Centripetal v. Palo Alto Networks: Federal Circuit Vacates Patentability Ruling
Centripetal Networks, LLC challenged a patentability determination against US9917856B2 — a patent covering rule-based threat detection for encrypted network communications — at the Federal Circuit against Palo Alto Networks, Keysight Technologies, and Cisco Systems. After 860 days, the court vacated the lower decision and remanded for further proceedings.
Federal Circuit resets the patentability fight over encrypted-traffic threat detection
Centripetal Networks, LLC filed Case No. 23-2027 at the Court of Appeals for the Federal Circuit on 15 June 2023, appealing a patentability determination — classified as an invalidity or cancellation action — concerning US9917856B2 (application no. US14/757638). The patent covers rule-based detection of network threats within encrypted communications, a technically significant capability in the cybersecurity stack. The defendants include three major industry players: Palo Alto Networks, Inc., Keysight Technologies, Inc., and Cisco Systems, Inc.
On 22 October 2025, the Federal Circuit issued a disposition of VACATED AND REMANDED. This outcome means the appellate court identified legal error or insufficient reasoning in the lower tribunal’s patentability ruling sufficient to nullify it entirely — but stopped short of resolving the merits itself, instead returning the matter for reconsideration consistent with its guidance. Neither party has achieved a final win on validity at this stage.
The 860-day duration suggests substantive briefing and potentially oral argument before the panel reached its decision, consistent with the technical complexity of encrypted-traffic threat detection claims. The remand leaves US9917856B2’s validity unresolved, which prolongs commercial uncertainty for both Centripetal and the three defendants operating in adjacent cybersecurity markets. What specific legal error the Federal Circuit identified — claim construction, obviousness analysis, or evidentiary sufficiency — is not determinable from the public docket data alone.
Filing to Vacated and Remanded in 860 days
860 days from filing to Federal Circuit disposition — above average for CAFC appeals
Federal Circuit vacates: what the remand means for both sides
Vacated means the lower ruling is legally void
A Federal Circuit vacatur nullifies the tribunal’s prior patentability determination — it has no legal force going forward. Unlike an affirmance or reversal, vacatur typically signals that the panel found a flaw in the legal framework applied or the sufficiency of reasoning below, without being able to resolve the question itself. The remand instructs the lower body to reconsider under corrected guidance.
Decision nullified on appealCentripetal avoids a final invalidity ruling — for now
For Centripetal Networks, vacatur is a meaningful reprieve. A final invalidity finding would have extinguished US9917856B2’s enforceability across the market. Instead, the patent’s validity is again an open question, and Centripetal retains the opportunity to argue for its survival on remand. However, the uncertainty also prolongs the period in which the patent cannot be fully leveraged in licensing or enforcement campaigns.
Validity question reopenedDefendants must re-litigate patentability on remand
Palo Alto Networks, Keysight Technologies, and Cisco Systems did not secure the definitive invalidity ruling they likely sought. The vacatur resets the proceeding, requiring the defendants to re-engage in the lower forum under whatever corrected standard the Federal Circuit has specified. This extends litigation costs and leaves the defendants exposed to potential patent enforceability if validity is ultimately confirmed on remand.
No final win for challengersEncrypted-threat-detection IP remains commercially unsettled
US9917856B2 covers a capability — rule-based threat detection in encrypted traffic — that sits at the core of next-generation firewall and network security products. With validity unresolved, vendors competing in this space face continued FTO risk. The remand also signals that the Federal Circuit views the patentability analysis as insufficiently rigorous, which may affect how similar claims in this technology domain are examined going forward.
Sector FTO risk persistsFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | Centripetal Networks, LLC | Company | Cybersecurity IP licensor — holder of US9917856B2 covering encrypted-traffic threat detectionSearch in Eureka ↗ |
| Defendant | Palo Alto Networks, Inc. | Company | Palo Alto Networks, Keysight Technologies, and Cisco Systems — major cybersecurity and networking vendorsSearch in Eureka ↗ |
| Co-Defendant | Keysight Technologies, Inc. | Company | Search in Eureka ↗ |
| Co-Defendant | Cisco Systems, Inc. | Company | Search in Eureka ↗ |
| Plaintiff counsel | Joseph DeMott | Attorney | Counsel for Centripetal Networks, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Matthew James Dowd | Attorney | Counsel for Centripetal Networks, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Matthew Rowen | Attorney | Counsel for Centripetal Networks, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Paul D. Clement | Attorney | Counsel for Centripetal Networks, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Robert James Scheffel | Attorney | Counsel for Centripetal Networks, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Clement & Murphy, PLLC | Law Firm | Representing Centripetal Networks, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Dowd Scheffel PLLC | Law Firm | Representing Centripetal Networks, LLCSearch in Eureka ↗ |
| Defendant counsel | Andrew T. Radsch | Attorney | Counsel for Palo Alto Networks, Inc.Search in Eureka ↗ |
| Defendant counsel | Douglas HallwardDriemeier | Attorney | Counsel for Palo Alto Networks, Inc.Search in Eureka ↗ |
| Defendant counsel | James Richard Batchelder | Attorney | Counsel for Palo Alto Networks, Inc.Search in Eureka ↗ |
| Defendant law firm | Ropes & Gray, LLP | Law Firm | Representing Palo Alto Networks, Inc.Search in Eureka ↗ |
| Presiding judge | Judge N/A | Judge | Court of Appeals for the Federal CircuitSearch in Eureka ↗ |
Official order — verbatim text
The Federal Circuit’s order — ‘VACATED AND REMANDED’ — is a substantive appellate disposition indicating the court found reversible legal error in the tribunal below’s patentability determination. Vacatur carries a higher threshold than mere disagreement with factual findings; it typically reflects a deficiency in legal standard application, claim construction, or reasoning sufficiency. For Centripetal, it preserves the patent’s validity as a live issue. For the defendants, it eliminates the invalidity shield they had secured at the lower level, requiring re-litigation on remand under the Federal Circuit’s corrected framework.
US9917856B2 — Rule-based network-threat detection for encrypted communications
US9917856B2, filed under application number US14/757638, protects methods and systems for detecting network threats within encrypted communications using rule-based analysis. This capability addresses a critical gap in traditional network security: the inability to inspect encrypted traffic for malicious behaviour without decrypting it. The patent’s claims are positioned in the network detection and response (NDR) and next-generation firewall (NGFW) space, where encrypted traffic analysis has become a core competitive differentiator.
The strategic importance of US9917856B2 is evidenced by the breadth of defendants — Palo Alto Networks, Keysight Technologies, and Cisco Systems — all of whom offer products operating in or adjacent to encrypted-traffic threat detection. For any vendor deploying rule-based correlation engines against TLS or other encrypted protocol flows, this patent represents a live enforcement risk. The Federal Circuit’s vacatur of the invalidity ruling means the patent’s claims have not been extinguished and must be treated as presumptively valid pending remand resolution.
Should you run an FTO against US9917856B2?
Any R&D or product team developing network security solutions that involve detecting threats within encrypted communications — including TLS inspection bypass, behavioural analytics on encrypted flows, or rule-based correlation for NDR or NGFW platforms — should treat US9917856B2 as a priority FTO target. The Federal Circuit’s vacatur means no invalidity shield exists from this proceeding, and the patent remains enforceable pending remand. With Centripetal having demonstrated willingness to pursue major vendors, smaller players are not insulated from risk.
PatSnap Eureka’s FTO Search Agent allows you to map your product’s technical architecture against the claims of US9917856B2, identify potential design-arounds, and monitor the remand proceedings for changes in validity status. Eureka’s claim chart automation and prior art discovery tools can accelerate the analysis across the encrypted-traffic detection claim landscape — delivering actionable FTO conclusions faster than traditional manual review.
Run a freedom-to-operate analysis on US9917856B2 to assess your product’s exposure
Run FTO in Eureka →Similar Federal Circuit patentability appeals in cybersecurity and network security
Cases involving network security patent validity at the Federal Circuit, particularly those concerning encrypted communications and threat detection technology.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Rule-based network-threat detection for encrypted communications-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedCentripetal Networks, LLC’s broader IP enforcement history
Centripetal Networks, LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the cybersecurity patent IP landscape
A Federal Circuit vacatur in a multi-defendant patentability appeal keeps encrypted-traffic security IP in legal play — with implications across the sector.
Vacatur restores enforcement optionality for US9917856B2
With no final invalidity ruling in place, Centripetal retains the right to assert US9917856B2 in licensing negotiations and enforcement actions. Companies currently practicing rule-based threat detection for encrypted communications — particularly in NGFW, NDR, and network monitoring products — should treat this patent as active enforcement risk until the remand concludes.
Multi-defendant structure signals broad market relevance of the claims
The presence of Palo Alto Networks, Keysight Technologies, and Cisco Systems as co-defendants in a single invalidity action suggests these claims read broadly enough to threaten multiple product lines simultaneously. This pattern is consistent with a patent holder pursuing high-value, portfolio-level licensing leverage across the network security stack.
Federal Circuit’s error signal constrains the remand tribunal’s options
When the Federal Circuit vacates rather than affirms, it implicitly identifies the analytical framework the lower body must correct. Patent professionals tracking this remand should monitor what specific legal error was cited — claim construction errors typically yield broader validity restoration, while evidentiary gaps may result in a narrower outcome on remand.
Competing vendors face asymmetric cost exposure during remand
Cisco, Palo Alto Networks, and Keysight each face independent product-level FTO exposure while the remand proceeds. Smaller players in encrypted-traffic analytics who were not parties to this action have received no invalidity protection from these proceedings and should conduct independent FTO assessments against US9917856B2 without relying on the outcome here.
Centripetal v Palo — key questions answered
The Federal Circuit vacated and remanded the lower patentability determination concerning US9917856B2 on 22 October 2025. This means the court nullified the prior ruling and returned the case for reconsideration, without issuing a final validity decision itself. Neither party secured a definitive outcome on the merits.
US9917856B2 (application US14/757638) covers rule-based detection of network threats within encrypted communications. It is commercially significant because it addresses a core challenge in modern cybersecurity — identifying malicious activity in encrypted traffic without full decryption — which underpins capabilities in NGFW, NDR, and network monitoring products offered by major vendors.
A vacatur nullifies the lower tribunal’s patentability ruling, meaning any prior invalidity finding has no legal force. US9917856B2 retains its presumption of validity under 35 U.S.C. § 282 pending final resolution on remand. Parties cannot rely on the vacated decision as an invalidity shield in separate proceedings.
The multi-defendant structure suggests Centripetal’s claims under US9917856B2 read broadly enough to implicate products from multiple major cybersecurity and network infrastructure vendors simultaneously. This pattern is consistent with coordinated invalidity challenges — common when several industry players face exposure from a single foundational patent and share an interest in invalidating it.
Following a vacatur and remand, the lower tribunal — typically the Patent Trial and Appeal Board or a district court — must reconsider the patentability question under the corrected legal framework identified by the Federal Circuit. This may involve additional briefing, new claim construction analysis, or reassessment of prior art evidence. The outcome of the remand can again be appealed to the Federal Circuit.
Monitor the US9917856B2 remand and protect your network security products
With the Federal Circuit’s vacatur leaving US9917856B2’s validity unresolved, FTO exposure persists for vendors in encrypted-traffic threat detection. Use PatSnap Eureka to track the remand outcome and run automated claim analysis against your product architecture.
PatSnap Eureka searches patents and litigation data to answer instantly.