DCT
3:26-cv-02940
Speech Transcription LLC v. Darktrace Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Speech Transcription, LLC (Wyoming)
- Defendant: Darktrace, Inc. (Delaware)
- Plaintiff's Counsel: SML Avvocati P.C.
- Case Identification: 3:26-cv-02940, N.D. Cal., 04/06/2026
- Venue Allegations: Plaintiff alleges venue is proper because Defendant has maintained a regular and established place of business in the Northern District of California and has committed acts of patent infringement in the district.
- Core Dispute: Plaintiff alleges that Defendant's ActiveAI cybersecurity platform infringes a patent related to a unified security management system for endpoint computing devices.
- Technical Context: The technology concerns methods for consolidating and managing security functions (e.g., firewalls, antivirus) on endpoint devices like PCs and servers to reduce complexity and cost.
- Key Procedural History: The complaint notes that during the prosecution of the asserted patent, the U.S. Patent Examiner cited U.S. Patent No. 7,058,796 as the most relevant prior art reference.
Case Timeline
| Date | Event |
|---|---|
| 2004-09-14 | U.S. Patent No. 8,938,799 Priority Date |
| 2015-01-20 | U.S. Patent No. 8,938,799 Issue Date |
| 2026-04-06 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,938,799 - Security Protection Apparatus and Method for Endpoint Computing Systems
(Issued January 20, 2015)
The Invention Explained
- Problem Addressed: The patent describes the state of the art in endpoint security as being overly complex and inefficient Compl. ¶14 Managing multiple security products from different vendors on a single host computer leads to software conflicts, performance degradation, management complexity, and high total-cost-of-ownership '799 Patent, col. 3:49-67
- The Patented Solution: The invention proposes a "unified security management system" that uses a dedicated hardware and software "security subsystem," referred to as a Security Utility Blade (SUB), which resides on the endpoint but operates separately from the host's primary operating system '799 Patent, col. 5:21-29 '799 Patent, col. 7:7-10 This SUB acts as an "open platform" to run security software modules from various vendors, creating a "unified management zone" that isolates the security functions from the host and standardizes communication, thereby preventing direct access to the endpoint by vendors' management systems '799 Patent, abstract '799 Patent, col. 6:50-57 '799 Patent, Fig. 1B
- Technical Importance: This approach aimed to solve the problem of vendor lock-in and software bloat by creating a standardized, security-hardened layer within an endpoint computer to manage and execute diverse security applications from a centralized management server Compl. ¶19
Key Claims at a Glance
- The complaint asserts at least independent claim 16 Compl. ¶33
- Claim 16 requires:
- A security subsystem configurable in the path of communications between a network and a host system of a network endpoint.
- The subsystem comprises processing resources for providing security to the host system by executing security function software modules.
- The processing means includes "holding and executing in hardware means for at least one defense function software module."
- The processing means also includes "agent means for providing at least one immunization function."
- The complaint does not explicitly reserve the right to assert other claims.
III. The Accused Instrumentality
Product Identification
- The accused products are Defendant's "ActiveAI security platform" and "Darktrace/Endpoint" Compl. ¶28
Functionality and Market Context
- The complaint describes the accused products as a cybersecurity platform providing "real-time detection, and autonomous response to known and unknown threats" Compl. ¶28 The system allegedly secures endpoint devices against malicious connections and unauthorized file transfers by deploying "lightweight Darktrace agents that detect and neutralize unusual activity" Compl. ¶28
- The platform is alleged to provide "Prevent, Detect, Respond, and Heal functionalities" for end-to-end security and attack surface management Compl. ¶28
IV. Analysis of Infringement Allegations
The complaint references a claim chart (Exhibit B) that was not publicly filed with the complaint Compl. ¶33 Compl. ¶38 Therefore, a detailed element-by-element analysis is not possible based on the provided documents. The complaint alleges that the Accused Instrumentalities "practice the technology claimed by the '799 Patent" and "satisfy all elements of at least Claim 16" Compl. ¶38 The infringement theory appears to rest on the general functionality of the ActiveAI platform and its use of endpoint agents to provide security Compl. ¶28
No probative visual evidence provided in complaint.
- Identified Points of Contention:
- Structural Questions: A central question may be whether the accused "lightweight Darktrace agents," which are described as software, can meet the claim limitation of a "security subsystem" containing "hardware means." The patent specification repeatedly describes the inventive subsystem as a distinct hardware and/or software entity with its own operating system, separate from the host '799 Patent, col. 7:7-10 '799 Patent, col. 5:21-29 The infringement analysis may turn on whether the accused software-only agent architecture is structurally equivalent to the claimed subsystem.
- Functional Questions: The complaint lacks specific factual allegations explaining how the accused agents perform the functions recited in the means-plus-function limitations of Claim 16, such as "holding and executing in hardware means" for defense functions and "agent means" for immunization functions. The case will require evidence demonstrating that the accused agents perform the identical functions described in the patent's specification corresponding to those means.
V. Key Claim Terms for Construction
The Term: "security subsystem"
- Context and Importance: This term defines the fundamental nature of the claimed invention. Its construction will be critical to determining whether a software-only agent running on the host's general-purpose hardware falls within the scope of the claim, or if the claim requires a physically or logically distinct component with its own dedicated resources, as the patent specification suggests.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The term "subsystem" is not explicitly defined, which may permit an argument that it can encompass a comprehensive software agent that manages all security functions.
- Evidence for a Narrower Interpretation: The patent consistently describes the subsystem, or "SUB," as a "hardware and software 'security subsystem'" that "may run its own operating system with a dedicated processor" and is "separate from any host operating system" '799 Patent, col. 5:23-26 '799 Patent, col. 7:7-10 Figure 2B depicts the SUB as a physical card installed in a motherboard slot, suggesting a hardware-centric embodiment '799 Patent, Fig. 2B
The Term: "holding and executing in hardware means"
- Context and Importance: This is a means-plus-function limitation under 35 U.S.C. § 112(f). Its scope is limited to the corresponding structures disclosed in the specification and their equivalents. Practitioners may focus on this term because the accused instrumentality is described as a software "agent" Compl. ¶28, raising a significant question of whether it contains an equivalent structure to the "hardware means" disclosed in the patent.
- Intrinsic Evidence for Interpretation:
- The function is "holding and executing... at least one defense function software module" '799 Patent, col. 19:62-65
- The corresponding structure described in the specification includes a "Security Utility Unit (SUU)" which comprises a "General Purpose Processor," "Memory Systems," and a specialized "Data Stream Inspection and Treatment (DSI&T) unit" '799 Patent, col. 11:15-20 '799 Patent, Fig. 4 The analysis will focus on whether the accused agent's architecture is structurally equivalent to this disclosed combination of general and specialized hardware.
VI. Other Allegations
- Indirect Infringement: The complaint alleges both induced and contributory infringement Compl. ¶33 The factual basis for inducement is the allegation that Defendant distributes "product literature and website materials" that instruct and encourage end users to use the accused products in a manner that infringes the '799 Patent Compl. ¶36
- Willful Infringement: The complaint alleges that Defendant has knowledge of its infringement "at least as of the service of the present complaint" Compl. ¶31 It further alleges that Defendant "continues to make, use, test, sell, offer for sale, market, and/or import" the infringing products "[d]espite such actual knowledge," forming a basis for post-suit willful infringement Compl. ¶36
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of structural scope: can the claimed "security subsystem," which the patent specification describes as a distinct hardware and software component with its own operating system, be construed to cover the accused "lightweight Darktrace agents," which appear to be software operating on the host's general-purpose computing resources?
- A second central question will be one of evidentiary proof: given the complaint's lack of specific technical mappings, discovery will be critical. The case will likely hinge on whether Plaintiff can produce evidence that the accused software agents perform the identical functions recited in the patent's means-plus-function limitations using structures that are the same as or equivalent to those disclosed in the patent's specification.
Analysis metadata
Loading Complaint
Suggested improvements