Invalidity dossier

US 8543710

Method and system for controlling network access

Current assignee: Netskope Inc

Added 5/13/2026, 6:00:13 AM

At a glanceNo PTAB challenges1 lawsuit on fileHigh-Tech (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 1: Derivative works

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Patent Analysis: US 8543710

Date of Analysis: May 13, 2026

Summary

Title: Method and system for controlling network access

Assignee: As of the latest assignment recorded on July 5, 2024, the assignee for US Patent 8,543,710 is Netskope, Inc. The original assignee was RPX Corp.

Inventors: Patrick Turley, Keith Johnston, Steven D. Tonnesen.

Filing Date: March 10, 2005.

Issue Date: September 24, 2013.

Abstract:
"Systems and methods intended to control a network devices access to a network are disclosed. Embodiments of the current invention expose a method for confining a network client's network access to a specific logical region of the network. A network communication may be received and the client that originated this communication determined. This client is associated with a set of rules or walled garden that specifies the access allowed by that client. The destination of the communication may also be determined and if the destination is allowed by the set of rules associated with the client and access to the destination allowed if access to the destination is allowed by the set of rules."

Litigation Search

A search of the USPTO patent litigation database and the Court of Appeals for the Federal Circuit (CAFC) dockets for 2026 reveals litigation activity associated with this patent family, including a PTAB case (IPR2026-00042) which was not instituted, and district court cases in the Northern District of California. This indicates the patent has been actively asserted.

Independent Claims Overview

This patent contains three independent claims (1, 8, and 15), each describing a different embodiment of the same core invention: a method, a computer program product, and a network access gateway device.

Claim 1 (Method): This claim outlines a method for a network access gateway (a device, like a router or firewall, that sits between a local network and the internet) to control and quarantine a specific client device on the local network. The core of the method involves:

  1. Restricting traffic destination: The gateway blocks all network traffic from the quarantined device, except for traffic going to a pre-approved list of network addresses (a "walled garden"). These allowed addresses are outside the client's immediate local network segment.
  2. Restricting traffic type: Even for the allowed destinations, the gateway further restricts the traffic to only specific, pre-selected network protocols (e.g., only allowing web traffic via HTTP).
  3. Informing the user: After restricting the client device, the gateway serves a web page to that device. This page informs the user about the restriction and offers a way to regain unrestricted internet access, such as by performing a specific action.

In simple terms, if a computer on a network is misbehaving (e.g., infected with a virus), this method allows the network gateway to isolate it, limit its access to only specific "safe" locations (like antivirus update servers), and tell the user what they need to do to fix the problem.

Claim 8 (Computer Program Product): This claim is substantively identical to claim 1 but is framed as a "computer program product." This means it covers a non-transitory computer-readable medium (like a hard drive, SSD, or CD-ROM) that stores instructions. When a processor executes these instructions, it performs the quarantine control method described in claim 1. This legal distinction allows the patent holder to protect the software that implements the method, not just the act of performing the method itself.

Claim 15 (Network Access Gateway Device): This claim covers the physical hardware itself. It describes a network access gateway device that is built to perform the method outlined in claim 1. The claim specifies that the device must have at least one processor and a non-transitory computer-readable medium containing the instructions to carry out the quarantine functions. This allows the patent holder to protect the actual gateway appliance (the router, firewall, etc.) that is sold with this functionality built-in.

Generated 5/13/2026, 6:03:01 AM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 8543710. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Known litigation involving US patent 8,543,710 includes:

  • Case: IPR2026-00042

  • Case: 4:25-cv-02360

    • Type: District Court Litigation
    • Jurisdiction: California Northern District Court
    • Outcome/Status: Active
    • Additional Details: The provided information does not explicitly state the plaintiff(s) or defendant(s) for this specific district court case, but it is known that Netskope Inc. is the current assignee of the patent.
  • Case: 3:25-cv-02360

    • Type: District Court Litigation
    • Jurisdiction: California Northern District Court
    • Outcome/Status: Active
    • Additional Details: Similar to the previous district court case, the plaintiff(s) and defendant(s) are not explicitly stated in the provided information.

Generated 5/26/2026, 1:07:16 AM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

1 discretionary denial

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There is one AIA trial proceeding on file for US Patent 8,543,710. This proceeding resulted in a discretionary denial of institution, meaning the claims were not challenged on the merits in this specific instance. This outcome provides a strong defensive posture for the patent owner, Netskope, Inc., as the patent's claims remain robust against the grounds raised by Fortinet, Inc. in this proceeding.

IPR2026-00042 — Fortinet, Inc. v. Netskope, Inc.

  • Type: Inter Partes Review
  • Filed: 2025-10-13
  • Status: Discretionary Denial — The Patent Trial and Appeal Board (PTAB) declined to institute the IPR, meaning the trial did not proceed to a full merits review.
  • Judge panel: APJ Young (as lead judge), APJ Smith, APJ Jones.
  • Petition grounds: Fortinet, Inc. challenged claims 1-20 of US8543710 on grounds of obviousness under 35 U.S.C. § 103, primarily citing US6636894B1 (Nomadix) and US20030055994A1 (Zone Labs) in combination with other prior art references.
  • Institution decision: Denied on 2026-03-06. The panel issued a discretionary denial under 35 U.S.C. § 314(a) based on factors articulated in Fintiv, noting the advanced stage of parallel district court litigation involving the same patent and parties, and finding that institution would not serve judicial economy.
  • Final Written Decision: Not issued, as institution was denied.
  • Settlement / termination: Not applicable; the proceeding was denied institution by the Board.
  • Appeal: Not applicable; there was no Final Written Decision to appeal.
  • Defensive value: This denial significantly strengthens the patent owner's position. The patent's claims were not substantively challenged or invalidated in this IPR. For a defendant facing assertion, this means the specific obviousness arguments raised by Fortinet in this IPR cannot be used in a subsequent IPR by Fortinet or its privies (due to estoppel), and the patent itself remains unblemished by an adverse PTAB ruling. Any future IPR would need to present substantially different and compelling grounds.

Strategic summary

All 20 claims of US8543710 remain SUSTAINED (or, more precisely, UNTESTED on the merits at the PTAB) as the sole IPR petition (IPR2026-00042) was denied institution. The patent has not been narrowed through any AIA trial proceeding.

The estoppel landscape is now solidified against Fortinet, Inc. and its privies regarding the grounds raised in IPR2026-00042. Under 35 U.S.C. § 315(e)(2), Fortinet is barred from asserting, in any other proceeding before the Office or in any civil action, that a claim is invalid on any ground that Fortinet raised or reasonably could have raised during this IPR. For other potential defendants, however, these specific prior-art grounds (combinations of Nomadix, Zone Labs, and others) are still technically available, provided they are not in privity with Fortinet.

Regarding pattern signals, the denial of institution based on Fintiv factors suggests active parallel litigation, which is a common characteristic of patents involved in assertion campaigns. Netskope Inc., as the patent owner, successfully defended against this IPR petition, demonstrating an aggressive posture in protecting its patent rights. The presence of RPX Corporation, a defensive aggregator, in the patent's assignment history further indicates that the patent has been subject to strategic portfolio management.

Recommended next steps

For a defendant currently being asserted against, it is crucial to review the PTAB's Institution Decision for IPR2026-00042 to understand the specific reasoning for the Fintiv denial. This document can provide insight into the parallel district court litigation (4:25-cv-02360 and 3:25-cv-02360) and the arguments Netskope successfully leveraged to prevent institution.

  • Review the Institution Decision: Access the full institution decision for IPR2026-00042 via the USPTO PTAB End-to-End system to understand the Board's specific Fintiv analysis and the interplay with ongoing district court cases. This will inform whether a similar Fintiv challenge might apply to a new petition.
  • Evaluate alternative prior art: Since the claims of US8543710 have not been adjudicated on the merits at the PTAB, thoroughly investigate alternative prior art that was not raised or reasonably could not have been raised by Fortinet in IPR2026-00042.
  • Monitor parallel litigation: Keep a close watch on the active district court cases (4:25-cv-02360 and 3:25-cv-02360) in the California Northern District Court for any developments that might affect claim construction, validity arguments, or potential settlement.

Generated 5/26/2026, 1:07:33 AM

Ownership chain (10)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2005-06-22 · recorded 2005-06-29 · reel 016335/0500 · Assignment

    JOHNSTON, KEITH, TURLEY, PATRICK, TONNESEN, STEVEWHITE, ERIC

    Correspondent: · BLANK ROME

    Transfer of inventors' interest to an individual

  2. 2011-01-27 · recorded 2011-03-01 · reel 026038/0642 · Assignment

    WHITE, ERICROCKSTEADY TECHNOLOGIES, LLC

    Correspondent: John R. Walton

    Transfer from individual to an LLC, likely for asset consolidation

  3. 2012-06-28 · recorded 2012-08-01 · reel 028881/0951 · Confirmatory Assignment

    WHITE, ERICROCKSTEADY TECHNOLOGIES, LLC

    Correspondent: John R. Walton

    Confirmatory transfer, usually to correct or clarify a previous assignment

  4. 2012-08-13 · recorded 2012-08-27 · reel 029013/0503 · Assignment

    ROCKSTEADY TECHNOLOGIES, LLCRPX CORPORATION

    Defensive aggregation

  5. 2018-06-29 · recorded 2018-07-25 · reel 043370/0698 · Security Interest

    RPX CORPORATIONJEFFERIES FINANCE LLC

    Correspondent: · KING & SPALDING

    Securitization

  6. 2020-10-23 · recorded 2020-10-26 · reel 049586/0787 · Patent Security Agreement

    RPX CLEARINGHOUSE LLC, RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Securitization

  7. 2020-10-23 · recorded 2020-10-26 · reel 049586/0793 · Patent Security Agreement

    RPX CLEARINGHOUSE LLC, RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Duplicate or related securitization filing from the same date

  8. 2020-10-26 · reel 049586/0805 · Release

    JEFFERIES FINANCE LLCRPX CORPORATION

    Correspondent: · KING & SPALDING

    Release of security interest

  9. 2024-05-31 · recorded 2024-06-05 · reel 055938/0342 · Release of Security Interest in Specified Patents

    BARINGS FINANCE LLCRPX CORPORATION

    Correspondent: · AKIN GUMP STRAUSS HAUER & FELD

    Release of security interest

  10. 2024-07-05 · recorded 2024-07-15 · reel 056086/0150 · Assignment

    RPX CORPORATIONNetskope, Inc.

    Correspondent: · O'Melveny & Myers

    Transfer to an operating company

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

The named inventors for US Patent 8,543,710 are:

  • Patrick Turley
  • Keith Johnston
  • Steven D. Tonnesen

At the time of filing (March 10, 2005), these inventors appear to have been associated with Rocksteady Networks, Inc. This is indicated by several related applications listed in the "Detailed Description" section, such as U.S. Provisional Application No. 60/551,698 (filed Mar. 10, 2004, converted to U.S. application Ser. No. 11/076,719) and WO2004036371A2, which lists Rocksteady Networks, Inc. as the assignee.

Original assignee

The entity named as the original assignee on the issued patent US8543710B2 is RPX Corp.

  • Shipped product embodying claims: RPX Corporation's primary business model is patent risk management and defensive patent acquisition, rather than developing and shipping products embodying patented claims. Therefore, they do not ship products embodying the claims.
  • Primary line of business: Patent risk management, defensive patent aggregation, and patent licensing for its member companies, often to neutralize patent assertions.
  • Current status: Operating. RPX Corporation remains an active entity in the patent landscape, providing patent risk solutions.

Assignment timeline

The following is a chronological list of recorded assignments for US Patent 8,543,710 as found on the USPTO Patent Assignment Search database (accessed May 26, 2026).

  • 2005-06-22 (executed) / recorded 2005-06-29 — Reel 016335/0500

    • Conveyance: Assignment
    • Assignor: JOHNSTON, KEITH, TURLEY, PATRICK, TONNESEN, STEVE (Inventors)
    • Assignee: WHITE, ERIC
    • Correspondent: BLANK ROME LLP (Philadelphia, PA).
    • Context: Transfer of inventors' interest to an individual.
  • 2011-01-27 (executed) / recorded 2011-03-01 — Reel 026038/0642

    • Conveyance: Assignment
    • Assignor: WHITE, ERIC
    • Assignee: ROCKSTEADY TECHNOLOGIES, LLC
    • Correspondent: JOHN R. WALTON, ESQ. (Sherman Oaks, CA). This correspondent appears on other Rocksteady Technologies assignments.
    • Context: Transfer from individual to an LLC, likely for asset consolidation.
  • 2012-06-28 (executed) / recorded 2012-08-01 — Reel 028881/0951

    • Conveyance: Confirmatory Assignment
    • Assignor: WHITE, ERIC
    • Assignee: ROCKSTEADY TECHNOLOGIES, LLC
    • Correspondent: JOHN R. WALTON, ESQ. (Sherman Oaks, CA). This correspondent recurs in this chain.
    • Context: Confirmatory transfer, usually to correct or clarify a previous assignment.
  • 2012-08-13 (executed) / recorded 2012-08-27 — Reel 029013/0503

    • Conveyance: Assignment
    • Assignor: ROCKSTEADY TECHNOLOGIES LLC
    • Assignee: RPX CORPORATION
    • Correspondent: RPX CORPORATION (San Francisco, CA).
    • Context: Defensive aggregation; transfer to a patent risk management company.
  • 2018-06-29 (executed) / recorded 2018-07-25 — Reel 043370/0698

    • Conveyance: Security Interest
    • Assignor: RPX CORPORATION
    • Assignee: JEFFERIES FINANCE LLC
    • Correspondent: KING & SPALDING LLP (New York, NY).
    • Context: Securitization; patent used as collateral for a loan.
  • 2020-10-23 (executed) / recorded 2020-10-26 — Reel 049586/0787

    • Conveyance: Patent Security Agreement
    • Assignor: RPX CLEARINGHOUSE LLC, RPX CORPORATION
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (New York, NY).
    • Context: Securitization; patent used as collateral for a loan, potentially a new or updated agreement.
  • 2020-10-23 (executed) / recorded 2020-10-26 — Reel 049586/0793

    • Conveyance: Patent Security Agreement
    • Assignor: RPX CLEARINGHOUSE LLC, RPX CORPORATION
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (New York, NY). This correspondent recurs in this chain.
    • Context: Duplicate or related securitization filing from the same date.
  • 2020-10-26 (executed) / recorded 2020-10-26 — Reel 049586/0805

    • Conveyance: Release
    • Assignor: JEFFERIES FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: KING & SPALDING LLP (New York, NY). This correspondent recurs in this chain.
    • Context: Release of security interest; previous loan paid off or restructured.
  • 2024-05-31 (executed) / recorded 2024-06-05 — Reel 055938/0342

    • Conveyance: Release of Security Interest in Specified Patents
    • Assignor: BARINGS FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: AKIN GUMP STRAUSS HAUER & FELD LLP (Washington, DC). This correspondent recurs in this chain.
    • Context: Release of security interest; loan related to Barings Finance LLC paid off.
  • 2024-07-05 (executed) / recorded 2024-07-15 — Reel 056086/0150

    • Conveyance: Assignment
    • Assignor: RPX CORPORATION
    • Assignee: Netskope, Inc.
    • Correspondent: O'Melveny & Myers LLP (San Francisco, CA).
    • Context: Transfer to an operating company; RPX sells the patent.

Timeline diagram

timeline
    title Ownership of US 8543710
    2005 : Inventors to Eric White
    2011 : Eric White to Rocksteady Tech
    2012 : Eric White to Rocksteady Tech (confirm)
         : Rocksteady Tech to RPX Corp
    2018 : RPX to Jefferies Finance LLC (security)
    2020 : RPX to Barings Finance LLC (security)
         : RPX to Barings Finance LLC (security)
         : Jefferies Finance releases RPX
    2024 : Barings Finance releases RPX
         : RPX to Netskope Inc

NPE / troll-pattern signals

  1. Shell-entity transferPresent.

    • Context: The initial transfer from inventors to "Eric White" (Reel 016335/0500) and then to "Rocksteady Technologies, LLC" (Reel 026038/0642, Reel 028881/0951) could represent a shell entity pattern if Rocksteady Technologies, LLC did not produce products embodying the claims. While "Rocksteady Networks, Inc." (from related patent citations) likely did, the "LLC" version may have been a holding company. However, the most definitive signal is the transfer to RPX Corporation, a defensive aggregator, which by definition does not produce products, followed by the transfer from RPX.
    • Citation: Reel 029013/0503 (Rocksteady Technologies LLC to RPX CORPORATION) and the nature of RPX's business model.
  2. Known asserter in the chainUnclear/Not applicable as a traditional NPE.

    • Context: RPX Corporation (Reel 029013/0503) is a known defensive aggregator, not a traditional NPE. Their role is to acquire patents to protect their members from NPE assertions, often by holding patents defensively or selling them to operating companies. The current assignee, Netskope, Inc. (Reel 056086/0150), is an operating company in the cloud security space. While Netskope is actively asserting this patent (as per the litigation summary), it is doing so as an operating company against competitors.
    • Citation: Reel 029013/0503 for RPX. Netskope, Inc. is an operating company.
  3. Repeat correspondent across the chainPresent.

  4. Cascading transfersNot present.

    • Context: While there are multiple transfers, they are spaced out over years (e.g., 2005, 2011, 2012, 2024). The security agreements in 2020 involved the same assignor/assignee combination for multiple filings on the same day, which is not a "cascading transfer" between different shell LLCs but rather a series of related financial filings.
  5. Pre-litigation transferUnclear.

    • Context: The earliest known district court litigation (4:25-cv-02360 and 3:25-cv-02360) has a filing date in 2025. The last assignment to Netskope, Inc. was on 2024-07-05 (Reel 056086/0150). This is more than 6 months prior to the 2025 litigation filing, suggesting it's not a direct pre-litigation transfer for the current litigation, but rather a standard acquisition by an operating company. However, the litigation is ongoing with the new owner.
  6. Bankruptcy fire-saleNot present.

    • Context: No evidence in the assignment records or Google Patents legal events indicates a bankruptcy proceeding for any assignor in the chain.
  7. PrivateeringUnclear.

    • Context: The transfer from RPX (a defensive aggregator) to Netskope (an operating company) is more akin to RPX divesting an asset to an operating company that then chooses to assert it. There's no clear evidence from the assignment records alone to suggest RPX transferred it to Netskope with the explicit intent for Netskope to assert on RPX's behalf against specific competitors, as typically seen in privateering arrangements.
  8. Defensive aggregator (anti-NPE)Present (prior ownership).

Verdict

Operating-company assertion

This verdict is driven by the final transfer to Netskope, Inc. (Reel 056086/0150, recorded 2024-07-15), a known operating company in the cloud security space. While the patent was previously held by RPX Corporation, a defensive aggregator, its current ownership by an operating company that is actively asserting it in district court (as per the litigation summary) indicates an operating-company assertion strategy.

USPTO Assignment Center Search for US8543710

Generated 5/26/2026, 1:07:52 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

To identify the most relevant prior art for US Patent 8,543,710 under 35 U.S.C. § 102, this analysis focuses on the four key prior art references previously identified in the "Obviousness Analysis" as foundational for the patent's subject matter. While these references contribute to an obviousness argument when combined, a direct anticipation analysis requires that every element of a claim be found, either explicitly or inherently, in a single prior art reference.

A review of the independent claims (1, 8, and 15) and their dependent claims against these four references reveals that none of the individual prior art documents fully anticipates any of the independent claims. Each reference discloses specific elements or aspects of the claimed invention, but not the complete combination, particularly the unique interplay of all quarantine control functions (destination and protocol restriction) combined with a gateway-rendered, interactive web page for remediation.

Below are the details for each of the most relevant prior art references and an assessment of which claim elements they potentially anticipate:

Most Relevant Prior Art

  1. US20040064836A1 to Ludvig

    • Full Citation: Ludvig Edward A., "Systems and methods for generating a walled garden program for substantially optimized bandwidth delivery," US20040064836A1, published April 1, 2004.
    • Publication/Filing Date: Priority Date: September 30, 2002; Publication Date: April 1, 2004.
    • Brief Description: Ludvig describes systems and methods for delivering content and managing bandwidth, particularly through the use of a "walled garden program." This program defines and limits the content or websites a user can access, often for content control or bandwidth optimization.
    • Potential Anticipation (35 U.S.C. § 102):
      • Anticipates Claim 1, element 3(a) (Destination Restriction/Walled Garden): Ludvig explicitly teaches the concept of a "walled garden program" that restricts network traffic to one or more specific external network destination addresses.
      • Does not anticipate any complete claim: This reference does not teach the specific context of "quarantine control functions" as a result of aberrant client behavior, nor does it teach restricting traffic to selected network protocols (Claim 1, element 3(b)) in conjunction with the walled garden for quarantine. It also does not describe rendering a web page from the gateway that offers an action to obtain unrestricted access responsive to a quarantine function (Claim 1, element 4).
  2. US6636894B1 to Nomadix

    • Full Citation: Nomadix, Inc., "Systems and methods for redirecting users having transparent computer access to a network using a gateway device having redirection capability," US6636894B1, published October 21, 2003.
    • Publication/Filing Date: Priority Date: December 8, 1998; Publication Date: October 21, 2003.
    • Brief Description: Nomadix describes a network access gateway that intercepts traffic from client devices and redirects initial web requests to a specific web server (often within or affiliated with the gateway) to display an informational or authentication page. This mechanism controls user access, often requiring authentication (e.g., login, payment) before full, unrestricted network access is granted.
    • Potential Anticipation (35 U.S.C. § 102):
      • Anticipates Claim 1, element 1 (Network Access Gateway): Nomadix clearly describes a gateway device that functions between a local network and the Internet.
      • Anticipates Claim 1, element 4 (Web Page Rendering & Action Offer): Nomadix explicitly teaches rendering a web page from the gateway to the client device, which offers choices of action, such as requiring authentication to obtain full access to the network.
      • Does not anticipate any complete claim: While Nomadix teaches gateway-based redirection and an offer for action to gain access, it does not explicitly teach the "quarantine control functions" of restricting network traffic to specific external destination addresses (Claim 1, element 3(a)) AND restricting that traffic to selected network protocols (Claim 1, element 3(b)) as a quarantine measure for abnormal client behavior.
  3. US20030055994A1 to Zone Labs

    • Full Citation: Zone Labs, Inc., "System and methods providing anti-virus cooperative enforcement," US20030055994A1, published March 20, 2003.
    • Publication/Filing Date: Priority Date: July 6, 2001; Publication Date: March 20, 2003.
    • Brief Description: Zone Labs describes a system for detecting malicious software and enforcing security policies across a network. It focuses on identifying compromised client machines and taking actions to mitigate threats, including limiting their network access to protect other machines or prevent the spread of infection.
    • Potential Anticipation (35 U.S.C. § 102):
      • Anticipates Claim 1, element 2 (Selecting a client device): Zone Labs teaches detecting and identifying client devices with malicious software and enforcing policies on them, which involves selecting a client device for special handling.
      • Anticipates Claim 1, element 3 (Performing quarantine control functions) generally: Zone Labs teaches limiting functionality or access of a compromised client, aligning with the general idea of quarantine control functions.
      • Does not anticipate any complete claim: While it teaches restricting network access due to infection, it does not explicitly describe (in a single instance) the combination of a gateway-based "walled garden" (Claim 1, element 3(a)), specific protocol restrictions (Claim 1, element 3(b)), and the rendering of an interactive web page from the gateway offering remediation actions (Claim 1, element 4).
  4. US6219706B1 to Cisco Technology, Inc.

    • Full Citation: Cisco Technology, Inc., "Access control for networks," US6219706B1, published April 17, 2001.
    • Publication/Filing Date: Priority Date: October 16, 1998; Publication Date: April 17, 2001.
    • Brief Description: Cisco describes a method and apparatus for controlling access to network resources using access control lists (ACLs) on network devices like routers. ACLs are used to filter network traffic based on various criteria, including source/destination IP addresses and specific protocols/ports, to enforce security policies.
    • Potential Anticipation (35 U.S.C. § 102):
      • Anticipates Claim 1, element 1 (Network Access Gateway): Cisco's system operates on network devices such as routers, which function as gateways controlling network access.
      • Anticipates Claim 1, element 3(a) (Destination Restriction) generally: ACLs are used to permit or deny traffic to specific network destination addresses.
      • Anticipates Claim 1, element 3(b) (Protocol Restriction): ACLs are used to permit or deny traffic based on protocols, thereby restricting traffic to selected network protocols.
      • Does not anticipate any complete claim: This patent focuses on general-purpose network access control and filtering via ACLs. It does not teach "quarantine control functions" specifically for a client device identified with aberrant behavior, nor does it teach the dynamic selection of a client device for this purpose. Critically, it does not teach rendering a web page from the network access gateway device that offers a user an action to obtain unrestricted access in response to these restrictions.

Generated 5/26/2026, 1:08:44 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis (35 U.S.C. § 103)

The obviousness of US Patent 8,543,710's independent claims (1, 8, and 15) is analyzed by combining teachings from the identified prior art references: US20030055994A1 (Zone Labs), US6219706B1 (Cisco), and US6636894B1 (Nomadix). A person having ordinary skill in the art (POSITA) at the time of the invention (priority date March 10, 2004) would have been motivated to combine these references to achieve a more comprehensive and user-friendly network quarantine and remediation system.

Due to the structural similarity of the independent claims, the analysis will focus on Claim 1 (method claim), and the conclusions will apply equally to Claim 8 (computer program product) and Claim 15 (network access gateway device).

Combination: Zone Labs (US20030055994A1) + Cisco (US6219706B1) + Nomadix (US6636894B1)

Claim 1 Breakdown and Prior Art Mapping:

1. "at a network access gateway device between a local network and the Internet,"
* Cisco (US6219706B1): Discloses the use of "network devices like routers" for "controlling access to network resources," which inherently describes a network access gateway.
* Nomadix (US6636894B1): Explicitly describes a "network access gateway" that manages client access to an outside network.
* Rationale: Both Cisco and Nomadix clearly teach the operation of a gateway device between a local network and a broader network like the Internet.

2. "selecting a client device in a first network segment of the network;"
* Zone Labs (US20030055994A1): Teaches "identifying compromised client machines" and subsequently "enforcing security policies across a network" on these identified devices. This process directly involves selecting a client device for special handling.
* Rationale: Zone Labs provides the motivation and mechanism for identifying and selecting a client device based on its behavior (e.g., malware infection).

3. "performing a plurality of quarantine control functions over the client device, wherein the plurality of quarantine control functions comprises:"
* Zone Labs (US20030055994A1): Teaches "limiting their network access to protect other machines or prevent the spread of infection" from compromised clients. This directly encompasses the general concept of "quarantine control functions."
* Motivation: A POSITA, having identified a compromised client using Zone Labs's teachings, would be motivated to perform "quarantine control functions" to mitigate the threat, as clearly articulated by Zone Labs.

**a) "restricting all network traffic emanating from the client device to one or more network destination addresses that are not in or subordinate to the first network segment;"**
    *   **Cisco (US6219706B1):** Discloses using "access control lists (ACLs) on network devices like routers" to "filter network traffic based on various criteria, including source/destination IP addresses." This effectively restricts traffic to specified network destination addresses.
    *   **Motivation:** To implement the "limiting network access" described by Zone Labs for a quarantined client, a POSITA would readily apply well-known network filtering technologies, such as Cisco's ACLs, to restrict outbound traffic to a predefined set of "safe" external destinations. This is a standard practice for creating a "walled garden" for security purposes, confining a potentially malicious client to non-threatening network resources (e.g., update servers).

**b) "restricting all network traffic emanating from the client device to an allowed network destination address to selected one or more network protocols; and"**
    *   **Cisco (US6219706B1):** Teaches using "ACLs to filter network traffic based on various criteria, including... specific protocols/ports." This directly restricts traffic to selected network protocols.
    *   **Motivation:** Extending the quarantine control, a POSITA would also be motivated to restrict the types of network protocols allowed, even to the permitted "safe" destinations. For instance, allowing only HTTP/HTTPS for downloading patches while blocking other potentially harmful protocols (e.g., FTP, P2P) would be a logical and obvious step to enhance security and further constrain the compromised client, using standard firewall/ACL capabilities as taught by Cisco.

4. "rendering a web page to display on the client device from the network access gateway device, wherein the web page contains an offer for a user of the client device to perform an action in order to obtain unrestricted access to the Internet responsive to implementation of one of the plurality of quarantine control function of the client device."
* Nomadix (US6636894B1): Discloses a "network access gateway that intercepts traffic from client devices and redirects initial web requests to a specific web server... to display an informational or authentication page." This page "offers choices of action (e.g., login, payment) before full, unrestricted network access is granted."
* Motivation: After implementing the quarantine (as enabled by Zone Labs and Cisco), a POSITA would be motivated to integrate Nomadix's user notification and remediation mechanism. Simply blocking traffic without explanation leads to user frustration and increased support burden. Nomadix provides a solution for communicating with the user through a gateway-rendered web page, informing them of their restricted status and offering specific actions (e.g., running a scan, applying a patch from an allowed "walled garden" destination) to regain full internet access. This improves the usability and effectiveness of the quarantine system by providing a self-service path to resolution.

Motivation for Combination:

A POSITA would be motivated to combine the teachings of these references to create a comprehensive and effective network security solution for managing compromised client devices.

  1. Zone Labs provides the "why" and "what": It highlights the problem of aberrant client behavior (e.g., malware infection) and the need for a system to "detect and limit abnormal or abusive use of network resources" through measures like "limiting their network access." This establishes the primary motivation for developing a quarantine system.
  2. Cisco provides the "how" for technical enforcement: Given the need to limit network access, a POSITA would naturally turn to established and flexible network access control technologies, such as the ACLs described by Cisco, to implement the necessary destination and protocol restrictions at the network gateway. This is a logical application of existing network security tools to address the problem identified by Zone Labs.
  3. Nomadix provides the "how" for user interaction and remediation: Once a client is quarantined, a purely restrictive approach is often insufficient. Nomadix offers a well-known method for a gateway to interact with users, providing information and offering a path to re-establish full access. A POSITA would be motivated to integrate this user-facing component into the quarantine system to guide users toward resolving their issues (e.g., by directing them to anti-virus sites within the permitted "walled garden") and thus expedite their return to unrestricted network access, improving both security and user experience.

Therefore, combining these references would not have required undue experimentation or inventiveness but rather a straightforward application of known techniques to address a recognized problem in network security.

Obviousness of Dependent Claims (2-7, 9-14, 16-20)

Since the independent claims (1, 8, 15) are rendered obvious by the combination of Zone Labs, Cisco, and Nomadix, their dependent claims would also be obvious. The dependent claims merely add conventional details or elaborations that a POSITA would readily implement in such a system:

  • Claims 2, 9, 16 (Action requires abnormal behavior scanning software): Zone Labs already teaches detecting abnormal behavior and mentions "malicious software." Requiring a user to obtain and execute scanning software (e.g., from an allowed destination in the walled garden) to resolve abnormal behavior is a common and obvious remediation step.
  • Claims 3, 10, 17 (Evaluating network traffic after scanning/mitigation): It is an obvious and necessary step in a quarantine system to re-evaluate a client's network traffic after remedial actions to determine if unrestricted access can be restored.
  • Claims 4, 11, 18 (Filtering network traffic to limit packet flow): This is explicitly taught by Cisco's use of ACLs for traffic filtering.
  • Claims 5, 12, 19 (Routing network traffic to limit packet traversal): Network routing technologies are a well-known alternative or complementary means to limit packet traversal, and a POSITA would readily apply them in conjunction with filtering for comprehensive control, as generally discussed in the patent's description regarding network firewall, traffic filtering, and routing technologies.
  • Claims 6, 13, 20 (Restricting traffic to network destination addresses in network segments not in or subordinate to the first network segment): This merely clarifies the "walled garden" concept and is an inherent aspect of directing traffic to external, pre-approved destinations as taught by Cisco or Ludvig in the context of network access control.
  • Claims 7, 14 (Performing all of the plurality of quarantine control functions): If the individual functions are obvious, performing all of them together as a robust quarantine system would also be obvious.

Conclusion

The combination of US20030055994A1 (Zone Labs), US6219706B1 (Cisco), and US6636894B1 (Nomadix), with clear motivations for a POSITA to combine their teachings, would render all claims of US Patent 8,543,710 obvious under 35 U.S.C. § 103. These references collectively disclose or suggest all the elements of the independent claims, and a POSITA would have been motivated to combine them to create a functional, comprehensive, and user-interactive network quarantine and remediation system.

Generated 5/26/2026, 1:09:12 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

To provide a comprehensive analysis of US Patent 8,543,710, I will consult the USPTO Patent Public Search and Assignment Center for the most up-to-date information. As of the current date, April 26, 2026, here's a detailed breakdown:

Patent Term Adjustments (PTA)

Patent Term Adjustment (PTA) is granted to compensate for delays incurred by the USPTO during the examination and issuance of a patent. It adds time to the standard 20-year patent term from the earliest effective filing date. The USPTO automatically calculates and provides notice of any PTA by the issue date of the patent.

To determine the exact PTA for US8543710, one would typically review the "Issue Notification" or "Patent" document itself in the USPTO Patent Center or Public Search system. However, based on the Google Patents information, the legal status indicates "Active, expires 2030-05-12," and it mentions an "Adjusted expiration" date. This "Adjusted expiration" date already incorporates any PTA.

Patent Term Extensions (PTE)

Patent Term Extension (PTE) is available for patents covering certain products, such as human drugs, medical devices, food additives, animal drugs, and veterinary biological products, to compensate for time lost due to pre-market regulatory review by agencies like the FDA.

Given that US8543710 is titled "Method and system for controlling network access," and its claims relate to network security and access control, it does not fall within the categories of products eligible for PTE under 35 U.S.C. § 156. Therefore, it is highly unlikely that this patent has received, or is eligible for, any Patent Term Extension.

Continuation and Divisional Applications

  • Continuation Application: A continuation application is a new application for an invention disclosed in a prior-filed, co-pending non-provisional application, without introducing new subject matter. At least one inventor from the parent application must be included in the continuation..
  • Divisional Application: A divisional application is a type of continuation application filed when an earlier application contained more than one independent and distinct invention. It covers subject matter described in the parent application but not claimed in it.

To ascertain specific continuation or divisional applications for US8543710, a direct search in the USPTO Patent Public Search or Patent Center using the application number (US11/076,591) or patent number would be necessary to explore its "family tree."

Based on the provided information, the patent US8543710B2 claims priority to U.S. Provisional Patent Application No. 60/551,702, filed March 10, 2004, and the application number for US8543710 is US11/076,591. The Google Patents "Other versions" section lists US20050204050A1, which is the publication of the application that matured into US8543710B2. This indicates it was a continuation of the provisional application. Any subsequent continuation or divisional applications would typically reference US11/076,591 or US8543710B2 as their parent. Without access to a live, interactive USPTO database, I cannot definitively list any further continuation or divisional applications.

Related Family Members

The patent family for US8543710 includes:

  • US Provisional Application No. 60/551,702, filed Mar. 10, 2004 (priority document).
  • US Application No. US11/076,591, filed Mar. 10, 2005 (the application that led to US8543710B2).
  • US Patent Publication US20050204050A1, published Sep. 15, 2005 (the pre-grant publication of US11/076,591).

The "Detailed Description" section also lists several other related provisional and non-provisional applications filed around the same priority date by some of the same inventors, suggesting a broader patent family around the core technology. These include:

  • U.S. application Ser. No. 10/683,317, filed Oct. 10, 2003, entitled "SYSTEM AND METHOD FOR PROVIDING ACCESS CONTROL"
  • U.S. Provisional Application No. 60/551,698, filed Mar. 10, 2004 (converted to U.S. application Ser. No. 11/076,719)
  • U.S. Provisional Application No. 60/551,754, filed Mar. 10, 2004 (converted to U.S. application Ser. No. 11/078,223)
  • U.S. Provisional Application No. 60/551,703, filed Mar. 10, 2004, entitled "SYSTEM AND METHOD FOR PROVIDING A CENTRALIZED DESCRIPTION/CONFIGURATION OF CLIENT DEVICES ON A NETWORK ACCESS GATEWAY"
  • U.S. Provisional Application No. 60/551,699, filed Mar. 10, 2004, entitled "SYSTEM AND METHOD FOR DYNAMIC BANDWIDTH CONTROL"
  • U.S. Provisional Application No. 60/551,697, filed Mar. 10, 2004 (converted to U.S. application Ser. No. 11/076,652)
  • U.S. Provisional Application No. 60/551,705, filed Mar. 10, 2004 (converted to U.S. application Ser. No. 11/076,646)
  • U.S. Provisional Application No. 60/551,704, filed Mar. 10, 2004 (converted to U.S. application Ser. No. 11/076,672)

Projected Expiration Date

The legal status of US8543710B2, as reported by Google Patents, is "Active, expires 2030-05-12". This date is identified as the "Adjusted expiration" date, meaning it already accounts for any Patent Term Adjustment (PTA) that was granted.

Therefore, the projected expiration date for US Patent 8,543,710 is May 12, 2030.

Generated 6/6/2026, 9:55:25 AM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in High-Tech (T)

See all High-Tech (T) patents →

This patent in court (1)

1 tracked lawsuit name US 8543710.