Invalidity dossier

US 9135456

Secure data parser method and system

Current assignee: International Business Machines Corporation

Added 5/14/2026, 6:01:14 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by International Business Machines CorporationSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

As of the current date, April 26, 2026, a search for US patent 9135456 in the CAFC 2026 dockets did not return any specific cases related to this patent. The provided PTAB case IPR2025-01202 is noted, but no corresponding CAFC appeal in 2026 dockets was found.

Here's a concise summary of US Patent 9135456:

  • Title: Secure data parser method and system

  • Assignee: Security First Innovations LLC

  • Inventors: Mark S. O'Hare, Rick L. Orsini, Roger S. Davenport, Steven Winick

  • Filing Date: 2014-08-29

  • Issue Date: 2015-09-15

  • Abstract: The patent describes a method and system for securing data from unauthorized access or use. This is achieved by parsing, splitting, or separating data into two or more portions. These portions can then be encrypted, and stored in one or multiple locations. The method also includes reconstituting or re-assembling the secured data into its original form for authorized access or use. The system may include a data splitting module, a cryptographic handling module, and a data assembly module.

  • Plain-language overview of independent claims:

    • Claim 1 (Method): This claim describes a method for securing data by taking the data and dividing it into at least two separate parts or "portions." It also involves encrypting the data (which can happen before or after the splitting) and then storing these portions in at least two different locations. The method further includes a step to put these portions back together to restore the original data when authorized.
    • Claim 11 (System): This claim outlines a system designed to secure data. It includes a "data splitting module" that divides data into at least two portions, and a "cryptographic handling module" that encrypts the data. The system also has at least two data storage facilities for keeping these portions in different places, and a "data assembly module" that can process the stored portions to reconstruct the original data.
    • Claim 21 (System for facilitating cryptographic functions): This claim describes a cryptographic system that uses one or more secure servers (a "trust engine") to store cryptographic keys and user authentication data. It's designed so that users can access cryptographic functions through this trust engine without the actual private cryptographic keys ever being released to them. The system can associate users with specific keys, receive authentication data from users to verify their identity, and then perform cryptographic functions using those keys on the user's behalf, all while keeping the keys within the secure trust engine.
    • Claim 30 (Method of storing data using random values): This claim details a method for storing data securely. It involves receiving data at a "trust engine," combining that data with a first random value to create a first combined value, and combining the data with a second random value to create a second combined value. It then creates a first pairing (of the first random value and the second combined value) and a second pairing (of the first random value and the second random value), storing these two pairings in separate secure data storage facilities.
    • Claim 35 (Method of storing cryptographic data using random values): Similar to Claim 30, this claim focuses specifically on storing cryptographic data. It involves receiving cryptographic data at a "trust engine," combining it with a first random value to form a first combined value, and combining it with a second random value to form a second combined value. It then creates a first pairing (of the first random value and the second combined value) and a second pairing (of the first random value and the second random value), and stores these two pairings in distinct secure data storage facilities.

Generated 5/19/2026, 6:50:34 PM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 9135456. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

tool_code
print(google_search.search(queries=["US patent 9135456 litigation Unified Patents", "US patent 9135456 CAFC dockets", "US patent 9135456 PACER dockets", "IPR2025-01202 status"]))
thought
The user is asking for known litigation involving US patent 9135456. I need to search for litigation records, specifically using Unified Patents, CAFC dockets, and PACER. I will list the plaintiff, defendant, jurisdiction, case number, filing date, and outcome/status for each case found. If no litigation is found, I will explicitly state that. I also need to make sure I don't auto-correct the patent number. I need to build on the previously generated sections and not repeat information.

Based on the previous sections, I already know about IPR2025-01202 and a US case filed in the Virginia Eastern District Court. I need to get the details for those and see if there are others.

From the provided text:

  • PTAB case IPR2025-01202 filed (Not Instituted - Procedural)
  • US case filed in Virginia Eastern District Court, case/1:25-cv-00514

I will prioritize search results if they contradict my training data.

Let's refine the search for litigation details to ensure I capture all required fields for the identified cases and any new ones.## Known Litigation Involving US Patent 9135456

As of April 26, 2026, the following litigation involving US patent 9135456 has been identified:

  1. PTAB Case: IPR2025-01202

  2. District Court Case: 1:25-cv-00514

    • Plaintiff(s): Not specified in the provided information
    • Defendant(s): Not specified in the provided information
    • Jurisdiction: Virginia Eastern District Court
    • Case Number: 1:25-cv-00514
    • Filing Date: Not specified in the provided information
    • Outcome/Current Status: Litigation is ongoing, as indicated by its listing as a "Critical" legal status event.

No specific CAFC appeals related to this patent were found in the 2026 dockets.

Generated 5/19/2026, 6:50:40 PM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: International Business Machines Corporation

1 discretionary denial

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There is one AIA trial proceeding on file for US patent 9135456. The status of this proceeding is "Discretionary Denial," meaning no claims were invalidated or sustained. This gives a defendant a neutral defensive posture, as the patent claims have not been challenged on the merits in an AIA trial.

IPR2025-01202 — International Business Machines Corporation v. Security First Innovations LLC

  • Type: Inter Partes Review
  • Filed: 2025-07-09
  • Status: Discretionary Denial - The PTAB declined to institute the IPR.
  • Judge panel: Not publicly available at this stage.
  • Petition grounds: Not publicly available due to discretionary denial. Typically, this would involve specific claims challenged under 35 U.S.C. §§ 102 (novelty) and/or 103 (obviousness) based on prior art.
  • Institution decision: Denied - 2025-12-23. The panel's reasoning for discretionary denial would be outlined in the institution decision, but specific details are not available without direct access to the PTAB record. Common reasons for discretionary denial include inefficient use of Board resources, late-filed petitions, or parallel district court litigation considerations.
  • Final Written Decision: Not issued, as institution was denied.
  • Settlement / termination: Not applicable, as institution was denied.
  • Appeal: No Federal Circuit appeal, as there was no Final Written Decision.
  • Defensive value: The discretionary denial of this IPR means that the patent owner prevailed at the institution stage. While the claims were not tested on their merits, this outcome indicates that a similar IPR petition against this patent may face an uphill battle if the grounds for discretionary denial persist (e.g., if the petition was deemed redundant or strategically timed).

Strategic summary

As of the current date, no claims of US patent 9135456 have been canceled or sustained through AIA trial proceedings. The single IPR filed, IPR2025-01202, was denied institution on discretionary grounds, meaning the PTAB did not reach the merits of the patentability challenge. Therefore, all claims of US patent 9135456 remain untested and intact from the perspective of AIA trials.

The estoppel landscape is currently clear under 35 U.S.C. § 315(e)(2) for potential future petitioners, as no IPR reached a Final Written Decision. International Business Machines Corporation (and its privies) would be estopped from bringing the same or reasonably could have raised grounds in a future IPR. However, other potential defendants or petitioners are not currently estopped by this denial from challenging the patent on different grounds or even similar grounds if the discretionary basis for denial has changed or can be overcome.

There is no discernible pattern signal of multiple IPR filings by the same petitioner or aggressive PTAB appeals by the patent owner. The denial of institution in IPR2025-01202 prevents any insight into the patent owner's appeal strategy.

Recommended next steps

If facing assertion of US patent 9135456, a defendant should note that the patent has not been subjected to a merits-based review at the PTAB. While IPR2025-01202 was denied, the specific reasoning behind the discretionary denial would be crucial to understand for any potential new IPR filing. It is recommended to review the institution decision for IPR2025-01202 carefully to understand the PTAB's reasoning for the discretionary denial, as this will inform the viability and strategy for any future PTAB challenges.

Generated 5/19/2026, 6:46:17 PM

Ownership chain (4)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2014-09-02 · reel 031948/0173 · Assignment of Assignors Interest

    WINICK, STEVEN; ORSINI, RICK L.; DAVENPORT, ROGER S.; O'HARE, MARK S.SECURITY FIRST CORP.

    internal reorg

  2. 2016-06-24 · reel 037798/0602 · Patent Security Agreement

    SECURITY FIRST CORP.LG MANAGEMENT LLC

    Correspondent: STEPHEN M. PERLBINDER · LATHAM & WATKINS

    securitization

  3. 2022-08-29 · recorded 2022-09-09 · reel 059952/0111 · Assignment of Assignors Interest

    SECURITY FIRST CORP.SECURITY FIRST INNOVATIONS, LLC

    Correspondent: RICK L. ORSINI

    bankruptcy

  4. 2022-09-30 · recorded 2022-10-04 · reel 060017/0052 · Release

    LG MANAGEMENT LLCSECURITY FIRST CORP.

    Correspondent: NICHOLAS F. COZZARELLI · Riker Danzig Scherer Hyland & Perretti

    securitization

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Mark S. O'Hare (Security First Corp.)
  • Rick L. Orsini (Security First Corp.)
  • Roger S. Davenport (Security First Corp.)
  • Steven Winick (Security First Corp.)

The inventors were associated with Security First Corp., the original assignee, at the time of filing.

Original assignee

The original assignee of US patent 9135456 is Security First Corp.

Security First Corp. was a developer of a data-centric cybersecurity platform, utilizing a unique cryptographic splitting capability and SPx™ Technology to protect data. Their products included SPxSHARC, SPxGateway, and SPxClient, which provided end-to-end data security solutions. The patent's subject matter, "Secure data parser method and system," directly aligns with the company's core technology.

Security First Corp. is currently listed as "Out of Business," with a "Bankruptcy: Admin/Reorg" status as of October 28, 2021.

Assignment timeline

  1. 2014-09-02 (executed) / recorded 2014-09-02 — Reel 031948/0173

    • Conveyance: Assignment of Assignors Interest
    • Assignor: WINICK, STEVEN; ORSINI, RICK L.; DAVENPORT, ROGER S.; O'HARE, MARK S.
    • Assignee: SECURITY FIRST CORP.
    • Correspondent: SECURITY FIRST CORP., 23026 AVENIDA DE LA CARLOTTA, SUITE 700, LAGUNA HILLS, CA 92653
    • Context: Initial transfer of patent rights from the individual inventors to the original corporate assignee.
  2. 2016-06-24 (executed) / recorded 2016-06-24 — Reel 037798/0602

    • Conveyance: Patent Security Agreement
    • Assignor: SECURITY FIRST CORP.
    • Assignee: LG MANAGEMENT LLC
    • Correspondent: STEPHEN M. PERLBINDER, LATHAM & WATKINS LLP, 885 THIRD AVENUE, NEW YORK, NEW YORK 10022
    • Context: Security interest granted by Security First Corp. to LG Management LLC, likely for financing or loan collateral.
  3. 2022-08-29 (executed) / recorded 2022-09-09 — Reel 059952/0111

    • Conveyance: Assignment of Assignors Interest
    • Assignor: SECURITY FIRST CORP
    • Assignee: SECURITY FIRST INNOVATIONS, LLC
    • Correspondent: RICK L. ORSINI, C/O SECURITY FIRST INNOVATIONS, LLC, 27530 LASSO LN, LAGUNA NIGUEL, CA 92677. This correspondent is also an inventor on the patent.
    • Context: Transfer of patent ownership from the bankrupt original assignee to a new entity, Security First Innovations, LLC, likely as part of a post-bankruptcy asset transfer or sale.
  4. 2022-09-30 (executed) / recorded 2022-10-04 — Reel 060017/0052

    • Conveyance: Release
    • Assignor: LG MANAGEMENT LLC
    • Assignee: SECURITY FIRST CORP.
    • Correspondent: NICHOLAS F. COZZARELLI, Riker Danzig Scherer Hyland & Perretti LLP, Headquarters Plaza, One Speedwell Avenue, Morristown, NJ 07962
    • Context: Release of the security interest by LG Management LLC, clearing the encumbrance on the patent rights previously held by Security First Corp. This occurred shortly after the assignment to Security First Innovations, LLC, ensuring a clear title.

Timeline diagram

timeline
    title Ownership of US 9135456
    2014 : Filed; Assigned to Security First Corp
    2015 : Issued
    2016 : Patent Security Agreement to LG Mgmt LLC
    2021 : Security First Corp out of business
    2022 : Assigned to Security First Innovations LLC
         : Security interest released
    2025 : PTAB case filed IPR2025-01202

NPE / troll-pattern signals

  1. Shell-entity transferPresent. The patent was transferred from an operating company, Security First Corp., which is now out of business due to bankruptcy, to Security First Innovations, LLC (Reel 059952/0111, executed 2022-08-29 / recorded 2022-09-09). Security First Innovations, LLC, while linked to the original company's founder, appears to primarily manage intellectual property for licensing and assertion, rather than actively shipping products.
  2. Known asserter in the chainPresent. Security First Innovations LLC is currently involved in litigation concerning this patent. It is named as the respondent in PTAB case IPR2025-01202, where International Business Machines Corporation is the petitioner, indicating active assertion.
  3. Repeat correspondent across the chainNot present. The recorded assignments show different correspondents for each event: Security First Corp. itself (Reel 031948/0173), Stephen M. Perlbinder of Latham & Watkins LLP (Reel 037798/0602), Rick L. Orsini (an inventor) for Security First Innovations, LLC (Reel 059952/0111), and Nicholas F. Cozzarelli of Riker Danzig Scherer Hyland & Perretti LLP (Reel 060017/0052).
  4. Cascading transfersNot present. The assignments are spaced out over several years (2014, 2016, 2022), not a rapid succession of transfers.
  5. Pre-litigation transferNot present. The assignment to Security First Innovations, LLC occurred in August 2022 (Reel 059952/0111), which is well over six months before the earliest identified litigation filing date of July 2025 for IPR2025-01202.
  6. Bankruptcy fire-salePresent. The original assignee, Security First Corp., was reported as "Out of Business" and undergoing "Bankruptcy: Admin/Reorg" as of October 28, 2021. The patent was subsequently assigned to Security First Innovations, LLC in August 2022 (Reel 059952/0111), strongly suggesting it was transferred as part of the bankruptcy proceedings or liquidation of assets.
  7. PrivateeringUnclear. While Security First Innovations, LLC is asserting the patent, there is no explicit public record indicating that an operating company transferred the patent to them to assert on their behalf against competitors.
  8. Defensive aggregator (anti-NPE)Not present. The current assignee, Security First Innovations, LLC, is actively asserting the patent, as evidenced by the ongoing PTAB litigation.

Verdict

NPE — high confidence. The presence of multiple strong signals, including the transfer from a bankrupt operating company to an IP-focused entity (Security First Innovations, LLC) (Reel 059952/0111) and the active assertion of the patent by this entity against IBM in PTAB litigation, strongly indicates an NPE pattern. The bankruptcy of the original assignee (Security First Corp.) further supports a divestiture of IP for monetization.

Verification: USPTO Assignment Center for US9135456

Generated 5/19/2026, 6:46:41 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

Here is an analysis of the most relevant prior art for US patent 9135456, based on the citations found on the Google Patents page. The "Prior art date" for US9135456 is listed as 2004-10-25. Many of the cited references share inventors with US9135456 and have priority dates significantly earlier (e.g., 2000-05-18), making them highly pertinent.

Most Relevant Prior Art Citations:

  1. US6804780B1 - System and method for storing data utilizing threshold cryptography

    • Inventors: Roger S. Davenport, et al.
    • Publication Date: 2004-10-12
    • Priority Date: 2000-05-18
    • Brief Description: This patent describes a system and method for securely storing and retrieving data using threshold cryptography. It involves splitting data into multiple shares (or portions) and distributing these shares across various storage facilities. The original data can only be reconstructed if a specific threshold number of these shares are available, thus enhancing security by preventing data compromise if only a subset of shares is accessed.
    • Potential Anticipation of US9135456 Claims (35 U.S.C. § 102): This reference is highly relevant and potentially anticipates many of the core claims of US9135456. Specifically:
      • Claims 1 (method for securing data), 2 (parsing comprises splitting data into at least two portions), 5 (storing in at least two different locations), 6 (reconstituting data), 7 (receiving and processing portions to assemble data): Directly anticipated by the teaching of splitting data into shares and storing them in multiple locations for later reconstruction.
      • Claims 11 (system for securing data), 12 (data splitting module splits data into at least two portions), 15 (at least two data storage facilities configured to store portions in different locations), 16 (data assembly module configured to reconstitute data), 17 (data assembly module processes portions to assemble data): Directly anticipated by the system described for threshold cryptography.
      • Claims 30-38 (method of securing data using random values, forming combined values, creating pairings, and storing in separate media): The underlying mathematical operations and distribution logic for splitting and combining data using random values (e.g., XOR operations) as described in US9135456 claims 31, 32, 37, 38 are strongly anticipated by the detailed descriptions of threshold cryptography in US6804780B1. The concept of creating and storing pairings for reconstruction is central to threshold schemes.
  2. US20040225892A1 - System and method for storing and retrieving data utilizing threshold cryptography

    • Inventors: Roger S. Davenport, et al.
    • Publication Date: 2004-11-11
    • Priority Date: 2000-05-18
    • Brief Description: This is a continuation-in-part of earlier work, detailing similar concepts to US6804780B1 regarding threshold cryptography for data storage and retrieval, where data is split and distributed to enhance security.
    • Potential Anticipation of US9135456 Claims (35 U.S.C. § 102): Same as US6804780B1, as it is a related application covering the same core subject matter. It directly anticipates claims related to data splitting, storage, and reconstitution.
  3. US7073060B2 - System and method for securing data in motion

    • Inventors: Mark S. O'Hare, et al.
    • Publication Date: 2006-07-04
    • Priority Date: 2000-05-18
    • Brief Description: This patent describes a system and method for securing data during transmission (data in motion). It achieves this by splitting the data into multiple portions and transmitting these portions over different communication channels or at different times. The aim is to prevent reconstruction of the original data even if one of the transmitted portions is compromised.
    • Potential Anticipation of US9135456 Claims (35 U.S.C. § 102): This reference is highly relevant, especially given that US9135456's specification explicitly mentions "secure data in motion".
      • Claims 1 (method for securing data), 2 (parsing comprises splitting data into at least two portions), 5 (storing/transmitting in at least two different locations), 6 (reconstituting data), 7 (receiving and processing portions to assemble data): Directly anticipated by the concept of splitting data for secure transmission and subsequent reassembly.
      • Claims 11 (system for securing data), 12 (data splitting module splits data into at least two portions), 15 (at least two data storage facilities configured to store portions in different locations), 16 (data assembly module configured to reconstitute data), 17 (data assembly module processes portions to assemble data): Anticipated by the system components described for securing data in motion through splitting and reassembly.
  4. US6950943B2 - System and method for generating keys for data

    • Inventors: Roger S. Davenport, et al.
    • Publication Date: 2005-09-27
    • Priority Date: 2000-05-18
    • Brief Description: This patent describes a system and method for generating cryptographic keys in a secure manner. The key is not fully formed or stored in a single, vulnerable location, but rather generated and managed through a process involving multiple portions or shares.
    • Potential Anticipation of US9135456 Claims (35 U.S.C. § 102): This reference is highly relevant to the secure handling of cryptographic keys.
      • Claims 8 (data comprises at least one cryptographic key), 18 (system where data comprises at least one cryptographic key), 21 (system for facilitating cryptographic functions), 27 (data splitting module configured to split cryptographic keys into at least two portions), 28 (data storage facilities configured to store portions of cryptographic keys in different locations), 29 (data assembling module processes portions to assemble cryptographic keys): Directly anticipated by the teachings of generating and managing cryptographic keys in a split and distributed manner, where the complete key is never exposed.
  5. US7100057B1 - System and method for providing user-independent security, portability, availability, and straightforwardness for cryptographic functions

    • Inventors: Rick L. Orsini, et al.
    • Publication Date: 2006-08-29
    • Priority Date: 2000-05-18
    • Brief Description: This patent describes a system and method designed to offer user-independent security for cryptographic functions by managing cryptographic keys and authentication data on a secure, centralized server (a "trust engine"). This approach prevents "key migration" and enhances portability and availability by not releasing the actual keys to client devices.
    • Potential Anticipation of US9135456 Claims (35 U.S.C. § 102): This is highly relevant as it describes the core "trust engine" concept emphasized in US9135456's specification.
      • Claims 8 (data comprises at least one cryptographic key), 18 (system where data comprises at least one cryptographic key), 21 (system for facilitating cryptographic functions), 25 (cryptographic handling module performs cryptographic functions), 26 (cryptographic keys comprise symmetric, public, private keys): Anticipated by the server-centric management and use of cryptographic keys within a secure system without releasing them to users.
      • Claims 1, 11, 30, 35 (general methods/systems for securing data and cryptographic data): The overall architecture and philosophy of centralizing and securing cryptographic functions and data on a trusted server are anticipated.
  6. US6975736B1 - Biometric based cryptographic system

    • Inventors: Rick L. Orsini, et al.
    • Publication Date: 2005-12-13
    • Priority Date: 2000-05-18
    • Brief Description: This patent describes a cryptographic system that integrates biometric authentication. It focuses on securely storing biometric data and using it to authenticate a user for cryptographic operations, ensuring that private keys remain secure and are not exposed during the process.
    • Potential Anticipation of US9135456 Claims (35 U.S.C. § 102): This reference is highly relevant to the biometric and authentication aspects of US9135456.
      • Claims 9 (data comprises at least one biometric), 19 (system where data comprises at least one biometric), 21 (system for facilitating cryptographic functions), 22 (data splitting module configured to split authentication data into at least two portions), 23 (data storage facilities store portions of authentication data), 24 (data assembling module processes portions to assemble authentication data), 34 (data comprises authentication data): Directly anticipated by the secure storage, splitting (if applicable to biometric data in US6975736B1), and use of biometric data for authentication within a cryptographic system.

Other Relevant Prior Art Citations (sharing common inventors and/or priority dates):

Many other citations listed are related to the above core patents, often being applications (A1) or continuations (B2, B1). These also broadly anticipate claims related to:

  • Secure cryptographic functions via smart cards (US6859891B1, US20020152398A1, US20040225882A1): These patents discuss performing cryptographic functions without exposing sensitive data to the host, which generally relates to claims 1, 8, 11, 18, 21, 25, 30, 35 of US9135456.
  • Trusted digital signature and notarization (US6701431B1, US20020152399A1): These cover secure digital signing where private keys are kept on a server, anticipating claims related to secure cryptographic functions and key management.
  • Secure communication and storage of biometric authentication data (US7139925B2, US20020184518A1, US20040225894A1): These further reinforce the anticipation of claims related to biometric data and its secure handling for authentication.
  • User selectable levels of trust and authentication (US7003666B1, US7143431B2, US20030097587A1, US20040225885A1): These address dynamically adjusting authentication strength based on context, relevant to the authentication engine's heuristics mentioned in US9135456's specification.
  • Context sensitive authentication (US7003665B1, US20030097588A1, US20040225886A1): These specifically describe adapting authentication based on transaction context, anticipating aspects of the authentication process in US9135456.
  • Trust arbitrage (US6975734B1, US20020184520A1, US20040225887A1): These relate to comparing and translating trust levels between different systems, which US9135456 mentions in its interoperability process.
  • Multiple independent authentication systems (US7003667B1, US20030097589A1, US20040225888A1): These describe using redundancy in authentication, directly relating to the redundancy module in US9135456.
  • Audit trails for cryptographic processes (US6973574B1, US20020184521A1, US6519630B1, US20040225890A1): While not directly anticipating the core data parsing claims, these patents describe a supporting feature (audit trails) for secure cryptographic systems, a feature also present in US9135456.
  • General cryptographic systems and methods of use (US6854064B1, US20020161994A1, US20040225896A1): These provide broad coverage of secure cryptographic systems, which would generally anticipate the overall system and method claims of US9135456.

The significant overlap in inventors, priority dates, and technical subject matter indicates that many of these prior art documents collectively disclose and potentially anticipate a substantial portion of the inventions claimed in US9135456.

Generated 5/19/2026, 6:47:14 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

For an invention to be patentable in the United States, it must be non-obvious under 35 U.S.C. § 103. This means that the differences between the claimed invention and the prior art must be such that the claimed invention as a whole would not have been obvious at the time the invention was made to a person having ordinary skill in the art (PHOSITA) to which the claimed invention pertains. The obviousness analysis involves considering the scope and content of the prior art, the differences between the prior art and the claims, the level of ordinary skill in the pertinent art, and secondary considerations of non-obviousness.

US patent 9135456 describes a "Secure data parser method and system." The core of the invention involves securing data by parsing and splitting it into multiple portions, which are then stored or communicated distinctly. Encryption of the original data, the portions, or both, may be used for additional security. The system also includes a "trust engine" that stores cryptographic keys and user authentication data, performing cryptographic functions without releasing the actual keys to users.

Based on the provided information, the following combinations of prior art references could potentially render claims of US9135456 obvious:

1. Combination of general data security techniques (encryption, splitting) with secure server-centric key management:

  • Prior Art: The concept of protecting data by transforming it into an unreadable format (encryption) is a fundamental aspect of cryptography. Public key systems using a public and private key pair are also well-established.- The patent itself states that "Cryptography in general, refers to protecting data by transforming, or encrypting, it into an unreadable format." Additionally, the idea of splitting data into two or more parts or portions for security is explicitly mentioned as an aspect of the present invention, implying a recognition of its general utility.
  • Combination: A PHOSITA, aware of general cryptographic practices including encryption and data splitting, would be motivated to combine these techniques with a secure, server-centric key management system. The patent highlights the drawbacks of traditional key management, such as "key migration" and inadequate security with simple login/password access, which often exposes private keys.- A trust engine that stores cryptographic keys and user authentication data on a server, and performs cryptographic functions without releasing the keys, directly addresses these known problems., This combination would be a logical step to enhance data security by centralizing key management and preventing key exposure, which are recognized problems in the field.

Motivation for Combination: The motivation would stem from the desire to overcome the recognized security vulnerabilities associated with user-controlled or less-secure key storage. By combining the known techniques of data parsing/splitting and encryption with a robust, server-side key management system, a PHOSITA would aim to create a more secure and reliable method for protecting sensitive data, particularly cryptographic keys and authentication data. The explicit problem of "key migration" and the inadequacy of simple login/password security, as described in the patent, would strongly motivate a PHOSITA to explore solutions involving centralized, highly secure key storage and usage without direct key exposure to users or client devices.-,,

2. Combination of data splitting and geographically remote storage with redundancy for fault tolerance and enhanced security:

  • Prior Art: The patent describes a method of splitting data into portions, where the original data is not recreatable from an individual portion. It also discusses storing these portions in multiple data storage facilities, including geographically remote ones.,, Furthermore, the concept of redundancy to ensure functionality even if some storage facilities are inoperative is present. Error detection and correction by redundancy in data representation, such as using checking codes and parity data in RAID systems, are also listed as classifications for the patent, indicating these are known concepts in the prior art.
  • Combination: A PHOSITA would be motivated to combine data splitting with geographically remote and redundant storage to enhance both security and reliability. Distributing undecipherable portions of data across physically separated locations, where multiple portions are needed for reconstruction, directly addresses the risk of compromise of a single storage facility., The knowledge of fault-tolerant systems (like RAID) that use redundancy for data integrity would further motivate a PHOSITA to apply similar principles to distributed secure data storage.

Motivation for Combination: The motivation would be to achieve a higher level of data security and availability. The patent explicitly states that distributing sensitive data into distinct and independent storage facilities, some or all of which may be geographically separated, provides "redundancy along with additional security measures." The challenge of subverting multiple independent, geographically remote data storage facilities, even for a "rogue employee," highlights the security benefits. The application of redundancy, a known concept from fault-tolerant systems, to enhance the reliability of accessing the split data would also be a clear motivation.

3. Combining biometric authentication with server-side processing for secure authentication:

  • Prior Art: The use of biometrics for identification (e.g., fingerprints, speech) checked by automated systems is acknowledged. However, the patent also notes the drawbacks of storing biometrics and keys on mobile devices, including loss, theft, and susceptibility to compromise.- The patent's classification also includes "Network architectures or network communication protocols for network security for authentication of entities using certificates" and "based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint," indicating known authentication methods.
  • Combination: A PHOSITA would be motivated to combine biometric authentication with server-side processing to mitigate the risks associated with client-side storage and to provide a more secure and reliable authentication process. By having the trust engine receive biometric data from the user and compare it to enrollment authentication data stored in the secure depository, without the user's private key leaving the trust engine, the system addresses the identified vulnerabilities of mobile biometric systems.-,-

Motivation for Combination: The motivation is to overcome the security weaknesses of client-side biometric and key storage. The patent specifically points out that "the foregoing mobile biometric cryptographic system still suffers from a variety of drawbacks", including loss or theft of devices and compromise through open systems. By processing authentication data and performing cryptographic functions on a secure server ("trust engine") and not releasing sensitive data or keys, a PHOSITA would be motivated to create a more robust authentication system that addresses these known vulnerabilities.

It's important to note that a full obviousness analysis would require a detailed examination of each claim of US9135456 against the specific disclosures of identified prior art references and a determination of the PHOSITA's level of skill at the priority date of October 25, 2004. Secondary considerations of non-obviousness, such as commercial success or long-felt but unsolved needs, would also be considered if presented.

Generated 5/19/2026, 6:46:20 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

tool_code
print(google_search.search(queries=["US patent 9135456 patent term adjustments", "US patent 9135456 patent term extensions", "US patent 9135456 continuation applications", "US patent 9135456 divisional applications", "US patent 9135456 related family members", "US patent 9135456 projected expiration date"]))
thought
The user is asking for specific details about US patent 9135456, including:

  • Patent Term Adjustments (PTA)
  • Patent Term Extensions (PTE)
  • Continuation applications
  • Divisional applications
  • Related family members
  • Projected expiration date

I will use the Google Patents page as the primary source for this information, supplemented by additional searches if necessary. I need to ensure I interpret all alphanumeric IDs literally and prioritize search results if they contradict my training data.

Looking at the Google Patents page for US9135456:

  • "Prior art date: 2004-10-25"
  • "Filing date: 2014-08-29"
  • "Publication date: 2015-09-15"
  • "Application granted: 2015-09-15" (This is the issue date)
  • "Anticipated expiration: 2025-10-25" (This is already provided)
  • "Other versions: US20140372770A1" (This is likely a related family member, specifically a publication of the application)
  • "Priority to US14/473,813" (This is the application number for 9135456)
  • "Priority to US14/710,528" (This is a related application number, potentially a continuation or divisional)
  • "Priority to US14/828,377" (This is another related application number, potentially a continuation or divisional)
  • No explicit mention of PTA or PTE on the main Google Patents page, so I need to search for that specifically.

Let's break down the information needed and how to find it.

  1. Patent Term Adjustments (PTA) and Patent Term Extensions (PTE): This information is usually detailed on the USPTO Public Pair or Patent Center. Google Patents might show an adjusted expiration date but not the detailed calculation. My previous prompt mentions an "Anticipated expiration: 2025-10-25". The standard term is 20 years from the earliest filing date of the application from which priority is claimed. The priority date is 2004-10-25. 20 years from this date is 2024-10-25. The listed expiration date is 2025-10-25. This suggests a one-year adjustment. I need to confirm this and find the official PTA/PTE information.

  2. Continuation applications, Divisional applications, Related family members: The Google Patents page lists "Priority to US14/473,813", "Priority to US14/710,528", and "Priority to US14/828,377".

    • US14/473,813 is the application number for US9135456.
    • US20140372770A1 is "Other versions", likely the published application for US9135456.
    • I need to look up US14/710,528 and US14/828,377 to see their relationship (continuation, divisional, or continuation-in-part).
    • The "Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.) 2004-10-25" is also critical. This is the earliest priority date claimed.
  3. Projected expiration date: The Google Patents page states "Anticipated expiration: 2025-10-25". I will use this date.

Let's refine the search for PTA/PTE and the type of applications for the "Priority to" listed applications.## Patent Term Details for US9135456

As of April 26, 2026, here is a detailed analysis of US patent 9135456 regarding its term adjustments, related applications, and projected expiration:

Patent Term Adjustments (PTA) and Patent Term Extensions (PTE)

US Patent 9135456 has an anticipated expiration date of 2025-10-25. The initial priority date for the patent is 2004-10-25. The standard patent term is 20 years from the earliest claimed priority date. Therefore, 20 years from October 25, 2004, would be October 25, 2024. The difference between this calculation and the anticipated expiration date (October 25, 2025) suggests a Patent Term Adjustment (PTA) of approximately one year.

Further details regarding the specific calculation of this PTA or any Patent Term Extensions (PTE) are typically provided in the issue notification from the USPTO. Without direct access to the USPTO Patent Center or Public PAIR for this specific patent's file wrapper, the precise breakdown of the PTA calculation (e.g., A, B, and C delays) cannot be explicitly detailed here. However, the listed anticipated expiration date implicitly accounts for any such adjustments.

Continuation and Divisional Applications

The Google Patents record for US9135456 lists several priority claims, indicating a family of related applications:

  • US14/473,813: This is the application number that directly led to US9135456.
  • US14/710,528: This application claims priority to US9135456 and resulted in US9906500B2 (Method and system for managing cryptography system). Given that US14/710,528 was filed on 2015-05-12 (after the filing date of US14/473,813 but before the issue date of US9135456), it is likely a continuation or divisional application of the parent application leading to US9135456.
  • US14/828,377: This application claims priority to US9135456 and resulted in US20150381582A1 (Secure data parser method and system). This application also likely represents a continuation or divisional application. The Google Patents entry indicates it was filed on 2015-08-17.

Related Family Members

In addition to the applications listed above, the following related family member has been identified:

  • US20140372770A1: This is the patent application publication for US14/473,813, which matured into US9135456.

Projected Expiration Date

The projected expiration date for US patent 9135456 is 2025-10-25. This date is derived from the earliest priority date of 2004-10-25, plus any Patent Term Adjustments.

Generated 5/21/2026, 2:32:29 PM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

Defensive Disclosure: Derivatives of US Patent 9135456

This Defensive Disclosure document outlines a series of derivative works based on US Patent 9135456, "Secure data parser method and system." The purpose of this disclosure is to establish prior art for potential future incremental improvements by competitors, thereby rendering such improvements non-novel or obvious. The derivatives are generated across five distinct axes: Material & Component Substitution, Operational Parameter Expansion, Cross-Domain Application, Integration with Emerging Technologies, and the "Inverse" or Failure Mode.

Core Claims Addressed:

  • Claim 1: A method for securing data.
  • Claim 11: A system for securing data.
  • Claim 21: A system for facilitating cryptographic functions (Trust Engine).

Derivatives for Claim 1 (Method for securing data) and Claim 11 (System for securing data)

Original Claim 1 (Method): A method for securing data, comprising: parsing said data into at least two portions; encrypting said data; storing said portions in at least two different locations; and reconstituting said portions to assemble said data for authorized access.

Original Claim 11 (System): A system for securing data, comprising: a data splitting module configured to split said data into at least two portions; a cryptographic handling module configured to encrypt said data; at least two data storage facilities configured to store said portions in at least two different locations; and a data assembly module configured to process said portions from said at least two data storage facilities to assemble said data.


1. Material & Component Substitution

Derivative 1.1: Quantum State-Based Data Portions

  • Enabling Description: Instead of conventional digital bits stored in electronic or magnetic media, the data (or its portions) is encoded into the quantum states of entangled photons or superconducting qubits. The "parsing" involves generating a multi-qubit entangled state representing the data, and then performing quantum measurements to project the data into "portions" represented by the measurement outcomes (e.g., spin up/down, polarization). These quantum state portions are then physically transmitted (e.g., via optical fiber for photons, or microwave guides for qubits) to spatially separated quantum memory arrays (e.g., diamond nitrogen-vacancy centers or superconducting resonators) for storage. Encryption is inherent through the quantum properties (e.g., no-cloning theorem, quantum key distribution principles) and augmented by classical post-processing of measurement results. Reconstitution involves performing inverse quantum operations or correlating distributed quantum measurements to reconstruct the original entangled state or classical data representation.
  • Mermaid Diagram:
    flowchart TD
        A[Original Data] --> B{Quantum Encoder};
        B -- Entangled Qubits --> C{Quantum State Splitter};
        C -- Portions (Quantum States) --> D1[Quantum Memory Array 1];
        C -- Portions (Quantum States) --> D2[Quantum Memory Array 2];
        C -- Portions (Quantum States) --> Dn[Quantum Memory Array N];
        D1 & D2 & Dn -- Correlated Quantum States --> E{Quantum State Reconstructor};
        E --> F[Reconstituted Data];
    

Derivative 1.2: Biological Macromolecule-Based Data Portions

  • Enabling Description: Data is encoded into sequences of biological macromolecules, such as synthetic DNA strands or engineered peptides. The "parsing" involves enzymatic cleavage or synthesis of the master sequence into unique, non-overlapping or overlapping sub-sequences (portions). These portions are encapsulated in inert bio-compatible carriers (e.g., liposomes, synthetic cells) and stored in distinct, geographically isolated biorepositories under controlled environmental conditions (e.g., cryogenic freezers for DNA, desiccated environments for peptides). Encryption is achieved through obfuscation of the encoding scheme and by incorporating error-correcting codes and redundant sequences within each portion, making individual portions biologically meaningless without the full set. Reconstitution involves enzymatic ligation or directed self-assembly of the macromolecule portions, followed by high-throughput sequencing or mass spectrometry for decoding.
  • Mermaid Diagram:
    flowchart TD
        A[Digital Data] --> B{Bio-Encoder (DNA/Peptide Synthesis)};
        B -- Master Macromolecule --> C{Enzymatic/Chemical Splitter};
        C -- Macromolecule Portions --> D1[Biorepository 1];
        C -- Macromolecule Portions --> D2[Biorepository 2];
        C -- Macromolecule Portions --> Dn[Biorepository N];
        D1 & D2 & Dn -- Assembled Portions --> E{Bio-Decoder (Sequencing/Mass Spec)};
        E --> F[Reconstituted Digital Data];
    

2. Operational Parameter Expansion

Derivative 2.1: Hyper-Scale Industrial Data Security

  • Enabling Description: For industrial control systems (ICS) and SCADA networks managing critical infrastructure (e.g., national power grids, large-scale manufacturing plants), exabyte-scale operational data (sensor readings, control commands, telemetry) is continuously parsed into millions of encrypted micro-portions. This parsing is executed by a high-performance distributed computing cluster, capable of processing data streams at terabytes-per-second. The portions are stored across geographically disparate and independently administered "dark" data centers (no direct internet access) connected by dedicated, high-bandwidth optical networks. Reconstruction for auditing or recovery occurs within a specialized, air-gapped forensic analysis environment that requires physical multi-factor authentication from multiple custodians across various locations to activate the assembly process. Each portion is protected with homomorphic encryption, allowing certain computations to be performed on encrypted data without decryption, facilitating integrity checks at storage locations without revealing sensitive content.
  • Mermaid Diagram:
    graph LR
        subgraph Industrial Control Network
            SCADA -- Real-time Data --> HPC_Parser
            ICS_Sensors -- Real-time Data --> HPC_Parser
        end
    
        subgraph Distributed Parsing Cluster
            HPC_Parser[HPC Data Stream Parser] -- Micro-Portions (Encrypted) --> DC1(Dark Data Center 1)
            HPC_Parser -- Micro-Portions (Encrypted) --> DC2(Dark Data Center 2)
            HPC_Parser -- Micro-Portions (Encrypted) --> DCN(Dark Data Center N)
        end
    
        DC1 & DC2 & DCN -- Encrypted Portions --> Forensic_Env{Air-gapped Forensic Environment}
        Forensic_Env -- Multi-Custody Auth --> Data_Recon[Data Reconstitution Module]
        Data_Recon --> Audited_Data[Reconstituted Operational Data]
    

Derivative 2.2: Ultra-Low Latency Edge Micro-Transaction Security

  • Enabling Description: Securing individual, atomic micro-transactions (e.g., single bit updates, sub-millisecond control signals) in a highly distributed edge computing environment (e.g., autonomous vehicle sensor fusion, high-frequency trading). Data is parsed into picosecond-latency "micro-fragments" that are immediately encrypted and distributed across a mesh network of hardened edge computing nodes using ultra-low latency optical interconnects. Each fragment is ephemeral, existing only for nanoseconds before being stored or reassembled. The encryption protocol is a lightweight, symmetric key algorithm designed for extremely fast execution (e.g., AES-GCM with hardware acceleration). Reconstruction occurs on adjacent edge nodes within microsecond windows, triggered by event-driven queries. The system operates under extreme frequency (GHz range processing) to maintain data integrity and security within real-time critical systems.
  • Mermaid Diagram:
    sequenceDiagram
        participant ES as Edge Sensor
        participant ET as Edge Transactor
        participant ECN1 as Edge Compute Node 1
        participant ECN2 as Edge Compute Node 2
        participant ECNN as Edge Compute Node N
        participant AE as Assembly Engine
    
        ES->>ET: Micro-Transaction Data (picosecond latency)
        ET->>ECN1: Encrypted Micro-Fragment A
        ET->>ECN2: Encrypted Micro-Fragment B
        ET->>ECNN: Encrypted Micro-Fragment N
        Note over ECN1,ECN2,ECNN: Fragments stored ephemerally
        ECN1->>AE: Fragment A (on query)
        ECN2->>AE: Fragment B (on query)
        ECNN->>AE: Fragment N (on query)
        AE->>AE: Reconstitute Data (microsecond latency)
        AE->>ET: Authentication Result
    

3. Cross-Domain Application

Derivative 3.1: Aerospace - Black Box Flight Data Security

  • Enabling Description: For commercial aircraft flight recorders ("black boxes"), sensitive flight data (cockpit voice recordings, flight parameters, airframe stress data) is continuously parsed into encrypted portions. These portions are redundantly stored across physically distinct, hardened solid-state memory units distributed throughout the aircraft's airframe (e.g., in wings, tail, nose cone, landing gear bays) as well as broadcast to secure ground stations via encrypted satellite links. Each distributed unit is designed to withstand extreme forces, temperatures, and immersion. In the event of a catastrophic incident, retrieval of any two (or more, based on a threshold) of these physically separated and broadcast portions allows for full data reconstruction. The encryption scheme adapts to data criticality, with cockpit voice recordings using the strongest encryption.
  • Mermaid Diagram:
    graph TD
        A[Flight Data Recorder] --> B{Data Parser/Encryptor};
        B -- Encrypted Portion 1 --> C1[Hardened Memory Unit (Wing)];
        B -- Encrypted Portion 2 --> C2[Hardened Memory Unit (Tail)];
        B -- Encrypted Portion 3 --> C3[Hardened Memory Unit (Nose)];
        B -- Encrypted Portion 4 --> S(Encrypted Satellite Broadcast);
        S --> G[Secure Ground Station];
        C1 & C2 & C3 & G -- For Recovery --> D{Data Reassembly Module};
        D --> E[Reconstructed Flight Data];
    

Derivative 3.2: AgTech - Precision Agriculture Genomic Data Security

  • Enabling Description: In precision agriculture, vast amounts of genomic data for specific crop strains, livestock, and soil microbiome samples are parsed into encrypted fragments. These fragments are stored across a distributed network of secure, on-farm edge servers and regional agricultural research centers. Each fragment is cryptographically linked to its source metadata (e.g., GPS coordinates of sample, date, environmental conditions) and protected with a multi-party computation (MPC) scheme, allowing aggregate analysis across fragments (e.g., disease resistance patterns) without ever decrypting individual genomic sequences. Reconstitution of a full genomic sequence requires a quorum of fragments from different storage locations, verified by a distributed consensus mechanism. This prevents unauthorized access to proprietary genetic intellectual property or vulnerabilities.
  • Mermaid Diagram:
    graph LR
        A[Genomic Data (Crop/Livestock)] --> B{Data Parser/Encryptor};
        B -- Encrypted Fragment 1 (MPC) --> C1[On-Farm Edge Server 1];
        B -- Encrypted Fragment 2 (MPC) --> C2[On-Farm Edge Server 2];
        B -- Encrypted Fragment 3 (MPC) --> R1[Regional Research Center 1];
        B -- Encrypted Fragment 4 (MPC) --> R2[Regional Research Center 2];
        C1 & C2 & R1 & R2 -- For Aggregate Analysis --> D{Multi-Party Computation Engine};
        D -- On-Demand Reconstruction --> E{Data Reassembly Module};
        E --> F[Reconstructed Genomic Sequence];
    

Derivative 3.3: Consumer Electronics - Smart Home User Profile Security

  • Enabling Description: Sensitive user profile data within a smart home ecosystem (e.g., behavioral patterns, voice commands, biometric scans from smart locks, health data from wearables) is parsed into encrypted, anonymized micro-segments. These segments are distributed across local, mutually distrusting smart devices within the home (e.g., smart speaker, smart TV, home hub, smart refrigerator) and optionally mirrored to an obfuscated cloud storage service. No single device or the cloud service holds enough information to reconstruct the full user profile. Access to specific functions (e.g., unlocking a smart lock) requires cryptographic aggregation of necessary micro-segments from a predefined quorum of local devices, orchestrated by a local trust agent. Differential privacy techniques are applied during parsing to further anonymize data, even before splitting.
  • Mermaid Diagram:
    graph LR
        A[User Profile Data (Smart Home)] --> B{Data Parser/Encryptor (Anonymization)};
        B -- Encrypted Micro-Segment 1 --> C1[Smart Speaker];
        B -- Encrypted Micro-Segment 2 --> C2[Smart TV];
        B -- Encrypted Micro-Segment 3 --> C3[Home Hub];
        B -- Encrypted Micro-Segment 4 --> C4[Smart Refrigerator];
        C1 & C2 & C3 & C4 -- Local Aggregation for Function --> D{Local Trust Agent};
        D --> E[Smart Lock Unlock];
        D --> F[Climate Control];
    

4. Integration with Emerging Tech

Derivative 4.1: AI-Driven Dynamic Data Splitting & Storage Optimization

  • Enabling Description: An AI-driven optimization engine dynamically adjusts the parsing and distribution strategy of data portions based on real-time threat intelligence, data access patterns, and resource availability (network latency, storage load, energy costs). For example, if a data portion's access frequency increases, the AI might duplicate it across more readily available, but still secure, storage nodes. If a new threat vector is identified, the AI could trigger re-splitting of existing portions with a different cryptographic scheme or redistribute them to more resilient geographic locations. Machine learning models predict optimal splitting parameters (number of portions, size, encryption strength) and storage locations to balance security, performance, and cost, learning from past attack vectors and system performance.
  • Mermaid Diagram:
    flowchart TD
        A[Raw Data Stream] --> B{AI-Driven Parser/Encryptor};
        B -- Optimized Portions --> C{Dynamic Storage Orchestrator};
        C -- Distribute/Redistribute --> D1[Secure Cloud Storage 1];
        C -- Distribute/Redistribute --> D2[Secure Edge Storage 2];
        C -- Distribute/Redistribute --> D3[Quantum-Resistant Storage N];
        C -- Performance/Cost/Security Metrics --> B;
        TI[Threat Intelligence Feed] --> B;
        D1 & D2 & D3 -- Retrieve for Access --> E{Data Assembly Module};
        E --> F[Authorized Access];
    

Derivative 4.2: IoT Sensor Data Integrity with Blockchain Verification

  • Enabling Description: In a distributed IoT network (e.g., environmental monitoring, supply chain logistics), sensor data streams are parsed into encrypted portions. Each portion, along with its metadata (timestamp, sensor ID, location), is hashed, and this hash is securely anchored to a permissioned blockchain ledger. The portions themselves are stored off-chain in distributed, lightweight edge storage facilities. The "reconstituting" process involves retrieving the portions and then verifying their integrity against the corresponding hashes recorded on the blockchain. This provides an immutable audit trail and ensures that no single portion has been tampered with since its creation. Smart contracts on the blockchain can define access policies and triggers for data reconstitution.
  • Mermaid Diagram:
    graph TD
        A[IoT Sensor Data] --> B{Data Parser/Encryptor};
        B -- Encrypted Portion + Metadata --> C[Edge Storage Facility];
        B -- Hashed Portion Data --> D(Blockchain Ledger);
        C -- Retrieve Portion --> E{Data Assembly Module};
        D -- Retrieve Hash --> E;
        E -- Verify Hash --> F{Data Integrity Verifier};
        F -- Validated Data --> G[Authorized Access];
    

Derivative 4.3: Federated Learning for Secure Model Training Data

  • Enabling Description: In federated learning scenarios where multiple parties contribute data to train a shared AI model without sharing raw data, US9135456's method is applied to the training datasets. Each participating entity's raw training data is parsed into encrypted, differentially private portions. These portions are then stored in secure enclaves on each entity's local compute infrastructure. When the federated learning server requires model updates, it requests encrypted gradients derived from these data portions, rather than the portions themselves. The "reconstitution" in this context refers to the secure aggregation of these encrypted gradients from multiple participants to update the global model, ensuring no individual raw data point is ever exposed or fully reassembled by the central server. Secure multi-party computation (SMC) is used for gradient aggregation.
  • Mermaid Diagram:
    graph TD
        P1[Participant 1 Raw Data] --> DP1{Diff. Private Parser/Encryptor 1};
        DP1 -- Encrypted Portions --> ES1[Secure Enclave 1];
    
        P2[Participant 2 Raw Data] --> DP2{Diff. Private Parser/Encryptor 2};
        DP2 -- Encrypted Portions --> ES2[Secure Enclave 2];
    
        ES1 -- Encrypted Gradients --> SMC[SMC Aggregation Server];
        ES2 -- Encrypted Gradients --> SMC;
    
        SMC -- Global Model Update --> FL(Federated Learning Server);
    

5. The "Inverse" or Failure Mode

Derivative 5.1: Graceful Data Degradation and Secure Erasure Mode

  • Enabling Description: This derivative focuses on designing the system to safely degrade or securely erase data under specific conditions. When certain failure modes are detected (e.g., compromise of a quorum of storage facilities, unauthorized access attempts exceeding a threshold, or an explicit secure erasure command), the data assembly module is prevented from re-constituting the full original data. Instead, it enters a "graceful degradation" mode where only partial, non-sensitive metadata or anonymized aggregates can be recovered. For full secure erasure, the cryptographic keys used to encrypt the portions are themselves split into a larger number of shares and destroyed across a distributed network, making recovery of the full key (and thus decryption of the portions) mathematically impossible even if all data portions were retrieved. This "key-splitting-for-destruction" guarantees irreversible data loss.
  • Mermaid Diagram:
    stateDiagram-v2
        [*] --> Operational
        Operational --> Degrading: Threshold Breached / Command
        Degrading --> Erasing: Erasure Command / Irrecoverable
        Degrading --> Operational: Recovery / Mitigation
    
        Operational --> Data_Parsing_Storage: Normal Operation
        Data_Parsing_Storage --> Data_Reconstitution: Authorized Access
    
        Degrading --> Partial_Data_Access: Limited Functionality
        Erasing --> Data_Irrecoverable: Irreversible Destruction
    
        state Data_Parsing_Storage {
            Data --> Portions
            Portions --> Storage
        }
    
        state Data_Reconstitution {
            Storage --> Reassembly
            Reassembly --> Original_Data
        }
    

Derivative 5.2: Limited-Functionality "Safe Mode" for Cryptographic Engine

  • Enabling Description: In this mode, the "trust engine" (Claim 21) operates in a reduced capacity, prioritizing critical security functions while limiting exposure of sensitive data. If the trust engine detects an internal anomaly or external attack, it enters "Safe Mode." In this mode, the cryptographic engine (Claim 21) will only perform a limited set of cryptographic functions (e.g., hash generation for integrity checks, but not decryption or digital signing). It may only reassemble a minimal, non-sensitive subset of cryptographic keys or authentication data, sufficient for basic system diagnostics or to prove the existence of an identity without revealing its full credentials. Attempts to perform full cryptographic operations are blocked, and a high-alert notification is triggered. The data splitting module may be invoked to further re-split and redistribute existing portions to enhance resilience during this compromised state.
  • Mermaid Diagram:
    graph TD
        A[Trust Engine] --> B{Security Monitor};
        B -- Anomaly Detected --> C(Safe Mode Activation);
        C --> D{Limited Cryptographic Functions};
        D -- Allow --> E[Integrity Check];
        D -- Block --> F[Full Decryption/Signing Request];
        C --> G{Minimal Key/Auth Reassembly};
        G --> H[System Diagnostics/Identity Proof];
        C --> I[High Alert Notification];
        C --> J{Re-split & Redistribute Portions};
    

Combination Prior Art Scenarios

Here are at least three "Combination Prior Art" scenarios where US Patent 9135456 is combined with existing open-source standards:

1. US9135456 Data Splitting & Storage with IPFS (InterPlanetary File System)

  • Description: The "parsing said data into at least two portions" (Claim 1) and "storing said portions in at least two different locations" (Claim 1) of US9135456 can be combined with IPFS. In this scenario, after data is parsed and encrypted by the data splitting module (Claim 11) and cryptographic handling module (Claim 11), the resulting encrypted portions are not stored in traditional centralized data storage facilities but instead distributed across the decentralized peer-to-peer network provided by IPFS. Each portion would receive a content-addressed identifier (CID) from IPFS. The "reconstituting said portions" (Claim 1) and "data assembly module" (Claim 11) would then retrieve these portions from IPFS using their CIDs and reassemble the data. This provides a highly resilient, censorship-resistant, and geographically diverse storage solution for the data portions, leveraging IPFS's distributed hash table (DHT) for content discovery and retrieval.
  • Technical Details: The data splitting module generates 'n' portions (P1, P2, ..., Pn). Each Pi is encrypted (Ei). Each Ei is then added to a local IPFS node, yielding a unique CIDi. The CIDs are then stored (potentially themselves split and stored, or secured separately). The data assembly module retrieves the list of CIDs, requests each CIDi from the IPFS network, reconstructs Ei from the received content, decrypts, and reassembles.
  • Mermaid Diagram:
    graph TD
        A[Original Data] --> B{Data Splitter (US9135456)};
        B -- Portions --> C{Cryptographic Module (US9135456)};
        C -- Encrypted Portions --> D[IPFS Network];
        D -- CID1, CID2, ... --> E[CID Registry (Secured)];
        E -- Retrieve CIDs --> F{Data Assembly Module (US9135456)};
        F -- Request Portions by CID --> D;
        D -- Retrieved Encrypted Portions --> F;
        F --> G[Reconstituted Data];
    

2. US9135456 Trust Engine & Authentication with OAuth 2.0 / OpenID Connect

  • Description: The "system for facilitating cryptographic functions" (Claim 21), particularly the authentication engine (FIG. 5) and cryptographic engine (FIG. 6) residing within a "trust engine" (FIG. 2), can be combined with OAuth 2.0 for authorization and OpenID Connect (OIDC) for identity verification. The trust engine would act as the Authorization Server and OpenID Provider. Instead of directly releasing cryptographic keys, the trust engine would issue access tokens (OAuth 2.0) and ID tokens (OIDC) upon successful user authentication. The authentication process within the trust engine (comparing current authentication data to enrollment data, potentially involving biometrics and data splitting as per US9135456's claims 22-24) would precede the issuance of these tokens. Client applications (user systems or vendor systems) would then use these tokens to request cryptographic services from the trust engine's cryptographic handling module, which performs functions on behalf of the user without releasing the actual private keys.
  • Technical Details: A user authenticates to the Trust Engine. The Authentication Engine (FIG. 5), potentially using split biometric data from the Depository (FIG. 2), verifies the user's identity. Upon successful verification, the Trust Engine (acting as an OpenID Provider) issues an ID Token (JWT) and an Access Token (JWT) to the client application. The client application then presents the Access Token to the Trust Engine (acting as a Resource Server), requesting specific cryptographic functions (e.g., signing a document). The Cryptographic Engine (FIG. 6) performs the requested function using the user's stored, unreleased private key and returns the result.
  • Mermaid Diagram:
    sequenceDiagram
        participant U as User
        participant CA as Client App
        participant TE as Trust Engine (Auth/OIDC)
        participant DE as Depository (US9135456)
        participant AE as Auth Engine (US9135456)
        participant CE as Crypto Engine (US9135456)
        
        U->>CA: Initiate Login/Auth
        CA->>TE: Auth Request (via OAuth/OIDC)
        TE->>AE: Current Auth Data (from CA)
        AE->>DE: Request Enrollment Auth Portions
        DE->>AE: Auth Portions
        AE->>AE: Assemble & Compare (US9135456)
        AE-->>TE: Auth Result
        alt Successful Authentication
            TE->>CA: Access Token, ID Token
            CA->>CE: Request Cryptographic Function (with Access Token)
            CE->>DE: Request Cryptographic Key Portions
            DE->>CE: Key Portions
            CE->>CE: Assemble Key & Perform Function (US9135456)
            CE-->>CA: Cryptographic Result
        else Authentication Failed
            TE-->>CA: Auth Error
        end
    

3. US9135456 Secure Data in Motion with QUIC (Quick UDP Internet Connections)

  • Description: The "secure data in motion system whereby data may be transmitted in different portions that are secured in accordance with the present invention such that any one portion becoming compromised shall not provide sufficient data to restore the original data" (from the specification) can be enhanced by utilizing QUIC for the underlying transport layer. After the data is parsed into encrypted portions (Claim 1) by the data splitting module (Claim 11) and cryptographic handling module (Claim 11), these individual portions are transmitted over separate, multiplexed QUIC streams within a single connection. QUIC's inherent security (TLS 1.3 encryption for all data), connection migration capabilities, and improved head-of-line blocking mitigation would make the "data in motion" more robust and efficient. Even if a QUIC stream carrying one portion is intercepted, the other portions, transmitted over different streams and potentially different network paths (via connection migration), remain secure and individually undecipherable, aligning with the patent's goal of preventing restoration from a single compromised portion.
  • Technical Details: The source system's data splitting module divides the data into portions (P1, P2, ..., Pn). Each Pi is independently encrypted (Ei). The source system then initiates a QUIC connection to the destination. Each Ei is transmitted over a separate QUIC stream (Stream1, Stream2, ..., StreamN) within that connection. QUIC's TLS 1.3 encryption secures each stream. The destination system's data assembly module receives the encrypted portions from the various QUIC streams, reassembles, and decrypts them.
  • Mermaid Diagram:
    sequenceDiagram
        participant SS as Source System
        participant DS as Destination System
        
        SS->>SS: Data Parsing (US9135456)
        SS->>SS: Data Encryption (US9135456)
        SS->>DS: Initiate QUIC Connection (TLS 1.3)
        loop For each Encrypted Portion
            SS->>DS: Transmit Encrypted Portion over dedicated QUIC Stream
        end
        DS->>DS: Receive Encrypted Portions from QUIC Streams
        DS->>DS: Data Assembly (US9135456)
        DS->>DS: Data Decryption (US9135456)
        DS->>DS: Reconstituted Data
    

Generated 5/21/2026, 2:33:17 PM

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 9135456.