IP Law Daily, PATENT—Fed. Cir.: Invalidity of Centripetal's network threat detection patent affirmed on appeal, (Oct 31, 2024)
Law Firms Mentioned:Kramer Levin Naftalis & Frankel LLP | Ropes & Gray LLP
Organizations Mentioned:Centripetal Networks, LLC | Kramer Levin Naftalis & Frankel, LLP | Palo Alto Networks, Inc. | Ropes & Gray, LLP

By Saurabh Kashyap, B.A., LL.B., LL.M.
PTAB correctly found that patent claims were unpatentable as obvious in light of prior art references.
The U. S. Court of Appeals for the Federal Circuit upheld the Patent Trial and Appeal Board’s (PTAB) ruling in an inter partes review (IPR) that all claims of U.S. Patent No. 10,567,413 (the ’413 patent), held by Centripetal Networks, LLC, were unpatentable due to obviousness under 35 U.S.C. § 103. The appellate court ruled that the PTAB correctly identified two critical limitations of the '413 patent—its placement at the network boundary and its reputation-based scoring method—as unoriginal when assessed against prior references, thereby upholding the PTAB’s conclusion of unpatentability due to obviousness (Centripetal Networks, LLC v. Palo Alto Networks, Inc. , No. 23-1785 (Fed. Cir. Oct. 31, 2024)).
Background. The appellant, Centripetal Networks, LLC, operates within the cybersecurity industry, focusing on technologies designed to detect, analyze, and respond to potential network threats in real time. Its core product line includes network threat detection systems using advanced filtering rules and threat identifiers. The appellee, Palo Alto Networks, Inc. (PAN), is a global cybersecurity company providing enterprise security services and hardware. Its services include network security solutions, specifically firewall technologies, threat intelligence, and cloud-based security services.
The ’413 patent is titled “Rule-Based Network-Threat Detection.” It claims a method involving a “packet-filtering device” strategically positioned between protected and unprotected networks. The device uses packet-filtering rules to identify network threats and generates data logs with details about detected threats. Representative claim limitations of the '413 patent include (1) the packet-filtering device's placement at a “boundary” and (2) a scoring system based on the number of threat intelligence providers, which orders threat identifiers in a specific listing format. Claims 6–8, 15, and 20, dependent on the primary claims, detail further specific implementations of the score-determination process.
In March 2021, Centripetal Networks filed a lawsuit against PAN in district court alleging infringement of the ’413 patent along with other patents not relevant to this appeal. In July 2021, PAN filed an IPR petition with the PTAB asserting that the ’413 patent claims (1–20) were obvious and, therefore, unpatentable. PAN based its challenge on prior art references, including the Sourcefire 3D System User Guide (Sourcefire) and U.S. Patent Application Publication No. 2015/0207809 (Macaulay). The PTAB agreed to review the patent in February 2022. In a final written decision in February 2023, it concluded that all claims of the ’413 patent were unpatentable under the obviousness standard set by 35 U.S.C. § 103. Centripetal appealed.
“Boundary” limitation. One of Centripetal's primary arguments on appeal involved the “boundary” limitation, which defines the packet-filtering device's placement at the intersection of protected and unprotected networks. Centripetal contended that the PTAB's analysis incorrectly broadened the construction of the boundary limitation, resulting in an interpretation that conflicted with the ordinary and intended meaning of the term. The PTAB, however, rejected this view, emphasizing that the Sourcefire adequately taught the boundary element.
Relying on Phillips v. AWH Corp., 415 F.3d 1303 (Fed. Cir. 2005), the appellate court determined that Centripetal’s interpretation was overly restrictive. Citing the patent's Figure 2A to show that the boundary could encompass network devices like routers and taps, the court upheld the PTAB's boundary interpretation, finding it consistent with the patent's intrinsic evidence.
“Score-determination process.” The "score-determination process" in the patent claims described a method to rank or prioritize network threats based on information from multiple threat intelligence sources. The PTAB’s obviousness determination for the “score-determination” limitation centered on whether a skilled artisan would combine Sourcefire’s network security features with Macaulay’s system of reputation scores to create such a process.
Upon analysis, the PTAB found substantial evidence that the prior art's teachings could be reasonably combined. It noted that Sourcefire lacked a specific mechanism for prioritizing threats, which would logically lead one skilled in the art to incorporate Macaulay's scoring system. The Federal Circuit concurred, referencing Personalized Media Communications, LLC v. Apple Inc., 952 F.3d 1336 (Fed. Cir. 2020), confirming that the PTAB’s conclusions were supported by substantial evidence and sound reasoning.
Dependent claims analysis. Centripetal argued that PAN's petition failed to properly outline the obviousness challenge for claims 6–8, 15, and 20, asserting that PAN's cross-references to the independent claims were inadequate. The PTAB had considered PAN's references sufficient, determining that the arguments extended logically from the independent claims. Upon review, the Federal Circuit found PAN's references valid, noting that the petition incorporated the arguments made for the independent claims in its analysis of the dependent claims. Therefore, the Federal Circuit upheld the PTAB’s ruling, referencing Rovalma, S.A. v. Bohler-Edelstahl GmbH & Co. KG, 856 F.3d 1019 (Fed. Cir. 2017), to underscore that adequate notice was provided.
Motivation to combine. Finally, Centripetal argued that the PTAB failed to recognize a “teaching away” from combining Sourcefire's customizable priority system with Macaulay's generalized scoring method. Centripetal claimed Sourcefire's approach, which encourages setting priorities based on specific organizational needs, directly conflicted with Macaulay's reputation-based scoring, which uses general threat assessments rather than customized configurations. Centripetal contended that a skilled artisan would have been discouraged from integrating these two approaches as they served distinct operational goals.
The Federal Circuit disagreed, noting that “teaching away” requires the prior art to actively discourage or lead away from following the path of the claimed invention. Referencing In re Gurley, 27 F.3d 551, 553 (Fed. Cir. 1994), the court clarified that teaching away occurs only if a skilled artisan would be steered in a divergent direction or dissuaded from the claimed combination. The court affirmed the PTAB’s finding that Sourcefire’s customization and Macaulay’s reputation-based scoring, in the eyes of a skilled artisan, could complement one another, with Macaulay’s scores adding useful, broader threat data to Sourcefire’s priority settings.
Conclusion. Ultimately, the appellate court upheld the PTAB’s interpretation of claim terms, the adequacy of PAN’s references to dependent claims, and the motivation to combine the teachings of Sourcefire and Macaulay. Thus, the Federal Circuit affirmed the PTAB’s ruling that Centripetal’s asserted patent was unpatentable due to obviousness.
The Case is No. 23-1785.
Judge: Taranto, R.
Attorneys: James R. Hannah (Kramer Levin Naftalis & Frankel LLP) for Centripetal Networks, LLC. Douglas Hallward-Driemeier (Ropes & Gray LLP) for Palo Alto Networks, Inc.
Companies: Centripetal Networks, LLC; Palo Alto Networks, Inc.
MainStory: TopStory Patent FedCirNews USPTO GCNNews