4:26-cv-08886
Fortinet Inc v. Netskope Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Fortinet, Inc. (Delaware)
- Defendant: Netskope, Inc. (Delaware)
- Plaintiff’s Counsel: Quinn Emanuel Urquhart & Sullivan, LLP; Gish PLLC
- Case Identification: 4:26-cv-08886, N.D. Cal., 09/23/2026
- Venue Allegations: Venue is alleged to be proper in the Northern District of California because Netskope has committed acts of infringement in the District and maintains a regular and established place of business at its headquarters in Santa Clara, California.
- Core Dispute: Plaintiff alleges that Defendant’s cloud-based cybersecurity platform infringes five U.S. patents related to dynamic file access control, automated cloud resource tagging, cross-deployment security learning, shadow IT detection, and remote network threat reduction.
- Technical Context: The lawsuit concerns technologies central to modern enterprise cybersecurity, particularly in the context of Secure Access Service Edge (SASE), cloud security, and data loss prevention for distributed workforces.
- Key Procedural History: The complaint details a complex procedural history, beginning with licensing discussions in October 2021. This was followed by a declaratory judgment action filed by Netskope against Fortinet ("Netskope I"). In a separate case ("Netskope II"), Fortinet filed the present infringement allegations as counterclaims, which were then severed by court order into this new, standalone action. The complaint also notes that U.S. Patent No. 11,916,902 was recently amended via a certificate of correction to add a previously omitted claim limitation, and Fortinet is now asserting it in this First Amended Complaint.
Case Timeline
| Date | Event |
|---|---|
| 2017-11-27 | U.S. Patent No. 12,126,695 Priority Date |
| 2018-03-30 | U.S. Patent No. 12,244,621 Priority Date |
| 2019-03-22 | U.S. Patent No. 11,449,623 Priority Date |
| 2020-06-30 | U.S. Patent No. 11,290,527 Priority Date |
| 2021-02-25 | U.S. Patent No. 11,916,902 Priority Date |
| 2021-10-22 | Fortinet attempts to initiate licensing discussions with Netskope |
| 2022-03-29 | U.S. Patent No. 11,290,527 Issued |
| 2022-09-20 | U.S. Patent No. 11,449,623 Issued |
| 2024-02-27 | U.S. Patent No. 11,916,902 Issued |
| 2024-10-22 | U.S. Patent No. 12,126,695 Issued |
| 2025-03-04 | U.S. Patent No. 12,244,621 Issued |
| 2025-11-21 | Date by which Netskope allegedly had knowledge of the '623, '527, '695, and '621 patents |
| 2026-03-27 | Parties file stipulation to sever Fortinet's counterclaims into a new action |
| 2026-07-14 | Netskope notifies Fortinet of an error in the '902 patent's claims |
| 2026-07-24 | Fortinet notifies Netskope of intent to pursue a certificate of correction for the '902 patent |
| 2026-08-12 | Fortinet files request for certificate of correction for the '902 patent |
| 2026-08-18 | Court orders creation of a new case for Fortinet's counterclaims |
| 2026-09-08 | USPTO issues certificate of correction for the '902 patent |
| 2026-09-22 | Parties file joint stipulation to amend the complaint |
| 2026-09-23 | Fortinet files First Amended Complaint |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 11,449,623 - "File access control based on analysis of user behavior patterns"
- Patent Identification: U.S. Patent No. 11,449,623, "File access control based on analysis of user behavior patterns," issued September 20, 2022.
The Invention Explained
- Problem Addressed: The patent's background describes the limitations of conventional "policy-driven" file access controls, which are inflexible, require pre-calculation of all potential user behaviors, and cannot adapt to changing circumstances, creating "a need for a more effective file access control mechanism" Compl. ¶44 '623 patent, 1:46-2:10
- The Patented Solution: The invention proposes a dynamic, fine-grained access control system for encrypted files Compl. ¶45 It involves calculating a "risk level" for a user attempting to access a file, based on their current and historical behavior, and then using that risk score to either grant, deny, or limit access by controlling the release of the file's decryption key Compl. ¶46 '623 patent, 1:17-28 '623 patent, FIGS. 3A, 3B
- Technical Importance: This approach enabled an enterprise to enforce dynamic control over encrypted files, adapting to anomalous behavior in real-time, a capability that prior static mechanisms did not possess Compl. ¶49
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶52
- The essential elements of independent claim 1 are:
- Obtaining and storing historical user behavior of a plurality of users by observing their file access requests.
- Receiving a file access request from a first user for a file stored in encrypted form.
- Determining a risk score for the first user based on a plurality of factors, including historical user behavior, the file access request, and observed data from the request.
- Based on the risk score, permitting or denying access by returning or withholding a decryption key, comprising three specific tiers:
- If the score is below a first threshold, returning the key for full access.
- If the score is above a second threshold, withholding the key.
- If the score is between the thresholds, returning the key for limited access.
- The complaint notes that dependent claims 2, 4, 5, and 8 recite further technical limitations Compl. ¶50
U.S. Patent No. 11,290,527 - "Automatic tagging of cloud resources for implementing security policies"
- Patent Identification: U.S. Patent No. 11,290,527, "Automatic tagging of cloud resources for implementing security policies," issued March 29, 2022.
The Invention Explained
- Problem Addressed: The patent addresses the problem of inconsistent tag naming conventions used by different cloud providers (e.g., AWS, GCP, Microsoft Azure), which complicates the definition and implementation of security policies across a multi-cloud environment Compl. ¶81 '527 patent, 1:18-49 Manually reconciling these disparate tags is described as impractical and error-prone Compl. ¶82
- The Patented Solution: The patent discloses a "global tagging orchestrator" service that runs on a security manager Compl. ¶83 '527 patent, FIG. 1 This orchestrator receives information about resources from multiple cloud providers, identifies a "unified tag" for a resource based on a pre-defined global policy, and then assigns that unified tag to the resource via the cloud provider's own Application Programming Interface (API) Compl. ¶84 '527 patent, FIG. 4 This allows security policies to be applied uniformly across the multi-cloud environment Compl. ¶84 '527 patent, 2:52-56
- Technical Importance: The invention provided a unified, automated way to apply consistent security policies across heterogeneous cloud platforms, a task that was previously not well-understood, routine, or conventional Compl. ¶86
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶90
- The essential elements of independent claim 1 are:
- Receiving, by a cloud-tagging orchestrator service on a security manager, information regarding each cloud provider in a multi-cloud environment.
- Based on that information, for each cloud resource:
- Retrieving information associated with the cloud resource.
- Identifying a unified tag for the resource based on a pre-defined global tagging policy.
- Assigning the unified tag to the resource via the API of the cloud provider hosting it.
- The complaint notes that dependent claims 2 and 5 recite further technical limitations Compl. ¶88
U.S. Patent No. 12,126,695 - "Enhancing security of a cloud deployment based on learnings from other cloud deployments"
- Patent Identification: U.S. Patent No. 12,126,695, "Enhancing security of a cloud deployment based on learnings from other cloud deployments," issued October 22, 2024 Compl. ¶32
- Technology Synopsis: The patent addresses the limited visibility of security systems that monitor single cloud deployments in isolation Compl. ¶115 The invention discloses a system that leverages "cross-customer analysis" by ingesting data from multiple deployments, identifying effective security configurations from threats observed in some deployments, and recommending or implementing those configurations in other, similar deployments Compl. ¶¶117-119
- Asserted Claims: At least claim 1 is asserted Compl. ¶125
- Accused Features: The Netskope Threat Exchange, Cloud Threat Exchange (CTE), and Next Gen Secure Web Gateway are accused of infringing by sharing threat intelligence and configuration settings between different cloud deployments (Compl. ¶¶124; Compl. ¶126; Compl. ¶127).
U.S. Patent No. 12,244,621 - "Using activity monitored by multiple data sources to identify shadow systems"
- Patent Identification: U.S. Patent No. 12,244,621, "Using activity monitored by multiple data sources to identify shadow systems," issued March 4, 2025 Compl. ¶33
- Technology Synopsis: The patent addresses the security blind spot created by "shadow IT"—devices accessing resources while deliberately routing around an organization's security controls Compl. ¶¶148-149 The invention discloses a solution that correlates two independent data sources: "first information" from the organization's resources (e.g., API access records) and "second information" from client applications on user devices, identifying shadow systems by detecting discrepancies between the two data sets Compl. ¶¶150-151
- Asserted Claims: At least claim 1 is asserted Compl. ¶157
- Accused Features: The Netskope Shadow IT and Cloud Access Security Broker (CASB) products are accused of infringing by using multiple data sources (API connectors and client-based monitoring) to identify unmanaged or "shadow" systems based on discrepancies in the collected data (Compl. ¶¶156; Compl. ¶¶158-160).
U.S. Patent No. 11,916,902 - "Systems and methods for using a network access device to secure a network prior to requesting access to the network by the network access device"
- Patent Identification: U.S. Patent No. 11,916,902, "Systems and methods for using a network access device to secure a network prior to requesting access to the network by the network access device," issued February 27, 2024 Compl. ¶34
- Technology Synopsis: The patent addresses the threat posed by unsecured devices (e.g., IoT devices) on a remote network when a corporate device connects through it Compl. ¶¶179-180 The invention discloses using the connecting device to scan the remote network for "unsecure network elements" and denying or granting access to the secure corporate network based on the results of that scan, thereby conditioning access on a threat assessment of the remote network itself Compl. ¶¶181-182
- Asserted Claims: At least claim 1 is asserted Compl. ¶188
- Accused Features: The Netskope Zero Trust Engine, NewEdge Network, One Client, One Gateway, and Device Intelligence products are accused of infringing by receiving access requests from remote devices, scanning the remote network for unsecure elements, and then denying or granting access based on the scan results (Compl. ¶¶187; Compl. ¶¶189-191).
III. The Accused Instrumentality
Product Identification
The complaint identifies the "infringing Netskope products" as a suite of services that are part of the "Netskope Platform and/or Netskope Security Cloud" (Compl. ¶51). Specific accused products and services include Netskope Behavior Analytics, Data Loss Prevention (DLP), Netskope Encryption, Netskope Cloud Security Posture Management (CSPM), Netskope One Orchestrator, Netskope Threat Exchange, Netskope Shadow IT, Cloud Access Security Broker (CASB), and components of its Zero Trust solution like the Netskope One Client and NewEdge Network (Compl. ¶51; Compl. ¶89; Compl. ¶124; Compl. ¶156; Compl. ¶187).
Functionality and Market Context
- The complaint alleges that the accused products provide a comprehensive, cloud-based cybersecurity platform. Functionally, this includes capabilities for data loss prevention, analyzing user behavior to detect threats, managing security policies across multi-cloud environments, and providing secure remote access (Compl. ¶¶28; Compl. ¶¶53-54; Compl. ¶¶91-92). The complaint provides a system architecture diagram from Netskope's documentation illustrating how its "One Platform" connects users to applications via a centralized system that performs authentication, classification, and encryption Compl. p. 14
- The complaint positions these accused features as "critical capabilities" that are "important to Netskope's business," suggesting that it is not reasonably practical for Netskope to disable them without degrading its product offerings Compl. ¶28 Compl. ¶29
IV. Analysis of Infringement Allegations
'623 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A method comprising: obtaining and storing, by one or more servers associated with an enterprise network, information regarding historical user behavior of a plurality of users of the enterprise network by observing file access requests initiated by the plurality of users; | Netskope’s Platform and Security Cloud allegedly obtain and store historical user behavior through "Behavior Analytics," which tracks file access requests via audit logs. The complaint provides a screenshot of a "Behavior Analytics" dashboard showing "Top Users" based on activity Compl. p. 15 | ¶53 | col. 1:16-2:10 |
| receiving, by the one or more servers, a file access request initiated by a first user of the plurality of users, wherein the file access request relates to a file stored within the enterprise network in encrypted form; | Netskope's servers allegedly receive file access requests from users for files stored in encrypted form, as Netskope provides security solutions for encrypted file hosting and access. The complaint includes a data sheet for "Netskope Encryption" Compl. p. 18 | ¶58 | col. 2:14-16 |
| responsive to receipt of the file access request, determining, by the one or more servers, a risk score for the first user based on a plurality of factors, including information regarding historical user behavior, the file access request and observed data determined based on the file access request; | Netskope’s platform allegedly determines a risk score for users, utilizing a "User Confidence Index" (UCI) that is calculated based on detecting policy violations, such as "strange access" scenarios. The complaint includes a screenshot of an alert showing a user with a poor UCI score of 322 due to "Compromised credential - Strange access" Compl. p. 20 | ¶59 | col. 2:16-24 |
| and based on the risk score, permitting or denying, by the one or more servers, access to the file by returning a decryption key for the file or withholding the decryption key wherein said permitting or denying comprises: when the risk score is less than a first threshold, returning the decryption key and providing full access to the file; when the risk score is greater than a second threshold, withholding the decryption key; and when the risk score is between the first threshold and the second threshold, returning the decryption key and providing limited access to the file. | Based on the risk score (UCI), Netskope’s servers allegedly control access by allowing or blocking actions. The complaint describes configuring policies based on UCI thresholds to permit, limit, or block access to files, which corresponds to returning or withholding a decryption key. The complaint includes a screenshot showing policy configuration options based on UCI thresholds, such as "Good rating" or "Poor rating" Compl. p. 22 | ¶60; ¶61 | col. 2:25-29 |
'527 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A method comprising: receiving, by a cloud-tagging orchestrator service running on a security manager associated with a private network, information regarding each cloud provider of a plurality of cloud providers associated with a cloud environment used by the private network; | Netskope's Cloud Security Posture Management (CSPM) allegedly operates as a "cloud-tagging orchestrator" that provides an organization insight into the security posture of their public cloud resources across multiple providers (e.g., AWS, Azure, GCP), as shown in a diagram from Netskope's materials Compl. p. 30 | ¶91 | col. 6:10-18 |
| and based on the received information, for each cloud resource of a plurality of cloud resources hosted by the plurality of cloud providers on behalf of the private network: retrieving, by the cloud-tagging orchestrator service, information associated with the cloud resource; | The Netskope CSPM's "Auto-Remediation Framework" allegedly retrieves information for individual resources by using AWS Lambda functions to query the Netskope API and assess configurations. The complaint includes a diagram showing this resource-by-resource processing Compl. p. 31 | ¶93 | col. 6:21-25 |
| identifying, by the cloud-tagging orchestrator service, a unified tag of a plurality of unified tags for the cloud resource based on a pre-defined global tagging policy; | The CSPM "Advanced Tag Policy Framework" allegedly includes use cases for label policy enforcement, such as writing a rule to ensure every AWS EC2 instance has a tag named 'org-unit', which functions as a pre-defined global policy for identifying unified tags. The Netskope One Orchestrator is also alleged to provide for global policy coordination Compl. p. 33 | ¶94 | col. 6:26-30 |
| and assigning, by the cloud-tagging orchestrator service, the unified tag to the cloud resource via an application programming interface (API) of a cloud provider of the plurality of cloud providers hosting the resource. | The "Auto-Remediation Framework" allegedly demonstrates explicit tag assignment through CloudFormation, where a user can enter tags for a CloudFormation stack and create it, showing direct tag assignment functionality integrated into the cloud resource deployment via an API. | ¶94 | col. 6:31-36 |
- Identified Points of Contention:
- For the '623 Patent: A central question will be whether Netskope's "User Confidence Index" and associated policy actions constitute the specific three-tiered "risk score" system claimed in the patent. The analysis may focus on whether Netskope's system provides "full access," "limited access," and denial by "withholding the decryption key" in a manner that maps directly onto the claim's tiered threshold structure.
- For the '527 Patent: The dispute may turn on whether Netskope's CSPM and Orchestrator products function as the claimed "cloud-tagging orchestrator service running on a security manager associated with a private network." The defense could argue a technical or architectural mismatch, while the complaint's evidence suggests a system that unifies policy and tagging across multiple cloud providers, consistent with the patent's goal.
V. Key Claim Terms for Construction
'623 Patent, Claim 1
- The Term: "risk score"
- Context and Importance: This term is the core of the claimed invention. The infringement analysis will depend on whether Netskope's "User Confidence Index" (UCI) is determined to be a "risk score" as defined by the patent. Practitioners may focus on this term because the claim requires a specific three-tiered outcome based on the score, and the equivalence between the UCI and the claimed "risk score" is a central point of dispute.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification describes determining a "risk level" based on a user's "current and historical behavior" '623 patent, 1:24-26, which could support a broad interpretation covering any numerical index of user risk.
- Evidence for a Narrower Interpretation: The claim itself requires the "risk score" to be used in a specific three-threshold system (less than a first threshold, greater than a second, and in between) '623 patent, claim 1 The specification also details a system where this score is used to permit or deny access by returning or withholding a decryption key, which could support a narrower definition tied to this specific implementation '623 patent, 2:14-29
'527 Patent, Claim 1
- The Term: "cloud-tagging orchestrator service"
- Context and Importance: This term defines the central actor in the claimed method. The case's outcome may depend on whether Netskope's CSPM and One Orchestrator products meet the definition of this term, particularly the requirement that it is "running on a security manager associated with a private network."
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification's objective is to "facilitate uniform tagging of cloud resources" across multiple providers '527 patent, 2:54-55, suggesting the term could encompass any service that automates this function, regardless of its specific architectural location.
- Evidence for a Narrower Interpretation: The patent figures explicitly depict the "ORCHESTRATOR 120" as a component within a "SECURITY MANAGER 102" that is itself associated with a "PRIVATE NETWORK 114" '527 patent, FIG. 1 This specific architectural arrangement could support a narrower construction requiring the service to be part of an on-premises or private network-based security manager.
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement for all five asserted patents. The basis for inducement is that Netskope allegedly instructs customers and end-users on how to use the accused products in an infringing manner through its "marketing, promotional, and instructional materials," including data sheets, technical specifications, and a "Knowledge Portal" Compl. ¶66 Compl. ¶100 Compl. ¶133 Compl. ¶164 Compl. ¶197
- Willful Infringement: The complaint alleges willful infringement for all five asserted patents. For the '623, '527, '695, and '621 patents, willfulness is based on alleged pre-suit knowledge stemming from licensing discussions that began in October 2021 and from prior litigation where these patents were asserted as counterclaims Compl. ¶75 Compl. ¶96 Compl. ¶109 Compl. ¶142 Compl. ¶161 Compl. ¶173 For the '902 patent, willfulness is based on knowledge "since at least the filing date of this First Amended Complaint" Compl. ¶193
VII. Analyst’s Conclusion: Key Questions for the Case
Claim Construction and Scope: A primary issue will be one of definitional scope. Can key claim terms—such as the '623 patent’s three-tiered “risk score” framework and the '527 patent’s “cloud-tagging orchestrator service running on a security manager”—be construed to encompass the functionalities of Netskope’s User Confidence Index and Cloud Security Posture Management platform, or will the specific architectural and functional details in the patents prove too narrow?
Evidentiary Match: A key evidentiary question will be one of operational equivalence. Does the publicly available documentation for Netskope’s products provide sufficient evidence that they perform the precise, ordered steps of the asserted claims? For example, does Netskope's system for detecting "shadow IT" by correlating different data sources functionally match the "first information" and "second information" discrepancy analysis required by the '621 patent?
Impact of Procedural History: How will the extensive pre-suit interactions and prior litigation between the parties, including a declaratory judgment action by Netskope and the severing of these claims from another case, influence the proceedings? This history may be central to the willfulness allegations and could frame the parties' arguments regarding claim construction and infringement.