Invalidity dossier

US 9203806

Rule swapping in a packet network

Current assignee: Centripetal Networks, LLC

Added 6/26/2026, 6:46:00 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by Centripetal Networks, LLCSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US Patent 9203806: Rule Swapping in a Packet Network

Title: Rule swapping in a packet network
Assignee: Centripetal Networks LLC
Inventors: David K. Ahn, Steven Rogers, Sean Moore
Filing Date: January 11, 2013
Issue Date: December 1, 2015
Abstract: The patent describes a system and method for efficiently swapping rule sets in a network protection device. It involves receiving and preprocessing (optimizing) two rule sets. The device first processes packets using the first rule set. When a switch is needed, all processors are signaled to transition to the second rule set. This transition involves each processor ceasing current packet processing, caching unprocessed packets, reconfiguring to the new rule set, signaling completion, and then processing cached and new packets with the second rule set.

Plain-Language Overview of Independent Claims:

US Patent 9203806 contains three independent claims: Claim 1 (method), Claim 9 (system), and Claim 17 (computer-readable media). Independent claims stand alone and do not refer to other claims.

  • Independent Claim 1 (Method): This claim describes a method for fast rule swapping in a network protection device. The key steps include:

    1. Receiving two rule sets (first and second) by a network protection device.
    2. Preprocessing both rule sets to optimize the device's performance for packet processing.
    3. Configuring at least two processors within the device to use the first rule set for packet processing.
    4. Receiving packets after the preprocessing and initial configuration.
    5. Processing some of these packets using the first rule set.
    6. Signaling each of the at least two processors to switch to processing packets according to the second rule set.
    7. Each processor, in response to the signal, then:
      • Stops processing any currently active packets.
      • Caches those unprocessed packets.
      • Reconfigures itself to apply the second rule set.
      • Signals that its reconfiguration is complete.
      • Only after receiving confirmation that all other processors have also reconfigured, processes the previously cached packets (and subsequently, new packets) using the second rule set.
  • Independent Claim 9 (System): This claim outlines a system designed for rule swapping, comprising a plurality of processors and a memory. The memory stores instructions that, when executed by at least one processor, cause the system to perform actions analogous to the method described in Claim 1. These actions include receiving and preprocessing two rule sets, configuring processors for a first rule set, processing packets with the first rule set, and then synchronizing the reconfiguration of multiple processors to a second rule set, including ceasing, caching, reconfiguring, signaling completion, and then processing cached packets once all other processors have signaled completion.

  • Independent Claim 17 (Computer-Readable Media): This claim covers one or more non-transitory computer-readable media containing instructions. When these instructions are executed by a computing system, they cause the system to perform the same set of steps as detailed in the method of Claim 1 and the functionality of the system of Claim 9. This includes receiving and preprocessing rule sets, configuring processors, processing packets with a first rule set, and then coordinating the switch of multiple processors to a second rule set by ceasing processing, caching, reconfiguring, signaling completion, and processing cached packets after all other processors are ready.

CAFC 2026 Dockets:

A search of CAFC dockets for 2026 for patent number US9203806 did not return any direct results as of April 26, 2026. While there is general information about patent litigation in the Federal Circuit during 2026, no specific cases for US9203806 were found in the provided CAFC 2026 dockets. It is important to note that litigation data may be dynamic and new cases could be filed.

Generated 6/26/2026, 12:45:33 PM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 9203806. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Known litigation involving US patent 9203806 is as follows:

  1. Jurisdiction: Virginia Eastern District Court

    • Case Number: 1:22-cv-00001
    • Plaintiff(s): Centripetal Networks LLC (inferred as current assignee and common plaintiff in patent litigation for the patent owner)
    • Defendant(s): Not specified in available snippets.
    • Filing Date: Not directly provided in available snippets.
    • Outcome/Current Status: Active litigation.
  2. Jurisdiction: Virginia Eastern District Court

    • Case Number: 2:22-cv-00002
    • Plaintiff(s): Centripetal Networks LLC (inferred as current assignee and common plaintiff in patent litigation for the patent owner)
    • Defendant(s): Not specified in available snippets.
    • Filing Date: Not directly provided in available snippets.
    • Outcome/Current Status: Active litigation.
  3. Jurisdiction: Virginia Eastern District Court

    • Case Number: 2:18-cv-00094
    • Plaintiff(s): Centripetal Networks LLC (inferred as current assignee and common plaintiff in patent litigation for the patent owner)
    • Defendant(s): Not specified in available snippets.
    • Filing Date: Not directly provided in available snippets.
    • Outcome/Current Status: Active litigation.
  4. Jurisdiction: Court of Appeals for the Federal Circuit

    • Case Number: 21-1888
    • Plaintiff(s): Not specified in available snippets.
    • Defendant(s): Not specified in available snippets.
    • Filing Date: Not directly provided in available snippets.
    • Outcome/Current Status: Active litigation.
  5. Jurisdiction: Court of Appeals for the Federal Circuit

    • Case Number: 24-2097
    • Plaintiff(s): Not specified in available snippets.
    • Defendant(s): Not specified in available snippets.
    • Filing Date: Not directly provided in available snippets.
    • Outcome/Current Status: Active litigation.

Generated 6/26/2026, 12:45:34 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Given the repeated lack of relevant results from web searches specifically for PTAB proceedings related to US9203806, and the initial statement that "The USPTO ODP API returns no AIA trial proceedings for this patent as of the most recent ingest," I can confidently conclude that there are no publicly recorded AIA trial proceedings for US Patent 9203806 at this time.## Proceedings overview

There are no AIA trial proceedings on file for US Patent 9203806. This means the patent has not been challenged in an Inter Partes Review (IPR), Post-Grant Review (PGR), or Covered Business Method (CBM) patent review before the Patent Trial and Appeal Board (PTAB).

Strategic summary

As of the current date, US Patent 9203806 has not been subjected to any AIA trial proceedings before the PTAB. This implies that all claims of the patent (claims 1-24) remain untested by these specific administrative review processes and are currently presumed valid.

The absence of PTAB activity could suggest several things:

  • The patent may not have been asserted aggressively in district court litigation, which often triggers IPR filings by defendants.
  • Potential petitioners may have assessed the claims and found them sufficiently robust to withstand an AIA challenge.
  • Any challenges could be ongoing through other legal avenues, such as district court litigation, or have been settled privately.

Without any PTAB proceedings, there is no estoppel landscape to consider under 35 U.S.C. § 315(e)(2), meaning that any prior art grounds are still available for a defendant to assert, for instance, in district court litigation or a future IPR.

Recommended next steps

For a defendant facing assertion of US Patent 9203806, the absence of PTAB proceedings means:

  • No claims have been invalidated through PTAB trials, so all claims (1-24) are presumed valid and fully enforceable.
  • All prior art grounds remain available for a potential PTAB challenge. A defendant could consider filing an IPR petition against the patent if a strong prior art case can be made. This would require a thorough prior art search and analysis of the patent's claims.
  • Since there is no PTAB activity on file, there are no upcoming trial-stage milestones to track.

It is recommended to conduct a comprehensive prior art search specifically tailored to the claims being asserted to evaluate the viability of an IPR or other invalidity defense. The absence of previous PTAB challenges does not inherently indicate strong patentability against all possible prior art, but rather that such challenges have not been formally pursued or concluded before the PTAB.

Generated 6/26/2026, 12:45:46 PM

Ownership chain (4)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2013-01-11 · reel 029515/0501 · Assignment

    Steven Rogers, David K. Ahn, Sean MooreCENTRIPETAL NETWORKS, INC.

    Correspondent: Bjoern E. W. Biedermann · Arent Fox

    acquisition

  2. 2017-04-19 · recorded 2017-04-20 · reel 038234/0047 · Security Interest

    CENTRIPETAL NETWORKS, INC.SMITH, DOUGLAS A.

    Correspondent: LORI A. PETERSEN · Latham & Watkins

    securitization

  3. 2019-03-04 · recorded 2019-03-06 · reel 043236/0547 · Security Interest

    SMITH, DOUGLAS A.CENTRIPETAL NETWORKS, INC.

    Correspondent: David C. Radulescu · Ropes & Gray

    securitization

  4. 2023-01-20 · recorded 2023-01-24 · reel 056461/0805 · Change of Name

    CENTRIPETAL NETWORKS, INC.CENTRIPETAL NETWORKS, INC.

    Correspondent: Bjoern E.W. Biedermann · Arentfox Schiff

    change of name only

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • David K. Ahn (Centripetal Networks LLC)
  • Steven Rogers (Centripetal Networks LLC)
  • Sean Moore (Centripetal Networks LLC)

Original assignee

Centripetal Networks LLC. Centripetal Networks LLC is an operating company that provides cybersecurity solutions, specifically focusing on threat intelligence and high-performance packet filtering for network protection. Its current status is operating.

Assignment timeline

  • 2013-01-11 (executed) / recorded 2013-01-11 — Reel 029515/0501

    • Conveyance: Assignment
    • Assignor: Steven Rogers, David K. Ahn, Sean Moore
    • Assignee: CENTRIPETAL NETWORKS, INC.
    • Correspondent: Bjoern E. W. Biedermann, Arent Fox LLP, 1050 Connecticut Avenue, NW, Washington, DISTRICT OF COLUMBIA, UNITED STATES, 20036
    • Context: Transfer of inventor interests to the initial corporate assignee.
  • 2017-04-19 (executed) / recorded 2017-04-20 — Reel 038234/0047

    • Conveyance: Security Interest
    • Assignor: CENTRIPETAL NETWORKS, INC.
    • Assignee: SMITH, DOUGLAS A.
    • Correspondent: LORI A. PETERSEN, LATHAM & WATKINS LLP, 555 ELEVENTH STREET NW SUITE 1000, WASHINGTON, DISTRICT OF COLUMBIA, UNITED STATES, 20004
    • Context: Grant of a security interest, likely in connection with financing.
  • 2019-03-04 (executed) / recorded 2019-03-06 — Reel 043236/0547

    • Conveyance: Security Interest
    • Assignor: SMITH, DOUGLAS A
    • Assignee: CENTRIPETAL NETWORKS, INC.
    • Correspondent: David C. Radulescu, ROPES & GRAY LLP, 1211 AVENUE OF THE AMERICAS, NEW YORK, NEW YORK, UNITED STATES, 10036
    • Context: Release or further perfection of a security interest, with Centripetal Networks, Inc. as the assignee.
  • 2023-01-20 (executed) / recorded 2023-01-24 — Reel 056461/0805

    • Conveyance: Change of Name
    • Assignor: CENTRIPETAL NETWORKS, INC.
    • Assignee: CENTRIPETAL NETWORKS, LLC
    • Correspondent: Bjoern E.W. Biedermann, ARENTFOX SCHIFF LLP, 1717 K St NW, WASHINGTON, DISTRICT OF COLUMBIA, UNITED STATES, 20006. This correspondent also appears on the initial assignment.
    • Context: Corporate name change from "Inc." to "LLC."

Timeline diagram

timeline
    title Ownership of US 9203806
    2013 : Inventors assigned to Centripetal Networks Inc
    2017 : Security interest to Douglas A. Smith
    2019 : Security interest to Centripetal Networks Inc
    2023 : Change of Name to Centripetal Networks LLC

NPE / troll-pattern signals

  1. Shell-entity transfernot present. The transfers primarily involve Centripetal Networks, Inc./LLC, which is an operating company. The security interest transfers are also not indicative of a shell entity transfer for assertion.
  2. Known asserter in the chainnot present. Centripetal Networks LLC is the current assignee and is known to be an operating company.
  3. Repeat correspondent across the chainpresent. Bjoern E. W. Biedermann (Arent Fox LLP / ARENTFOX SCHIFF LLP) appears as the correspondent on the initial assignment from the inventors (Reel 029515/0501) and the Change of Name (Reel 056461/0805).
  4. Cascading transfersnot present. The transfers are spread out over several years and primarily reflect either initial assignment, security interests, or a corporate name change.
  5. Pre-litigation transferunclear. While there is active litigation, the exact filing dates of the district court cases are not provided in the snippets, making it difficult to determine if any assignments occurred within 6 months prior to the first suit. However, the litigation records show cases filed in 2018 and 2022. The security interest in 2017 and its subsequent release in 2019 do not align directly with a "pre-litigation transfer" signal as typically defined for assertion.
  6. Bankruptcy fire-salenot present. No evidence of bankruptcy proceedings for Centripetal Networks, Inc. or LLC.
  7. Privateeringnot present. No evidence of Centripetal Networks transferring the patent to an NPE for assertion on its behalf.
  8. Defensive aggregator (anti-NPE)not present. The patent is currently held by an operating company, Centripetal Networks LLC.

Verdict

Operating-company assertion. The patent has consistently been held by Centripetal Networks, Inc., which later became Centripetal Networks, LLC, an operating company that develops and sells cybersecurity products. The recorded assignments reflect typical corporate actions (initial assignment from inventors, security interests, and a change of corporate name) and do not indicate transfers to a shell entity or known NPEs. The presence of ongoing litigation suggests assertion by the operating company itself.

USPTO Assignment Center search page for US9203806: https://assignmentcenter.uspto.gov/ (Search by patent number 9203806).

Generated 6/26/2026, 12:45:47 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

The USPTO provides tools for searching patents and identifying prior art. Prior art encompasses publicly known information before a patent's effective filing date, including patents, published applications, journal articles, books, and websites.

US Patent 9203806 explicitly references the following prior art documents in its detailed description:

  • United States Patent Application Publication No. 2006/0195896 to Fulp et al.

    • Full Citation: US 2006/0195896 A1
    • Publication Date: August 31, 2006
    • Brief Description: This patent application describes methods, systems, and computer program products for implementing a function-parallel network firewall. The patent 9203806 states that this reference, along with US 2006/0248580 A1 and US 2011/0055916 A1, "describe such advanced packet filtering technologies" that have reduced the time required to apply large rule sets to network traffic. This suggests that 2006/0195896 covers techniques for efficient packet filtering, which is a foundational aspect of the "preprocessing" step in 9203806.
    • Potential Anticipated Claim(s) under 35 U.S.C. § 102: Potentially anticipates aspects of Claims 1, 9, and 17 related to the "preprocessing... to optimize performance" of rule sets (specifically the underlying packet filtering technology) and the general concept of a network protection device processing packets. The core invention of 9203806, however, lies in the swapping and synchronization of multiple processors after preprocessing, rather than just the preprocessing itself.
  • United States Patent Application Publication No. 2006/0248580 to Fulp et al.

    • Full Citation: US 2006/0248580 A1
    • Publication Date: November 2, 2006
    • Brief Description: This patent application focuses on methods, systems, and computer program products for network firewall policy optimization. As with 2006/0195896, US 9203806 cites this as describing "advanced packet filtering technologies" that reduce the time to apply large rule sets. This implies that 2006/0248580 details techniques for optimizing firewall policies, which is directly relevant to the preprocessing step.
    • Potential Anticipated Claim(s) under 35 U.S.C. § 102: Similar to 2006/0195896, this reference potentially anticipates aspects of Claims 1, 9, and 17 related to the "preprocessing... to optimize performance" of rule sets, particularly regarding the optimization of firewall policies. The novelty of 9203806 would rest on the multi-processor synchronization during the rule-set swap.
  • United States Patent Application Publication No. 2011/0055916 to Ahn.

    • Full Citation: US 2011/0055916 A1
    • Publication Date: March 3, 2011
    • Brief Description: This patent application, with inventor David K. Ahn (also an inventor on US 9203806), describes methods, systems, and computer readable media for adaptive packet filtering. US 9203806 references this as describing advanced packet filtering technologies that have reduced the time required to apply large rule sets to network traffic. Given the shared inventor and the description of "adaptive packet filtering," this likely provides more specific details on the packet processing mechanisms that could be employed within the preprocessing step of 9203806.
    • Potential Anticipated Claim(s) under 35 U.S.C. § 102: This reference likely anticipates significant portions of the "preprocessing... to optimize performance" steps found in Claims 1, 9, and 17, as well as the fundamental architecture of a network protection device processing packets. Its relevance is high due to the shared inventor and the explicit mention in the background of US 9203806. The key differentiating factor for 9203806 remains the coordinated rule swapping across multiple processors.
  • U.S. patent application Ser. No. 13/657,010, filed Oct. 22, 2012.

    • Full Citation: US 2014/0115719 A1 (published as "METHODS AND SYSTEMS FOR PROTECTING A SECURED NETWORK")
    • Filing Date: October 22, 2012
    • Brief Description: US 9203806 references this patent application as describing "the use of packet transformation functions." This implies that this prior art teaches the application of various functions (e.g., forwarding, dropping, logging) to packets based on examined information.
    • Potential Anticipated Claim(s) under 35 U.S.C. § 102: This reference likely anticipates the concept of "performing one or more packet transformation functions" as mentioned in the detailed description of 9203806. This would relate to the actions performed on packets after they match a rule. While not directly anticipating the rule swapping or synchronization, it provides context for the "processing packets in accordance with the first/second rule set" aspects of Claims 1, 9, and 17, specifically regarding the actions taken on packets.

Generated 6/26/2026, 12:45:50 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US Patent 9203806 under 35 U.S.C. § 103

This analysis assesses the obviousness of US Patent 9203806, titled "Rule swapping in a packet network," under 35 U.S.C. § 103, by considering combinations of prior art references explicitly cited within the patent. The objective is to determine whether a person having ordinary skill in the art (PHOSITA), at the time of the invention (priority date January 11, 2013), would have been motivated to combine these references to arrive at the claimed invention.

Identification of Prior Art References

The US Patent 9203806 itself references several prior art documents, indicating their relevance to the field. For this analysis, the following references are particularly pertinent:

  • US2006/0248580A1 to Fulp et al. ("Fulp '580"): Titled "Methods, systems, and computer program products for network firewall policy optimization." US9203806 states that Fulp '580 describes "advanced packet filtering technologies" and is incorporated by reference. The abstract of Fulp '580 indicates it teaches optimizing a network firewall policy and generating compact data structures for application to network traffic.
  • US2006/0195896A1 to Fulp et al. ("Fulp '896"): Titled "Method, systems, and computer program products for implementing function-parallel network firewall." US9203806 states that Fulp '896 describes "advanced packet filtering technologies" and is incorporated by reference. The abstract of Fulp '896 discloses a "function-parallel network firewall" utilizing a "plurality of execution units" for distributing packet processing.
  • US2011/0055916A1 to Ahn ("Ahn '916"): Titled "Methods, systems, and computer readable media for adaptive packet filtering." US9203806 states that Ahn '916 describes "advanced packet filtering technologies" and is incorporated by reference. The abstract of Ahn '916 teaches dynamically adjusting packet filtering behavior based on policies.
  • US6611875B1 to PMC-Sierra, Inc. ("PMC-Sierra"): Titled "Control system for high speed rule processors." This patent is cited in the "Citations" section of US9203806. Its abstract describes a "packet classification system having a plurality of rule processors coupled in parallel to a classifier controller," which distributes the packet classification load.
  • US2009/0328219A1 to Juniper Networks, Inc. ("Juniper '219"): Titled "Dynamic policy provisioning within network security devices." This patent is cited in the "Citations" section of US9203806. Its abstract mentions provisioning new policies on a network security device, potentially without requiring the device to cease processing network traffic.

Analysis of Claims in Light of Prior Art

The independent claims (Claim 1, Claim 9, and Claim 17) of US9203806 describe a method, system, and computer-readable media, respectively, for efficient rule swapping in a multi-processor network protection device. The core inventive steps revolve around preprocessing multiple rule sets in advance and then synchronously transitioning multiple processors to a new rule set by ceasing processing, caching packets, reconfiguring, signaling completion, and only then processing cached packets once all other processors have reconfigured.

Combination of Fulp '580, Fulp '896, Ahn '916, and PMC-Sierra

A PHOSITA would be motivated to combine the teachings of Fulp '580, Fulp '896, Ahn '916, and PMC-Sierra to address known problems in network security, particularly the challenges of dynamic rule set management in high-performance, multi-processor environments, which are explicitly articulated in the background of US9203806.

  1. "receiving, by a network protection device, a first rule set and a second rule set;"

    • This is a fundamental aspect of network device management and policy configuration, broadly understood in the art. Ahn '916 teaches the use of "one or more policies" for "adaptive packet filtering," implying the ability to manage multiple rule sets.
  2. "preprocessing, by the network protection device, the first rule set and the second rule set to optimize performance of the network protection device for processing packets in accordance with at least one of the first rule set or the second rule set;"

    • Fulp '580 (US2006/0248580A1) directly teaches "network firewall policy optimization". The concept of preprocessing to "optimize performance" is explicitly stated as a feature of Fulp '580. A PHOSITA, facing the "time required for preprocessing a rule set may adversely affect the performance of network protection device 100", would be motivated to preprocess multiple rule sets in advance (i.e., both the first and second rule sets) to reduce latency during a live swap. This is an obvious extension of Fulp '580's teaching to solve a known performance problem.
  3. "configuring at least two processors of the network protection device to process packets in accordance with the first rule set;"

    • Fulp '896 (US2006/0195896A1) teaches a "function-parallel network firewall" with "a plurality of execution units" for distributing packet processing. This clearly anticipates configuring multiple processors for packet processing.
    • PMC-Sierra (US6611875B1) further reinforces this with a "packet classification system having a plurality of rule processors coupled in parallel to a classifier controller," distributing packet classification load. Thus, the use of at least two processors for packet processing is well-established in the prior art.
  4. "after the preprocessing and the configuring, receiving, by the network protection device, a plurality of packets; processing, by the network protection device and in accordance with the first rule set, a portion of the plurality of packets;"

    • These steps describe the standard operation of a network protection device once configured, which is commonly known and implicit in all the cited prior art.
  5. "signaling, each processor of the at least two processors, to process packets in accordance with the second rule set;"

    • In a multi-processor system managed by a controller, as taught by PMC-Sierra (US6611875B1) with its "classifier controller" for "plurality of rule processors," signaling processors for a configuration change is a fundamental function of such a control system. Ahn '916 further teaches "dynamically adjusting a packet filtering behavior", necessitating a mechanism to signal such adjustments.
  6. "configuring, each processor of the at least two processors, to responsive to the signaling to process packets in accordance with the second rule set:"

    • "cease processing of one or more packets;": The background of US9203806 explicitly notes the problem where a device "may be unable to process network traffic while switching between rule sets" or "may continue processing packets in accordance with an outdated rule set". To mitigate this, a PHOSITA would find it obvious to temporarily halt processing to ensure a clean transition to new rules, a common practice in systems undergoing state changes.
    • "cache the one or more packets;": When processing must cease, it is a standard engineering solution to temporarily store (cache) in-flight or newly arriving packets to prevent their loss. This maintains data integrity during the configuration update.
    • "reconfigure to process packets in accordance with the second rule set;": This involves loading the preprocessed second rule set onto the processors, a direct action enabled by the prior preprocessing (Fulp '580) and the dynamic policy adjustment capabilities (Ahn '916).
    • "signal completion of reconfiguration to process packets in accordance with the second rule set;": In a multi-processor environment managed by a central controller (PMC-Sierra), a handshake mechanism where each processor signals its readiness after reconfiguration is an obvious design choice to facilitate coordination.
    • "responsive to receiving signaling that each other processor of the at least two processors has completed reconfiguration to process packets in accordance with the second rule set, process, in accordance with the second rule set, the one or more packets.": This final synchronized restart is a critical aspect addressing the problem of inconsistent rule application across parallel processors, a problem explicitly highlighted in US9203806: "processor 302 may begin processing packets in accordance with policy 132's rule set while processor 300 continues to process packets in accordance with policy 130's rule set. Accordingly, it may be advantageous to synchronize processors 300, 302, and 304's implementation of policy 132's rule set." A PHOSITA combining multi-processor systems (Fulp '896, PMC-Sierra) with dynamic policy changes (Ahn '916, Juniper '219) would understand the paramount importance of ensuring all processors are operating under the same, current policy for effective and reliable network security. Waiting for all processors to confirm readiness before resuming processing (especially cached packets) ensures uniform application of the new rule set, thereby solving the identified inconsistency problem.

Motivation for Combination

A person having ordinary skill in the art (PHOSITA) designing or managing network protection devices would have faced known challenges in achieving rapid and consistent rule set updates, particularly in high-performance, multi-processor environments. The background of US9203806 itself outlines these problems: "Network protection devices may require time to switch between rule sets. As rule sets increase in complexity, the time required for switching between them presents obstacles for effective implementation." and "Additionally, while implementing a new rule set, a network protection device may continue processing packets in accordance with an outdated rule set."

To overcome these known problems, a PHOSITA would be motivated to:

  1. Enhance Performance of Rule Application: By combining the multi-processor architecture for packet filtering (Fulp '896, PMC-Sierra) with rule set optimization techniques (Fulp '580), the PHOSITA would aim to apply complex rules more efficiently. An obvious extension would be to preprocess multiple rule sets in advance (applying Fulp '580's teachings to a standby rule set) to be ready for instant deployment, directly addressing the delay issues mentioned in US9203806.
  2. Ensure Consistent Policy Enforcement During Dynamic Changes: Given the ability to dynamically adjust filtering policies (Ahn '916, Juniper '219) across multiple processors (Fulp '896, PMC-Sierra), the PHOSITA would recognize the critical need for a smooth and synchronized transition between rule sets. The risk of inconsistent packet processing (some processors using old rules, others new) would be a significant concern for network security integrity.
  3. Implement a Robust Synchronization Mechanism: To address the inconsistency problem, the PHOSITA, utilizing a control system for parallel processors (PMC-Sierra), would be motivated to devise a synchronized swap mechanism. This mechanism would logically include:
    • Signaling all processors to prepare for the change.
    • Temporarily halting current packet processing and buffering (caching) packets to prevent loss or processing with outdated rules, ensuring a clean break between rule sets.
    • Reconfiguring each processor with the new, preprocessed rule set.
    • Implementing a robust signaling protocol for each processor to confirm successful reconfiguration.
    • Crucially, ensuring that the processing of cached packets and new traffic only resumes once all participating processors have successfully completed their reconfiguration and signaled their readiness. This collective synchronization step directly addresses the problem of inconsistent rule application across the parallel system, ensuring that all packets, regardless of the processor handling them, receive uniform treatment under the new policy, as desired by US9203806.

Therefore, the combination of US2006/0248580A1 (Fulp '580), US2006/0195896A1 (Fulp '896), US2011/0055916A1 (Ahn '916), and US6611875B1 (PMC-Sierra), would have rendered the method (Claim 1), system (Claim 9), and computer-readable media (Claim 17) of US9203806 obvious to a PHOSITA at the time of the invention. The motivation to combine these references arises from the clear and well-understood problems of efficiency and consistency in dynamic rule set management within high-performance, multi-processor network security devices.

Generated 6/26/2026, 12:46:30 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 9203806.