Table of Contents
Are cybersecurity methods patentable? Yes — but eligibility, not novelty, is where most security inventions live or die. A genuinely new threat-detection or encryption method can still be thrown out at the patent office door if it is claimed as an abstract idea rather than a concrete improvement to how a computer or network works. Since the Supreme Court’s 2014 Alice decision, US courts have drawn a workable line between the two, and the Federal Circuit has upheld security patents on one side of it and struck down others on the other. This guide walks through where that line falls, the cases that define it, and how to claim a cybersecurity method so it survives.
Are Cybersecurity Methods Patentable? The Short Answer

The short answer is yes. Cybersecurity methods are patentable subject matter in the United States and Europe, and thousands are granted every year — IFI CLAIMS reports cybersecurity patent grants growing about 11% a year for the past decade. What trips filers up is not whether security is patentable in principle, but whether a particular claim survives the eligibility test under 35 U.S.C. § 101.
Section 101 says you can patent a new and useful “process, machine, manufacture, or composition of matter.” The Supreme Court has read into it an implicit exception: you cannot patent an abstract idea. A cybersecurity method claimed at the level of “detect the bad thing and block it” reads as an abstract idea implemented on a generic computer. The same underlying invention claimed as a specific technical mechanism that improves how the computer or network operates is eligible. The whole game is on which side of that line your claim sits.
- Eligible — a specific technique that improves the functioning of a computer or network (e.g. a concrete intrusion-detection architecture).
- Ineligible — a result stated abstractly and applied on an ordinary computer (e.g. “filter content you don’t want”).
- The dividing question is technical improvement versus abstract result — not how clever or novel the idea is.
The Alice Two-Step, Applied to Security
Courts test eligibility with the two-step framework from Alice Corp. v. CLS Bank International, 573 U.S. 208 (2014). Step one asks whether the claim is “directed to” an abstract idea. Step two asks whether the claim nonetheless adds an “inventive concept” — something significantly more than the abstract idea implemented on generic hardware.
For cybersecurity, the decisive move usually happens at step one. If the claim recites a specific improvement to computer or network capability, the Federal Circuit has repeatedly held it is not directed to an abstract idea at all — and the analysis ends there, in the patentee’s favour, without ever reaching step two. If the claim is instead directed to an abstract result, the case turns on step two, where “apply it on a computer” almost never rescues it. That is why claim drafting, not the invention itself, tends to decide the outcome.
When Courts Say Yes: Finjan, SRI and Ancora

Three Federal Circuit decisions show what an eligible cybersecurity claim looks like, and each one stopped at Alice step one.
- Finjan, Inc. v. Blue Coat Systems, 879 F.3d 1299 (Fed. Cir. 2018) — Finjan’s ‘844 patent claimed behaviour-based malware detection that generates a security profile identifying suspicious code before it runs. The court held this a “non-abstract improvement in computer functionality,” eligible at step one, and upheld the underlying jury award of roughly $39.5 million.
- SRI International v. Cisco Systems, 930 F.3d 1295 (Fed. Cir. 2019) — SRI’s network-intrusion-detection patents recited a specific technique for monitoring and correlating network traffic. The court found the claims “improve the technical functioning of the computer and computer networks” and were not directed to an abstract idea.
- Ancora Technologies v. HTC America, 908 F.3d 1343 (Fed. Cir. 2018) — a method of verifying software licences using a computer’s BIOS memory was held eligible because it was a “concrete assignment of specified functions” that improved computer security.
The common thread is specificity. None of these claims said “detect threats”; each recited a particular technical mechanism located in the machine — a generated security profile, a traffic-correlation technique, a BIOS-anchored check — and tied it to an improvement in how the computer or network worked.
When Courts Say No: Intellectual Ventures v. Symantec
The counter-example is instructive because it involved the same broad problem — screening out malicious content — that Finjan won on. In Intellectual Ventures I LLC v. Symantec Corp., 838 F.3d 1307 (Fed. Cir. 2016), the court held claims of the ‘050 and ‘142 patents ineligible. The claims were directed to filtering emails and screening files for unwanted content — results the court found were long-practised abstract ideas, recited without a specific technical mechanism, and merely applied on conventional computers.
Tellingly, the same decision upheld one claim of a third patent (the ‘610) that recited a more concrete virus-screening architecture. So one opinion drew the line twice: the abstractly-claimed filtering fell, the concretely-claimed screening survived. The lesson for a cybersecurity filer is that the subject matter — malware, spam, viruses — does not decide eligibility. The specificity of the claimed technical solution does.
How to Claim a Cybersecurity Method So It Survives
If you are asking whether cybersecurity methods are patentable in your specific case, the practical answer is: they are, if you draft toward the technical-improvement side of the line. The case law and the USPTO’s 2019 Revised Patent Subject Matter Eligibility Guidance point to the same drafting discipline.
- Claim a mechanism, not a goal. Recite the specific technique — how the detection, correlation or verification actually works — rather than the security outcome it achieves.
- Anchor the improvement in the machine. Explain, in the claim and the specification, how the method improves the functioning of the computer, network or memory, the way Finjan and SRI did.
- Show a technical problem and a technical solution. Frame the invention as solving a computer-centric problem (a network-security limitation), not a business or human problem dressed in software.
- Write the specification to support it. Eligibility is often won on the technical detail the specification supplies, so describe the architecture concretely enough that the improvement is self-evident.
- Avoid pure result claiming. “Determine whether the traffic is malicious and block it” is the shape courts strike down; give the how.
Europe: A Different Test, Same Direction
The European Patent Office reaches a similar destination by a different route. Under the EPC, a computer-implemented method must have “technical character” to be patentable, and the EPO’s Guidelines for Examination (G‑II, 3.6) expressly treat security as technical: encrypting electronic communications produces a “further technical effect,” and processes that increase data integrity or security in storage, processing and retrieval are “by nature” technical.
In practice that means a well-drafted cybersecurity method — a cryptographic protocol, an intrusion-detection technique, an integrity-verification process — clears the EPO’s technical-character hurdle comfortably, and the real examination fight moves to novelty and inventive step. A filer building an international portfolio should draft once for both regimes: a claim written as a concrete technical improvement tends to satisfy Alice step one and the EPO’s technical-character test at the same time.
From Eligibility to Filing Strategy
Eligibility is the gate, not the goal. Knowing that cybersecurity methods are patentable when claimed technically only matters once you know which methods are worth filing — where the field is still open and where the incumbents have already blanketed the ground. That is a landscape question, and it is worth answering before you spend a drafting budget.
Our cybersecurity patent landscape analysis maps who leads each cluster, how the post-quantum transition is reshaping the cryptography race, and where the white space still sits. And our cybersecurity patent white space case study shows how a threat-detection challenger turned that reading into a ranked filing plan — targeting the open, defensible, and eligible fronts rather than the crowded core.
Patent Your Security Innovation With Confidence
PerspireIP helps security vendors and their counsel find the defensible, eligible white space and file into it. Tell us the cluster you are working in and we will map the landscape and the openings. Talk to our team.
Frequently Asked Questions
Are cybersecurity methods patentable in the United States?
Yes. Cybersecurity methods are patentable subject matter under 35 U.S.C. ยง 101, provided the claim recites a specific technical improvement to how a computer or network functions rather than an abstract idea applied on generic hardware. Thousands of security patents are granted each year.
Why do some cybersecurity patents get rejected under Section 101?
Because they are claimed too abstractly. If a claim states a security result โ ‘filter unwanted content’ or ‘detect and block threats’ โ without a specific technical mechanism, courts treat it as an abstract idea. The same invention claimed as a concrete technique that improves the machine is eligible.
What cases show cybersecurity patents are eligible?
Finjan v. Blue Coat (2018) upheld behaviour-based malware detection, SRI v. Cisco (2019) upheld network-intrusion detection, and Ancora v. HTC (2018) upheld BIOS-based licence verification. Each was found to improve computer or network functionality at Alice step one.
How should I draft a cybersecurity claim to pass Alice?
Claim the specific technical mechanism, not the security goal; anchor the improvement in the computer, network or memory; frame it as solving a technical problem; and support it with a concrete specification. Avoid result-only claiming, which courts routinely strike down.
Are cybersecurity inventions patentable at the European Patent Office?
Yes. The EPO requires ‘technical character,’ and its Guidelines treat encryption and data-security processes as technical by nature. A concretely drafted security method clears that hurdle, and examination then focuses on novelty and inventive step.