Fortinet, Inc. v. Palo Alto Networks, Inc.

753 F. Supp. 2d 1024, 2010 U.S. Dist. LEXIS 119656, 2010 WL 4698387
District Court, N.D. California·Decided November 8, 2010·No. C-09-00036 RMW·Published

Opinion

ORDER CONSTRUING CLAIMS OF THE '125 AND '311 PATENTS AND GRANTING IN PART AND DENYING IN PART PAN’S MOTION FOR SUMMARY JUDGMENT OF NON-INFRINGEMENT

RONALD M. WHYTE, District Judge.

Fortinet, Inc. (“Fortinet”) alleges that Palo Alto Networks, Inc. (“PAN”)’s PA-4000 Series, PA-2000 Series, and PA-500 Series Firewalls infringe claims 1 through 4 of United States Patent No. 7,376,125 (“'125 Patent”) and claims 1 through 16 of United States Patent No. 7,177,311 (“'311 Patent”). The parties seek construction of claim language in the '125 and '311 Patents. PAN moves for summary judgment that the accused products do not infringe the asserted claims of the '125 and '311 Patents. The court held a tutorial and claim construction hearing on July 20, 2010. After consideration of the claims, specification, prosecution history, and other relevant evidence, and after hearing the argument of the parties, the court construes the disputed claim language in the '125 and '311 Patents as set forth below. In addition, for the reasons set forth below, the court grants in part and denies in part the motion for summary judgment of non-infringement.

I. BACKGROUND

This case deals with firewall technology. Firewalls control network traffic traveling between networks or zones of different trust levels, such as between the Internet and a local area network (“LAN”). Dkt. No. 146 ¶ 12. In order to protect a LAN from undesirable content, such as viruses and spam, firewalls analyze incoming and outgoing network traffic. Id. ¶ 15. Network traffic consists of packets of data. Because analyzing each individual packet can be expensive, some firewalls will analyze a flow. Id. ¶ 30. A flow consists of all packets having the same source and the same endpoint. Id. A session consists of two flows, one including all packets having source A and endpoint B, and the other including all packets having source B and endpoint A. Id.

The '125 Patent teaches a system and method that involves: (1) establishing a *1027 flow cache for storing information learned from previous packets about how packets in a flow should be treated, (2) receiving a packet, (3) forwarding the packet to a virtual routing engine, and (4) using the flow cache to determine whether the packet requires processing by a virtual service engine. Similarly, the '311 Patent teaches a system and method that involves: (1) establishing a flow cache for storing information learned from previous packets about how packets in a flow should be treated, (2) receiving a packet, and (3) using the flow cache to determine whether to software forward or hardware forward the packet. For illustrative purposes, the language in claim 1 of the '125 Patent is set forth below:

A method comprising:
establishing a flow cache having a plurality of entries each identifying one of a plurality of virtual router (VR) flows through a VR-based network device and corresponding forwarding state information;
receiving a packet at an input port of a line interface module of the VR-based network device;
the line interface module forwarding the packet to a virtual routing engine (VRE);
the VRE determining one or more appropriate packet transformations for application to the packet by performing flow-based packet classification on the packet;
using a result of the flow-based packet classification to retrieve an entry of a plurality of entries of the flow cache; on a flow cache hit, determining, based on the corresponding forwarding state information of the retrieved flow cache entry, whether to process the packet with a virtual service engine (VSE) of the VR-based network device;
on a packet flow cache miss, identifying the existence of a new VR flow and upon successful allocation of a new entry of the packet flow cache for the new VR flow, forwarding the packet to software on the processor for flow learning.

'125 Patent 15:61-16:17.

The accused products are PAN’s PA-4000 Series, PA-2000 Series, and PA-500 Series Firewalls. [Redacted]

II. CLAIM CONSTRUCTION

The '125 and '311 Patent applications were filed concurrently, and their specifications are incorporated into one another by reference. See '125 Patent 1:24-30; '311 Patent 1:14-35. Hence, the parties agree that claim terms should be construed as having the same meaning in both patents. The parties seek construction of the following claim terms in bold: “upon successful allocation of a new entry of the packet flow cache for the new VR flow, forwarding the packet to software on the processor for flow learning.” '125 Patent 16:14-17 (claim 1), 16:45-48 (claim 3), 17:7-18:3 (claim 5); '311 Patent 15:25-28 (claim 1), 16:32-35 (claim 9), 17:43-46 (claim 17).

Initially, the parties disputed the proper construction of both “upon successful allocation of a new entry ... for the new VR flow” and “flow learning.” However, the parties have since reached agreement regarding the meaning of these terms. At the claim construction hearing on July 20, 2010, the parties agreed that “upon successful allocation of a new entry ... for the new VR flow” should be construed as meaning: after successful assignment of a new entry identifying the new VR flow. The parties also agreed that “flow learning” means determining *1028 how packets in the flow should be treated. The court thus adopts these constructions,

The parties’ proposed constructions for the remaining terms in dispute are set forth below:

[[Image here]]

A. “Packet Flow Cache”

In its supplemental briefing, Fortinet asserts for the first time that “flow cache” is a term of art in virtual routing but fails to point to any evidence suggesting that a “flow cache,” as understood by one of ordinary skill in the art of virtual routing, refers to something other than a cache used for flows. See Dkt. No. 213 n. 11; Dkt. No. 214 ¶ 17. In the absence of any evidence suggesting that the inventor sought to use the term “cache” in a manner different from its ordinary and customary meaning, the court concludes that a “packet flow cache,” as used in the '125 and '311 Patents, refers to a cache used for packet flows.

The parties agree that “cache” refers to memory for temporary storage of information. PAN argues that, in addition, “cache” necessarily refers to an intermediate memory location, separate from main memory, that permits faster access than would be possible from main memory. “Cache” is used in the '311 Patent in a manner consistent with PAN’s construction requiring it to be separate from main memory. See '311 Patent 4:29-5:6, Figs. 1, 2 (depicting memory 114 separate from the Packet Forwarding Engine 110 which contains cache 212). However, based on intrinsic evidence alone, it remains unclear whether a “cache” necessarily must be separate from main memory.

Free access — add to your briefcase to read the full text and ask questions with AI

Fortinet, Inc. v. Palo Alto Networks, Inc., 753 F. Supp. 2d 1024, 2010 U.S. Dist. LEXIS 119656, 2010 WL 4698387 (N.D. Cal. 2010).

753 F. Supp. 2d 1024 (Fortinet, Inc. v. Palo Alto Networks, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related