Invalidity dossier
US 9264370
Correlating packets in communications networks
Current assignee: Centripetal Networks, Inc.
Added 8/29/2026, 6:50:00 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language.
Let me retrieve the exact claims text of US9264370 from additional sources.
Summary of U.S. Patent 9,264,370
Note on sources: The full claims text was not included in the provided patent file, and my searches surfaced the claims only in part (via litigation exhibits). Where I am relying on corroborating sources rather than the verbatim USPTO text, I flag it below.
Bibliographic data (confirmed by Google Patents/USPTO data and a USPTO filing receipt in IPR2021-01150)
| Field | Value |
|---|---|
| Patent number | US 9,264,370 B1 (application no. 14/618,967) |
| Title | Correlating packets in communications networks |
| Inventors | David K. Ahn (Winston-Salem, NC); Peter P. Geremia (Portsmouth, NH); Pierre Mallett, III (Herndon, VA); Sean Moore (Hollis, NH); Robert T. Perry (Ashburn, VA) |
| Assignee | Centripetal Networks, Inc. (Herndon, VA) — later renamed Centripetal Networks, LLC (recorded name change, Jan. 2023) |
| Filing date | February 10, 2015 |
| Issue date | February 16, 2016 |
| Status | Active; anticipated expiration 2035-02-10 |
| Family litigation | E.D. Va. cases 2:17-cv-00383 (Centripetal v. Keysight), 2:22-cv-00002, 1:22-cv-00001; ITC Inv. 337-TA-1314; CAFC case 24-1416 |
Abstract (verbatim)
A computing system may identify packets received by a network device from a host located in a first network and may generate log entries corresponding to the packets received by the network device. The computing system may identify packets transmitted by the network device to a host located in a second network and may generate log entries corresponding to the packets transmitted by the network device. Utilizing the log entries corresponding to the packets received by the network device and the log entries corresponding to the packets transmitted by the network device, the computing system may correlate the packets transmitted by the network device with the packets received by the network device.
Plain-language overview of the independent claims
The patent addresses the problem that a network device (e.g., a NAT device, proxy, or VPN/tunneling gateway) can alter packets in ways that obscure which "flow" (end-to-end session) they belong to. The claimed solution places tap/filtering devices on both sides of the network device, logs matching packets on each side, and correlates the outgoing packets with the incoming packets.
Claim 1 (method — reconstructed from the spec/FIG. 4 and the abstract; numbering of the method claim is inferred). A method in which a computing system: (1) identifies a plurality of packets received by a network device from a host located in a first network; (2) generates log entries for those received packets; (3) identifies a plurality of packets transmitted by the network device to a host located in a second network; (4) generates log entries for those transmitted packets; and (5) correlates the transmitted packets with the received packets based on the two sets of log entries — thereby revealing, despite the network device's packet alterations, that the transmitted packets belong to the same flow(s) as the received packets.
*Claim 22 (system — verbatim elements corroborated by Centripetal's preliminary infringement contentions in Centripetal Networks, Inc. v. Keysight Technologies, Inc., E.D. Va. 2:17-cv-00383, Doc. 130-1).* A system with at least one processor and memory storing instructions that cause the system to:
- provision a device in a communication link interfacing the network device and a first network with rules configured to identify packets received by the network device from a host in the first network;
- provision the device (in the link between the network device and the second network) with rules specifying a set of network addresses and configured to cause the system to log packets destined for those addresses;
- configure the device on the first-network side to identify the received packets, generate log entries for them, and communicate those log entries to the system;
- configure the device on the second-network side to identify the transmitted packets, generate log entries for them, and communicate those log entries to the system;
- correlate the transmitted packets with the received packets based on the two sets of log entries; and
- responsive to that correlation, generate data identifying the host in the first network and communicate that data to a device located in the first network (e.g., notifying the host or a network administrator — the specification's malware/notification scenario).
Computer-readable medium claim (e.g., a later-numbered independent claim — numbering not independently verified). Based on the family's parallel claim structure (see the continuation publication US 2016/0234083, claims 36–37, and continuation US 10,931,797, claim 1), the '370 patent almost certainly also contains a non-transitory computer-readable medium claim mirroring the method claim (identify received packets → log entries → identify transmitted packets → log entries → correlate). I could not confirm the exact claim number for this '370 claim from the sources retrieved, so treat that numbering as uncertain.
CAFC 2026 docket search result
My search of 2026 CAFC activity surfaced a Federal Circuit opinion dated April 23, 2026 in Centripetal Networks, LLC v. Keysight Technologies, Inc. (CourtListener), affirming PTAB IPR obviousness findings. Caution: that opinion's discussed claims (e.g., claims 6, 16, and the "'917 Patent") appear to relate to the continuation U.S. 10,931,797, not to claims of 9,264,370 itself. I found no 2026 CAFC docket entry specifically directed to 9,264,370's own claims in my searches; the CAFC appeal 24-1416 listed in the family's litigation metadata is the likely appellate matter, but I could not confirm its scope from the retrieved sources.
Uncertainties
- Verbatim text of claims 1 and the medium claim of 9,264,370 — reconstructed from the specification, abstract, family claims, and litigation exhibits; exact numbering is inferred.
- Whether the April 2026 CAFC decision touches 9,264,370 directly — unresolved by my searches; it likely concerns a continuation patent.
- Current legal status (Active per Google Patents) is an assumption based on the USPTO assignment/status records reflected there, not a legal determination.
Generated 8/30/2026, 12:45:58 AM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 9264370. The free-form analysis below may also discuss cases beyond this list.
- Centripetal Networks, Inc. v. Keysight Technologies, Inc. et al.filed Jul 20, 20172:17-cv-00383U.S. District Court for the Eastern District of Virginia (Norfolk Division)terminated Oct 11, 2018terminated/settled
Defendants: Keysight Technologies, Inc., IXIA
- 2024-1416U.S. Court of Appeals for the Federal Circuitdecided; '526 findings not appealed
Defendants: International Trade Commission, Keysight Technologies, Inc.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US Patent 9,264,370. Let me run several searches to verify known cases and current status.
I found key leads. Let me verify the specific cases from the patent's litigation links and the Stanford NPE database.
I've confirmed the Keysight ITC case. Now let me check the two E.D. Va. cases listed on the patent's litigation page (2:22-cv-00002 and 1:22-cv-00001) and whether the Cisco case involved this patent.
Based on my research, US Patent 9,264,370 (the "'370 patent," titled "Correlating packets in communications networks," owned by Centripetal Networks, Inc./LLC) has been involved in several confirmed litigations. Here is the list, with the details I could verify from current sources.
Confirmed litigation involving US Patent 9,264,370
1. Centripetal Networks, Inc. v. Keysight Technologies, Inc. and IXIA ("Keysight I")
- Plaintiff: Centripetal Networks, Inc.
- Defendants: Keysight Technologies, Inc. and IXIA
- Jurisdiction: U.S. District Court for the Eastern District of Virginia (Norfolk Division)
- Case No.: 2:17-cv-00383 (HCM-LRL)
- Filing date: July 20, 2017
- Patents asserted: The '370 patent, along with U.S. Patent Nos. 9,137,205; 9,413,722; and 9,560,077
- Outcome/status: Terminated. A jury trial was held October 2–5, 2018, and the parties filed a joint stipulation of dismissal on October 11, 2018 (Dkt. 589), consistent with a settlement. Centripetal's later ITC complaint in Inv. No. 337-TA-1314 lists this case as "Terminated," and RPX reported that the prior litigation was ended by a limited-term license agreement. (Sources: https://law.justia.com/cases/federal/district-courts/virginia/vaedce/2:2017cv00383/[369444/484](https://assignmentcenter.uspto.gov/search/patent/reelFrameDetail?reelFrame=369444-0484)/; https://www.docketalarm.com/cases/Virginia_Eastern_District_Court/2--17-cv-00383/CENTRIPETAL_NETWORKS_INC._v._KEYSIGHT_TECHNOLOGIES_INC._et_al/; https://www.itcblog.com/images/Centripetal_Complaint_in_1314.pdf)
2. Centripetal Networks, Inc. v. Keysight Technologies, Inc. ("Keysight II")
- Plaintiff: Centripetal Networks, Inc.
- Defendant: Keysight Technologies, Inc.
- Jurisdiction: U.S. District Court for the Eastern District of Virginia
- Case Nos.: 1:22-cv-00001 and 2:22-cv-00002 (AWA-DEM) — the patent's litigation record lists both numbers; the 1:22-cv-00001 number appears in filings within the 2:22-cv-00002 docket (these appear to be related entries for the same Centripetal v. Keysight action filed in the E.D. Va.)
- Filing date: January 1, 2022 (filed the day after the prior limited-term license lapsed)
- Patents asserted: The '370 patent plus ten others (10,193,917; 10,284,526; 10,511,572; 10,567,343; 10,609,062; 10,659,573; 10,681,009; 10,785,266; 10,924,456; 11,012,474)
- Outcome/status: Pending/active as of the most recent information I found. Keysight moved to stay the case pending the parallel ITC investigation and filed multiple IPR petitions against the other asserted patents; notably, Keysight reported to the court that the '370 patent was "Not eligible for IPR" (time-barred). I did not find a final judgment in my search. (Sources: https://www.docketalarm.com/cases/Virginia_Eastern_District_Court/2--22-cv-00002/CENTRIPETAL_NETWORKS_INC._v._KEYSIGHT_TECHNOLOGIES_INC/; https://litigation.rpxcorp.com/news/69345-industry-coalitions-brief-enhancement-in-cisco-s-appeal-from-centripetal-judgment; https://ai-lab.exparte.com/case/dct/vaed/2:22-cv-00002/doc/analysis/1)
3. Certain Computer Network Security Equipment and Systems, Related Software, Components Thereof, and Products Containing Same — ITC Inv. No. 337-TA-1314
- Complainant: Centripetal Networks, Inc. (Reston, Virginia)
- Respondent: Keysight Technologies, Inc. (Santa Rosa, California)
- Jurisdiction: U.S. International Trade Commission (Section 337)
- Case No.: 337-TA-1314
- Complaint filed: April 19, 2022; investigation instituted May 18, 2022
- Patents asserted: The '370 patent, plus U.S. Patent Nos. 10,193,917 and 10,284,526
- Accused products: Keysight Vision One, Vision X, Vision 7300, Vision 7303, Vision Edge 1S, Trade Vision, ThreatArmor 1G, and ThreatArmor 10G
- Outcome/status: Terminated with a finding of no violation of Section 337. An Administrative Law Judge found no violation in August 2023; the Commission affirmed and terminated the investigation by notice dated December 5, 2023. (Sources: https://www.usitc.gov/press_room/news_release/2022/er0518ll1939.htm; https://www.lexology.com/library/detail.aspx?g=476f2c35-a15b-4345-b8f0-67d1c1f93b56; https://www.itcblog.com/images/Centripetal_Complaint_in_1314.pdf)
4. Centripetal Networks, LLC v. International Trade Commission (Keysight Technologies, Inc., Intervenor) — CAFC Appeal No. 24-1416
- Appellant: Centripetal Networks, LLC
- Appellee: International Trade Commission
- Intervenor: Keysight Technologies, Inc.
- Jurisdiction: U.S. Court of Appeals for the Federal Circuit
- Case No.: 24-1416
- Subject: Appeal of ITC Inv. No. 337-TA-1314 (no-violation determination on the '370 patent and related patents)
- Filing date: 2024 (appeal of the ITC final determination)
- Outcome/status: Affirmed for the ITC/Keysight on April 23, 2026 (nonprecedential). The Federal Circuit held that substantial evidence supported the Commission's finding that Centripetal failed the technical prong of the domestic industry requirement, and that Centripetal waived its challenge to the non-infringement finding; the court therefore did not reach patent ineligibility. (Sources: https://www.cafc.uscourts.gov/opinions-orders/24-1416.OPINION.4-23-2026_2681340.pdf; https://scalejuris.com/news/12434/federal-circuit-delivers-series-of-wins-; https://www.vitallaw.com/caselaw/centripetal-networks-llc-appellant-v-international-trade-commission-appellee-keysight-technologies-inc-intervenor/922237520993402fb56481eff923ac29)
Related matters I could NOT confirm as asserting the '370 patent itself
- Centripetal v. Cisco Systems, Inc. (E.D. Va., No. 2:18-cv-00094) and Centripetal v. Palo Alto Networks (E.D. Va., filed March 2021) are well-known Centripetal suits, and the '370 patent family (e.g., continuations such as 9,560,176, 10,530,903, 10,659,573, 10,931,797) has been litigated extensively. However, from the sources I reviewed, I could not confirm that the '370 patent itself (as opposed to family members) was asserted in those cases, and Google Patents' litigation listing for US9264370B1 identifies only the five matters above (2:22-cv-00002, 2:17-cv-00383, 1:22-cv-00001, 337-TA-1314, and 24-1416). If you need certainty on the Cisco/Palo Alto cases, I'd recommend checking the dockets or the Stanford NPE database page for 9264370 (https://npe.law.stanford.edu/patent/9264370).
Bottom line: US Patent 9,264,370 has been asserted by Centripetal in two E.D. Va. district-court actions against Keysight (2017 and 2022), one ITC investigation (337-TA-1314), and one Federal Circuit appeal (24-1416). Centripetal lost the ITC case and the appeal (affirmed April 23, 2026); Keysight I ended in dismissal/settlement; Keysight II was still pending as of my most recent information, with no final judgment located.
Generated 8/30/2026, 12:46:07 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Centripetal Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
Proceedings overview
Zero AIA trials on U.S. 9,264,370 itself. The canonical USPTO Open Data Portal block supplied for this task reports no AIA trial proceedings on file for the '370 patent, and my web searches corroborate that: every IPR I could locate in the Centripetal/Keysight/Cisco/Palo Alto disputes is against a continuation-family patent (e.g., '903, '176, '917, '856), not against 9,264,370. No claim of the '370 has ever been canceled, sustained, or even instituted upon by the PTAB — the patent is PTAB-untested and fully in force, though it has been wounded in parallel ITC/district-court litigation (ITC no-violation findings affirmed by the Federal Circuit on 2026-04-23). Bottom line for a defendant: the '370 has never faced an IPR; no § 315(e)(2) estoppel binds anyone on it, and every § 102/§ 103 ground remains available — but the patent owner has repeatedly survived PTAB challenges on the family's core "correlating packets" claims, so a fresh IPR is a meaningful but not easy path.
Direct proceedings on U.S. 9,264,370
None. The structured ODP data lists no IPR, PGR, or CBM directed to 9,264,370, and targeted searches (US9264370 inter partes review PTAB, Keysight IPR "9,264,370", '370 patent IPR) returned no PTAB case naming the '370 as the challenged patent. This is itself a signal worth reading (see Strategic summary below).
Related PTAB proceedings on continuation patents (context you must know)
These are not proceedings on the '370, but they adjudicate near-identical "correlating packets" claims from the same family and will dominate any invalidity strategy against the '370.
IPR2021-01150 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc. (IPR of U.S. 10,530,903)
- Type: Inter Partes Review
- Filed: 2021-07-20
- Status: Terminated — Final Written Decision; appealed (per RPX and docket records)
- Judge panel: Stacey G. White, Jon M. Jurgovan, Aaron W. Moore (Paper 37)
- Petition grounds: Claims 1–18 of the '903 continuation (the family's "correlating packets" claims, direct descendants of the '370) under § 103, obviousness over U.S. Pub. App. No. 2014/0280778 ("Paxton") and U.S. Pat. No. 8,413,238 ("Sutton") in view of U.S. Pat. No. 8,219,675 ("Ivershen"). PAN relied on Paxton for all but one element of independent claim 1, and on Sutton for the "transmit an indication of the first host responsive to the correlating" limitation.
- Institution decision: Instituted 2022-02-16 (Paper 9). The Board's institution survived Centripetal's argument that the Board impermissibly instituted on a ground not presented.
- Final Written Decision: Paper 37, entered 2023-02-15/16 — "Determining No Challenged Claims Unpatentable" (35 U.S.C. § 318(a)). The Board found claims 1–18 patentable, concluding PAN failed to show Paxton–Sutton (with Ivershen) taught remedial steps performed "responsive to the correlating," the "determining differences" limitation, and (for dependent claims) the network-interface-identifier, encapsulating, and drop-rule limitations. Oral hearing was held 2022-10-31.
- Appeal: PAN appealed 2023-02-21 (Notice of Appeal; CAFC No. 2023-1636). The Federal Circuit issued a decision on 2024-12-16 (Palo Alto Networks, Inc. v. Centripetal Networks, LLC, 2024 WL 5114204). Practitioner commentary on the decision is titled "Unclear Analysis at the PTAB Leads to Confusion at the Federal Circuit," indicating the panel was critical of the Board's analysis; I could not confirm from retrieved sources whether the disposition was affirmance, vacatur, or remand — verify the mandate before relying on this FWD's precedential value.
- Defensive value: Directly probative for the '370: the strongest known prior-art combination against this claim family (Paxton + Sutton + Ivershen) failed at the Board on the very "responsive to the correlating" and timestamp-difference limitations that the '370's claims 22/43 also recite. A defendant whose only theory is Paxton-based should expect resistance.
Sources: DocketAlarm Paper 37 (FWD), PAN Notice of Appeal (DocketAlarm), CourtListener CAFC opinion, ptablaw.com commentary, RPX Insight
IPR2018-01654 & IPR2018-01655 — Cisco Systems, Inc. v. Centripetal Networks, Inc. (IPR of U.S. 9,560,176)
- Type: Inter Partes Review (two petitions, substantively identical)
- Filed: 2018-09-17
- Status: Institution denied; rehearing denied
- Judge panel: Brian J. McNamara, J. John Lee, Aaron W. Moore (Moore writing)
- Petition grounds: Claims 1, 4–7, 9–11, 14–17, 19–21, 24–27, and 29–30 of U.S. 9,560,176 (the continuation of the '370 family filed 2015-05-15, i.e., the closest sibling to the '370) on § 103 obviousness, including over Ivershen and Rajan.
- Institution decision: Denied 2019-05-06 (Paper 7). The Board found Cisco failed to show a reason to combine (e.g., no showing that discarding non-invariant packet parts would materially save storage given Ivershen's millisecond-scale retention). Cisco's rehearing request was denied 2019-09-13 (Paper 9).
- Appeal: None located.
- Defensive value: The Board's denial — and the CAFC's later, harsher treatment of the same Ivershen-based arguments in the Cisco litigation (recusal/panel-challenge rulings) — means Ivershen-centered combinations are a weak anchor for attacking the '370.
Sources: DocketAlarm IPR2018-01654 docket, Paper 9 (rehearing denial), RPX Insight
Keysight IPRs on the '917 continuation ("Sourcefire" grounds) — affirmed by CAFC 2026-04-23
- Type: Inter Partes Review (Keysight; specific IPR numbers not confirmed from retrieved sources)
- Status: Claims held unpatentable; affirmed on appeal
- What happened: In Centripetal Networks, LLC v. Keysight Techs., Inc., No. 24-1406 (Fed. Cir. 2026-04-23), the Federal Circuit affirmed the unpatentability of claims 11 and 20 of U.S. 10,193,917 "in view of Sourcefire" — as the court itself noted in the companion ITC appeal (24-1416, slip op. at 5). Keysight's 10-Q confirms the broader pattern: "all or most claims being found invalid in each challenged patent" across its 2022 PTAB campaign, including "18 of 20 claims" of one ITC-asserted patent.
- Defensive value: The Sourcefire-based grounds that succeeded against the '917 (a sibling continuation in the same family, asserted in the same ITC investigation as the '370) are the single most valuable prior-art line for a defendant attacking the '370 — but note the '917 claims (threat-indicator packet filtering) are not identical to the '370's correlation claims.
Sources: CAFC 24-1416 opinion, p. 5, Keysight 10-Q, ScaleJuris summary
IPR2022-01421 — Keysight Technologies, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review
- Filed: 2022-08-12
- Status: Terminated 2024-11-01 — "Final Written Decision – Appealed" (per Track Docket)
- Note: The challenged patent number is not confirmed from retrieved sources; this is one of Keysight's 2022 PTAB challenges tied to Centripetal v. Keysight, No. 2:22-cv-00002 (E.D. Va., stayed). I could not verify whether it names the '370 — do not cite it as an '370 proceeding without checking PTAB E2E.
- Defensive value: Confirms Keysight's aggressive, largely successful PTAB campaign against the Centripetal family — but its bearing on the '370 specifically is unverified.
Source: Track Docket IPR2022-01421
Other family IPRs (briefly)
- IPR2022-01151 / IPR2022-01199 (Keysight v. Centripetal, IPR of U.S. 9,917,856): joined into IPR2022-00182; not the '370. (RPX Insight)
- IPR2021-01147 / IPR2021-01148 (Palo Alto Networks v. Centripetal): referenced in Centripetal's patent-owner responses; challenged patents not confirmed from retrieved sources — again, not shown to be the '370.
- IPR2021-01151 (Palo Alto Networks v. Centripetal): sibling to IPR2021-01150; challenged patent not confirmed from retrieved sources.
Strategic summary
Which claims of the '370 are CANCELED / SUSTAINED / UNTESTED. At the PTAB: none canceled, none sustained, all untested. No AIA petition has ever been filed against 9,264,370 itself. The '370's claims remain fully in force — the ITC and CAFC have not canceled them either. What has happened to the asserted claims (22–27, 42–48, 63) is: (1) the ITC's Initial Determination (Inv. No. 337-TA-1314, ID issued 2023-08-08) found asserted claims 22 and 43 not infringed and invalid (primarily § 101 ineligibility, with § 102/103 contentions pressed by Keysight); (2) the Commission affirmed no violation on 2023-12-05; and (3) the Federal Circuit affirmed on 2026-04-23 (Centripetal v. ITC, No. 24-1416) — but on the domestic-industry technical prong and waiver of the non-infringement challenge, expressly not reaching § 101. So the '370's claims are "wounded but standing": no tribunal has finally and bindingly invalidated them.
Estoppel landscape. Because no IPR has been instituted on the '370, no petitioner or privy is estopped under § 315(e)(2) with respect to the '370 — every § 102/§ 103 ground remains available to any defendant, including grounds that were previously litigated in family IPRs. Practical caveats: (i) a defendant that was served with an '370 complaint more than one year ago must check the § 315(b) bar before filing its own IPR; (ii) grounds already rejected at the Board (Paxton + Sutton + Ivershen against the '903; Ivershen/Rajan against the '176) are weak; (iii) the Sourcefire-based grounds that invalidated '917 claims 11 and 20 (affirmed, 24-1406) are the strongest known line, but require mapping to the '370's distinct "device on each side of the network device + correlation + responsive notification" claim elements.
Pattern signals. This is a heavily-litigated, heavily-challenged family, not a sleeping patent: Centripetal has faced IPRs from Cisco (2018), Palo Alto Networks (2021), and Keysight (2022) — with mixed results (Centripetal won IPR2021-01150 outright; Keysight won the '917 Sourcefire IPRs; Cisco was denied institution on the '176). The absence of any IPR on the '370 itself is conspicuous given it is the family's oldest and most-asserted patent (E.D. Va. 2:17-cv-00383, 2:22-cv-00002, 1:22-cv-00001, ITC 337-TA-1314). The likely explanations: the '370's earliest priority date (2015-02-10) and its Paxton-proximal subject matter made challengers prefer (a) district-court/ITC § 101 attacks and (b) IPRs on later, easier claims in the family. No defensive-aggregator (Unified Patents) IPR on the '370 was found. Keysight's 10-Q characterizes the 2022 PTAB campaign as "all or most claims being found invalid in each challenged patent" — but the '370 was not, on the record retrieved, one of the eight.
Recommended next steps
- Confirm the zero-IPR finding on PTAB E2E. Before filing anything, run the '370 (9,264,370) through the USPTO PTAB docket search and the ODP API yourself; also confirm whether IPR2022-01421 names the '370 (I could not). If it does, that changes the picture materially — a FWD issued 2024-11-01 with an appeal pending.
- If you are a defendant in the stayed E.D. Va. cases (2:22-cv-00002, 1:22-cv-00001) or facing a new demand: the single most potent, already-judicially-vetted ammunition is the ITC/CAFC record: ITC ID (2023-08-08) finding claims 22 and 43 not infringed and invalid, Commission determination (2023-12-05), and the CAFC affirmance (24-1416, 2026-04-23) on the technical prong and waiver. Quote the CAFC's holding that substantial evidence supports no-practice of claim 22's "device" limitations (limitations (b)–(f)) — that is a non-infringement/DI holding that maps directly onto how Centripetal must prove infringement in district court.
- If you have a clean § 315(b) window, consider a fresh IPR on the '370 — you face no estoppel. But budget for a hard fight: Centripetal beat the Paxton combination at the Board (IPR2021-01150), and the Board denied Cisco's Ivershen-based petitions (IPR2018-01654/01655). Lead with Sourcefire-based grounds (validated against the '917) and the ITC's § 101 analysis rather than re-running Paxton.
- Check the mandate in CAFC 2023-1636 before relying on the IPR2021-01150 FWD; and remember it binds nothing for the '370 directly.
- Do not overstate "the troll has no case." Unlike a claims-canceled scenario, the '370's claims are all alive. The accurate posture is: the patent is PTAB-untested, ITC-weakened (non-infringement + § 101), and the family's best prior-art attacks have either failed (Paxton/Ivershen) or succeeded only against different claims (Sourcefire/'917).
Key citations: CAFC 24-1416 opinion (2026-04-23): https://www.cafc.uscourts.gov/opinions-orders/24-1416.OPINION.4-23-2026_2681340.pdf · IPR2021-01150 FWD (Paper 37): https://www.docketalarm.com/cases/Virginia_Eastern_District_Court/2--21-cv-00137/Centripetal_Networks_LLC_v._Palo_Alto_Networks_Inc/docs/367/3.pdf · IPR2018-01654/01655 institution-denial & rehearing-denial records (links above) · Keysight 10-Q (2026): https://www.advfn.com/stock-market/NYSE/KEYS/stock-news/97991896/form-10-q-quarterly-report-sections-13-or-15d
Uncertainties flagged: (1) IPR2022-01421's challenged patent unconfirmed; (2) IPR2021-01147/01148/01151 challenged patents unconfirmed; (3) disposition of CAFC 2023-1636 not confirmed (affirm/vacate/remand); (4) "no PTAB activity on the '370" rests on ODP data plus negative search results — a proceeding filed after the ODP ingest or not surfaced by these searches would not appear here.
Generated 8/30/2026, 12:48:10 AM
Ownership chain (4)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2015-03-11 · Assignment
David K. Ahn; Sean Moore; Pierre Mallett, III; Peter P. Geremia; Robert T. PerryCENTRIPETAL NETWORKS, INC.
acquisition
2017-04-17 · recorded 2017-04-19 · Security Agreement
? · recorded 2019-03-04 · Release
? · recorded 2023-01-17 · Change of Name
CENTRIPETAL NETWORKS, INC.CENTRIPETAL NETWORKS, INC.
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Inventors
All five named inventors assigned their rights to Centripetal Networks, Inc. in the original recorded assignment (recorded 2015-03-11), consistent with employment at Centripetal at the time of filing (application filed 2015-02-10):
| Inventor | Role / employer at filing (as determinable) |
|---|---|
| David K. Ahn | Centripetal Networks, Inc. (co-founder / VP engineering per public sources) |
| Peter P. Geremia | Centripetal Networks, Inc. (engineer; Portsmouth, NH) |
| Pierre Mallett, III | Centripetal Networks, Inc. (engineer; Herndon, VA) |
| Sean Moore | Centripetal Networks, Inc. (CTO per public sources; Hollis, NH) |
| Robert T. Perry | Centripetal Networks, Inc. (engineer; Ashburn, VA) |
Unusual patterns: none observed. There is no evidence in the retrieved records of mass inventor departure within 12 months of filing, and the assignment pattern (all five → employer) is the ordinary employee-assignment form. I could not verify post-filing departures from public sources, so that specific pattern is simply not in evidence rather than affirmatively absent.
Original assignee
- Entity named on the issued patent: Centripetal Networks, Inc. (Delaware corporation; Herndon, VA, later Reston, VA / Portsmouth, NH).
- Primary line of business: Network security — packet-filtering security gateways/firewalls ("RuleGist," "CleanINTERNET" product lines).
- Shipped product embodying the claims: Yes. Centripetal is an operating company; in the ITC investigation (337-TA-1314) it asserted a domestic-industry position based on its security gateway products (the Commission ultimately found Centripetal failed the technical prong of the domestic-industry requirement, but that is a litigation outcome, not evidence the company lacks products — Centripetal is a known seller of security appliances).
- Current status: Operating. Renamed Centripetal Networks, LLC via recorded change of name (2023-01-17); still active in litigation (CAFC appeal 24-1416 affirmed against Centripetal April 23, 2026). Not acquired, not dissolved, not in bankruptcy.
Assignment timeline
I could not retrieve reel/frame numbers for any of these recordings from the sources available to me (the USPTO Assignment Center is interactive and its API requires a key; Google Patents' legal-event feed and the litigation exhibit below do not display reel/frame). I have not fabricated them. The substantive content of each recording is corroborated by the Google Patents legal-event feed and, for the 2017 security agreement, by the recorded cover sheet filed as Exhibit in Centripetal Networks, Inc. v. Keysight Technologies, Inc. (E.D. Va. 2:17-cv-00383, Doc. 28-4 — https://www.docketalarm.com/cases/Virginia_Eastern_District_Court/2--17-cv-00383/CENTRIPETAL_NETWORKS_INC._v._KEYSIGHT_TECHNOLOGIES_INC._et_al/docs/28/4.pdf). There is no indication the Assignment Center holds any recordings beyond these four events.
executed ~2015-02 (not shown in retrieved record) / recorded 2015-03-11 — Reel/frame not retrieved
- Conveyance: Assignment of Assignors' Interest ("ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
- Assignor: David K. Ahn; Sean Moore; Pierre Mallett, III; Peter P. Geremia; Robert T. Perry
- Assignee: Centripetal Networks, Inc.
- Correspondent: not retrieved
- Context: original inventors-to-employer assignment at filing; ordinary, not a transfer of a mature asset.
executed 2017-04-17 / recorded 2017-04-19 — EPAS ID PAT4374169 (cover sheet); reel/frame not retrieved
- Conveyance: Security Interest — "Patent and Trademark Security Agreement" entered in connection with a "Note and Warrant Purchase Agreement" (a private loan)
- Assignor (Grantor): Centripetal Networks, Inc.
- Assignee (Grantee): Douglas A. Smith, an individual, 12770 Merit Drive, Suite 800, Dallas, TX 75251
- Correspondent: contact phone (617) 951-8000, fax (617) 951-8736 (Boston-area; this number is consistent with Morgan, Lewis & Bockius LLP's Boston office — flagged as an inference from the phone number, as the correspondent name itself was not shown in the retrieved snippet). No recurrence data available.
- Context: portfolio-level collateral lien — the agreement encumbers 14 properties (13 patents including 9,264,370, plus one application) to secure private debt financing. This is a lender security interest, not a transfer of title. (Note: this is a debt-financing lien, not a transfer to an asserting entity.)
recorded 2019-03-04 — Reel/frame not retrieved
- Conveyance: Release of Security Interest ("SECURITY INTEREST" — assignor Smith back to Centripetal)
- Assignor: Douglas A. Smith
- Assignee: Centripetal Networks, Inc.
- Correspondent: not retrieved
- Context: loan satisfied; lien released; title cleanly back with Centripetal.
recorded 2023-01-17 — Reel/frame not retrieved
- Conveyance: Change of Name ("CHANGE OF NAME (SEE DOCUMENT FOR DETAILS)")
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: not retrieved
- Context: corporate form change only (C-corp → LLC); no change in beneficial ownership.
Bottom line on the record: the patent has never left the Centripetal family. The only non-Centripetal party ever on the record is an individual lender holding a temporary security interest (2017–2019). No third-party assignee of title has ever been recorded, and no transfer-to-assertion-vehicle exists. Current owner of record: Centripetal Networks, LLC.
Timeline diagram
timeline
title Ownership of US 9264370
2015 : Filed by Centripetal Networks Inc
: Inventors assign to Centripetal Inc
2016 : Patent issued
2017 : Security interest to lender Smith
: First suit filed vs Keysight
2019 : Security interest released
2023 : Name change to Centripetal Networks LLC
NPE / troll-pattern signals
Shell-entity transfer — Not present. The patent never moved from the operating company to a licensing-only LLC. The only LLC-form event is the 2023-01-17 change of name (Centripetal Networks, Inc. → Centripetal Networks, LLC), which is a re-organization of the same operating company, not a transfer to a shell. The lone non-Centripetal recipient, Douglas A. Smith (recorded 2017-04-19, EPAS PAT4374169), is an individual lender under a Note and Warrant Purchase Agreement, holding a security interest that was released 2019-03-04 — not a shell, and no title ever passed.
Known asserter in the chain — Not present. The current and only title-holder, Centripetal Networks, is the plaintiff in every asserted action naming the '370 patent (E.D. Va. 2:17-cv-00383; E.D. Va. 2:22-cv-00002 / 1:22-cv-00001; ITC 337-TA-1314; CAFC 24-1416). Centripetal is an operating security vendor and does not appear on RPX/Unified Patents NPE lists; Unified Patents tracks it as a litigant, not an NPE (https://portal.unifiedpatents.com/patents/patent/9264370).
Repeat correspondent across the chain — Unclear. Only one correspondent contact was retrievable (the 2017 security-interest cover sheet, EPAS PAT4374169): phone (617) 951-8000 / fax (617) 951-8736, a Boston number consistent with Morgan, Lewis & Bockius LLP (flagged inference). A single appearance cannot establish recurrence, so this signal is neither present nor affirmatively absent on the evidence retrieved.
Cascading transfers — Not present. Four recordings in ten years, no chained LLCs, no shared registered-agent addresses, no rapid-fire assignee changes.
Pre-litigation transfer — Not present as a title transfer. The 2017-04-17 security interest (recorded 2017-04-19) falls within six months of the first '370 suit (Keysight I, filed 2017-07-20), but it is a lender collateral lien, not an assignment of title, and it ran to an individual financier rather than an asserting entity. It does not fit the "chain arranged to enable assertion / venue / standing" pattern.
Bankruptcy fire-sale — Not present. No bankruptcy proceedings involving Centripetal or the '370 patent found; Centripetal remains an active operating and litigating company (still pursuing appeals into 2026).
Privateering — Not present. Centripetal asserts in its own name against competitors (Keysight; and family patents against Cisco and Palo Alto Networks). There is no operating-company-to-NPE arrangement, and no SEC filing evidence of such (Centripetal is privately held; no relevant public-company disclosures).
Defensive aggregator (anti-NPE) — Not present. No RPX, AST, LOT Network, Unified Patents, or OIN interest in the chain. The patent remains assertable, and is being asserted, by its operating-company owner.
Verdict
Operating-company assertion.
The record shows no NPE pattern at all: the '370 patent has been continuously owned by Centripetal Networks, Inc./LLC since the inventors' assignment (recorded 2015-03-11), with the only intervening event a lender security interest to individual financier Douglas A. Smith (executed 2017-04-17, recorded 2017-04-19, EPAS PAT4374169) that was released in full on 2019-03-04, followed by a 2023-01-17 name change. Centripetal is an operating network-security vendor that has asserted the patent in its own name against competitor Keysight in district court (2:17-cv-00383; 2:22-cv-00002) and the ITC (337-TA-1314). Verification: search patent number 9264370 at https://assignmentcenter.uspto.gov/ or https://assignment.uspto.gov/patent/index.html; note that I could not pull reel/frame numbers from the sources available to me and they should be confirmed against the Assignment Center directly.
Generated 8/30/2026, 12:47:49 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I've reached the limit of tool calls for this session, so I'll answer from the information gathered. Let me be upfront about a key limitation before presenting the analysis.
Prior-Art Analysis for US Patent 9,264,370
⚠️ Critical sourcing caveat (read first)
The full patent text you provided (authoritative Google Patents fetch) does not include the "Citations" (backward references) section of US9264370. The front-page "References Cited" list (the examiner-cited art) was not retrievable in full from the sources I could reach within this session's step budget. What I did recover:
- Family "Patent Art" aggregates (e.g., Unified Patents portal pages for the continuations US10931797 and US9560176), which compile prior art from the family's IPR petitions and litigation invalidity contentions — not necessarily the examiner's on-face citations.
- Google Patents "Cited By" linkage artifacts that indicate the '370 backward-cites certain older patents (e.g., the search-result format "
<older patent title> - US9264370B1" appears when the older patent's page lists US9264370 under "Cited By," which means US9264370 cites that older patent). - The family's file-wrapper exhibit (DocketAlarm, IPR2021-01150, Ex. 1002-3, file history of US10530903), confirming only the family/prosecution chain, not the citation list.
Bottom line: I can identify the most relevant prior art for the '370 with high confidence from the family/litigation record, but I cannot certify that every reference below is literally on the face of the '370. I flag each reference's provenance accordingly. Where a reference is a confirmed backward citation, I say so; where it is litigation/IPR art, I say so.
The claims to test (working reference)
- Claim 1 (method, numbering inferred): identify packets received by a network device from a host in a first network → generate log entries → identify packets transmitted by the network device to a host in a second network → generate log entries → correlate the transmitted packets with the received packets based on both sets of log entries.
- Claim 22 (system, verbatim elements corroborated by Centripetal's preliminary infringement contentions, Centripetal v. Keysight, E.D. Va. 2:17-cv-00383, Doc. 130-1): provision devices on both sides of the network device with rules; rules specify a set of network addresses and cause logging of packets destined for those addresses; configure the devices to identify received/transmitted packets, generate log entries, and communicate them to the system; correlate; and, responsive to correlation, generate data identifying the first-network host and communicate it to a device in the first network.
Priority date for §102 analysis: February 10, 2015 (filing date; no earlier priority claimed). Prior art = any reference published, or (under AIA §102(a)(2)) having an effective filing date, before that date.
A. Confirmed backward-citation candidates (highest confidence as "patent citations for 9264370")
1. US 8,806,638 B2 — "Systems and methods for protecting networks from infected computing devices"
- Inventors: David K. Ahn; Pierre Mallett, III; Sean Moore (the same Centripetal team as the '370)
- Assignee: Centripetal Networks, Inc.
- Issued: August 12, 2014 (before the '370's Feb 10, 2015 filing → valid §102 art)
- Provenance: Google Patents page for US8806638 lists US9264370 in its "Cited By," indicating the '370 cites it.
- Description: Discloses an inline network-security appliance that applies rules to identify packets, logs packet data, and drops/quarantines traffic from infected hosts — the same rule-provisioning/log-entry architecture the '370 builds on.
- §102 analysis: Discloses the identify + log legs and rule-based filtering, but does not disclose the two-sided correlation of pre-/post-transformation packets to recover flow association. Strong §103 base; §102 anticipation of claim 1's full correlation limitation is unlikely.
2. US 7,602,775 B1 — "Internet security device and method"
- Issued: October 13, 2009
- Provenance: Google Patents "Cited By" linkage (the '370 cites it).
- Description: Classic inline security-gateway patent — a device interposed between networks that examines and filters packets.
- §102 analysis: Predates the '370 by years; discloses inline inspection and filtering but not the correlation of logs across a flow-transforming device. Relevant §103; not a plausible §102 anticipator of the correlation-based claims.
B. Family/litigation art — most relevant references in the '370 family's prior-art universe
These appear in the Unified Patents "Patent Art" aggregates for the '370's continuations (US10931797, US9560176) and in Centripetal's IPR record. They are the art most likely to be asserted against the '370's claims in IPR/invalidity contexts:
3. US 9,137,205 B2 / US 2014/0115654 A1 — "Methods and Systems for Protecting a Secured Network"
- Inventors: Rogers et al.
- Assignee: Centripetal Networks, Inc.
- Filed: October 21, 2012; Published: April 24, 2014 (before Feb 10, 2015 → §102(a)(1)/(2) art); Issued: September 15, 2015
- Description: Centripetal's earlier inline security-appliance patent: rule-based packet filtering, threat-intelligence-driven blocking, and packet logging between secured and unsecured networks — the direct precursor of the '370's environment.
- §102 analysis: The closest family prior art. Discloses devices provisioned with rules on a communication link, identifying and logging packets. What it does not clearly disclose is the correlative step: matching the outbound (post-transformation) packet logs to the inbound (pre-transformation) logs to associate packets with a flow that the intermediary (NAT/proxy/tunnel) obscured. If a finder of fact reads the correlation limitation broadly, this reference is the strongest anticipation candidate; realistically it is the strongest §103 combination anchor.
4. US 7,143,438 B1 — "Methods and Apparatus for a Computer Network Firewall with Multiple Domain Support"
- Assignee: Nokia of America Corp.
- Filed: September 11, 1997; Issued: November 28, 2006
- Description: Firewall architecture supporting multiple security domains/interfaces.
- §102 analysis: Decades-old; covers multi-domain firewall filtering only. Not an anticipator; weak §103 relevance to the correlation concept.
5. US 8,789,135 B1 — "Scalable Stateful Firewall Design in OpenFlow Based Networks"
- Assignee: Google LLC
- Filed: June 14, 2012; Issued: July 22, 2014
- Description: Rule-based stateful firewall using OpenFlow switches.
- §102 analysis: §102 art by date; discloses rule provisioning and packet classification but nothing about cross-device log correlation. §103 only.
6. US 2006/0195896 A1 — "Method, Systems, and Computer Program Products for Implementing Function-parallel Network Firewall"
- Assignee: Wake Forest University
- Filed: December 21, 2004; Published: August 31, 2006
- Description: Parallel firewall processing across rule subsets.
- §102 analysis: §102 art by date; §103 relevance only (rule partitioning, not correlation).
7. CA 2,600,236 A1 / EP 1,864,226 B1 — "Methods, Systems, and Computer Program Products for Network Firewall Policy Optimization"
- Assignee: Wake Forest University
- Filed: March 27, 2005
- Description: Firewall policy optimization.
- §102 analysis: §102 art by date; §103 relevance only.
8. US 2007/0147380 A1 — "Systems and Methods for Implementing Protocol-aware Network Firewall"
- Assignee: Verizon Patent and Licensing Inc.
- Filed: November 7, 2005; Published: June 28, 2007
- Description: Protocol-aware firewall inspection.
- §102 analysis: §102 art by date; §103 relevance only.
9. US 2011/0055916 A1 — "Methods, Systems, and Computer Readable Media for Adaptive Packet Filtering"
- Assignee: Great Wall Systems
- Filed: August 27, 2009; Published: March 3, 2011
- Description: Adaptive packet filtering.
- §102 analysis: §102 art by date; §103 relevance only.
C. Synthesis: which claim(s) could each reference anticipate under §102
| Reference | Date status vs. 2/10/2015 | Anticipates claim 1 (method)? | Anticipates claim 22 (system)? | Likely role |
|---|---|---|---|---|
| US 8,806,638 B2 | Issued 8/2014 — §102 art | No — lacks correlation of pre-/post-transformation logs | No — lacks correlation + responsive host-identification/communication | §103 anchor |
| US 7,602,775 B1 | Issued 2009 — §102 art | No | No | §103 |
| US 9,137,205 B2 / US2014/0115654 A1 | Published 4/2014 — §102 art | Closest — arguably discloses two-sided rule-based logging, but not the correlation step | Not without the correlation + responsive-notification elements | Primary §103 anchor / best anticipation argument |
| US 7,143,438 B1 | Issued 2006 — §102 art | No | No | §103 |
| US 8,789,135 B1 | Issued 7/2014 — §102 art | No | No | §103 |
| US 2006/0195896 A1 | Published 2006 — §102 art | No | No | §103 |
| CA 2,600,236 A1 / EP 1,864,226 B1 | Filed 2005 — §102 art | No | No | §103 |
| US 2007/0147380 A1 | Published 2007 — §102 art | No | No | §103 |
| US 2011/0055916 A1 | Published 2011 — §102 art | No | No | §103 |
Core observation: The '370's inventive heart is the correlation of packet logs from both sides of a flow-transforming network device (NAT, proxy, VPN/tunneling gateway — see specification §§ [0030]–[0038]) so that the post-transformation packets can be re-associated with the flow(s) of the pre-transformation packets, and (claim 22) the responsive identification/notification of the originating host. None of the classic firewall references (Nokia, Wake Forest, Verizon, Google, Great Wall) discloses that two-sided log correlation, which is why none is a clean §102 anticipator of the full independent claims. The strongest §102 case would have to be built on Centripetal's own US 9,137,205 (US2014/0115654), and even that reference appears to lack the explicit correlation step.
D. Explicit uncertainties (as required)
- On-face citation list not fully retrieved. The complete examiner-cited references on the front page of US9264370 could not be confirmed within this session's step limit. References in Sections A and B are identified from (A) Google Patents Cited By linkage and (B) family/litigation prior-art aggregates — both strong indicators, but neither is the equivalent of the USPTO front-page citation list. If you need the verbatim "References Cited" page, the authoritative sources are USPTO Patent Center/Patent Public Search for US 9,264,370 (application 14/618,967) or the Google Patents "Citations" tab.
- Claim numbering. Claims 1 and 22 are reconstructed/partially corroborated (claim 22's elements from the Keysight infringement-contentions exhibit; claim 1's from the spec/abstract/family claims). Any §102 "claim" mapping is therefore provisional on the exact claim language.
- No merits holding on the '370's validity. The ITC (337-TA-1314) and CAFC (24-1416, affirmed April 23, 2026) decisions turned on domestic-industry and non-infringement grounds; the CAFC did not reach patent ineligibility, and no tribunal has rendered a §102/§103 merits decision on the '370's own claims that I could verify. Keysight reported in the E.D. Va. case (2:22-cv-00002) that the '370 was time-barred for IPR, so no PTAB merits decision on the '370 exists either.
- Non-patent literature (NPL). I did not locate any NPL citations for the '370 in this session; the family aggregates I found were patent-art only.
Generated 8/30/2026, 12:48:17 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
The searches surfaced the key prior-art landscape from the ITC investigation (337-TA-1314) and the earlier E.D. Va. litigation. Let me dig deeper into the specific references identified in Keysight's invalidity contentions for the '370 patent and the Sorini/Exponent report.
Obviousness Analysis — U.S. Patent 9,264,370 ("Correlating Packets in Communications Networks") under 35 U.S.C. § 103
Note on the "Prior Art section": No prior-art section was included in the materials provided to me for this task, so I reconstructed the relevant prior art from (i) the litigation/PTAB/ITC records identified in the previously generated sections, and (ii) the live searches I ran above. The most probative sources are Keysight's invalidity contentions in ITC Inv. No. 337-TA-1314, the Sorini/Exponent invalidity report in Centripetal v. Keysight (E.D. Va. 2:17-cv-00383), and the IPR2021-01150/01151 petitions against the continuation patent U.S. 10,530,903. Where a reference's disclosure could not be verified from my sources, I say so explicitly.
1. Claims in play and the governing legal framework
Asserted claims. In the most recent merits proceeding (ITC 337-TA-1314), Centripetal asserted claims 22–27, 42–48, and 63 of the '370 patent; the investigation was terminated as to all but claims 22 and 43. The Federal Circuit's April 23, 2026 affirmance identifies claim 22 as representative of the claims at issue (24-1416, Op. at 6; see also the IP Law Daily summary). Claim 22, as corroborated by Centripetal's infringement contentions in Keysight I (Doc. 130-1) and the CAFC opinion, is a system claim requiring:
- at least one processor and memory storing instructions;
- provisioning a first device on the first-network side of a network device with rules to identify packets received by the network device from a host in the first network;
- provisioning a second device on the second-network side with rules specifying a set of network addresses, to log packets destined for those addresses;
- generating log entries for the received and transmitted packets and communicating those log entries to the system;
- correlating the transmitted packets with the received packets based on the log entries; and
- responsive to the correlation, generating data identifying the first-network host and communicating that data to a device located in the first network.
The independent method claim (reconstructed from the specification/FIG. 4 and the abstract) and the computer-readable-medium claim track the same five-step flow (identify received → log → identify transmitted → log → correlate). Because claim 22 is representative and the method/medium claims are narrower in form but not in substance, the analysis below focuses on claim 22 and applies equally to the parallel independent claims.
Legal standard. Obviousness under § 103 is a question of law based on Graham factual inquiries (scope/content of prior art, differences, level of ordinary skill, secondary considerations), informed by KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007) — including that a combination of known elements "may prove obvious if a person of ordinary skill can implement a predictable variation," and that "[t]he test is not that the claimed invention must be expressly suggested in any one or all of the references," but "what the combined teachings of the references would have suggested to those of ordinary skill in the art." MCM Portfolio LLC v. Hewlett-Packard Co., cited approvingly by the Federal Circuit in Palo Alto Networks v. Centripetal, No. 2023-1636 (Fed. Cir. Dec. 16, 2024).
Level of ordinary skill. A POSITA would have a B.S./M.S. in computer science/engineering (or equivalent experience) and 2–5 years' experience in network security, packet processing, and network monitoring — the field of the patent's specification (tap/filtering devices, NAT, proxies, VPN gateways, log correlation).
2. The primary prior-art references (verified)
Paxton — U.S. 2014/0280778 A1, "Tracking Network Packets Across Translational Boundaries" (filed Mar. 13, 2014; published Sept. 18, 2014; granted as U.S. 9,686,233). This is the closest single reference. Verified disclosures (from the published application and the companion IEEE CollaborateCom 2014 paper):
- An inside sensor before a NAT boundary and an outside sensor after the boundary, each computing a hash (e.g., MD5) of the application-layer payload and storing a hash data record containing the hash value, IP address, and timestamp.
- The records from both sensors are collected at a unified location and matched using a FIFO queue ordered by timestamps, with matching based on hash, time, and IP address — i.e., correlating the pre-boundary packet with the post-boundary packet.
- Paxton's stated purpose is security attribution: "The ability to identify the true source of packet transmission through a boundary can provide significant benefits to network security … quickly identify nodes that are infected with malicious content, which can allow the network administrator to better identify the scope of the malicious incident" and "attribute malicious activity sensed at the edge of a network back to its original source."
That is, Paxton alone discloses the sensor placement on both sides of a flow-transforming device (boundary), log-entry generation for received and transmitted packets (hash+IP+timestamp records), correlation by record comparison, and identification of the original first-network host. This covers the majority of claim 22.
Sutton — U.S. 8,413,238 B2, "Monitoring Darknet Access to Identify Malicious Activity." Verified (via the CAFC's PAN v. Centripetal opinion and the IPR record): teaches monitoring for potentially malicious activity (access to darknet/unassigned addresses), and that a "notification of potential malicious activity originating from the protected network can be provided to an administrator," and that "traffic may be automatically blocked, redirected or filtered based on predefined rules." Sutton supplies the post-correlation action element of claim 22 (communicating data identifying the suspect host to a device — an administrator's system — in the first/protected network).
Ivershen — U.S. 8,219,675 B2. Verified via the IPR2021-01151 petition analysis: expressly teaches correlating packets across a NAT by comparing parameters including ports and flow-starting timestamps within a close time window to increase correlation accuracy — the same timestamp-window correlation logic the '370 specification describes (T4−T1 < THRESHOLD, smallest-difference matching, threshold latency).
Blöcher — U.S. 9,979,695 B2, "Method, device, and system for monitoring a security network interface unit" (Siemens). Verified from the patent text: monitors a security gateway by duplicating/tapping the data stream at a second interface downstream of the gateway, checking the output stream for impermissible traffic, transmitting a warning message to the gateway if impermissible traffic is detected, and restricting the data stream. Supplies post-gateway monitoring plus responsive action.
Other asserted references (listed in the ITC and Keysight I records; individual disclosures not fully verified in my searches):
- Zuo — U.S. 8,930,690 (cited with Paxton and Sutton in ITC Exhibit A18). I could not verify its title or disclosure; it appears intended to supply rule-based packet filtering/logging at a network device. Flagged: unverified.
- Trama — U.S. 8,955,128 (cited in Keysight I via the Sorini report with PoliWall and Ixia NTO 7300). Flagged: unverified.
- Product references: TippingPoint IPS and Check Point R77 (Sorini report, Keysight I — asserted as anticipating/obvious for the '370 patent); A10 Thunder + Splunk and A10 + Lancope StealthWatch (ITC Exhibits A19–A20). I verified only that these grounds were asserted, not their detailed mappings. Flagged: unverified mappings.
3. Combination 1 (strongest): Paxton + Sutton (+ Ivershen and/or Zuo/McDonald)
Element-by-element mapping of claim 22
| Claim 22 element | Paxton | Gap-filler |
|---|---|---|
| Processor + memory | System with inside/outside sensor modules and matching module on commodity servers | — |
| First device in link between network device and first network, provisioned with rules to identify received packets | Inside sensor 120 placed before the boundary, capturing packets from the client (host in first network); sensors run "full packet capture in a promiscuous mode" | Rule-based provisioning: Ivershen/Zuo/McDonald (IPR record: McDonald "cure[s] this deficiency" of provisioning taps with rules to select packets) |
| Log entries for received packets | First hash data records (hash value, IP address, timestamp) | — |
| Second device in link between network device and second network, logging packets destined for a set of addresses | Outside sensor 125 after the boundary | — |
| Log entries for transmitted packets | Second hash data records | — |
| Correlate transmitted with received based on log entries | FIFO matching of hash records by hash+time+IP; timestamp-ordered matching | Ivershen's port + flow-start timestamp window comparison |
| Responsive to correlation, generate data identifying first-network host | Paxton attributes malicious activity to the original pre-boundary source (the client's true IP) | — |
| Communicate that data to a device in the first network | Not expressly taught (Paxton only suggests the administrator "better identify the scope") | Sutton: notify an administrator of the protected network; automatically block/redirect/filter per rules |
Motivation to combine
The motivation is unusually well documented because Paxton itself states the problem that Sutton solves. Paxton says the value of cross-boundary correlation is to "identify nodes that are infected with malicious content" and let the "network administrator better identify the scope of the malicious incident." Sutton teaches exactly the missing completion of that workflow: once a host is identified as malicious, notify the administrator of the protected network and automatically block/filter future traffic. A POSITA seeking a complete security-attribution-and-response system would combine them as "an application of known techniques to improve similar devices … to provide predictable results in the same way" (KSR).
Critically, the Federal Circuit has already signaled that this combination is viable for the '370 family. In Palo Alto Networks v. Centripetal, No. 2023-1636 (Fed. Cir. Dec. 16, 2024), the court vacated the PTAB's non-obviousness finding for the continuation '903 patent (same specification, same claim flow) over Paxton + Sutton + Ivershen, holding that the Board failed to explain why a POSITA would not be motivated to combine Paxton's correlation with Sutton's administrator notification. The court emphasized that obviousness is judged by "what the combined teachings of the references would have suggested" and rejected the Board's unexplained "necessary bridge" requirement. Although that IPR concerned U.S. 10,530,903 rather than 9,264,370 itself (Keysight was time-barred from IPR on the '370), the claims share the identical correlation-plus-notification architecture, so the Federal Circuit's reasoning transfers directly.
Weaknesses of this ground (and responses)
- The "rules provisioning" element: Paxton's sensors passively capture rather than being "provisioned with rules specifying a set of network addresses." This is the main textual gap. It is curable with Zuo/McDonald (rule-based tap provisioning) and is, in any event, a conventional configuration step. Note that broader claim language makes § 103 easier, not harder: the '370 claims require only a set of destination addresses in the rules, and Paxton's sensors are inherently configured to capture traffic to particular destinations.
- The "responsive to the correlation" transmission: The PTAB (in the '903 IPR) found Sutton's notification "unrelated to any correlation." But the Federal Circuit vacated that reasoning, and the gap is modest: Sutton teaches notification of malicious-activity identification; Paxton teaches the identification; bridging them is the routine application of a known response to a known detection. Under KSR, express suggestion in a single reference is not required.
4. Combination 2: Paxton + Blöcher (ITC Exhibit A17)
Blöcher teaches tapping a data stream at a second interface downstream of a security gateway, checking for impermissible traffic, and transmitting a warning to the gateway and restricting the data stream. Combining with Paxton gives: sensors both sides (Paxton) + post-gateway integrity monitoring and responsive enforcement (Blöcher). Motivation: both references address the same failure mode — a boundary/gateway that alters or mis-handles traffic — and the combination yields correlation plus enforcement. Blöcher's responsive warning/restriction maps more weakly than Sutton's administrator notification to the "communicate data identifying the host to a device in the first network" element (Blöcher warns the gateway, not a device in the protected network), so this ground is secondary to Paxton+Sutton.
5. Combination 3: Paxton + Zuo + Sutton (ITC Exhibit A18)
If Zuo (unverified) provides rule-based identification/logging at a packet-filtering network device, the trio supplies every element: Paxton (dual-sided correlation), Zuo (rule-provisioned packet identification/logging), Sutton (administrator notification + automated blocking). Motivation: Zuo and Paxton operate in the same packet-filtering/NAT domain; both were cited together with Sutton in the same invalidity chart, and the motivation rationale is the same security-attribution workflow as Combination 1.
6. Product-based grounds (from the litigation record)
- TippingPoint IPS and Check Point R77 (Sorini/Exponent report, Keysight I): enterprise security gateways with dual-interface packet filtering, logging, and alerting. The Sorini report apparently mapped these to the '370 claims as anticipating and/or obvious. I could not verify the detailed mappings from my sources, so these are lower-confidence grounds.
- A10 Thunder + Splunk and A10 + Lancope StealthWatch (ITC Exhibits A19–A20): A10 application-delivery/security devices performing NAT and filtering, combined with a log-analytics platform (Splunk) or network-visibility/flow-correlation system (StealthWatch). The combination theory is that A10 provides the flow-transforming network device and tap points, while Splunk/StealthWatch provide log correlation and alerting — the functional equivalent of the claimed system. Mappings unverified.
- Trama (U.S. 8,955,128) + PoliWall + Ixia NTO 7300 (Sorini report): Trama's rule-based packet filtering plus Ixia network-packet-broker products (PoliWall, NTO 7300) providing tap/copy functionality. Mappings unverified.
7. Secondary considerations and counterarguments
Centripetal would likely counter with:
- Long-felt need / failure of others: the '370 specification itself opens with "there is a need for correlating packets in communications networks" — but need alone, unaccompanied by evidence of unsuccessful attempts, does not negate obviousness where the art supplies the solution (Paxton already solved the correlation problem in 2014, before the '370's February 2015 filing).
- Commercial success: Centripetal's CleanINTERNET/RuleGATE products. This is significantly weakened by the ITC's finding that the DI product failed the technical prong (did not practice claim 22's "device" limitations) — a nexus problem: success of products that do not practice the claims cannot rebut obviousness.
- Licensing (Keysight I settlement): a limited-term license is ambiguous evidence of non-obviousness and is not a merits adjudication.
- The "rules" and "responsive communication" limitations: the strongest textual arguments, addressed above; the Federal Circuit's December 2024 vacatur substantially undercuts them.
Procedural caveats: The ITC's Final ID actually invalidated claims 22 and 43 under § 101 (abstract idea), not § 103 — the § 103 grounds (Exhibits A17–A20) were not the basis of the final invalidity, and the Federal Circuit (April 23, 2026) affirmed on the domestic-industry technical prong and non-infringement waiver without reaching invalidity. The PTAB's only merits decision on this claim family (IPR2021-01150, finding Paxton+Sutton+Ivershen insufficient for the '903 patent) was vacated and remanded by the Federal Circuit in December 2024. No post-remand PTAB decision was located in my searches.
8. Bottom line
The strongest § 103 case is Paxton (U.S. 2014/0280778) + Sutton (U.S. 8,413,238), optionally + Ivershen (U.S. 8,219,675) for the system claim 22 and the parallel method/medium claims:
- Paxton discloses every technical element of the correlation architecture — sensors on both sides of a flow-transforming boundary, log records (hash+IP+timestamp) for received and transmitted packets, timestamp-ordered correlation, and attribution of the original first-network host — which is the heart of the claimed invention.
- Sutton supplies the only material gap (responsive administrator notification / automated blocking), and Paxton's own text expressly identifies the security-attribution goal that Sutton's notification implements.
- The Federal Circuit has already vacated the only contrary merits decision for the identical claim architecture (continuation '903), holding the Board failed to justify why a POSITA would not combine Paxton and Sutton.
- The supplemental references (Ivershen for timestamp-window correlation; Zuo/McDonald for rule-based tap provisioning; Blöcher for post-gateway monitoring and enforcement) fill any residual textual gaps and were each formally asserted in the ITC or IPR records.
Confidence levels: High confidence that Paxton+Sutton(+Ivershen) renders the method/medium claims and the correlation-plus-notification aspects of claim 22 obvious. Moderate confidence for the full system claim 22, given the "rules provisioning" and "responsive transmission to a device in the first network" limitations — the latter being precisely the element over which the PTAB and Federal Circuit have diverged. Low-to-moderate confidence on the product-based grounds (TippingPoint, Check Point, A10/Splunk/StealthWatch, PoliWall/NTO 7300), whose detailed mappings I could not verify from available sources.
Generated 8/30/2026, 12:48:41 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, LLC
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9137205Summary: US Patent 9,137,205 (US9137205B2) Bibliographic data | Field | Value | |---|---| | Title | Methods and systems for protecting a secured network | | Patent / Publication No. | US 9,137,205 B2 (US9137205B2) | | Application No. | US…
Other patents in Software Technology & Computing Systems (T)
- US 9565213I'll search the USPTO database and CAFC dockets for this specific patent number. I have solid data on the patent itself. Now let me find the actual claim text and check for CAFC 2026 docket entries specific to this patent. US Patent…
- US 8527591US Patent 8,527,591 B2 — Summary Bibliographic Data (from Google Patents / USPTO records) | Field | Value | |---|---| | Patent No. | US 8,527,591 B2 (application US 12/783,743) | | Title | Method and apparatus for the implementation of a…
- US 9185145I'll search for the specific patent number and related dockets, prioritizing live results over my training data. The initial searches confirm the patent identity but returned no CAFC 2026 dockets. Let me search more specifically for the…
- US 9729594The CAFC search returned no direct hits. Let me search further for the claims text and the Federal Circuit appeal associated with this patent. I found the CAFC docket (24-1630, Rule 36 affirmance on 2026-03-09). Now let me retrieve the…
- US 10067942I'll search for authoritative information about US patent 10067942, including any CAFC 2026 docket activity. Let me dig deeper into the CAFC appeal status and USPTO records. I've gathered what's available. Note: I hit a search-step limit…
- US 9143561I'll search for the current authoritative status of US Patent 9,143,561, including any USPTO and CAFC docket activity. US Patent 9,143,561 — Analyst Summary Verification note I searched for the exact number 9143561 (USPTO/Google Patents…
- US 9483448I'll search for the specific patent number 9483448 and any CAFC docket references. Both searches returned no results. Let me try alternate search formulations. I have good confirmation of the patent's core details and litigation history…
- US 6965920US Patent 6,965,920 — Summary Bibliographic data | Field | Value | |---|---| | Title | Profile responsive electronic message management system | | Patent No. | US 6,965,920 B2 (application no. 09/904,270) | | Inventor | Peter Henrik…
This patent in court (2)
2 tracked lawsuits name US 9264370.