DCT

2:26-cv-01504

Regions Bank v. BenedorTSE LLC

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:26-cv-01504, N.D. Ala., 08/25/2026
  • Venue Allegations: Venue is alleged to be proper in the Northern District of Alabama because a substantial part of the events giving rise to the claim occurred in the district, where Plaintiff Regions Bank is headquartered. Defendant BenedorTSE, LLC is alleged to have initiated contact and sent correspondence accusing Regions of infringement within the district.
  • Core Dispute: Plaintiff Regions Bank seeks a declaratory judgment that its operations, including its Mobile App, do not infringe three of Defendant BenedorTSE's patents related to methods for securing online transactions.
  • Technical Context: The patents address securing e-commerce transactions by encrypting user and device-specific identifiers for verification, aiming to replace the direct transmission of sensitive credit card information.
  • Key Procedural History: The complaint notes that this action follows a series of licensing communications from BenedorTSE, including a letter with a claim chart for one patent and threats of litigation. It also highlights a pattern of litigation by BenedorTSE, citing four prior patent infringement lawsuits filed against Wells Fargo Bank, Apple Inc., Google LLC, and Samsung Electronics Co., Ltd. asserting various combinations of the same patents-in-suit.

Case Timeline

Date Event
2000-12-01 Earliest Priority Date for '723, '713, and '979 Patents
2012-09-04 U.S. Patent No. 8,260,723 Issues
2013-06-11 U.S. Patent No. 8,463,713 Issues
2016-07-26 U.S. Patent No. 9,400,979 Issues
2025-11-17 BenedorTSE files suit against Wells Fargo Bank
2025-12-19 BenedorTSE files suit against Apple Inc.
2026-05-01 BenedorTSE files suit against Google LLC
2026-05-28 BenedorTSE sends letter to Regions alleging infringement
2026-05-29 BenedorTSE files suit against Samsung Electronics
2026-07-08 Regions directs BenedorTSE to its outside patent counsel
2026-07-30 BenedorTSE's counsel emails Regions' counsel about litigation
2026-08-12 BenedorTSE's counsel demands license negotiations from Regions
2026-08-25 Complaint for Declaratory Judgment filed by Regions Bank

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 8,260,723 - "Transactional Security Over a Network"

The Invention Explained

  • Problem Addressed: The patent's background section describes the security risks in conventional e-commerce, where a customer must provide private information (like credit card numbers) to merchants and other parties, creating vulnerability to data theft US 8,260,723 B2, col. 1:51-65 US 8,260,723 B2, col. 2:11-23
  • The Patented Solution: The invention proposes a system where customer information is encrypted into a "customer code" on the customer's own device. This code, rather than the raw financial data, is sent to a merchant, who forwards it to a financial institution for decryption and authorization US 8,260,723 B2, abstract US 8,260,723 B2, col. 2:26-39 The system ties the transaction to the user's specific hardware by reading and encrypting hardware identifiers from the device US 8,260,723 B2, col. 8:11-16
  • Technical Importance: This approach sought to enhance transaction security by preventing merchants from ever accessing or storing sensitive customer financial data, thereby reducing the risk of large-scale data breaches US 8,260,723 B2, col. 2:40-44

Key Claims at a Glance

  • The complaint asserts non-infringement of independent claims 1, 7, 12, and 17 Compl. ¶¶32-35
  • The essential elements of independent claim 1, a method claim, include:
    • Receiving and validating a password on an electronic device.
    • Based on password validity, reading a "plurality of hardware identifiers" from the device's hardware.
    • Determining if the read hardware identifiers are valid by comparing them to a "list of permitted hardware identifiers."
    • Based on hardware identifier validity, retrieving a "customer identifier string" from the device's storage.
    • Creating an "encrypted customer code" by encrypting the customer identifier string, the hardware identifiers, and a count value.
    • Transmitting the encrypted customer code to a merchant "instead of customer credit card information."
  • The complaint states that because none of the independent claims are infringed, none of the dependent claims can be infringed Compl. ¶36

U.S. Patent No. 8,463,713 - "Transactional Security Over a Network"

The Invention Explained

  • Problem Addressed: The patent addresses the same security vulnerabilities in online transactions as the '723 Patent, focusing on the repeated exposure of a customer's sensitive information across different merchants and databases US 8,463,713 B2, col. 1:49-54 US 8,463,713 B2, col. 2:11-24
  • The Patented Solution: This patent builds on the same core concept but introduces a "verification entity" and a "user agreement identifier." The verification entity creates the user agreement identifier, which identifies both the user and the agreement. This identifier, along with hardware identifiers, is then used to create a single-use encrypted code for transaction authorization US 8,463,713 B2, abstract US 8,463,713 B2, col. 5:6-30
  • Technical Importance: This refinement introduced a contractual and verification layer to the transaction process, aiming to create a "signature present" equivalent for online purchases that could be relied upon by all parties while still protecting user identity US 8,463,713 B2, col. 5:31-36

Key Claims at a Glance

  • The complaint asserts non-infringement of independent claims 1, 7, 13, 19, 25, and 31 Compl. ¶¶46-51
  • The essential elements of independent claim 1, a method claim, include:
    • A "verification entity" creating a "user agreement identifier" that identifies the agreement and the user.
    • Downloading a software application and the user agreement identifier to the user's device.
    • Storing credentials, including hardware identifiers and the user agreement identifier, on the device.
    • Validating a password and reading a hardware identifier from the device.
    • Creating an "encrypted user code" by encrypting the user agreement identifier and the hardware identifier, with the code being valid for a single request.
    • Transmitting the encrypted user code to a provider, who sends it to the verification entity for a decision.
  • The complaint states that because none of the independent claims are infringed, none of the dependent claims can be infringed Compl. ¶52

U.S. Patent No. 9,400,979 - "Transactional Security Over a Network"

  • Technology Synopsis: The '979 Patent continues to refine the secure transaction system. It describes a method where, after password validation, a hardware identifier is read from a user's device and validated. A "user agreement identifier" is then retrieved, and these two identifiers are encrypted into a "user code" for transmission to a provider to authorize a transaction US 9,400,979 B2, abstract US 9,400,979 B2, col. 2:26-38
  • Asserted Claims: The complaint asserts non-infringement of independent claims 1, 7, 13, 19, and 25 Compl. ¶¶62-66 Benedor is specifically noted to have alleged infringement of at least claim 19 Compl. ¶59
  • Accused Features: The complaint alleges that the "Regions Mobile App" does not perform the steps of the asserted claims Compl. ¶¶62-66

III. The Accused Instrumentality

Product Identification

The accused instrumentalities are Plaintiff's "operations" generally and the "Regions Mobile App" specifically Compl. ¶1 Compl. ¶15

Functionality and Market Context

  • The complaint does not provide a detailed technical description of the Regions Mobile App's functionality. Instead, it makes conclusory allegations that neither Regions nor the use of the app performs the specific steps recited in the asserted claims Compl. ¶¶32-35 Compl. ¶¶46-51 Compl. ¶¶62-66
  • The complaint does not provide specific details for analysis of the product's commercial importance, other than its general use as a mobile banking application for a state-chartered bank Compl. ¶2

IV. Analysis of Infringement Allegations

The complaint seeks a declaratory judgment of non-infringement. It does not affirmatively allege that the Regions Mobile App performs any of the claimed functions. The tables below summarize Plaintiff's non-infringement contentions.

U.S. Patent No. 8,260,723 Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
based on said determining whether said password is valid, reading a plurality of hardware identifiers from hardware of said electronic device... The complaint alleges that the Regions Mobile App does not perform this step. ¶32 col. 8:11-19
determining whether said plurality of hardware identifiers are valid, by said processor by comparing said read hardware identifiers with a list of permitted hardware identifiers; The complaint alleges that the Regions Mobile App does not perform this step. ¶32 col. 11:32-37
based on said determining of whether said plurality of hardware identifiers are valid, retrieving a customer identifier string from a storage media of said electronic device... The complaint alleges that the Regions Mobile App does not perform this step. ¶32 col. 11:42-46
creating an encrypted customer code by encrypting said customer identifier string, said plurality of hardware identifiers, and said count value, by said processor; The complaint alleges that the Regions Mobile App does not perform this step. ¶32 col. 11:50-54
transmitting said encrypted customer code to a merchant in a purchase transaction over a computer network, instead of customer credit card information... The complaint alleges that the Regions Mobile App does not perform this step. ¶32 col. 7:62-67

U.S. Patent No. 8,463,713 Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
creating, by said verification entity, a user agreement identifier that identifies said agreement and identifies said user; The complaint alleges that the Regions Mobile App does not perform this step. ¶46 col. 30:57-60
downloading a software application from said verification entity and said user agreement identifier over a computer network to an input and output device... The complaint alleges that the Regions Mobile App does not perform this step. ¶46 col. 30:61-65
using, by a processor of said computerized device, said software application to store at least one permitted password, at least one user identifier string, permitted hardware identifiers, and said agreement identifier in a storage media... The complaint alleges that the Regions Mobile App does not perform this step. ¶46 col. 30:66-31:4
based on said password being valid, reading, by said processor, a hardware identifier from hardware of said computerized device; The complaint alleges that the Regions Mobile App does not perform this step. ¶46 col. 31:5-8
creating, by said processor, an encrypted user code by encrypting said user agreement identifier and said hardware identifier, each said encrypted code being valid only for a single request... The complaint alleges that the Regions Mobile App does not perform this step. ¶46 col. 31:21-26
transmitting, by said input and output device...said encrypted user code to a provider...said encrypted user code being sent by said provider to said verification entity for an authorization decision; The complaint alleges that the Regions Mobile App does not perform this step. ¶46 col. 31:27-34
  • Identified Points of Contention:
    • Evidentiary Questions: The complaint makes bare assertions of non-infringement without providing any technical details about how the Regions Mobile App actually functions. A primary point of contention will be an evidentiary one: what technical evidence can either party present to demonstrate whether the accused app performs the functions required by the claims, such as reading device hardware identifiers or creating encrypted codes based on those identifiers?
    • Scope Questions: A key question will be whether the specific identifiers used in modern mobile banking apps (which are not described in the complaint) fall within the scope of claim terms like "hardware identifiers" and "customer identifier string" as defined and described in the patents from the early 2000s.

V. Key Claim Terms for Construction

  • The Term: "hardware identifiers"
  • Context and Importance: This term is fundamental to all asserted patents, as it forms the basis for linking a transaction to a specific physical device. The scope of this term will be critical, as its interpretation will determine whether modern mobile device identifiers (e.g., UDID, IMEI, Advertising IDs) are covered by claims written with early 2000s personal computer hardware in mind. Practitioners may focus on this term because the accused product is a modern mobile app, whereas the patent's examples are PC-based.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The language in claim 1 of the '723 Patent is broad, requiring only "at least a portion of a serial number of at least one hardware component of said electronic device" US 8,260,723 B2, col. 35:1-5 This could support an argument that any unique number derived from a hardware component is sufficient.
    • Evidence for a Narrower Interpretation: Claim 12 of the '723 Patent explicitly recites "a serial number of at least one of a motherboard, a hard drive, and said processor of said electronic device" US 8,260,723 B2, col. 36:26-31 The specification also provides these as the primary examples US 8,260,723 B2, col. 8:13-16 This may support an argument that the term is limited to identifiers of core PC components and does not extend to identifiers common in modern smartphones.
  • The Term: "user agreement identifier"
  • Context and Importance: This term appears in the independent claims of the '713 and '979 Patents. Its definition is crucial for determining how an "agreement" is technically represented and used in the patented method. The dispute may turn on whether the accused app's user authentication or session tokens function as the claimed "user agreement identifier" that "identifies said agreement and identifies said user" US 8,463,713 B2, col. 34:57-60
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The claims do not specify the format of the identifier, only its function: to identify the user and the agreement. This could support a broad interpretation covering any data string that serves this dual identification purpose within a transaction authorization flow US 8,463,713 B2, col. 35:19-22
    • Evidence for a Narrower Interpretation: The specification discusses the identifier in the context of a formal "customer-credit issuer agreement" that establishes terms for "signature present" transactions and copyright enforcement US 8,463,713 B2, col. 5:6-12 US 8,463,713 B2, col. 6:31-36 This may support a narrower interpretation requiring the identifier to be directly tied to a specific, pre-established contractual instrument, rather than a more general user account or session token.

VI. Other Allegations

  • Indirect Infringement: The complaint denies inducement or contributory infringement for all three patents Compl. ¶39 Compl. ¶55 Compl. ¶70 It also raises the issue of divided infringement, alleging that the asserted method claims require actions performed by "users, user-operated devices, and other entities," and that Regions does not perform or direct the performance of all claimed steps as required for infringement Compl. ¶37 Compl. ¶53 Compl. ¶68
  • Willful Infringement: While this is a declaratory judgment action and contains no allegation of willfulness against Regions, the complaint establishes a basis for a future willfulness claim by Benedor. It documents pre-suit knowledge through a series of communications, including a May 28, 2026 letter from Benedor that "accused Regions of infringing the Asserted Patents" and included a claim chart Compl. ¶¶14-15, and a July 30, 2026 email from Benedor's counsel Compl. ¶16 An email from Defendant's counsel to Plaintiff's counsel mentioning prior lawsuits and encouraging a license is included as visual evidence in the complaint Compl. ¶16, p. 4

VII. Analyst's Conclusion: Key Questions for the Case

  • Divided Infringement: A central issue will be whether the asserted method claims are unenforceably divided. The court will need to determine if Plaintiff Regions Bank directs or controls its end-users to perform the claimed steps in a manner that would attribute their actions to Regions for the purpose of finding direct infringement under a single-entity theory.
  • Claim Scope and Evolving Technology: The case presents a classic question of how patent claims drafted for one technological era apply to a later one. A key question will be one of definitional scope: can terms like "hardware identifiers", rooted in the context of 2000s-era personal computers (e.g., motherboard, hard drive serial numbers), be construed to cover the unique device identifiers used in modern smartphone operating systems?
  • Evidentiary Sufficiency: As this is a declaratory judgment action initiated with bare denials of infringement, a fundamental question will be one of evidentiary proof. The dispute will likely depend on which party can produce persuasive technical evidence-through discovery, expert testimony, and source code review-to either prove or disprove that the Regions Mobile App's security architecture and transaction protocols meet the specific limitations recited in the asserted claims.