DCT
1:26-cv-00925
Kmizra LLC v. Twingate Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: K.Mizra LLC (Delaware)
- Defendant: Twingate Inc. (Delaware)
- Plaintiff's Counsel: Sheridan Ross P.C.
- Case Identification: 1:26-cv-00925, D. Del., 07/28/2026
- Venue Allegations: Venue is alleged to be proper in the District of Delaware because Defendant Twingate Inc. is a Delaware corporation and therefore resides in the district.
- Core Dispute: Plaintiff alleges that Defendant's Zero Trust Network Access service infringes a patent related to methods for verifying the security posture of a device before granting it access to a protected network and quarantining non-compliant devices.
- Technical Context: The technology concerns network security, specifically within the "Zero Trust" framework, where devices are untrusted by default and must be verified before connecting to network resources, a critical function for enterprises with remote workforces.
- Key Procedural History: The complaint notes that the asserted patent previously survived an Inter Partes Review (IPR) at the Patent Trial and Appeal Board (PTAB), where the claims were found not unpatentable. While the decision was appealed and remanded on procedural grounds, the PTAB ultimately dismissed the IPR petition with prejudice. The complaint also states that a court in a prior litigation found the asserted independent claim not directed to an abstract idea.
Case Timeline
| Date | Event |
|---|---|
| 2004-09-27 | U.S. Patent No. 8,234,705 Priority Date |
| 2012-07-31 | U.S. Patent No. 8,234,705 Issued |
| 2025-06-01 | Alleged Pre-Suit Notice of Infringement Sent (approx.) |
| 2026-07-28 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,234,705 - "Contagion Isolation and Inoculation"
- Patent Identification: U.S. Patent No. 8,234,705, "Contagion Isolation and Inoculation", issued July 31, 2012 Compl. ¶14
The Invention Explained
- Problem Addressed: The patent's background section identifies a security threat posed by mobile computers (e.g., laptops) that connect to untrusted networks like the internet or public Wi-Fi, where they may become infected with viruses, worms, or other malicious software ("contagion") Compl. ¶21 '705 Patent, col. 1:14-24 When these compromised devices subsequently connect to a secure "protected network," they can infect other network resources before conventional security measures have a chance to detect and prevent the harm '705 Patent, col. 1:34-38
- The Patented Solution: The invention provides a method and system to automatically assess a device's security state, or "cleanliness," before granting it full access to a protected network '705 Patent, abstract Upon receiving a connection request from a host, the system determines if the host needs to be "quarantined" '705 Patent, col. 3:9-12 A quarantined host is given only limited network access, sufficient to connect to "remediation" resources (e.g., an update server) to download patches or remove malicious software '705 Patent, col. 3:13-21 Once remediated, the host can be granted full access. The general process is depicted in a flowchart in the complaint, illustrating the steps of detection, quarantine, and providing remediation access (Compl. ¶27, referencing Fig. 10A).
- Technical Importance: This approach provided a technical framework for managing the security risks of an increasingly mobile workforce, moving beyond a perimeter-based security model that assumed all devices inside the network were trustworthy Compl. ¶20
Key Claims at a Glance
- The complaint asserts infringement of at least independent Claim 19 ('705 Patent, Compl. ¶24; Compl. ¶41).
- The essential elements of Claim 19, a computer program product, include:
- Detecting an insecure condition on a first host connecting to a protected network.
- This detection includes contacting a "trusted computing base associated with a trusted platform module" within the host.
- It also includes receiving a response and determining if it contains a "valid digitally signed attestation of cleanliness," which confirms the host is not infested and has a required software patch or patch level.
- If the attestation is not valid, "quarantining the first host" by preventing it from sending data to other hosts on the network.
- The quarantine process includes receiving a service request (e.g., web or DNS) and, in response, serving a "quarantine notification page" or providing the IP address of a "quarantine server."
- Permitting the host to communicate with a "remediation host" to remedy the insecure condition.
- The complaint notes that Plaintiff reserves the right to assert additional claims, including dependent claims Compl. ¶24
III. The Accused Instrumentality
Product Identification
- The accused instrumentality is "Twingate Zero Trust Access" Compl. ¶36
Functionality and Market Context
- The complaint describes Twingate Zero Trust Access as a "cloud-based service that provides secured remote access to an organization's networks," presented as an alternative to traditional business VPNs Compl. ¶43 A core feature is its ability to "deliver endpoint posture assessments and ensure that endpoints meet security and compliance policies before they connect to the network" Compl. ¶44 A diagram from Twingate's marketing materials shows this process, where factors like "Device Posture" (e.g., macOS 13+, Firewall Enabled) are checked before a device is granted access (Compl. ¶44, referencing Ex. 4). The service is alleged to establish direct peer-to-peer connections to protected resources, with each request being verified before it leaves the device Compl. ¶43
IV. Analysis of Infringement Allegations
U.S. Patent No. 8,234,705 Infringement Allegations
| Claim Element (from Independent Claim 19) - | Alleged Infringing Functionality - | Complaint Citation | Patent Citation |
|---|---|---|---|
| [A] detecting an insecure condition on a first host that has connected or is attempting to connect to a protected network, | Twingate's products deliver "endpoint posture assessments" and check that endpoints meet security and compliance policies before they connect to the network. - | ¶44 | col. 3:9-12 |
| [B1] contacting a trusted computing base associated with a trusted platform module within the first host, - | The accused product integrates with Microsoft's Intune service, which is alleged to implement "Trusted Platform Module (TPM) technology to enhance... defense against threats." A diagram in the complaint illustrates this attestation process Compl. ¶45 Compl. p. 19 | ¶45 | col. 13:50-57 |
| [B2] receiving a response, and determining whether the response includes a valid digitally signed attestation of cleanliness, - | Through the Intune integration, Twingate products allegedly receive information from the host via digitally-signed certificates and determine if the host is secure and trusted based on that information. - | ¶46 | col. 13:58-62 |
| [C] wherein the valid digitally signed attestation of cleanliness includes at least one of an attestation that the trusted computing base has ascertained that the first host is not infested, and an attestation that the trusted computing base has ascertained the presence of a patch or a patch level associated with a software component on the first host; | The Twingate service allegedly checks endpoint device compliance by matching its configuration parameters, such as antivirus status and minimum OS version, against profile attributes. - | ¶47 | col. 14:1-8 |
| [D] when it is determined that the response does not include a valid digitally signed attestation of cleanliness, quarantining the first host, including by preventing the first host from sending data to one or more other hosts associated with the protected network, - | The accused product allegedly quarantines noncompliant devices. A user of a blocked device sees a message in the Twingate Client explaining that the device does not meet security requirements. - | ¶48 | col. 14:9-14 |
| [E1] ...receiving a service request sent by the first host, serving a quarantine notification page to the first host when the service request comprises a web server request, - | When a device is blocked, a "quarantine message is also delivered to the unclean endpoint device." The complaint includes a screenshot of a "Verified device required" notification page Compl. ¶49 Compl. p. 24 - | ¶49 | col. 16:1-4 |
| [E2] ...in the event the service request comprises a DNS query, providing in response an IP address of a quarantine server... - | The accused product allegedly provides a quarantine notification page with links or IP addresses for remediation and can route a non-compliant device's connection to a "quarantined network for remediation." - | ¶50 | col. 16:5-24 |
| [F] permitting the first host to communicate with the remediation host. - | The accused product allegedly allows a quarantined device to access "remediation resources to help make the device complaint." - | ¶51 | col. 15:28-34 |
- Identified Points of Contention:
- Scope Questions: The complaint alleges that the "trusted computing base associated with a trusted platform module" limitation is met through integration with Microsoft's Intune service Compl. ¶45 A potential point of contention is whether this third-party, cloud-integrated service performs the functions of the "trusted computing base" as that term is understood in the context of the patent, which originates from 2004-era security concepts.
- Technical Questions: The infringement allegations rely heavily on Defendant's public-facing marketing materials, documentation, and diagrams to describe the functionality of the accused product Compl. ¶43 Compl. ¶44 Compl. ¶45 Compl. ¶46 Compl. ¶47 Compl. ¶48 Compl. ¶49 Compl. ¶50 Compl. ¶51 A key question for the court may be whether this public information provides sufficient evidentiary detail to establish that the accused system's internal operations map directly onto the specific technical steps recited in Claim 19, particularly concerning the handling of digitally signed attestations and the specific network routing actions involved in quarantining.
V. Key Claim Terms for Construction
The Term: "trusted computing base"
- Context and Importance: This term is central to the verification mechanism of the asserted claim. The infringement theory depends on construing this term to cover a modern, third-party device management service (Microsoft Intune) that the accused product integrates with Compl. ¶45 Practitioners may focus on this term because its scope will determine whether a hardware-anchored, on-device entity is required or if a distributed, software-defined service suffices.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent does not appear to provide a single, restrictive definition. The specification refers to concepts like the "Paladium security initiative" and "TCG specifications," which were evolving standards, suggesting the term may not be limited to one specific implementation '705 Patent, col. 13:50-57 This could support an interpretation that includes any system providing a verifiable root of trust.
- Evidence for a Narrower Interpretation: Claim 19 explicitly links the "trusted computing base" to a "trusted platform module within the first host" '705 Patent, col. 22:23-25 This language may support an argument that the term requires a specific hardware component physically present on the host computer that is interrogated directly, rather than through a cloud service API.
The Term: "quarantining the first host"
- Context and Importance: This term defines the core punitive and remedial action taken against a non-compliant device. The infringement analysis hinges on whether the accused product's action of blocking a device and displaying a notification Compl. ¶48 Compl. ¶49 constitutes "quarantining" as claimed.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: Claim 19 itself defines quarantining as "including by preventing the first host from sending data to one or more other hosts associated with the protected network" '705 Patent, col. 22:10-14 This could support a reading where any form of blocking access meets the limitation.
- Evidence for a Narrower Interpretation: The specification and other claim elements describe a specific architecture where requests are redirected to a "quarantine server" that serves a notification page and handles DNS queries for remediation hosts '705 Patent, col. 12:5-13 '705 Patent, cl. 19 This may support an argument that "quarantining" requires this specific traffic redirection mechanism, not just a simple block.
VI. Other Allegations
- Indirect Infringement: The complaint alleges that Twingate actively induces infringement by "promoting, advertising, and instructing" its customers to use the accused products in a manner that directly infringes the '705 Patent Compl. ¶52
- Willful Infringement: Willfulness is alleged based on Twingate's purported pre-suit and post-suit knowledge of the '705 Patent. The complaint alleges Twingate received a notice letter with a claim chart "no later than June 2025" and has had actual knowledge since at least the filing of the complaint Compl. ¶37 Compl. ¶53
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: can the term "trusted computing base," rooted in the patent's 2004 priority date and associated with on-device hardware modules, be construed to cover a modern, cloud-based device management service (Microsoft Intune) that the accused product integrates with to perform security attestations?
- A key evidentiary question will be one of functional correspondence: does the accused Twingate service's method of blocking a non-compliant device and presenting a notification meet the specific, multi-part "quarantining" process recited in Claim 19, which includes distinct actions for handling web server requests and DNS queries by redirecting them to a quarantine server?
- A third central question will concern proof of operation: will the plaintiff's reliance on the defendant's marketing materials and technical documentation be sufficient to prove that the accused system's internal functions perform the precise steps required by the claims, or will more direct evidence of the system's architecture and code be necessary to establish infringement?
Analysis metadata
Loading Complaint
Suggested improvements