DCT

1:26-cv-01257

Kmizra LLC v. Omnissa LLC

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 1:26-cv-01257, D. Del., 09/28/2026
  • Venue Allegations: Venue is alleged to be proper in the District of Delaware because Defendant Omnissa is a Delaware corporation and therefore resides in the district.
  • Core Dispute: Plaintiff alleges that Defendant’s Omnissa Workspace ONE product infringes a patent related to methods for isolating and remediating potentially infected computer systems before they connect to a protected network.
  • Technical Context: The technology addresses network access control, a fundamental aspect of modern cybersecurity that involves verifying the security posture of a device before granting it access to sensitive corporate resources.
  • Key Procedural History: The complaint notes that the patent-in-suit, the ’705 Patent, has survived multiple challenges. It was the subject of an Inter Partes Review (IPR) where the Patent Trial and Appeal Board (PTAB) found the claims were not unpatentable; this decision was appealed and remanded on procedural grounds, after which the PTAB dismissed the petition with prejudice. More recent IPR petitions by other parties were either voluntarily withdrawn or discretionarily denied. The complaint also references a court denial of a motion to dismiss on patent-eligibility (§ 101) grounds in a separate litigation involving the ’705 Patent.

Case Timeline

Date Event
2004-09-27 U.S. Provisional Application No. 60/613,909 Filing Date
2012-07-31 U.S. Patent No. 8,234,705 Issued
2025-04-XX Plaintiff sends pre-suit notice letter to Defendant
2026-09-28 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

  • Patent Identification: U.S. Patent No. 8,234,705, “Contagion Isolation and Inoculation,” issued July 31, 2012 (the “’705 Patent”).

The Invention Explained

  • Problem Addressed: The patent’s background section identifies a security threat posed by mobile computers, such as laptops, that connect to various unsecured public networks ’705 Patent, col. 1:14-23 These devices may become infected with viruses, worms, or other malicious software and then, upon reconnecting to a protected corporate network, can "infect or otherwise harm resources associated with the protected network before measures can be taken to detect and prevent the spread of such infections or harm" ’705 Patent, col. 1:34-38
  • The Patented Solution: The invention describes a system and method for intercepting a host computer's request to join a protected network and determining if it needs to be quarantined ’705 Patent, abstract If quarantined, the host is granted limited network access, sufficient only to connect to remediation resources (e.g., a server for downloading security patches or updates) while being blocked from accessing the broader protected network ’705 Patent, abstract ’705 Patent, col. 3:9-21 This process is designed to automatically detect an insecure condition and manage the remediation process without manual intervention ’705 Patent, col. 10:29-45
  • Technical Importance: The patent describes an architectural approach for automated network access control, a concept that predates but is foundational to modern "Zero Trust" security frameworks, which operate on the principle of never trusting a device by default and always verifying its security posture.

Key Claims at a Glance

  • The complaint asserts at least independent claim 19 of the ’705 Patent Compl. ¶25 Compl. ¶44
  • The essential elements of Claim 19, a computer program product, include computer instructions for:
    • Detecting an insecure condition on a "first host" attempting to connect to a protected network.
    • This detection includes contacting a "trusted computing base" associated with a "trusted platform module" within the host.
    • It further includes receiving a response and determining if it contains a "valid digitally signed attestation of cleanliness."
    • The valid attestation must confirm both that the host is not infested and that a certain patch or patch level is present.
    • If no valid attestation is received, "quarantining the first host."
    • Quarantining includes preventing the host from sending data to the network, which involves handling web server and DNS requests by directing the host to a quarantine server or page.
    • Finally, permitting the host to communicate with a "remediation host."
  • The complaint reserves the right to assert additional claims Compl. ¶25

III. The Accused Instrumentality

Product Identification

  • The complaint identifies "Omnissa Workspace ONE enabling Zero Trust application access" as the primary accused instrumentality Compl. ¶39

Functionality and Market Context

  • The complaint alleges that Workspace ONE is a platform for managing device access to corporate resources, which "enforces access decisions based on device compliance and identity context" Compl. ¶46 A screenshot from Omnissa's website describes it as a "digital platform that delivers and manages any app on any device by integrating access control, application management, and unified endpoint management" Compl. ¶46 The complaint alleges that Workspace ONE uses the Windows Health Attestation service to "detect compromised Windows Desktop devices," which in turn utilizes a device's built-in Trusted Platform Module (TPM) chip to ensure device integrity during startup Compl. ¶¶47-48

IV. Analysis of Infringement Allegations

The complaint alleges that the Omnissa Workspace ONE platform infringes at least Claim 19 of the ’705 Patent. A diagram illustrates the three-part interaction between a TPM-enabled device, a Device Management Server, and a Device Health Attestation Service for verifying device health Compl. ¶49

’705 Patent Infringement Allegations

Claim Element (from Independent Claim 19) Alleged Infringing Functionality Complaint Citation Patent Citation
"[A] detecting an insecure condition on a first host that has connected or is attempting to connect to a protected network" Omnissa's Workspace ONE products enable restrictions on device access to corporate data based on compliance checks. ¶47 col. 22:18-21
"[B1] contacting a trusted computing base associated with a trusted platform module within the first host" Workspace ONE utilizes the Windows Health Attestation Service (the "trusted computing base"), which accesses data collected and protected by a device's TPM chip (the "trusted platform module"). ¶48 col. 22:24-26
"[B2] receiving a response, and determining whether the response includes a valid digitally signed attestation of cleanliness" Workspace ONE receives a "tamper resistant and tamper evident report (DHA report)" from the Device Health Attestation service and evaluates it to determine if the device is compliant. ¶49 col. 22:27-30
"[C] wherein the valid digitally signed attestation...includes...an attestation that the first host is not infested, and an attestation that the trusted computing base has ascertained the presence of a patch or a patch level" Workspace ONE checks compliance by matching device attributes against policies, which can include verifying AntiVirus status ("not infested") and OS version ("patch level"). ¶50 col. 22:31-38
"[D] when it is determined that the response does not include a valid digitally signed attestation of cleanliness, quarantining the first host" Workspace ONE quarantines noncompliant devices by restricting access to corporate resources. The complaint includes a screenshot describing this functionality Compl. ¶46 ¶51 col. 22:39-41
"[E1] receiving a service request...serving a quarantine notification page to the first host when the service request comprises a web server request" When a non-compliant device is blocked, Workspace ONE delivers a "custom access denied error message" to the user, which functions as the "quarantine notification page." ¶52 col. 22:44-46
"[E2] ...in the event the service request comprises a DNS query, providing in response an IP address of a quarantine server" The "custom access denied error message" can include a link to another URL (a "remediation host") to help users resolve their issues, thereby directing them to resources functionally equivalent to a quarantine server. ¶53 col. 22:47-52
"[F] permitting the first host to communicate with the remediation host." Workspace ONE allows a quarantined device to access remediation resources to help make the device compliant. ¶54 col. 23:1-2
  • Identified Points of Contention:
    • Scope Questions: The analysis may raise the question of whether the accused product's use of standard, third-party operating system components (Microsoft's Device Health Attestation service) constitutes "contacting a trusted computing base" within the meaning of the patent, which was filed before such services were widely integrated.
    • Technical Questions: A key technical question may be whether Workspace ONE’s functionality of providing a "custom access denied error message" with an optional link Compl. ¶53 is the technical equivalent of the claim's specific requirement to provide "an IP address of a quarantine server" in response to a DNS query. The defense may argue a mismatch between the general-purpose error message and the specific DNS-level redirection recited in the claim.

V. Key Claim Terms for Construction

  • The Term: "trusted computing base"

    • Context and Importance: This term is central to the infringement allegation, as the plaintiff maps it to the combination of a device's TPM chip and Microsoft's Device Health Attestation (DHA) service Compl. ¶48 The viability of the infringement case may depend on whether this modern, OS-level security architecture falls within the scope of a term conceived in the 2004-era priority date of the patent.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: The patent does not appear to explicitly define the term, leaving it open to a construction based on its plain and ordinary meaning to a person of skill in the art at the time. The specification's focus on receiving an "attestation of cleanliness" could support an interpretation that any secure component capable of providing such an attestation qualifies.
      • Evidence for a Narrower Interpretation: The claim links the "trusted computing base" to a "trusted platform module" ’705 Patent, col. 22:25-26 A party might argue that this ties the term to the specific standards and architectures of the Trusted Computing Group (TCG) from that era, potentially narrowing its scope to exclude more modern or different implementations.
  • The Term: "quarantining the first host"

    • Context and Importance: The definition of this term is critical because Claim 19 provides a detailed, multi-part definition of what "quarantining" entails, including specific actions for web and DNS requests (Limitations E1 and E2). Practitioners may focus on this term because the infringement read will depend on whether the accused product's access denial mechanism performs all the specific sub-steps required by the claim.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: The patent’s abstract and background focus on the general concept of providing "only limited access to the protected network" ’705 Patent, abstract This could support an argument that any form of access restriction constitutes "quarantining."
      • Evidence for a Narrower Interpretation: The claim language itself provides a narrow definition, stating that "preventing the first host from sending data... includes" the specific steps of serving a notification page for web requests and providing a quarantine server IP for DNS queries ’705 Patent, col. 22:42-52 A party may argue that these are not merely examples but required components of the claimed "quarantining" process.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges active inducement of infringement, stating that Omnissa encourages its customers to use Workspace ONE in an infringing manner through its marketing, advertising, and user instructions Compl. ¶55 The basis for Omnissa's knowledge is the pre-suit notice letter sent in April 2025 Compl. ¶55
  • Willful Infringement: The complaint alleges willful infringement based on Omnissa’s alleged actual knowledge of the ’705 Patent since at least April 2025, when it received a notice letter and a claim chart via FedEx to its General Counsel Compl. ¶40 The complaint alleges that Omnissa continued its infringing conduct without responding, which it characterizes as willful Compl. ¶40 Compl. ¶56

VII. Analyst’s Conclusion: Key Questions for the Case

  • A core issue will be one of definitional scope: can the term "trusted computing base," rooted in the context of 2004-era security architecture, be construed to cover the accused product's use of modern, standardized operating system services like Microsoft's Device Health Attestation and the underlying hardware TPM?
  • A key evidentiary question will be one of technical equivalence: does the accused product's "custom access denied error message" functionality perform the specific, multi-part logical steps required by Claim 19's definition of "quarantining," particularly the requirement to respond to a DNS query by providing the IP address of a quarantine server?
  • A third question will concern willfulness: given the complaint's specific allegations of a pre-suit notice letter and claim chart sent directly to Omnissa's General Counsel, the court will likely examine whether Omnissa's continued conduct following receipt of this notice was objectively reckless, which could expose the company to the risk of enhanced damages.