Invalidity dossier
US 8484736
Storage device having an anti-malware protection
Current assignee: SanDisk Technologies LLC
Added 6/16/2026, 6:00:23 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
US patent 8484736, titled "Storage device having an anti-malware protection," was filed on June 6, 2008, and issued on July 9, 2013. The inventors are Judah Gamliel Hahn and Yaakov Ben-Tsvi. The original assignee was SanDisk IL Ltd, with the current assignee listed as SanDisk Technologies LLC.
Abstract:
The patent describes a storage device equipped with anti-malware protection. This protection operates by having a security processor in the storage device function in a "security" mode when interfaced with a host device. In this mode, the security processor filters commands received from the host device and directed to the storage controller. Once the security processor determines that the "security" mode is no longer necessary, it transitions to a "safe" mode, where it ceases to filter commands and instead forwards them unfiltered to the storage controller.
Independent Claims Overview:
Claim 1 (Method Claim): This claim describes a method for protecting a storage device when it's connected to a host device.
- Initial Security Mode: Upon initialization, the storage device operates in a "security" mode.
- Command Reception and Anti-Virus Check: The security processor receives a command from the host device and checks if it contains an indication that an anti-virus application is running on the host.
- Transition to Safe Mode: If such an indication is present, the device transitions to a "safe" mode.
- Security Threat Determination (if no anti-virus indication): If there is no anti-virus indication, the security processor determines if the received command poses a security threat.
- Handling Security Threats: If a threat is detected, the command is logged in a command alert log (CAL), stored in a volatile memory within the storage area, blocked from reaching the storage controller, and the host is notified that the command was "executed as expected."
- Handling Non-Threatening Commands: If no security threat is detected, the command is passed directly to the storage controller.
- Safe Mode Operation: In the "safe" mode, the security processor forwards all commands from the host to the storage controller without filtering them.
Claim 18 (Apparatus Claim): This claim describes a data storage device designed to implement the protection method.
- Components: The device includes a host interface, a memory for storing data, a storage controller for managing the memory and responding to host commands, and a security processor.
- Security Processor Functionality (Security Mode): While in "security" mode, the security processor is configured to:
- Receive commands from the host.
- Determine if the command includes an indication from the host that an anti-virus application is running.
- Transition to "safe" mode if the indication is present.
- Determine if a command poses a security threat when no anti-virus indication is present.
- If a security threat is identified, log the command in a CAL, store it in volatile memory, block it from the storage controller, and notify the host that the command was "executed as expected."
- Pass non-threatening commands to the storage controller.
- Security Processor Functionality (Safe Mode): While in "safe" mode, the security processor is configured to forward all host commands to the storage controller without filtering.
CAFC 2026 Dockets:
A search of CAFC 2026 dockets for patent number 8484736 did not return any specific results. Therefore, there is no authoritative information currently available regarding active litigation for this patent in the CAFC for the year 2026.
Generated 6/16/2026, 6:01:05 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 8484736. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
As a patent attorney, I have searched for known litigation involving US patent 8484736. Based on the available information, there is no known litigation directly involving US patent 8484736.
Searches of publicly accessible databases like Unified Patents and PACER, as well as general patent litigation searches, did not return any specific cases citing US patent 8484736 as being involved in litigation. Unified Patents, for example, lists PTAB cases, ex-parte reexams, and litigation cases, but a search for 8484736 did not yield results in these categories. Similarly, there was no authoritative information found regarding active litigation for this patent in the CAFC for the year 2026.
Generated 6/16/2026, 6:45:44 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
There are no PTAB proceedings on file for US patent 8484736. This indicates that the patent has not been challenged in an AIA trial proceeding, which means all claims of the patent remain untested by this specific avenue. For a defendant, this means the patent is not hardened by surviving IPRs, nor have any claims been invalidated via PTAB.
Strategic summary
As of today, June 16, 2026, all 23 claims of US patent 8484736 remain patentable and untested by PTAB proceedings. No claims have been canceled, sustained, or otherwise altered by inter partes review (IPR), post-grant review (PGR), or covered business method (CBM) proceedings.
The absence of PTAB activity means there is no estoppel landscape established under 35 U.S.C. § 315(e)(2). Therefore, a defendant currently being asserted against would not be barred from raising any available prior art grounds in a new IPR or other relevant proceeding, assuming they meet the statutory requirements for filing. There is no pattern of filings by any petitioner, nor has the patent owner pursued PTAB appeals. The absence of PTAB challenges for this patent, despite its issue date of July 9, 2013, could be a signal that it has not been extensively asserted, or that prior art challenges were not considered strong enough to warrant an AIA trial.
Recommended next steps
If you are a defendant facing assertion of US patent 8484736, the absence of PTAB activity means a challenge through IPR or other AIA trial proceedings remains an open strategic option. Your legal team should conduct a thorough prior art search to assess the patentability of the claims and determine if a strong petition can be filed. As there are no active proceedings, there are no upcoming trial-stage milestones to consider.
Generated 6/16/2026, 6:45:36 PM
Ownership chain (3)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2008-06-06 · reel 021081/0410 · Assignment of Assignors Interest
HAHN, JUDAH GAMLIEL; BEN-TSVI, YAAKOVSANDISK IL LTD.
Correspondent: E. K. SAAVAGE
initial assignment from inventors to their employer at the time of filing
2019-11-12 · recorded 2020-08-21 · reel 053574/0513 · Change of Name
SANDISK IL LTD.Western Digital Israel Ltd.
Correspondent: KYOUNG JOO BAE
internal reorg
2024-10-22 · recorded 2024-10-24 · reel 069267/0794 · Assignment of Assignors Interest
Western Digital Israel Ltd.SanDisk Technologies Inc.
Correspondent: KYOUNG JOO BAE
internal reorg
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
- Judah Gamliel Hahn (SanDisk IL Ltd)
- Yaakov Ben-Tsvi (SanDisk IL Ltd)
Both inventors appear to have been employed by SanDisk IL Ltd at the time of filing, as the patent was assigned to SanDisk IL Ltd on the same date it was filed. There is no indication of all inventors departing the original assignee within 12 months of filing.
Original assignee
The original assignee named on the issued patent is SanDisk IL Ltd. SanDisk is a well-known manufacturer of flash memory products, including USB flash drives, SD cards, and solid-state drives, which embody the claims of the patent. The primary line of business for SanDisk IL Ltd would have been research and development related to non-volatile memory and storage solutions. SanDisk, the parent company, was acquired by Western Digital in 2016. SanDisk IL Ltd subsequently underwent a name change to Western Digital Israel Ltd.. The patent itself is now expired due to failure to pay maintenance fees as of August 11, 2025.
Assignment timeline
2008-06-06 (executed) / recorded 2008-06-06 — Reel 021081/0410
- Conveyance: Assignment of Assignors Interest
- Assignor: HAHN, JUDAH GAMLIEL; BEN-TSVI, YAAKOV
- Assignee: SANDISK IL LTD.
- Correspondent: E. K. SAAVAGE - SUITE 160, 20400 STEVENS CREEK BLVD., CUPERTINO, CA, 95014.
- Context: Initial assignment from inventors to their employer at the time of filing.
2019-11-12 (executed) / recorded 2020-08-21 — Reel 053574/0513
- Conveyance: Change of Name
- Assignor: SANDISK IL LTD.
- Assignee: WESTERN DIGITAL ISRAEL LTD
- Correspondent: BAE, KYOUNG JOO - WESTERN DIGITAL TECHNOLOGIES, INC. - 5601 GREAT OAKS PKWY, SAN JOSE, CA 95119. This correspondent recurs in this chain.
- Context: Internal corporate reorganization/name change following the acquisition of SanDisk by Western Digital.
2024-10-22 (executed) / recorded 2024-10-24 — Reel 069267/0794
- Conveyance: Assignment of Assignors Interest
- Assignor: WESTERN DIGITAL ISRAEL, LTD.
- Assignee: SANDISK TECHNOLOGIES, INC.
- Correspondent: BAE, KYOUNG JOO - WESTERN DIGITAL TECHNOLOGIES, INC. - 5601 GREAT OAKS PKWY., SAN JOSE, CA, 95119. This correspondent recurs in this chain.
- Context: Internal corporate transfer of patent ownership within the Western Digital/SanDisk corporate family.
Timeline diagram
timeline
title Ownership of US 8484736
2008 : Filed by inventors
: Assigned to SanDisk IL Ltd
2013 : Patent granted
2019 : SanDisk IL Ltd becomes W.D. Israel Ltd
2024 : Assigned to SanDisk Tech Inc
2025 : Patent expired
NPE / troll-pattern signals
- Shell-entity transfer: Not present. All entities in the assignment chain (SanDisk IL Ltd, Western Digital Israel Ltd, SanDisk Technologies, Inc.) are operating companies associated with the design and manufacture of storage devices.
- Known asserter in the chain: Not present. None of the listed assignees are identified as known Non-Practicing Entities (NPEs) or patent trolls.
- Repeat correspondent across the chain: Present. Kyoung Joo Bae of Western Digital Technologies, Inc. is listed as the correspondent for the 2020 change of name (Reel 053574/0513) and the 2024 assignment (Reel 069267/0794). This indicates consistent legal representation for internal corporate transactions within the Western Digital/SanDisk group.
- Cascading transfers: Not present. The transfers are spaced over several years (2008, 2019/2020, 2024) and reflect corporate structuring rather than rapid-fire transfers.
- Pre-litigation transfer: Not present. The patent expired in 2025, and there are no public records of litigation occurring within six months prior to the final assignment in 2024 or before its expiration.
- Bankruptcy fire-sale: Not present. SanDisk was acquired by Western Digital through a corporate merger, not as a result of bankruptcy proceedings.
- Privateering: Not present. The ownership chain remains within a single operating company and its subsidiaries.
- Defensive aggregator (anti-NPE): Not present. The patent was not transferred to an entity like RPX, AST, or LOT Network.
Verdict
Operating-company assertion. The patent's ownership history consistently resides within SanDisk and its acquiring entity, Western Digital, both prominent operating companies in the storage device industry. While the patent is now expired and cannot be asserted, its historical chain of title shows no patterns indicative of NPE activity, but rather typical corporate assignments and name changes (Reel 021081/0410, Reel 053574/0513, Reel 069267/0794).
Generated 6/16/2026, 6:45:49 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
To identify the most relevant prior art for US patent 8484736, I will examine the patent citations listed within the patent itself. The USPTO provides access to issued patents and published applications.
Here are the prior art references cited in US patent 8484736, along with their details and potential anticipatory aspects under 35 U.S.C. § 102:
1. US20020162015A1
- Full Citation: US20020162015A1 (Tang)
- Publication Date: October 31, 2002
- Brief Description: This patent application describes a method and system for scanning and cleaning known and unknown computer viruses. It also covers recording and transmission media for the same.
- Potential Anticipation: This reference potentially anticipates elements of Claim 1 and Claim 18 relating to the general concept of anti-malware protection and scanning for viruses. Specifically, the idea of identifying and dealing with threats could overlap with "determining whether the received command poses a security threat" (Claim 1) and the functionality of the security processor to "determine whether the received command poses a security threat" (Claim 18).
2. US6526489B1
- Full Citation: US6526489B1 (Nec Corporation)
- Publication Date: February 25, 2003
- Brief Description: This patent describes a data storage apparatus with an improved security process and partition allocation functions.
- Potential Anticipation: This patent might anticipate elements of Claim 1 and Claim 18 concerning the secure management of a storage device, particularly "a storage area for storing data" and "a storage controller for managing the storage area" (Claim 1 and 18). The "improved security process" could also touch upon the general idea of protecting the storage device.
3. US20060294370A1
- Full Citation: US20060294370A1 (Greenspan)
- Publication Date: December 28, 2006
- Brief Description: This patent application describes a method, device, and system for maintaining a context of a secure execution environment.
- Potential Anticipation: This reference could be relevant to the operation of the security processor in the "security" mode and the transition to the "safe" mode (Claim 1 and 18). Maintaining a "secure execution environment" might be seen as analogous to the security mode where commands are filtered.
4. US20070261118A1
- Full Citation: US20070261118A1 (Lu)
- Publication Date: November 8, 2007
- Brief Description: This patent application describes a portable storage device with standalone antivirus capability.
- Potential Anticipation: This reference is highly relevant as it describes a portable storage device with anti-virus capabilities, similar to the overall goal of US8484736. It could anticipate various aspects of both Claim 1 and Claim 18, particularly the presence of an anti-virus mechanism within the storage device. The standalone nature might differ from the host-based anti-virus described in US8484736, but the core concept of protection within the device is similar.
5. US20070266063A1
- Full Citation: US20070266063A1 (Camiel)
- Publication Date: November 15, 2007
- Brief Description: This patent application describes a system and method for data storage firewall on a data storage unit.
- Potential Anticipation: The concept of a "data storage firewall" directly relates to the security processor's function of filtering commands in the "security" mode (Claim 1 and 18). This reference could anticipate the mechanism of intercepting and evaluating commands before they reach the storage controller.
6. US20080052507A1
- Full Citation: US20080052507A1 (Super Talent Electronics Inc.)
- Publication Date: February 28, 2008
- Brief Description: This patent application describes a multi-partition USB device that re-boots a PC to an alternate operating system for virus recovery.
- Potential Anticipation: While the specific mechanism of re-booting to an alternate OS differs, this reference addresses virus recovery in a USB device. Elements related to the interaction between a storage device and a host for security purposes, especially during initialization or recovery, could be relevant to Claim 1 and 18, particularly the broader context of protecting the storage device from host-borne threats.
7. US20080098478A1
- Full Citation: US20080098478A1 (Redcannon, Inc.)
- Publication Date: April 24, 2008
- Brief Description: This patent application describes a system, method, and computer program product for administering trust-dependent functional control over a portable endpoint security device.
- Potential Anticipation: This is highly relevant due to the "trust-dependent functional control" over a "portable endpoint security device." This could anticipate the mechanism of the security processor determining whether the host can be trusted (e.g., if an anti-virus is running), leading to the transition between security and safe modes (Claim 1 and 18).
8. US20080134281A1
- Full Citation: US20080134281A1 (McAfee, Inc.)
- Publication Date: June 5, 2008
- Brief Description: This patent application describes a method and system for enhanced wireless network security.
- Potential Anticipation: While focused on wireless networks, the underlying principles of "enhanced security" and method/system for protection might have general applicability. Depending on the specifics of the enhanced security methods, some broad concepts could potentially anticipate parts of Claim 1 or 18 related to command filtering or threat detection. However, the specific domain (wireless network) makes direct anticipation of a storage device's internal anti-malware less likely.
9. US20080162784A1
- Full Citation: US20080162784A1 (Spansion Llc)
- Publication Date: July 3, 2008
- Brief Description: This patent application describes systems and methods for access violation management of secured memory.
- Potential Anticipation: This reference deals with "access violation management of secured memory," which is directly relevant to protecting a "storage area for storing data" (Claim 1 and 18). The security processor blocking commands from reaching the storage controller when a threat is detected (Claim 1 and 18) could be considered a form of access violation management.
10. US7853999B2
- Full Citation: US7853999B2 (Microsoft Corporation)
- Publication Date: December 14, 2010 (Note: This patent was granted after the filing date of US8484736, but its priority date would be key for prior art analysis under 35 U.S.C. § 102. The publication date of the application US20070271633A1 was November 22, 2007, which precedes the filing date of US8484736).
- Brief Description: This patent describes a trusted operating environment for malware detection.
- Potential Anticipation: This reference's concept of a "trusted operating environment for malware detection" directly relates to the security mode and safe mode functionality of US8484736. The determination of whether an anti-virus is executing on the host and the subsequent trust decision are central to both. This could potentially anticipate aspects of Claim 1 and 18, particularly the transition based on the host's anti-virus status.
Generated 6/16/2026, 6:45:47 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll ground the obviousness analysis by confirming details on the most relevant references before building the combinations.
Now let me confirm the remaining key references: Redcannon's trust-dependent control, Microsoft's trusted environment, and Spansion's access violation management.
Let me verify one citation detail that appears inconsistent in the prior-art section before relying on it.
Obviousness Analysis — US 8484736 under 35 U.S.C. § 103
Preliminary notes, scope, and flagged discrepancies
Before the analysis, three things in the record must be reconciled. I am flagging these rather than silently correcting them, per the operating rules.
Governing law is pre-AIA § 103. US 12/134,746 was filed June 6, 2008 and claims no earlier priority (no provisional or foreign priority is listed). The AIA's first-inventor-to-file provisions therefore do not apply. The analysis below uses pre-AIA 35 U.S.C. §§ 102/103 as construed by Graham v. John Deere Co., 383 U.S. 1 (1966), and KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007). The critical date for prior-art qualification is June 6, 2008.
The patent is expired. The file history shows maintenance-fee lapse effective July 9, 2025, with expiration entered August 11, 2025, notwithstanding the "adjusted expiration 2030-03-11" line that reflects the pre-lapse PTA-based term. This § 103 analysis is therefore retrospective (relevant to past-damages exposure, licensing/rep warranties, or to sibling-family patents), not to prospective assertion.
Date inconsistency in the working record (flagged, not corrected). The task header states "Current Date: April 26, 2026"; the previously generated PTAB section is dated "as of today, June 16, 2026"; the tooling environment states 2026-09-25. These cannot all be right. I have not used any of them as a substantive input, so the analysis is unaffected — but the arbitration date of "within six months of the 2024 assignment" reasoning in the assignment section should be re-checked against a single authoritative date.
One citation problem I could not resolve (flagged). The Prior Art section states that US7853999B2's "publication date of the application US20070271633A1 was November 22, 2007." I could not verify that identifier. US7853999B2 (Khilnani et al., Microsoft) issued from application 11/747,416, filed May 11, 2007, and its pre-grant publication appears to be US2008/0282351A1, which would publish after the June 6, 2008 critical date. US20070271633A1 does not appear to be the corresponding publication. I recommend verification via USPTO PatentCenter before relying on any "November 22, 2007" date. Importantly, the conclusion is unaffected: US7853999B2 qualifies as pre-AIA § 102(e) prior art regardless, because § 102(e) keys to the US filing date (May 11, 2007), not the grant date or publication date.
A second qualification gap in the Prior Art section (flagged). The table listed publication dates without checking them against the June 6, 2008 critical date. Two references publish after that date and are therefore usable only under § 102(e) as US application publications filed before June 6, 2008:
| Reference | Filed | Published | Qualifies under |
|---|---|---|---|
| US20080162784A1 (Spansion) | 2006-12-29 | 2008-07-03 | § 102(e) only |
| US20080052507A1 (Super Talent) | 2000-01-06 (per listing) | 2008-02-28 | § 102(a)/(e) |
All other cited references published before June 6, 2008 and are available under § 102(a) and/or § 102(e).
I did not retrieve the full text of US6526489B1 (NEC) or US20020162015A1 (Tang); for those I rely on the description in the Prior Art section and on their abstracts as reproduced there, and I say so where it matters.
1. Claim construction of the limitations that carry the weight
Under Phillips v. AWH Corp., 415 F.3d 1303 (Fed. Cir. 2005) (en banc), the dispositive limitations are:
| Term | Construction | Weight-bearing? |
|---|---|---|
| "security mode" / "safe mode" | Two mutually exclusive operating states of the security processor; the sole stated distinction is whether received host commands are filtered or forwarded unfiltered. Spec: safe mode = "command-wise transparent to storage controller." | Yes — the mode switch is the alleged point of novelty |
| "indication … that an anti-virus application is executing on the host device" | Claim 9 defines it as any one of a message, a message over a secure session, or a signal received during mutual authentication. This is deliberately broad. | Yes, but broad |
| "poses a security threat" | Spec: a command that "poses a virus threat … in itself or in conjunction with other previously received command(s) and/or future command(s)." | Yes |
| "command alert log" (CAL) | Persistent (NVM) log of alertable commands, distinct from the volatile "commands history." | Moderate |
| "storing … in a volatile memory in the storage area" | The transient commands-history buffer (Fig. 3, 395 in RAM 390). | Weak (claim 16) |
| "notifying the host device that the command was executed as expected by the host device" | The host is told the command succeeded when in fact it was blocked (a decoy/spoofed completion). | Most probative |
Applicant's own admissions. The specification is unusually candid, and those statements are usable as prior art under Southwall Techs. v. Cardinal IG Co., 54 F.3d 1570, 1575–76 (Fed. Cir. 1995). The Background admits: (i) some portable storage devices "are provided with an anti-virus … application to protect … the data stored therein"; (ii) such applications "are usually executed on the host device rather than by the storage device"; (iii) "one of the initialization steps … involves transferring, by the storage device, the anti-virus application to the host device"; and (iv) handshaking and the IEEE 1667 Authentication Silo key-exchange mechanism are known. Each of these admissions narrows the space the claims can occupy.
2. Element-by-element mapping of claim 1 (and parallel elements of claim 18)
| Claim 1 / 18 limitation | Disclosure |
|---|---|
| storage device: host interface, storage area, storage controller, security processor | Camiel (US20070266063A1): I/O unit 12, non-volatile memory unit 16, storage firewall 14 "located between I/O unit 12 and non-volatile memory unit 16"; Spansion (US20080162784A1): host processor 110 coupled to security processor 130 and memory 140 "in a series connection," security processor 130 between host and memory |
| operate in security mode in response to initialization | Camiel: firewall "is activated by default and enforced by the media device"; Lu (US20070261118A1): start-up sequence on insertion (steps 301–308) launches the on-device protection program; patent's own FIG. 2 |
| receive a command from the host | Camiel: "deciding whether or not to allow requested commands received from I/O unit"; Spansion: host memory I/F 150 "monitor[s] information being communicated from the host processor to the memory" |
| determine whether the command includes an indication that AV is executing on the host | Redcannon (US20080098478A1): reconnoitering application + trust enforcement policy determines the host's "relative trusted state"; Lu: the device knows when its protection program has been loaded and launched |
| transition to safe mode when the indication is present | Redcannon: "execution of internally maintained applications when the relative trusted state … may be low and execution of external applications when the relative trusted state … may be high" |
| when no indication, determine whether the command poses a security threat | Camiel: per-LBA permission values "for allowing or rejecting read and/or write commands," policies "compared to internal policy mode and … carried out or blocked based on the combination result of the two policies"; Spansion: validity check + partition-rights check; Greenspan (US20060294370A1): context maintenance |
| log the command in a command alert log | Redcannon: administration of "audit functions internal to the portable endpoint security device"; Camiel: file table 22 / location table 26 bookkeeping |
| store command/info in volatile memory in the storage area | Greenspan: maintaining the context of a secure execution environment; allocation of a transient session buffer to volatile memory is a routine design choice (MPEP 2144.04) |
| block the command from reaching the storage controller | Camiel: reject/block disallowed read/write by LBA; Spansion: "If the command is illegal … abort the operation associated with the command and prevent the command from executing," I/F and memory revert to idle |
| notify the host that the command was executed as expected | Spansion: "the host memory I/F can cause replacement data to be sent to the memory location … such that the information at that memory location will not be affected," and "can generate a different and unique command resulting in a different operation being performed"; Camiel: protection "work[s] by default … without the user being required to activate protection or be aware of security" |
| safe mode: forward without filtering | Redcannon: trust-dependent relaxation of device-side control (the stated purpose is to stop "negatively impacting a user's productivity, providing unnecessary transactions and adding to the processing burden") |
Every limitation of claim 1 and claim 18 is accounted for. That is not itself the test — In re Merck & Co., 800 F.2d 1091, 1097 (Fed. Cir. 1986) (the test is what the combined teachings suggest, not whether references are bodily incorporable) — but it establishes the foundation for the combinations.
3. The three combinations that render claims 1 and 18 obvious
Combination A (primary): Camiel + Redcannon + Lu
Camiel supplies the entire security-mode apparatus: an enforcement block physically interposed between the host interface and non-volatile memory, holding rules that evaluate host commands and block those that violate policy, "protect[ing] media device from viruses and other malicious attacks," and doing so "by default" in a manner that "cannot be affected by a compromised digital appliance." Camiel even uses the patent's own two-part architecture — data store + policy table + a "device mode unit" 28.
Lu supplies the reason the enforcement must be temporary: the anti-virus burden is shifted to the host ("protection program … loaded and run in memory 108"), and it is the device that triggers and observes that shift (steps 305–308, including the auto-run launch from a read-only CD-ROM partition). Lu therefore supplies both the "anti-virus application transferred to the host" element of claim 21 and claim 13, and the factual predicate for the device knowing that host-side AV is running.
Redcannon supplies the missing mode switch and, critically, the motivation. Redcannon's preamble states the problem in exactly the terms that make the claimed invention obvious: a portable security device's own controls "negatively impact a user's productivity, provid[e] unnecessary transactions and add[] to the processing burden of the available computing resource," and therefore "a highly portable device which determines the relative trusted state of the available computing resource would be highly advantageous." That is a textbook express motivation to do precisely what claims 1 and 18 recite: filter while the host is untrusted, and stop filtering once the host's trusted state is established. Redcannon supplies a finite, two-state solution (low trust → rely on device-internal applications; high trust → rely on host-external applications), which satisfies the KSR "finite number of identified, predictable solutions" formulation.
Why a POSITA would combine. All three are in the same field of endeavor (portable storage/host interface security) and are reasonably pertinent to the same problem (KSR; In re Clay analogous-art test). The combination yields nothing more than the predictable aggregation of known functions: an in-line command filter (Camiel) + a trust-state-driven relaxation of that filter (Redcannon) + a host-side AV handoff whose completion signals the trust state (Lu). Under KSR, "the combination of familiar elements according to known methods is likely to be obvious when it does no more than yield predictable results."
Combination B: Spansion + Redcannon + Lu
This is the stronger combination for the "notify the host that the command was executed as expected" limitation, because Spansion does not merely block — it affirmatively substitutes a benign operation so that the host's transaction continues to appear to succeed ("replacement data … such that the information at that memory location will not be affected"; "generate a different and unique command resulting in a different operation being performed"). Spansion additionally confirms the exact hardware topography of claims 1 and 18 — a security processor in series between the host and the memory, monitoring every command on the bus.
Spansion's weakness is the absence of both a persistent CAL and any explicit pass-through mode; Redcannon cures the latter and Camiel (or claim 16's routine design choice) cures the former.
Combination C: Camiel + Microsoft (US7853999B2) + Redcannon
Substitutes the § 102(e) Microsoft reference for Lu where claim language about trust matters (claims 15 and 17). Microsoft discloses a "trusted operating environment" embodied on removable media, authenticated via "authentication protocols" and digital signatures (X.509), and verified as originating "from a trusted authority." That is the "indication from the host device that the anti-virus application executing on the host device is trusted" of claim 17, and it supports claim 15's "all clear" as no more than a protocol message confirming a state the device already knows how to verify.
KSR / MPEP 2143 rationales that apply across all three combinations
- (A) Known elements combined to yield predictable results — an in-line policy filter, a trust evaluation, and a pass-through default are each known; the two-state result is the arithmetic of the two extremes.
- (C/D) Known technique improving a similar device, device ready for improvement — Camiel's firewall is expressly "activated by default"; once a trusted-host determination exists (Redcannon), the only remaining design question is whether to keep enforcing. Camiel itself disparages host-resident AV ("Anti-virus or firewall programs running on a computer may crash or malfunction"), while Lu and the patent's own background disparage the unprotected window. The two-state design answers both critiques simultaneously.
- (F) Design incentives / market forces — Redcannon articulates the productivity/processing-burden incentive verbatim.
- (E) Obvious to try — the art presents a binary: always enforce (Camiel) or never enforce (patent's FIG. 1 prior art). Interpolating between two disclosed options in the same field is the paradigm KSR fact pattern.
4. Dependent claims
| Claim | Most likely ground | Notes |
|---|---|---|
| 2, 19 (embedded) | NEC US6526489B1; Super Talent US20080052507A1; Camiel (firewall integral to the media device) | Embedded vs. removable is a recited design choice; the spec itself claims both embodiments |
| 3 (flash) | Lu; Camiel (flash disk); Super Talent | Admitted in the Background |
| 4, 23 (threat alone or in conjunction with prior/subsequent commands) | Camiel (LBA policy "compared to internal policy mode" and blocked "based on the combination result of the two policies"); Greenspan (context of the secure execution environment); Redcannon (context-dependent characteristics: "a memory execution stack, a registry entry, … a service, a process") | Look-ahead to a "subsequently received command" is the weakest-supported sub-element; likely treated as routine buffering/state-machine design under MPEP 2144.01 |
| 5 (host access to CAL after transition) | Redcannon ("controlling audit functions internal to the PEPS"; "displaying graphical indicia of malware detected") | Reasonable, but a patent owner can argue no reference discloses conditional access gated on the mode transition. Moderately vulnerable to challenge |
| 6, 7 (sequence; interspersed alertable commands) | Greenspan (context of a secure execution environment); Camiel (policy-combination result) | Strong |
| 8 (security rules) | Camiel (per-LBA permission policies) | Very strong |
| 9, 10 (message / secure session / mutual auth; key exchange) | Microsoft (authentication protocols, digital signatures, trusted authority); Spansion (authentication component 160 with password/biometric credentials); patent's own admission re IEEE 1667 | Very strong; claim 9 is a Markush of three conventional handshake mechanisms |
| 11, 12 (sequential time periods; second begins in response to the indication) | Redcannon (trust state is determined, then functional control is administered); Lu (protection program lifetime is bounded by device presence) | Strong |
| 13 (device-transferred AV vs. host-based AV) | Lu (device-transferred: read-only partition → host memory 108); host-based AV admitted as known | Very strong; both alternatives come from a single reference plus an admission |
| 14 (re-enter security mode on reconnection) | Lu (protection program "stop[s] running in the main memory upon removal," and re-launches on re-insertion, step 301); patent's own FIG. 2 state machine (210→215→225→235) | Very strong |
| 15 (all clear message) | Lu; Microsoft; Redcannon trust enforcement policy | Strong |
| 16 (commands history file in volatile memory) | Greenspan; routine allocation of transient session state to RAM | Weak claim; MPEP 2144.04 (design choice) |
| 17 (indication indicates AV is trusted) | Microsoft (trusted authority, authenticated updates); Redcannon (trust enforcement policy) | Strong |
| 20 (security mode entered on detecting connection) | Lu (detection/start-up on insertion); Camiel ("activated by default") | Strong |
| 21 (AV stored in memory; caused to be transferred on connection) | Lu — directly | Anticipation-adjacent |
| 22 (USB flash drive, SD, miniSD, microSD, MMC, SSD) | Lu (USB); patent's own Background list of MMC/SD/miniSD/microSD; Camiel (flash disk) | Very strong |
5. The patent owner's best (and likely losing) non-obviousness arguments
A well-prepared owner would argue the following. I assess each candidly.
Argument 1: none of the references discloses both halves of the binary — an enforcement mode and a transparent mode — in one device. This is the strongest point: Camiel enforces, Spansion enforces, and neither discloses a pass-through state. But the argument fails under KSR because Redcannon expressly teaches allocating security functions between the device-internal and host-external domains as a function of the host's trust state. Combining a known filter with a known trust-dependent relaxation is a predictable, two-option design, and the owner must also overcome the KSR "obvious to try" rationale, since the art discloses a finite set of identified solutions.
Argument 2: the "notify the host that the command was executed as expected" step is a novel deception of the host, not disclosed or motivated. Spansion undercuts this: it discloses substituting a benign operation ("replacement data") and generating "a different and unique command" so the memory "continue[s] to operate smoothly." If the host is not told of the substitution, the difference from claim 1 is one of degree. Camiel supplies the additional motivation ("without the user being required to activate protection or be aware of security"). This is the most contestable claim element, but I do not think it survives Combination B.
Argument 3: claim 5's CAL access is conditional on the transition. Plausible but narrow; Redcannon's audit-function and malware-indicia-display disclosures supply the reporting function, and conditioning a report on the termination of a protective mode is a predictable sequencing choice.
Argument 4: the claimed solution is not "obvious to try" because the art teaches away — Camiel teaches that device-side protection should always be on. This mischaracterizes Camiel, which is silent on host trust; silence is not a teaching away. In re Kahn, 441 F.3d 977, 988 (Fed. Cir. 2006), and In re Merck require an affirmative teaching away, not mere absence.
Argument 5: the examiner allowed the claims over all ten references. True, and worth noting — every reference in this analysis was before the examiner. But the prosecution record does not show that the Redcannon trust-state-teaches-mode-switch reading was considered; the notice of allowance was entered without a PTAB test, and no post-grant proceeding exists to harden the claims. The absence of any IPR (per the earlier section) means no claim has been tested by an adversarial tribunal, so the "allowed over the art" point carries little defensive weight.
6. Objective indicia (secondary considerations)
Under Graham step four and WBIP, LLC v. Kohler Co., 829 F.3d 1317 (Fed. Cir. 2016), the owner bears the burden of establishing a nexus. On the public record available:
- No evidence of commercial success with a nexus to the claimed two-mode architecture.
- No copying evidence.
- No licensing attributable to this patent.
- No unexpected results disclosed in the specification; the stated benefits (protection during the initialization window) are the very benefits Lu and Camiel each pursue.
- No industry praise or long-felt-need evidence; the need was articulated in the art itself (Redcannon, Camiel), which cuts against non-obviousness.
The written description's own framing — that the problem and its host-side AV solution "ha[ve] been rapidly increasing," i.e., were conventional — further erodes any secondary-considerations story.
7. Bottom line
Claims 1 and 18 would, in my assessment, be more likely than not invalid under § 103 on Camiel + Redcannon + Lu, with Spansion added (or substituted for Camiel) to dispose of the blocked-command-plus-normal-completion limitation. The combination is a predictable aggregation of known elements with an express motivation in the art, and it satisfies at least four of the MPEP 2143 rationales.
Claims 3, 8, 11, 12, 13, 14, 15, 17, 20, 21 and 22 are highly vulnerable — most are effectively anticipated or obvious over Lu plus Camiel (or Microsoft) with minimal additional reasoning. Claim 21 in particular reads directly onto Lu.
Claims 5, 16, and the "subsequently received command" sub-element of claims 4/23 are the most defensible, on a narrow reading, but none is stronger than a "moderate" risk.
Caveats on my confidence. (i) I did not retrieve the full texts of US6526489B1 (NEC) or US20020162015A1 (Tang); my treatment of those two rests on the prior-art description and abstracts reproduced in the working record. (ii) I could not verify the US7853999B2 pre-grant publication identifier asserted in the Prior Art section (US20070271633A1, Nov. 22, 2007), and I recommend confirming it before citing it; the § 102(e) qualification of US7853999B2 stands independently on its May 11, 2007 US filing date. (iii) Two references publish after the June 6, 2008 critical date and are reachable only under § 102(e) — a point the Prior Art section did not flag and which a petitioner would need to plead correctly. (iv) My assessment is a merits view, not a validity opinion; no PTAB or court has construed these terms, and a contrary claim construction of "indication" or of "notifying the host that the command was executed as expected" could shift the outcome.
Generated 9/25/2026, 11:21:46 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 6286050I'll search for authoritative information on US 6286050, including any 2026 CAFC docket activity. Let me check for any litigation or post-grant proceedings specifically involving this patent. US Patent 6,286,050 — Verification Summary…
- US 8117644I'll research this specific patent number. Let me run targeted searches. Let me run additional targeted searches on litigation, PTAB, and any 2026 appellate activity. Let me verify the claim structure and check for any 2026 appellate or…
- US 5835667I'll research this patent number across the sources you specified. Let me run a few more targeted searches to check for litigation and confirm the bibliographic record. Research Findings — US Patent No. 5,835,667 Sources consulted and…
- US 5821945I'll search for authoritative information on this patent, including any litigation or CAFC docket activity. US Patent 5,821,945 — Summary Caveat up front: The search did not surface any U.S. court docket, PTAB proceeding, or CAFC appeal…
- US 7165131I'll search for authoritative information on US patent 7165131, including any litigation or CAFC docket activity. Let me run additional targeted searches for litigation/PTAB activity and USPTO status. US Patent 7,165,131 — Analyst Summary…
- US 6658526I'll research this patent. Let me search the available sources. Let me check specifically for any litigation or CAFC docket activity tied to this patent number. US Patent 6,658,526 — "Network Attached Virtual Data Storage Subsystem" Note…
- US 10909229I'll search for authoritative information on this specific patent number and any associated litigation. Let me search for the specific claims and any 2025–2026 appellate activity involving this patent. Let me attempt to retrieve the…
- US 5736721I'll verify the patent record against live sources, particularly for any 2026 CAFC docket activity. Verification note I searched for US 5,736,721 specifically (and checked for 2026 Federal Circuit / PTAB activity). Findings: - No 2026 CAFC…