 5, 2001 Change Notice #1 (k = (z₁×2¹⁶⁰ + z₂) mod q), which is a post-priority document and therefore not § 102(b)/(a) art, and not a US patent/application publication for § 102(e). It cannot be used as a teaching. It can be used, carefully, in the objective-indicia analysis — see § 7.4. Claim 9 is therefore the most defensible independent claim of the four, on the existing art, even though it is not the claim asserted in the district court cases.


6. Claim-by-claim disposition

Claim Content Best combination Assessment
1 Method: seed→hash→pre-reduction test→accept k=H(SV) Ground IV (Nel + DSS + Schneier + Rose), then Ground V ('433 + DSS + Rose) Moderately strong. Depends on curing Rose's four deficiencies with an explicit motivation
2 Fresh seed on rejection Ground I (DSS's re-selection loop) + Rose redraw Strong
3 Store the key '433 (store/validate) / FIG. 1 registers Strong
4 Key used to generate a public key DSS (r = (g^k mod p) mod q; y = g^x mod p) Strong
5, 6 q prime of L bits; output of L bits DSS (160-bit q; 160-bit SHA‑1 G) + Nel Strong
7, 8 On rejection, increment output by deterministic function / add a constant, re-hash FIPS 186‑2 XKEY = (1 + XKEY + x_j) mod 2^b; '433 counter concatenation Strong — DSS literally increments and re-hashes
9 Two-hash + combine + pre-reduction test Ground VII Weakest to attack — the closest combination art (Oct. 2001 CN #1) is not prior art
10, 11 New seed, or increment seed, on rejection DSS loop; '433 Strong
12, 13 Bit string > L; select L-bit string; further selection on rejection Nel (per petitioner chart) + sliding-window/extended-output practice Moderate — rests on Nel's unverified content
14 Reject excess bits so output is L bits Nel (per petitioner chart) Moderate — same dependency
15–22 CRM versions of 1–8 Same as 1–8 + US 6,088,798 (program storage medium) Strong — parallel to 1–8, with an added conventional medium
23–27 Cryptographic unit / arithmetic processor Ground III (DSS + Rose/Menezes + Rao + Floyd + US 6,327,660) Strongest of the briefed grounds — additional limitations purely conventional
28, 29, 30 L-bit output; re-hash on rejection; add a constant As 6, 7, 8 Strong

7. Where the theory breaks, and the patent owner's best answers

7.1 The 2019 denial is the single most important real-world datum — and it is not a merits finding. The Board's Nov. 5, 2019 decision denied institution, and its stated reasons were targeted at Rose: Rose does not (1) disclose hashing the random number, (2) contemplate application to cryptographic key generation, (3) contemplate avoiding bias in the output of a hash function, or (4) contemplate iteratively repeating selection and hashing. A challenger must therefore cure each point expressly — and the natural cure for (1)–(3) is DSS (hashing + crypto + the flawed hash-output derivation) while the cure for (4) is the DSS iteration/FIPS loop. Note the asymmetry: the Board's reasons describe what Rose alone lacks; they do not hold that the combination was improperly motivated, because the Board never reached a merits FWD.

7.2 "Obvious to try" vs. "multiple different approaches." BlackBerry's POPR argued the petition "falsely contends that a limited number of solutions to mitigating modulo bias would have rendered [the] approach obvious to try, as evidenced by the fact that subsequent versions of DSS addressed the modulo bias problem using multiple approaches fundamentally different from Rose." That is the strongest non-obviousness argument in the file, and it maps onto the KSR "finite number of identified, predictable solutions" / In re Cyclobenzaprine line. Its weakness: the evidence postdates the 2000‑12‑27 priority date. NIST's Oct. 2001 Change Notice and SP 800‑XX (Oct. 2001) both postdate the invention; using them to prove the solution space was unpredictable as of December 2000 is methodologically dubious — they are evidence of what NIST chose, not of what a POSITA would have foreseen. Expect the patent owner to use this anyway, and expect the challenger to move to exclude it as art.

7.3 The Nel linchpin is unverified. Both this section and the Prior Art section rest on the petitioner's characterization that Nel discloses "the output from said hash function is a bit string of predetermined length L" and "rejecting excess bits such that said new output is a bit string of length L." If Nel genuinely teaches that, claims 6, 12 and 14 fall fairly easily and Ground IV becomes the best theory on the patent. If Nel merely criticizes DSS key generation without disclosing rejection, the theory loses its anchor and reverts to Ground I/II. Pull the Nel paper (DOI 10.1109/COMSIG.1993.365882, pp. 6–11) before committing.

7.4 Secondary considerations — real but double-edged.

  • Industry adoption / copying. BlackBerry has asserted that "[t]he '961 patent's solution … was therefore adopted by many in the industry, including as part of the popular and commercially successful OpenSSL software library, and aspects … were further included in the ANSI X9.62 standard … and the IEEE P1363a standard," and that "OpenSSL … copied the inventions of the '961 patent" (quoted in Petitioner's Preliminary Reply, quoting Ex. 1037). This is a credible non-obviousness narrative (copying + industry adoption).
  • The counter: ANSI X9.62/X9.63 and the IEEE P1363a/X9.63 lineage, and NIST's Oct. 2001 Change Notice, use the concatenate-then-reduce construction — not the claim-1 rejection construction. If that is right, then the industry's standardized fix was not the '961's solution; the adoption evidence then proves only that OpenSSL happened to implement rejection sampling, which is the very thing the art of uniform sampling already taught. This cuts both ways and must be developed with the actual standard texts.
  • Long-felt need / skepticism. Weak: the bias was identified in the art (Nel 1993; the doubled-probability property of mod q), and the remedial technique was standard. The patent owner's best version is that the exploitability was not publicly appreciated until Bleichenbacher's work (Lucent press article Feb. 25, 2001 — after the priority date). That is a legitimate KSR "predictable solutions" rejoinder, but it is also an admission that the problem was not recognized — which undercuts long-felt need ("the need must have been a recognized need").
  • Unexpected results. None identified in the record.

7.5 § 325(d) and the reexamination track. Because DSS, Schneier, Nel, '433, '938, '798 and '660 are all of record, a PTAB petition built only on them invites discretionary denial under Advanced Bionics/Becton, Dickinson. The new art is Rose, Menezes (HAC), Rao, Floyd — all of which were already presented and rejected at the § 314(a) stage in 2019. A 2026 challenger needs materially new art or a materially new theory — the Ground IV "Nel-as-motivation" framing and Ground V "'433-substitution" framing are the two candidates. Meanwhile the pending ex parte reexamination (request effective 2025‑01‑06, docketed 2026‑03‑10) is the central cancellation track, and on an expired patent the claims can only be confirmed or cancelled.


8. Net assessment

  1. No reference anticipates claim 1 (§ 102 fails). The negative limitation "prior to reducing mod q" is met by nothing in the record head-on; US 6,195,433, FIPS 186‑2 and DSS all reduce first.
  2. Claims 1, 2, 5–8, 15–22 and 23–30 are vulnerable to § 103, and the apparatus claims 23–27 are the most vulnerable because their added subject matter (an arithmetic processor, a unit) is conventional and independently supplied by US 6,327,660, US 6,088,798, Rao and Floyd.
  3. The two best theories are Ground IV (Nel-forward) — because Nel is the only reference expressly about DSS key generation and expressly promising "effective techniques" to avoid the problem — and Ground V ('433-forward) — because Certicom's own earlier patent teaches generate-test-reject with hash and counter iteration, differing only in the ordering.
  4. Claim 9 is the hard target. Its closest combination art (NIST Change Notice #1, Oct. 5, 2001) is not prior art against a Dec. 27, 2000 priority. Attacking claim 9 requires assembling the "combine two hash outputs / select an L-bit string" step from Nel (unverified) plus '433's counter-concatenation.
  5. A real invalidity case today requires (a) attributing a date to Rose's USENET post, (b) reading Nel and HAC's actual text, and (c) neutralizing BlackBerry's "multiple fundamentally different approaches" argument by moving it off the post-priority NIST documents. The 2019 denial tells you exactly where the prior petition was weak — and it is a § 314(a) threshold ruling, not a holding that the claims are valid.

9. Cross-reference and contradiction flags

  1. Resolved (new facts): "Rose" = Re: "Card‑shuffling" algorithms, USENET, sci.crypt (1993) (Facebook Ex. 1006); "Menezes" = Handbook of Applied Cryptography (1997) (Ex. 1011); "Rao" = Error Coding for Arithmetic Processors (1974) (Ex. 1018); "Floyd" = Essentials of Data Processing (1987) (Ex. 1019). This closes three of the four unresolved-reference items the Prior Art section flagged as "will not guess."
  2. Resolved (new facts): the IPR2019‑00923 ground structure is Ground 1: claims 1, 2, 5, 15, 16, 19 — DSS + Schneier + Rose; Ground 2: same claims — DSS + Schneier + Menezes; Grounds 3–4: claims 23, 24, 27 — Grounds 1/2 further in view of Rao and Floyd. The challenge set was 1–2, 5, 15–16, 19, 23–24, 27. Claims 3–4, 6–14, 17–18, 20–22 and 25–26, 28–30 were never challenged anywhere.
  3. Contradiction to flag — prior section's § 102(e) treatment of US 2003/0084332 A1. The Prior Art section stated § 102(e) was "the only possible basis" because its 2001‑10‑26 filing "predates the '961's filing date (2001‑12‑26) by only two months." That is not the pre-AIA test: under pre-AIA § 102(e), the reference's U.S. filing must precede the applicant's invention date, which is at least the 2000‑12‑27 foreign priority date. A 2001‑10‑26 filing is therefore after the critical date and is not § 102(e) art at all. I have not auto-corrected the number — I flag the legal analysis as likely in error, and the citation as anomalous.
  4. Corroborated: the Prior Art section's caution that Nel be treated as a lead, not a finding, stands. This section adds the specific limitations Nel was charted against (L-bit output; rejecting excess bits) — claims 6, 12, 14.
  5. Reinforced: the low-Hamming-weight masking embodiments remain carved out to the US 8,000,470 continuation. No combination above should be built on EP 0 854 603 / US 6,337,909 / CA 2,217,925 for the '961 claims — those are irrelevant to claims 1–30.
  6. New asymmetry to carry forward: the art most resembling claim 9's combine step is a post-priority NIST document and is disqualified as prior art. Do not cite it as a teaching; if it appears in an invalidity contention, expect a motion to strike.

Sources relied on for the new facts in this section

Generated 9/28/2026, 8:32:47 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by BlackBerry Limited

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (5)

5 tracked lawsuits name US 7372961.