Invalidity dossier

US 9137205

Methods and systems for protecting a secured network

Current assignee: Centripetal Networks, Inc.

Added 8/26/2026, 8:20:51 AM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by Centripetal Networks, Inc.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Summary: US Patent 9,137,205 (US9137205B2)

Bibliographic data

Field Value
Title Methods and systems for protecting a secured network
Patent / Publication No. US 9,137,205 B2 (US9137205B2)
Application No. US 13/657,010
Inventors Steven Rogers; Sean Moore
Original Assignee Centripetal Networks, Inc. (now Centripetal Networks, LLC, per recorded change of name)
Filing date October 22, 2012
Issue (grant) date September 15, 2015
Priority date October 22, 2012
Status Active (adjusted expiration ~May 8, 2033 per Google Patents)
Examiner Kenneth W. Chang (per Unified Patents/PTAB file-history records)
CPC classifications H04L63/00, H04L63/20, H04L63/02, H04L63/0209, H04L63/0218, H04L63/0227, H04L63/0236, H04L63/0263, H04L67/01, H04L67/02

Sources: Google Patents (patents.google.com/patent/US9137205/en); OEPM record for priority application PCT/US2013/057502 (WO2014/065943); Unified Patents portal.

Abstract (verbatim)

"Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets. Performing the at least one of multiple packet transformation functions specified by the dynamic security policy on the packets may include performing at least one packet transformation function other than forwarding or dropping the packets."

Plain-language overview of the independent claims

The granted patent (36 claims per the Justia record) has three independent claims — claim 1 (method), claim 17 (system), and claim 33 (non-transitory computer-readable media). All three share the same core combination of features; claim 17 adds a "computer hardware and logic" recital and claim 33 is a storage-medium recital.

Claim 1 — Method. At each packet security gateway (an edge device associated with a central security policy management server):

  1. Receive a plurality of dynamic security policies from the server, which includes:
    • an "allowlist"-style rule pair: at least one rule saying packets to a specified set of network addresses should be forwarded, plus at least one rule saying packets to addresses outside that set should be dropped; and
    • a phased-restoration sequence: a first policy (received at a first time) specifying a first set of addresses to forward; a second policy (received at a second time) specifying a second, larger set; and a third policy (received at a third time) specifying a third, even larger set — i.e., progressively expanding the set of allowed/forwarded addresses over time.
  2. Receive packets associated with the network protected by the gateway.
  3. Perform, packet-by-packet, at least one of multiple packet transformation functions specified by those policies — and crucially, at least one of the performed functions must be something other than simply forwarding or dropping packets (e.g., rerouting/encapsulation, queueing at differential rates, sending to a monitoring device, IPsec processing, etc.).

In plain terms: the invention is a centrally managed, high-resolution packet-filtering gateway that supports (a) allowlist/blocklist enforcement and (b) a time-phased "gradual reopening" of the network after an attack (starting with mission-critical addresses and expanding to larger sets), while also being capable of doing more sophisticated per-packet transformations than just pass/block.

Claim 17 — System. A system comprising a security policy management server and one or more packet security gateways, where each gateway comprises computer hardware and logic configured to perform the same functions as claim 1 (receive the plurality of dynamic policies including the allowlist rule pair and the three progressively larger address-set policies at successive times; receive protected-network packets; and perform, packet-by-packet, at least one transformation function other than forwarding or dropping).

Claim 33 — Computer-readable media. One or more non-transitory computer-readable media storing instructions that, when executed, cause each packet security gateway associated with a security policy management server to perform the same set of functions as claims 1 and 17 (receive the dynamic policies, receive the packets, and perform a packet-transformation function other than forwarding/dropping on a packet-by-packet basis).

Dependent claims add details such as gateways in series (claims 2–3, 18–19, 34–35), a blocklist variant (claims 4, 20, 36), VoIP-session-based rule creation (claims 5, 21), differential forwarding queues (claims 6, 22), SIP-URI-based rerouting to a monitoring/copy device with encapsulation (claims 7–8, 23–24), IPsec-stack forwarding (claims 9, 25), five-tuple rule matching (claims 10, 26), DSCP selectors (claims 11, 27), network-layer-transparent operation with secured management interface (claims 12–13, 28–29), malicious-address subscription-service rules (claims 14, 30), spoofed-source-address rules that differ by boundary (claims 15, 31), and gateway placement at every protected/unprotected boundary (claims 16, 32).

Notable litigation / docket observations (with uncertainty flagged)

  • USPTO / PTAB: IPR2018-01443 and IPR2018-01444 (petitioner: Cisco, per the "Cisco Ex 1002 — File History 205 Patent" record) reached Final Written Decisions; IPR2018-01505 and IPR2018-01506 were not instituted (per the Google Patents litigation listing for US9137205).
  • District court: Stanford NPE Litigation Database lists 2:17-cv-00383 (E.D. Va.), Centripetal Networks, Inc. v. Keysight Technologies, Inc., et al., involving patent 9137205. Google Patents also lists 2:18-cv-00094, 2:22-cv-00001, and 2:22-cv-00002 for this patent family.
  • CAFC: Google Patents associates CAFC appeals 20-1713, 20-1714, 21-1888, and 24-2097 with this patent. I could not confirm from my searches a 2026 CAFC docket naming 9137205 specifically. The 2026 Federal Circuit Centripetal decisions I found — Keysight Technologies, Inc. v. Centripetal Networks, LLC, No. 25-1053 (opinion July 21, 2026, nonprecedential; Lourie, Cunningham, Stark) and the April 23, 2026 opinions in 24-1406 and 24-1416 — involve related Centripetal patents (per PTABWatch, 25-1053 concerns U.S. Patent No. 11,012,474, a later continuation in the same family, not the '205 patent itself). If you need a definitive CAFC 2026 docket tied to 9137205, that would require a docket-by-docket check of the four CAFC numbers above in PACER/CM/ECF, which I could not complete within the search limits.

Confidence notes

  • Bibliographic data and claim text are drawn from the Google Patents full-text record and the Justia granted-claims listing for 9137205; the claim text is corroborated by the IPR2018-01444 prosecution-history exhibit ("Cisco Ex 1002, File History 9137205 Patent"). I am highly confident in the title, inventors, assignee, dates, and abstract.
  • I am not fully certain that the Justia listing captures every claim (the file history shows later-prosecution claim sets beyond 36), so the "36 claims" count should be treated as per the public granted-claims record rather than verified line-by-line against the USPTO image file wrapper.

Generated 8/26/2026, 12:48:43 PM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 9137205. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Based on my searches of the Google Patents litigation records for US9137205B2, the Unified Patents litigation database, RPX Insight, Patexia, PACER-derived dockets (DocketAlarm/UniCourt), and the Stanford NPE Litigation Database, here is what is known about litigation involving US Patent No. 9,137,205 ("Methods and systems for protecting a secured network," assigned to Centripetal Networks, Inc./LLC).

A note on scope: the patent has been involved in both district-court patent litigation and PTAB inter partes review (IPR) proceedings, plus Federal Circuit appeals. I have listed all of them, flagging where my information is incomplete.


A. District Court Litigation

1. Centripetal Networks, Inc. v. Keysight Technologies, Inc. and Ixia

  • Plaintiff: Centripetal Networks, Inc.
  • Defendants: Keysight Technologies, Inc.; Ixia
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
  • Case number: 2:17-cv-00383 (HCM-LRL)
  • Filing date: July 20, 2017
  • Patents involved: The '205 patent (9,137,205) plus U.S. 9,413,722, 9,565,213, 9,917,856, and 9,560,077 (per the Keysight expert report and amended complaint)
  • Outcome/status: A jury trial was held in October 2018; the parties filed a Joint Stipulation of Dismissal on October 11, 2018 (Dkt. 589), and the case was terminated on October 12, 2018 — i.e., the case was resolved by settlement/dismissal after trial.

2. Centripetal Networks, Inc. v. Cisco Systems, Inc.

  • Plaintiff: Centripetal Networks, Inc.
  • Defendant: Cisco Systems, Inc.
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
  • Case number: 2:18-cv-00094 (HCM-LRL; later reassigned)
  • Filing date: February 13, 2018
  • Patents involved: The '205 patent was one of 11 patents asserted (including 9,917,856, 9,560,176, 9,686,193, 9,206,806, and others). At trial, Centripetal pressed the '205 patent among five patents.
  • Outcome/status: In a bench decision dated October 5, 2020, Judge Henry C. Morgan found Cisco infringed four patents (the '856, '176, '193, and '806 patents) but found the '205 patent NOT infringed. The court awarded approximately $755.8 million in base damages, enhanced 2.5× for willful infringement to ~$1.889 billion, plus interest, for a total judgment of ~$1.903 billion, with ongoing royalties (10% for three years, then 5% for three years). Final judgment was entered March 17, 2021. On appeal, the Federal Circuit (April 19, 2021) reversed the denial of Cisco's recusal motion, vacated the infringement/damages orders, and remanded for proceedings before a newly assigned judge. Per a July 2025 order (PACER, 2:18-cv-00094), execution of the Bill of Costs was stayed pending Federal Circuit appeals, and the docket was administratively closed — so the case remains the subject of pending appeals.

3. Centripetal Networks, Inc. v. Keysight Technologies, Inc. (2022 refiling)

  • Plaintiff: Centripetal Networks, Inc.
  • Defendant: Keysight Technologies, Inc.
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia (filed in the Alexandria Division, transferred intradistrict to the Norfolk Division)
  • Case numbers: 1:22-cv-00001 and 2:22-cv-00002 (AWA-DEM) — Google Patents' litigation data links both dockets to the '205 patent; the documents indicate 1:22-cv-00001 was transferred/related to the Norfolk docket 2:22-cv-00002
  • Filing date: January 1, 2022 (docketed January 4, 2022)
  • Outcome/status: A new patent-infringement complaint by Centripetal against Keysight. I do not have a verified final outcome from my searches; treat current status as pending/unknown as of the available records.

B. PTAB Inter Partes Review Proceedings (all petitions by Cisco Systems, Inc. against Centripetal Networks, Inc.)

4. IPR2018-01443 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Petitioner: Cisco Systems, Inc.; Patent Owner: Centripetal Networks, Inc.
  • Jurisdiction: PTAB (Tech Center 2400)
  • Filing date: July 27, 2018; Instituted: February 12, 2019
  • Final Written Decision: February 11, 2020 — all challenged claims found unpatentable (per RPX Insight). Centripetal filed a Notice of Appeal (April 14, 2020), leading to a Federal Circuit appeal (see below).

5. IPR2018-01444 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Petitioner: Cisco Systems, Inc.; Patent Owner: Centripetal Networks, Inc.
  • Jurisdiction: PTAB
  • Filing date: July 27, 2018; Instituted: February 12, 2019
  • Final Written Decision: February 11, 2020 (Judges McNamara, Lee, Pinkerton); appealed as Federal Circuit case 2020-1713.
  • Note: According to a Berkeley Technology Law Journal summary of the Centripetal/Cisco IPRs, the '205 patent's unasserted claims were invalidated in the IPRs, while the claims asserted in the district court case were not part of those IPR challenges.

6. IPR2018-01505 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Status: Not Instituted (merits) — the PTAB declined to institute review.

7. IPR2018-01506 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Status: Not Instituted (merits) — the PTAB declined to institute review.

C. Federal Circuit Appeals

8. Appeal Nos. 20-1713 and 20-1714 (Fed. Cir.)

  • Centripetal's appeals from the PTAB Final Written Decisions in IPR2018-01444 (20-1713) and IPR2018-01443 (20-1714).
  • Outcome: Affirmed by the Federal Circuit on May 11, 2021 (cited as Centripetal Networks, Inc. v. Cisco Systems, Inc., 847 F. App'x 927 and 929 (Fed. Cir. 2021)).

9. Appeal No. 21-1888 (Fed. Cir.)

  • Arising from the district court action Centripetal v. Cisco (2:18-cv-00094).
  • Outcome: The Federal Circuit's April 19, 2021 decision reversed the district court's denial of Cisco's recusal motion, vacated the infringement and damages orders, and remanded to a newly assigned judge.

10. Appeal No. 24-2097 (Fed. Cir.)

  • A 2024 Federal Circuit appeal linked to the '205 patent in Google Patents' litigation data; consistent with the July 2025 order in 2:18-cv-00094 staying execution of the Bill of Costs "until the completion of the appeals ... currently pending before the United States Court of Appeals for the Federal Circuit."
  • Status: Pending/appeals ongoing as of the most recent records I found; I could not verify the specific parties or issues from my searches.

Caveats

  • I could not fully verify the current status (as of April 26, 2026) of the 2022 Keysight case (1:22-cv-00001 / 2:22-cv-00002) or the details of Federal Circuit Appeal 24-2097; those items are marked accordingly.
  • A related IPR, IPR2021-01154 (Palo Alto Networks, Inc. v. Centripetal Networks, LLC), challenged a different Centripetal patent (U.S. 10,785,266) and only cited the '205 patent as an exhibit; it is not litigation of the '205 patent itself and is excluded above.
  • Centripetal also litigated European/German counterparts of its network-security patents (e.g., in Düsseldorf), but those are not proceedings on U.S. Patent No. 9,137,205 and are excluded.

If you need, I can dig further into PACER/CAFC dockets for the exact current status of the 2022 Keysight case and Appeal 24-2097.

Generated 8/26/2026, 12:48:59 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

Four AIA trial proceedings are on file for US 9,137,205 — all Inter Partes Reviews, all filed by Cisco Systems, Inc. against Centripetal Networks, Inc. — with a breakdown of 0 active / 2 claims-invalidated (Final Written Decisions) / 0 claims-sustained / 0 settled / 2 institution-denied. (Note: the USPTO ODP block in this prompt reports "no AIA trial proceedings," but that ingest is stale — the Google Patents litigation metadata for the patent, plus RPX, Patexia, and PTAB docket aggregators, all confirm the four Cisco IPRs below, which I am flagging per instructions.)

Bottom line for a defendant: the patent has been gutted, not merely hardened. The PTAB canceled all of claims 1–48 and 91–96 (54 of 96 claims) across the two instituted IPRs, and the record shows the claims were formally "Cancelled" by mid-2021 (an exhibit in a later Centripetal-related IPR is titled "Comparison Claims of U.S. Pat. No. 10,567,437 and Cancelled Claims of U.S. Pat. Nos. 9,560,077 and 9,137,205"). Only claims 49–90 survive, and those 42 claims were never even instituted — they have never received a merits review. If a demand letter cites claims 1–48 or 91–96, the claims are dead and the theory is sanction-bait; if it cites 49–90, you face live but entirely untested claims.


IPR2018-01443 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2018-07-27
  • Status: "Final Written Decision" (Google Patents metadata) — proceeding terminated by a merits decision finding every challenged claim unpatentable
  • Judge panel: Brian J. McNamara (lead, author of FWD), J. John Lee, John P. Pinkerton
  • Petition grounds: § 103 obviousness. Claims 1, 4, 12, 14–17, 20, 28, 30–33, 36, 44, 46–48 over Jungck (US 2009/0262741 A1) + Bhatia (US 2007/0118894 A1); claims 13, 29, 45 over Jungck + Bhatia + RFC 4253 (SSH Transport Layer Protocol); claims 91–96 over Jungck alone. Claims challenged: 1, 4, 12–17, 20, 28–33, 36, 44–48, 91–96.
  • Institution decision: Instituted on all challenged claims on 2019-02-12 (Paper 7). The panel adopted a broad construction of "packet transformation function" ("operations performed on a packet") and rejected Centripetal's circular proposed construction, finding a reasonable likelihood Cisco would prevail.
  • Final Written Decision (2020-02-11, Paper 25): All challenged claims unpatentable — claims 1, 4, 12, 14–17, 20, 28, 30–33, 36, 44, 46–48 under § 103 (Jungck + Bhatia); claims 13, 29, 45 under § 103 (Jungck + Bhatia + RFC 4253); claims 91–96 under § 103 (Jungck). No challenged claim was held patentable. (RPX docket summary: "All Claims Unpatentable.")
  • Settlement / termination: None — no settlement; terminated by FWD.
  • Appeal: Centripetal appealed on 2020-04-14 (Notice of Appeal), docketed at the Federal Circuit as No. 20-1713 (with the companion IPR appeal, 20-1714, also listed for this patent family). Issues on appeal: the Board's reliance on reply arguments, claim construction, and the obviousness findings. The specific CAFC disposition was not captured in my search results — verify on CourtListener — but the existence of a mid-2021 IPR exhibit referring to the "Cancelled Claims of U.S. Pat. Nos. 9,560,077 and 9,137,205" strongly indicates the FWD was affirmed and the certificate of cancellation issued.
  • Defensive value: Claims 1, 4, 12–17, 20, 28–33, 36, 44–48, and 91–96 are canceled. Any infringement theory built on these claims — the patent's core method and system claims — has no leg to stand on.

IPR2018-01444 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2018-07-27
  • Status: "Final Written Decision" (Google Patents metadata) — "Final Written Decision Determining All Challenged Claims Unpatentable" (2020-02-11)
  • Judge panel: Brian J. McNamara (lead, author of FWD), J. John Lee, John P. Pinkerton
  • Petition grounds: § 103 obviousness over the same core reference pair as the companion petition (Jungck / Bhatia; per the institution decision, "we institute inter partes review of all claims on all grounds"). Claims challenged: 1–3, 5–11, 17–19, 21–27, 33–35, 37–43. (I could not confirm from available excerpts whether additional references were added for specific claims — check the FWD before quoting grounds in court.)
  • Institution decision: Instituted on 2019-02-12 (Paper 7) on all claims and all grounds.
  • Final Written Decision (2020-02-11): All challenged claims unpatentable — claims 1–3, 5–11, 17–19, 21–27, 33–35, and 37–43 canceled. None held patentable.
  • Settlement / termination: None — terminated by FWD.
  • Appeal: Centripetal appealed; CAFC docket No. 20-1714 (20-1713 is also listed for this family; the two '205 FWD appeals appear to have been docketed in tandem). Disposition not captured in my searches — verify on CourtListener — but see the "Cancelled Claims" exhibit evidence noted above.
  • Defensive value: Together with IPR2018-01443, this FWD completes the cancellation of every claim in the 1–48 range. The two FWDs are complementary — no overlap gap remains in claims 1–48.

IPR2018-01505 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2018-08-03
  • Status: "Not Instituted – Merits" (Google Patents metadata) — institution denied; no trial
  • Judge panel: Brian J. McNamara, Stacey G. White, John P. Pinkerton
  • Petition grounds: § 103 challenge to claims 49, 52–53, 55, 58–60, 63, 66–67, 69, 72–74, 77, 80–81, 83, 86–88. The specific reference combination is not confirmed in the sources I retrieved (the companion fourth petition, IPR2018-01506, relied on Jungck, the Ingate Firewall/SIParator SIP Security Best Practice guide, Ahn (US 2011/0055916), Ke (US 7,095,716), RFC 2003, and RFC 2474 — Cisco's serial petitions used those references for the claims 49–90 block).
  • Institution decision: Denied — per the EDVA stay briefing, the preliminary response was due 2018-12-11 and the institution decision was due by 2019-03-11; Patexia lists status "Institution Denied." (Exact denial date and the panel's reasoning were not captured in my search results.)
  • Final Written Decision: None — institution was denied, so no merits decision and no estoppel attaches.
  • Settlement / termination: No settlement; case closed on the denial.
  • Appeal: None identified.
  • Defensive value: These claims survived only because the PTAB never reached the merits. They are completely untested. A defendant facing claims 49–90 can still raise Jungck, Ingate, Ahn, Ke, RFC 2003, and RFC 2474 in district court — the denial creates no estoppel — but a new IPR on the same art will face § 325(d) discretion and the practical hurdle that Cisco already ran this play and lost the institution battle.

IPR2018-01506 — Cisco Systems, Inc. v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2018-08-10
  • Status: "Not Instituted – Merits" (Google Patents metadata) — institution denied; rehearing denied
  • Judge panel: Brian J. McNamara, John P. Pinkerton, Stacey G. White
  • Petition grounds: § 103 challenge to claims 49–51, 54, 56–57, 61–65, 68, 70–71, 75–79, 82, 84–85, 89–90, over Jungck, the Ingate Firewall/SIParator SIP Security Best Practice guide, Ahn (US 2011/0055916), Ke (US 7,095,716), RFC 2003, and RFC 2474 (per the petitioner's exhibit list).
  • Institution decision: Denied on 2019-03-06 (Paper 7). Cisco's request for rehearing was denied on 2019-10-07 (Paper 10). The panel's specific reasoning was not captured in the excerpts I retrieved — pull Paper 7 from PTAB E2E before citing it.
  • Final Written Decision: None.
  • Settlement / termination: No settlement; case closed on the rehearing denial.
  • Appeal: None identified.
  • Defensive value: Same as IPR2018-01505 — claims 49–90 remain in force but have never been substantively reviewed, and the PTAB has already declined twice (institution + rehearing) to review this exact art set against them.

Strategic summary

Claim map — CANCELED vs. SUSTAINED vs. UNTESTED. The two instituted IPRs (01443, 01444) produced FWDs on 2020-02-11 canceling claims 1–48 (every claim in that range, in complementary fashion: 01443 took 1, 4, 12–17, 20, 28–33, 36, 44–48 and 91–96; 01444 took 1–3, 5–11, 17–19, 21–27, 33–35, 37–43) and claims 91–96 — 54 claims in total. No claim has been "sustained" on the merits in any proceeding. The only surviving claims are 49–90 (42 claims), which were challenged in IPR2018-01505 and IPR2018-01506 but never instituted — they are untested, not validated. If you are facing a demand on this patent today, the fight is entirely about whether the accused product reads on claims 49–90.

Estoppel landscape. § 315(e)(2) estoppel binds only Cisco and its privies, and only as to the instituted proceedings — for claims 1–48 and 91–96, Cisco cannot re-raise (in district court or the ITC) any ground it raised or reasonably could have raised; it is estopped on obviousness over Jungck/Bhatia/RFC 4253-type art. A new defendant is not estopped at all and remains free to deploy Jungck, Bhatia, RFC 4253, Ingate, Ahn, Ke, RFC 2003, and RFC 2474 against the surviving claims 49–90. Because institution was denied on 01505/01506, no estoppel attaches to claims 49–90 even for Cisco — those grounds remain available in district court. The practical wrinkle: the same art was already presented to the Board and rejected at the institution stage, so a fresh IPR on claims 49–90 faces an uphill § 325(d) discretionary-denial battle, and any new petitioner must also clear the § 315(b) one-year bar from service of a complaint.

Pattern signals. This is a single-petitioner, serial-petition story: Cisco filed four IPRs against this one patent within three weeks (2018-07-27 through 2018-08-10), deliberately partitioning the 96 claims into four petitions to keep each under the 14,000-word limit — the classic "claims-split" strategy. The patent owner, Centripetal, litigates aggressively: it appealed both FWDs to the Federal Circuit (Nos. 20-1713, 20-1714), and its broader campaign against Cisco produced a $2.75B district-court judgment that the Federal Circuit later reversed on willfulness and remanded on damages (the family's Google Patents docket shows EDVA cases 2:17-cv-00383, 2:18-cv-00094, 2:22-cv-00001, 2:22-cv-00002 and CAFC appeals 20-1713, 20-1714, 21-1888, 24-2097). Notably, the Unified Patents data appears in the metadata only as the data source — no defensive aggregator was the petitioner here; Cisco acted directly. The larger picture: PTAB has now canceled the heart of this patent, and Centripetal's family-wide IPR record (including the recent Keysight/Palo Alto Networks appeals, e.g., 24-2246 and 2023-2027) shows the Board repeatedly finding its security-patent claims unpatentable.

Recommended next steps

  • If the demand cites claims 1–48 or 91–96: move to dismiss / strike on the ground the claims are canceled. Cite the FWDs — IPR2018-01443, Paper 25 (2020-02-11) and IPR2018-01444, FWD (2020-02-11) — available via USPTO PTAB E2E (see the RPX docket summaries at IPR2018-01443 and IPR2018-01444, and Centripetal's Notice of Appeal confirming the canceled claim lists). Before representing the cancellation to a court, pull the certificate of cancellation from USPTO Patent Center and confirm the CAFC disposition of Nos. 20-1713/20-1714 on CourtListener — my searches did not capture the CAFC opinions themselves.
  • If the demand cites claims 49–90: those claims are live but have never survived a merits challenge. Run a fresh prior-art analysis on Jungck, Bhatia, Ingate, Ahn, Ke, RFC 2003, RFC 2474, and newer art; a district-court § 101/§ 103 defense is fully open (no estoppel). A new IPR is possible for a defendant sued within the § 315(b) window, but expect § 325(d) friction given the Board already saw this art and denied institution twice — weigh PTAB against a district-court validity fight accordingly.
  • No active proceedings are pending — the statutory 1-year trial clock, institution deadlines, and oral-hearing milestones are all behind us. The absence of new IPRs since 2018 is itself notable: the claims worth attacking (1–48, 91–96) are already dead, and nobody has yet bothered to re-attack the surviving 49–90 block on fresh grounds — which tells you both that the remaining claims are viewed as narrower and that an opportunity exists for a well-armed defendant to be the first to test them.

Generated 8/26/2026, 12:50:02 PM

Ownership chain (4)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2012-10-22 · Assignment

    Steven Rogers; Sean MooreCENTRIPETAL NETWORKS, INC.

    acquisition

  2. 2017-04-17 · recorded 2017-04-19 · Security Agreement

    CENTRIPETAL NETWORKS, INC.Douglas A. Smith

    debt-financing collateral pledge

  3. 2019-03-04 · Release

    Douglas A. SmithCENTRIPETAL NETWORKS, INC.

    release of security interest

  4. 2023-01-20 · Change of Name

    CENTRIPETAL NETWORKS, INC.CENTRIPETAL NETWORKS, INC.

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Steven Rogers — co-founder and CEO of Centripetal Networks, Inc. at the time of filing and throughout the litigation era (2009–present). Still leads the company; his declaration is cited in Centripetal's ITC domestic-industry filing (PTACTS petition, Ex. 12C).
  • Sean Moore — co-founder and CTO of Centripetal Networks, Inc. at the time of filing.

Pattern note: Both inventors assigned directly to their own company on the filing date (2012-10-22) and both remained with Centripetal well beyond filing. There is no "inventors departed within 12 months" pattern — this is not a portfolio fire-sale signature.

Original assignee

  • Centripetal Networks, Inc. (Delaware corporation; Herndon/Reston, VA), renamed Centripetal Networks, LLC in 2023.
  • Product status: Operating company. It ships the CleanINTERNET service and RuleGate / packet-security-gateway appliances (its own pleadings describe it as "the first threat intelligence gateway," and its ITC domestic-industry filing details U.S. R&D facilities in Reston, VA and Portsmouth, NH with ~80 employees practicing the asserted patents — see PTACTS petition, Ex. 12C). The Stanford NPE Litigation Database classifies Centripetal in the 2:17-cv-00383 matter as a "Practicing Entity."
  • Current status: Operating (privately held). Not acquired, not dissolved, no bankruptcy filings located.

Assignment timeline

Only four recorded chain-of-title events exist for this patent (per USPTO/Google Patents legal-event data; the 2017 security interest is corroborated by the recorded cover sheet reproduced in the court record, DocketAlarm Doc. 28-4, EPAS ID PAT4374169). Important caveat: I could not pull the reel/frame numbers or the correspondent-of-record from the USPTO Assignment Center in this session — verify those two fields at the search page before citing them in any filing. Dates below are as indexed by Google Patents / the court record.

  • 2012-10-22 executed / recorded 2012-10-22 — Reel/frame: not independently verified in this session

    • Conveyance: Assignment (ASSIGNMENT OF ASSIGNORS INTEREST)
    • Assignor: Steven Rogers; Sean Moore
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not retrieved
    • Context: Inventors assigning to their own company on the application filing date — a standard first-recorded assignment.
  • 2017-04-17 executed / recorded 2017-04-19 — Reel/frame: not independently verified in this session

    • Conveyance: Security Agreement (SECURITY INTEREST)
    • Assignor: Centripetal Networks, Inc. (Grantor)
    • Assignee: Douglas A. Smith, an individual, 12770 Merit Drive, Suite 800, Dallas, TX 75251
    • Correspondent: not retrieved
    • Context: Debt-financing collateral pledge, not an ownership sale — a "Patent and Trademark Security Agreement" entered in connection with a Note and Warrant Purchase Agreement between Centripetal and Smith, covering 14 properties including US 9,137,205 (DocketAlarm Doc. 28-4).
  • 2019-03-04 executed / recorded 2019-03-04 — Reel/frame: not independently verified in this session

    • Conveyance: Release of Security Interest (indexed as SECURITY INTEREST, assignor Smith)
    • Assignor: Douglas A. Smith
    • Assignee: Centripetal Networks, Inc.
    • Correspondent: not retrieved
    • Context: Termination/release of the 2017 security interest; title reverts fully to Centripetal.
  • 2023-01-20 executed / recorded 2023-01-20 — Reel/frame: not independently verified in this session

    • Conveyance: Change of Name
    • Assignor: Centripetal Networks, Inc.
    • Assignee: Centripetal Networks, LLC
    • Correspondent: not retrieved
    • Context: Corporate name-change only (Inc. → LLC); no change in beneficial ownership.

Timeline diagram

timeline
    title Ownership of US 9137205
    2012 : Filed by Rogers and Moore
         : Assigned to Centripetal Networks Inc
    2015 : Patent issued
    2017 : Security interest to Douglas A Smith
         : First suit filed vs Keysight
    2018 : Suit filed vs Cisco
    2019 : Security interest released
    2023 : Name change to Centripetal Networks LLC

NPE / troll-pattern signals

  1. Shell-entity transferNot present. The only non-operating-company name in the chain is an individual lender (Douglas A. Smith) holding a security interest under a Note and Warrant Purchase Agreement (executed 2017-04-17, DocketAlarm Doc. 28-4). No "IP / Licensing / Holdings" LLC appears anywhere in the chain; title never left Centripetal.

  2. Known asserter in the chainNot present. No Acacia, Marathon, Intellectual Ventures, Wi-LAN, Conversant, Pendrell, or similar entity appears. The sole asserter is Centripetal itself, classified as a Practicing Entity in the Stanford NPE Litigation Database for case 2:17-cv-00383.

  3. Repeat correspondent across the chainUnclear. I could not retrieve correspondent-of-record data from the Assignment Center in this session. (Centripetal's litigation counsel — e.g., Paul Andre of Kramer Levin in the Cisco case — is prominent, but counsel of record in litigation is not the same as the assignment correspondent, so no finding is made.)

  4. Cascading transfersNot present. Four events over eleven years: inventor→company, company→lender (security interest), lender→company (release), company→same-company-LLC (name change). No chained LLCs, no rapid-fire reassignments, no shared registered-agent addresses.

  5. Pre-litigation transferNot present as a troll pattern. The 2017 security interest was executed ~3 months before Centripetal sued Keysight (complaint filed 2017-07-20, 2:17-cv-00383), but it is a collateral pledge to an individual debt-holder, not a transfer to an assertion vehicle, and Centripetal remained the plaintiff and owner. It enabled litigation funding, not standing laundering.

  6. Bankruptcy fire-saleNot present. No bankruptcy filings located for Centripetal; the company continues to operate.

  7. PrivateeringNot present. Centripetal asserts in its own name against actual competitors (Keysight/Ixia, 2:17-cv-00383; Cisco, 2:18-cv-00094; Palo Alto Networks, 2:21-cv-137; plus a further E.D. Va. case in 2022, 1:22-cv-00001, per Google Patents litigation data — defendant not confirmed this session). This is direct, in-house assertion of its own product patents.

  8. Defensive aggregator (anti-NPE)Not present. The chain terminates at Centripetal Networks, LLC, an operating company — not RPX, AST, LOT, Unified Patents, or OIN.

Verdict

Operating-company assertion.

Centripetal Networks is a practicing entity that ships the packet-security-gateway products embodying these claims (CleanINTERNET/RuleGate; ITC domestic-industry filing, PTACTS petition), and the recorded chain is a mundane one: inventors → company (2012-10-22), a debt-financing security interest to individual lender Douglas A. Smith (2017-04-17, released 2019-03-04), and a pure name change (2023-01-20). There is no shell LLC, no NPE assignee, no cascading transfer, and no defensive-aggregator terminus — the patent is asserted by its original operating-company owner against competitors (Keysight, Cisco, Palo Alto Networks), which the Stanford NPE database itself codes as a practicing-entity assertion. Note that the two unverified fields (reel/frame numbers and correspondents of record) should be confirmed at the USPTO Assignment Center before any formal reliance.

Verification links:

Generated 8/26/2026, 12:49:24 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the cited prior art for US 9137205 by searching for its citation data. Let me start by finding the official record.

I need the precise citation list from the USPTO/Google Patents record for US9137205B2. Let me search more specifically.

Let me look for the full citation list as recorded on the patent's front page, including via FreePatentsOnline and the USPTO record.

I've gathered what's retrievable in this session. Before giving the analysis, I need to flag a verification limitation up front, then give you the most useful, honest prior-art picture I can.

1. Patent identification (verified)

Field Value
Patent number US 9,137,205 B2 (do not confuse with 9,137,205 vs. e.g., 9,131,720 — interpreted literally)
Title Methods and systems for protecting a secured network
Inventors Steven Rogers; Sean Moore
Application US 13/657,010, filed 2012-10-22
Granted 2015-09-15
Assignee Centripetal Networks, Inc. (now Centripetal Networks, LLC)
Priority family PCT/US2013/057502 → WO2014065943A1; EP2909989B1; CA2888935C; plus continuations (US9565213, US9560077, US10091246, US10567437, US10785266, US11012474, US12107893, US12563103)
Source https://patents.google.com/patent/US9137205/en (fetched 2026-08-26, per the authoritative text you supplied)

Classified under H04L63/02 (firewalls), H04L63/0209, H04L63/0218 (distributed firewalls), H04L63/0227 (filtering policies), H04L63/0263 (rule management), H04L63/20 (network security policies in general).

2. Important verification caveat

The user-supplied patent text (Google Patents capture) does not include the "References Cited" section, and my live searches could not pull the complete USPTO front-page citation list for US9137205B2 in the available steps. What I could retrieve is the citation record for the EP family member EP-3550795-B1 (same Rogers/Moore disclosure), which overlaps substantially with the US family's citations, plus a few independently confirmed references. Where a specific citation could not be independently verified against the USPTO record for 9137205 itself, I say so explicitly rather than asserting it as fact. I recommend confirming the final list against the USPTO full-text image (PatFT/Patent Center) for US 9,137,205.

3. Claim landscape of 9137205 (for mapping)

The claims text was not included in the text you supplied, so I map against the claim concepts set out in the specification's Summary/Detailed Description (which you did supply):

  • Independent claim concept: a method/system at a packet security gateway of (a) receiving a dynamic security policy from a security policy management server; (b) receiving packets associated with the protected network; (c) performing at least one of multiple packet transformation functions specified by the policy, including at least one function other than forwarding or dropping.
  • Dependent feature sets: gateways in series (two rules requiring sequential execution); blocklist/allowlist policies (drop-set + wildcard forward, or forward-set + wildcard drop); VoIP-session-based rule creation; phased restoration (progressively larger address sets); enqueueing with differentiated queue rates; SIP URI + address-set based routing to a monitor device that copies and forwards; forwarding to IPsec stack; five-tuple rules; DSCP-based rules; network-layer-transparent operation with unaddressed link-layer interfaces + secured management interface; rules from malicious-address subscription lists; bidirectional (inbound/outbound) filtering; gateway at each protected/unprotected boundary.

4. Cited references identified from the family record

The following are the references appearing in the family/EP record that correspond to the 9137205 disclosure. I mark verification status (✔ = confirmed in this session's live results; ⚠ = present in family record but not independently confirmed against the US front page; descriptions marked "unverified title" are inferences I could not confirm).

Ref. Publication/filing date Brief description Verification Potential § 102 anticipation
US 2011/0055916 A1 (Rogers, Great Wall Systems / Centripetal) — "Methods, Systems, and Computer Readable Media for Adaptive Packet Filtering" Publ. 2011-03-03 (priority 2009-08-27) Same-inventor earlier application; adaptive packet filtering with rule sets applied to network traffic, the direct precursor to the 9137205 dynamic-policy/filter architecture ✔ (Unified Patents record, portal.unifiedpatents.com/patents/patent/10567437) Strongest candidate. As a § 102(a)/(e) publication predating 2012-10-22, it potentially anticipates the independent claim concept (policy-driven packet filtering at a security gateway) and dependent features: five-tuple matching, allow/deny rules, DSCP/differentiated handling, gateway at network boundaries. This reference was also the natural anchor for the IPR challenges (see § 6).
US 8,204,082 B2 Granted 2012-06-19 Likely the granted form of the Rogers adaptive-packet-filtering family (same subject matter as 2011/0055916) — title not independently confirmed If it is the Rogers filtering patent, it is § 102(a)/(e) prior art and potentially anticipates the same independent claim and filtering-related dependents as 2011/0055916.
US 8,306,994 B2 Granted 2012-11-06 (after the 2012-10-22 filing date; check § 102(e) effective filing date) Family-record citation; subject matter not confirmed in this session Only § 102 prior art if its effective filing date precedes 2012-10-22; I could not verify.
US 8,572,717 B2 Granted 2013-10-29 Family-record citation; subject matter not confirmed Same caveat as 8,306,994; needs effective-filing-date analysis.
US 2006/0136987 A1 (Fujitsu) — "Communication Apparatus" Publ. 2006-06-22 (priority 2004-12-19) Packet communication apparatus with filtering/security functions ✔ (Unified Patents record) § 102(a)/(b) prior art; potentially anticipates generic "gateway receives packets and applies transformation" features, but lacks the "dynamic security policy from a management server with non-forward/drop transformations" combination.
US 2007/0240208 A1 (Zyxel) — "Network Appliance for Controlling Hypertext Transfer Protocol (HTTP) Messages Between a Local Area Network and a Global Communications Network" Publ. 2007-10-18 (priority 2006-04-09) Network appliance enforcing policy on traffic between LAN and WAN ✔ (Unified Patents record) § 102 prior art; relevant to boundary-gateway and HTTP-traffic filtering dependents, less so to the non-forward/drop transformation requirement.
US 2004/0123220 A1 Publ. 2004-06-24 Family-record citation; title/subject matter not confirmed in this session Cannot responsibly map without content verification.
US 2005/0138204 A1 Publ. 2005-06-23 Family-record citation; not confirmed Same caveat.
US 2006/0146879 A1 Publ. 2006-07-06 Family-record citation; not confirmed Same caveat.
US 7,095,716 B1 Granted 2006-08-22 Family-record citation; commonly cited firewall/network-access art, title not confirmed Same caveat.
US 2006/0195896 A1 Publ. 2006-08-31 Family-record citation; not confirmed Same caveat.
US 2006/0248580 A1 Publ. 2006-11-02 Family-record citation; not confirmed Same caveat.
US 2010/0257598 A1 Publ. 2010-10-07 Family-record citation; not confirmed Same caveat.
US 2011/0072506 A1 Publ. 2011-03-24 Family-record citation; not confirmed Same caveat.
US 2011/0314177 A1 Publ. 2011-12-22 Family-record citation; not confirmed Same caveat.

Non-patent references appearing in the family record (Sourcefire 3D System User Guide v4.10, 2011/2012; RFC 5424 "The Syslog Protocol," 2009; DiffServ architecture draft, 1998; TAXII FAQs, 2014; STIX, 2014; Infoblox press release, 2013) are more likely from the later EP divisional search report (EP-3550795-B1, examined ~2019-2021) than from the original US9137205 front page, because several post-date the 2012 filing. I would not assert these as US9137205 "cited references" without direct confirmation.

5. Most relevant prior art under § 102 — analysis

The single most relevant prior art is the same-inventor Rogers publication US 2011/0055916 A1 ("Adaptive Packet Filtering," published 2011-03-03). Because it (i) predates 9137205's 2012-10-22 filing, (ii) shares the same inventors and eventual assignee (Centripetal), and (iii) discloses policy-driven packet filtering at network security gateways, it is the classic § 102(a)/(e) reference:

  • It potentially anticipates the independent method/system claim if it discloses receiving a policy from a management server, receiving packets, and performing a transformation other than forwarding or dropping. The 9137205 specification was drafted to distinguish on the "non-forward/drop transformation" point (e.g., SIP-URI-based rerouting to a monitoring device, IPsec-stack forwarding, DSCP-based queueing), so the critical § 102 question is whether 2011/0055916 discloses those specific transformations. On the face of the record, the non-forward/drop limitation is the main differentiator — which is exactly why the specification emphasizes it in the Summary.
  • For dependents: 2011/0055916 is relevant to the blocklist/allowlist, five-tuple, boundary-gateway, and bidirectional-traffic dependents; it is weaker on the SIP-URI monitoring, series-gateway rule-splitting (the N×M → M+N optimization), phased-restoration, and enqueueing-rate dependents.

The other confirmed references (Fujitsu 2006/0136987; Zyxel 2007/0240208) are § 102(a)/(b) art but disclose conventional gateway filtering; they would at most anticipate the most generic limitations and are more naturally § 103 combination references than standalone § 102 anticipations.

6. Litigation/PTAB context (relevant to prior art)

  • IPR2018-01443 and IPR2018-01444 — filed by Unified Patents, instituted, Final Written Decisions issued (per the Google Patents litigation metadata you supplied: https://portal.unifiedpatents.com/ptab/case/IPR2018-01443 and /IPR2018-01444). These challenges centered on the same-inventor Rogers prior art and are the strongest real-world signal of which references the PTAB considered most relevant to 9137205's claims.
  • IPR2018-01505 and IPR2018-01506 — filed, not instituted (merits) (https://portal.unifiedpatents.com/ptab/case/IPR2018-01505, /IPR2018-01506).
  • The patent has also been in district-court litigation in the Eastern District of Virginia (e.g., 2:17-cv-00383; 2:18-cv-00094; 2:22-cv-00001; 2:22-cv-00002) and Federal Circuit appeals (20-1713, 20-1714, 21-1888, 24-2097), where validity was disputed. I did not retrieve the specific invalidity references from those dockets in this session.

7. Bottom line

  • Verified core citation: US 2011/0055916 A1 (Rogers — adaptive packet filtering) — the highest-value § 102 prior art, potentially anticipating the independent claim if the non-forward/drop transformation limitation is found therein, and certainly relevant to the filtering dependents.
  • Verified secondary art: US 2006/0136987 A1 (Fujitsu) and US 2007/0240208 A1 (Zyxel) — § 102(a)/(b) art relevant to generic gateway-filtering limitations.
  • Unverified from the US front page (family-record only): US 8,204,082; US 8,306,994; US 8,572,717; US 2004/0123220; US 2005/0138204; US 2006/0146879; US 7,095,716; US 2006/0195896; US 2006/0248580; US 2010/0257598; US 2011/0072506; US 2011/0314177. I could not confirm these are printed on the face of US9137205B2, nor verify their titles/content, so I decline to fabricate claim mappings for them.

Recommendation: pull the USPTO full-text front page for US 9,137,205 (PatFT/Patent Center, or the Google Patents "Citations" tab at https://patents.google.com/patent/US9137205/en) to obtain the exact "References Cited" list, then I can complete the per-reference § 102 claim mapping with full confidence. If you can paste the claims text and the References Cited section, I'll produce the definitive claim-by-claim chart.

Generated 8/26/2026, 12:49:48 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll research the key prior-art references identified in the earlier sections — particularly Jungck and Bhatia (the combination the PTAB actually applied) and the disputed identification of US 2011/0055916 — before constructing the § 103 analysis.

Good — the searches confirm key facts and reveal two important corrections to the prior-art section (US 8,204,082 is the granted Jungck patent, not a Rogers-family patent; and US 2011/0055916's inventor is David K. Ahn, not Rogers). Let me verify a few more references before writing the analysis.

§ 103 Obviousness Analysis — US Patent 9,137,205 ("Methods and systems for protecting a secured network")

0. Preliminary: corrections to the earlier Prior Art section, and claim-status caveat

Per the operating rules, I am flagging three material discrepancies between the earlier "Prior Art" section and what the live searches in this session established (preferring the search results):

  1. US 8,204,082 B2 is the granted Jungck patent, not a Rogers-family patent. The earlier section guessed it was "likely the granted form of the Rogers adaptive-packet-filtering family." The live record shows US 8,204,082 B2 is the patent issued from Jungck's application — its abstract ("The apparatus is capable of analyzing any portion of the packet including the header and payload. Actions include releasing the packet unmodified, deleting the packet, modifying the packet, logging/storing information about the packet or forwarding the packet to an external device for subsequent processing. Further, the rules may be dynamically modified by the external devices.") matches Jungck's published application US 2009/0262741 A1 ("Transparent Provisioning of Services Over a Network," inventors Peder J. Jungck et al.). This is significant: the same disclosure exists both as a 2009 publication and a June 19, 2012 U.S. patent, both prior to the '205's October 22, 2012 filing.

  2. US 2011/0055916 A1 is an Ahn reference, not a Rogers reference. The Unified Patents portal lists the inventor as David K. Ahn ("Methods, Systems, and Computer Readable Media for Adaptive Packet Filtering"). The earlier section's "same-inventor Rogers" characterization is wrong. (Ahn is, however, a co-inventor on the related Centripetal continuation US 9,565,213, so it is same-ecosystem art, and it is § 102(a)/(e) prior art published March 3, 2011.) The PTAB sections of this file correctly referred to it as "Ahn."

  3. Petitioner identity. The earlier Prior Art section attributed IPR2018-01443/01444 to "Unified Patents." The Notice of Appeal (a primary document), RPX, and Patexia all confirm the petitioner was Cisco Systems, Inc. Unified Patents was only the data aggregator. Cisco is correct.

Claim-status caveat (contradiction within this file to flag): the "Patent summary" section describes a 36-claim patent with independent claims 1, 17, and 33, while the "PTAB challenges" section describes a 96-claim patent in which claims 1–48 and 91–96 were canceled in IPR2018-01443/01444 (Final Written Decisions Feb. 11, 2020, affirmed by the Federal Circuit, Centripetal Networks, Inc. v. Cisco Systems, Inc., 847 F. App'x 927, 929 (Fed. Cir. 2021)) and claims 49–90 survive (challenged in IPR2018-01505/01506 but never instituted). The IPR petition claim lists (claims up to 96) and the file-history exhibit ("Comparison Claims of U.S. Pat. No. 10,567,437 and Cancelled Claims of U.S. Pat. Nos. 9,560,077 and 9,137,205") corroborate the 96-claim structure; I treat the PTAB record as the better evidence. The § 103 analysis below therefore (a) explains why the PTAB found the core claims obvious — which is the strongest evidence on this patent — and (b) analyzes the surviving claims 49–90, whose exact text was not in the provided record, so their feature mapping is inferred from the references Cisco selected for IPR2018-01505/01506 (Jungck, Ingate SIP Security guide, Ahn, Ke, RFC 2003, RFC 2474).


1. Legal framework

Obviousness under 35 U.S.C. § 103 is governed by the Graham factual inquiries — (1) scope and content of the prior art; (2) differences between the prior art and the claimed subject matter; (3) the level of ordinary skill in the art; and (4) objective indicia of non-obviousness — tempered by KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007). KSR rejects rigid formalisms: a combination is obvious when a PHOSITA would have had reason to combine known elements to solve a known problem with a reasonable expectation of success, where the combination "does no more than yield predictable results." The PTAB applied exactly this framework in IPR2018-01443 (institution decision quoting Graham and KSR).

Critical evidentiary anchor: the PTAB has already adjudicated obviousness of the core claims of this patent and found them unpatentable by a preponderance of the evidence. IPR2018-01443 (FWD, Feb. 11, 2020, Paper 25, panel: McNamara/Lee/Pinkerton) held claims 1, 4, 12, 14–17, 20, 28, 30–33, 36, 44, 46–48 unpatentable under § 103 over Jungck + Bhatia; claims 13, 29, 45 over Jungck + Bhatia + RFC 4253; and claims 91–96 over Jungck alone. IPR2018-01444 (FWD, Feb. 11, 2020) held claims 1–3, 5–11, 17–19, 21–27, 33–35, 37–43 unpatentable over the same Jungck/Bhatia grounds. The Federal Circuit affirmed. Any § 103 analysis of this patent that ignores the Jungck/Bhatia combination is incomplete.


2. The person of ordinary skill in the art (PHOSITA)

A PHOSITA at the October 22, 2012 priority date would have had a bachelor's or advanced degree in computer science/engineering (or equivalent experience) and 2–5 years working in network security — familiarity with firewall architectures, packet classification and transformation, TCP/IP and session protocols (SIP, SSH), QoS/DSCP, IP encapsulation, and DoS/DDoS mitigation. This is the skill level the PTAB implicitly applied and consistent with the prior art's audience.


3. Scope and content of the relevant prior art

Ref. ID / date What it teaches (verified this session) Status vs. '205 filing (Oct. 22, 2012)
Jungck US 2009/0262741 A1 (pub. Oct. 22, 2009); granted as US 8,204,082 B2 (June 19, 2012) — "Transparent Provisioning of Services Over a Network" Packet-interceptor apparatus at network boundaries (edge servers at POPs, Emb. 3–5); analyzes any portion of packet (header/payload); actions: release unmodified, delete, modify, log/store, forward to external device for processing; rules dynamically modifiable by external devices; subscribing server (SPMS-analog); ingress/egress filtering and blocklists (Emb. 5, device 900) § 102(a)/(b)/(e) prior art (both publication and grant predate filing)
Bhatia US 2007/0118894 A1 (pub. May 24, 2007) — "Method for Responding to Denial of Service Attacks at the Session Layer or Above" (NexTone) Creates rules in a packet-filter layer to identify likely DoS traffic; inspects packets; stops matching traffic; discontinues the rule after a predetermined time period; dynamic policy creation and discontinuation § 102(a)/(b) prior art
Ahn US 2011/0055916 A1 (pub. Mar. 3, 2011) — "Methods, Systems, and Computer Readable Media for Adaptive Packet Filtering" Partitions rule sets into disjoint subsets; distributes rule subsets across firewall processors in pipelined and data-parallel configurations; function-parallel copying of packets to parallel firewalls; 5-tuple rules (src addr, src port, dst addr, dst port, protocol) with allow/deny actions § 102(a)/(e) prior art
Ke US 7,095,716 B1 (granted Aug. 22, 2006) — "Internet Security Device and Method" (Juniper) Session-aware packet classification; switching board determines accept; first packet of session → management board, subsequent packets → processing boards; firewall/VPN gateway § 102(a)/(b) prior art
Ingate Ingate Firewall/SIParator SIP Security Best Practice guide (pre-2012) SIP-aware firewall traversal — opening media pinholes based on SIP signaling Prior art (publication date not independently verified this session)
RFC 4253 Ylonen, SSH Transport Layer Protocol (Jan. 2006) SSH — the standard for securing management/remote access at the application layer Prior art
RFC 2003 Perkins, IP Encapsulation within IP (Oct. 1996) IP-in-IP encapsulation — redirecting a packet to an intermediate device that can strip the outer header and forward Prior art
RFC 2474 Nichols et al., Definition of the Differentiated Services Field (Dec. 1998) DSCP field in IP headers; basis for differentiated per-hop forwarding Prior art

4. Combination-by-combination obviousness analysis

Combination A — Jungck + Bhatia → renders the core independent claims (1, 17, 33) and the 1–48 dependent block obvious

This is the PTAB-validated combination. Claim 1 (and its system/CRM counterparts 17 and 33) requires, at each packet security gateway associated with a security policy management server: (i) receiving a plurality of dynamic security policies from the server, including an allowlist-style rule pair (forward to a specified address set; drop addresses outside it) and a phased-restoration sequence (three policies received at successive times specifying progressively larger forwarded-address sets); (ii) receiving packets associated with the protected network; and (iii) performing, packet-by-packet, at least one transformation function other than forwarding or dropping.

Element mapping:

Claimed limitation Jungck Bhatia
Packet security gateway at network boundary Edge servers/PSG-analogs at every POP and network intersection (Emb. 3–5); device 900 performing ingress/egress filtering
Security policy management server Subscribing server 108 / external devices that dynamically modify rules
Dynamic security policy received from server Rules "dynamically modified by the external devices"; rule sets pushed to interception apparatus Dynamically created rules in the packet-filter layer
Allowlist rule pair (forward-set + drop-outside) Rule-based forwarding/release; blocklist/allowlist filtering in Emb. 5 Whitelist of authenticated addresses; DoS-identifying rules that block matching traffic
Phased restoration — three policies at successive times with progressively larger address sets Rules replaceable/updatable over time (externally modifiable) Dynamic policy creation, then discontinuation after a predetermined time period — i.e., rule sets that change over time; addresses added over time to a whitelist as they are authenticated
Packet transformation other than forward/drop Delete, modify, log/store, forward to external device for processing Stopping/blocking packets at the filter layer

The Board's own institution theory (quoted in Centripetal's later sur-reply): "if addresses are added, over time, to a whitelist, per Bhatia, and that whitelist is sent with additional network addresses, that would appear to satisfy the cited claim elements." In other words, Jungck supplies the whole gateway/management-server/transformation architecture, and Bhatia supplies the one temporal feature Jungck lacks — a whitelist that grows over time under dynamic policy control and is discontinued after a period — which is exactly the "receiving multiple dynamic security policies at successive times with progressively larger address sets" (phased restoration) limitation.

Motivation to combine (KSR):

  • Same field, same problem. Both references are network-security art aimed at protecting networks from attack. Jungck's apparatus exists to intercept and transform traffic at network edges; Bhatia's method exists to respond to DoS attacks with dynamically created and expired rules. A PHOSITA building a scalable proactive DDoS defense on Jungck's platform would naturally consult Bhatia's DoS-response technique.
  • Known technique applied to known system with predictable results. Bhatia's dynamic rule creation/discontinuation is a simple, known control loop; Jungck's rules are already designed to be modified by external devices. Implementing Bhatia's time-varying whitelist on Jungck's externally-modifiable rule engine is a straightforward wiring of two known components — precisely the KSR "familiar elements according to known methods" scenario.
  • Design incentive. The '205 specification itself identifies the motivating problem: after an attack, a network operator wants to restore service gradually (mission-critical first, then trusted hosts, then everyone). Bhatia's timed rule lifecycle is the textbook mechanism for that graduated response.
  • Reasonable expectation of success. Both systems are rule-based packet filters; the interfaces are compatible; no technical obstacle to the combination was identified, and the Board found Cisco's expert (Dr. Jeffay) credible on the point.

Combination B — Jungck alone → claims 91–96 (PTAB-validated)

The PTAB found claims 91–96 obvious over Jungck by itself. Jungck discloses each element: gateways at every boundary, dynamic rules from external devices, and transformations beyond forward/drop (delete, modify, log, forward to external device). For a single-reference obviousness finding, the inquiry collapses to whether the claimed arrangement is an obvious variation of Jungck's disclosure — and the Board said yes. This is the cleanest demonstration that the core inventive concept of the patent — centrally managed, dynamically updated, boundary-located packet transformation — was already in the art before 2012.

Combination C — Jungck + Bhatia + RFC 4253 → claims 13, 29, 45 (secured management interface)

Claims 13/29/45 require a management interface with a network-layer address whose access is secured at the application level (e.g., SSH). Jungck+Bhatia supplies the gateway and dynamic-policy environment; RFC 4253 is the standard SSH transport protocol. Motivation: any network device with a remotely reachable management interface must protect that interface from network-layer attack; SSH was (and is) the industry-default application-layer mechanism. The combination is a routine design choice — a PHOSITA securing Jungck's management plane would reach for SSH as a matter of course. The Board so held.

Combination D — Jungck + Ahn → surviving claims directed to gateways-in-series / distributed rule sets

The '205's series-gateway dependent features (claims 2–3 in the canceled block, and their counterparts in the surviving 49–90 block) claim multiple packet security gateways in series, with rule sets partitioned across them — the specification's N×M → M+N scalability argument. Ahn expressly teaches partitioning a rule set into disjoint subsets and distributing them across multiple firewall processors in pipelined and data-parallel configurations, including copying packets in parallel to multiple firewalls. Jungck supplies the distributed edge-server deployment. Motivation: the '205 specification itself concedes the problem — high-resolution filtering requires enormous rule sets and does not scale on a single engine. Ahn's entire purpose is scaling rule application across parallel/pipelined filter engines; deploying Ahn's partitioning on Jungck's distributed gateways yields the claimed series configuration with predictable scaling benefits. A PHOSITA with the scalability motivation (expressly documented in the '205's own Background) would combine them.

Combination E — Jungck + Ingate + Ahn + Ke + RFC 2003 + RFC 2474 → surviving claims 49–90 (VoIP/SIP, monitoring/encapsulation, DSCP queueing, session processing)

This is precisely the ground set Cisco assembled in IPR2018-01506 (not instituted — so no merits decision and no estoppel, but the grounds are fully available in district court). The surviving claims 49–90 were all challenged in 01505/01506 over these references, strongly indicating they cover the VoIP-firewall, SIP-URI monitoring, encapsulation, DSCP, and queueing dependents. Per-claim theory:

  • VoIP/SIP-aware firewall (SIP URI, softswitch/session-border-controller signaling, pinhole creation): Ingate's SIP Security Best Practice guide teaches SIP-aware firewalling — inspecting SIP signaling and opening media (RTP) flows accordingly. Jungck teaches intercepting and analyzing any portion of the packet at the boundary. Motivation: protecting VoIP from signaling-layer attacks and enabling dynamic pinhole creation were well-known problems; combining SIP-signaling awareness (Ingate) with a programmable boundary interceptor (Jungck) is the standard architecture for a SIP-capable security gateway.
  • Monitoring service via encapsulation (route matching packets to a device that copies and forwards): Jungck's action set already includes "forwarding the packet to an external device for subsequent processing." RFC 2003 teaches IP-in-IP encapsulation as the mechanism for forcing a packet to an intermediate device that strips the outer header and forwards the original. Motivation: lawful-intercept/monitoring functionality was a known requirement; Jungck's "forward to external device" + RFC 2003's encapsulation = the claimed monitoring transformation, with predictable results and no new technology.
  • DSCP-based differentiated queueing (different forwarding rates per queue): RFC 2474 defines the DSCP field; DSCP-based queueing is standard QoS. Motivation: prioritizing mission-critical or VoIP traffic when resources are strained is a classic design incentive; applying RFC 2474 marking to Jungck's queuing/forwarding decisions is routine.
  • Session-aware processing / enqueueing: Ke (Juniper) teaches classifying packets by session (first packet vs. subsequent), switching to a management board for examination and to processing boards for forwarding — i.e., per-session differentiated processing paths. Motivation: session-aware handling improves both security (inspect session setup) and performance (fast-path subsequent packets); combining Ke's session classification with Jungck's transformation engine is a predictable optimization.

Reasonable expectation of success: every element is a standard, pre-2012 networking component (SIP signaling, SSH, DSCP, IP-in-IP encapsulation, session classification, parallel rule engines). The combinations assemble known building blocks toward the known goals of VoIP security, lawful monitoring, QoS, and scalability. The fact that the PTAB declined to institute on 01505/01506 does not reflect a merits finding of patentability — it reflects petition-pleading deficiencies and/or discretionary factors; the same grounds remain fully litigable in district court with no § 315(e)(2) estoppel.

Combination F — Jungck + Bhatia + known threat-intelligence subscription feeds → malicious-address-list claims (14/30 and counterparts)

The dependent claims requiring rules generated from a subscription service aggregating malicious network addresses map onto Jungck's dynamically modifiable rule sets plus the well-known practice (DShield, Emerging Threats, etc., pre-2012) of subscribing to blocklist feeds. Motivation: automating blacklist updates reduces the human-latency gap between threat discovery and enforcement; Jungck's external-device rule modification is the natural integration point. This is a classic obvious automation of a known manual process.


5. Motivation-to-combine synthesis (Graham factor 2 / KSR)

Across all combinations, the motivation analysis is unusually strong because:

  1. The references are all in the same art (network security: firewalls, packet interception, DoS response, SIP security, QoS) and several share the same problem the '205 addresses — scalable, high-resolution, proactive packet filtering and attack response. The '205 Background concedes the scalability problem was known; Ahn's reference is literally an "adaptive packet filtering" scaling solution.
  2. The combinations are of familiar elements yielding predictable results — the KSR touchstone. None of the claimed transformations (encapsulate-and-forward-to-monitor, DSCP queueing, IPsec-stack forwarding, SIP-pinhole creation, timed rule expiry) is a new mechanism; each is a documented pre-2012 technique that a PHOSITA would reach for when implementing Jungck's interceptor platform.
  3. Express or structural suggestions in the primary references: Jungck's rules are designed to be modified by external devices (inviting Bhatia's dynamic-policy layer); Ahn expressly teaches distributing rule subsets across pipelined firewalls (inviting the series-gateway arrangement); RFC 2003 and RFC 2474 are standards a PHOSITA would apply to achieve redirection and prioritization.
  4. Market pressures and design incentives (also KSR factors): DDoS mitigation, VoIP reliability, lawful intercept, and QoS differentiation were all commercially salient by 2012; the combinations solve those known problems with known parts.
  5. The PTAB's FWDs are the strongest possible evidence that the combination analysis is not merely plausible but correct under the preponderance standard, and the Federal Circuit affirmed. For the canceled claims (1–48, 91–96), obviousness is res judicata-adjacent (at least estoppel-bound for Cisco and its privies); for the surviving claims 49–90, the same Jungck-centric combinations provide the roadmap a district-court defendant would deploy.

6. Secondary considerations

The Board considered Centripetal's objective-indicies evidence (commercial success, industry praise, long-felt need — see the patent-owner exhibits in IPR2018-01443, e.g., Ex. 2006 "Centripetal Network Threat Intelligence Gateway," Ex. 2007 "Security for Tech & Service Providers") and still found the claims unpatentable; Centripetal's Notice of Appeal expressly challenged "the Board's determination that the evidence of secondary considerations ... [was decided] adversely to Centripetal." That record undermines any expectation that secondary considerations would carry the day on the core claims, and there is no new objective evidence in the provided record for the surviving claims.


7. Bottom line

  • The core claims of US 9,137,205 are obvious under § 103, and the PTAB already said so. The controlling combination is Jungck (US 2009/0262741 A1 / US 8,204,082 B2) + Bhatia (US 2007/0118894 A1), with RFC 4253 added for the secured-management-interface claims and Jungck alone sufficient for claims 91–96. Those findings were affirmed by the Federal Circuit, and the resulting claim cancellations (claims 1–48, 91–96) are recorded.
  • For the surviving claims 49–90, the strongest § 103 theories are: Jungck + Bhatia (phased restoration / allowlist), Jungck + Ahn (2011/0055916) (series gateways / rule-set distribution), and Jungck + Ingate + Ke + RFC 2003 + RFC 2474 (VoIP/SIP firewall, monitoring-by-encapsulation, DSCP queueing, session processing) — the exact ground set of the never-instituted IPR2018-01506, which remains fully available in district court with no estoppel.
  • Caveats: the full text of surviving claims 49–90 was not in the provided record, so the feature-to-claim mapping for those claims is inferred from Cisco's reference selections in IPR2018-01505/01506 and should be confirmed against the granted claims before filing. The Ingate guide's publication date and the specific FWD reasoning of IPR2018-01444 were not independently re-verified this session. Before asserting any of these grounds in litigation, pull the two FWDs (IPR2018-01443, Paper 25; IPR2018-01444) from PTAB E2E and the certificate of cancellation from Patent Center, and confirm the CAFC mandate on Nos. 20-1713/20-1714.

Generated 8/26/2026, 6:47:45 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 9137205.