2:26-cv-01845
DISH Network LLC v. Eleven Software Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: DISH Network L.L.C. (Colorado)
- Defendant: Eleven Software Inc. (Delaware)
- Plaintiff’s Counsel: Kaempfer Crowell
- Case Identification: 2:26-cv-01845, D. Nev., 09/24/2026
- Venue Allegations: Plaintiff alleges venue is proper in the District of Nevada because Defendant has its principal place of business in Las Vegas, maintains a regular and established place of business in the District, and has committed alleged acts of infringement within the District.
- Core Dispute: Plaintiff alleges that Defendant’s ElevenOS cloud-based Wi-Fi management platform, including its "Personal Pass Key" feature, infringes two patents related to methods for securely provisioning and managing wireless network access using unique pre-shared keys (PSKs).
- Technical Context: The technology addresses security and management challenges in large-scale Wi-Fi networks, such as those in hotels or multi-family housing, by replacing a single, insecure shared password with a system that manages unique keys for each user via a centralized, cloud-based authentication system.
- Key Procedural History: The complaint alleges that Defendant was put on notice of the technology as early as April 30, 2020, via receipt of a provisional patent application to which the asserted patents claim priority. The complaint further alleges that Plaintiff sent a formal notice letter to Defendant regarding the asserted patents on June 13, 2025.
Case Timeline
| Date | Event |
|---|---|
| 2019-09-30 | Priority Date for '285 and '884 Patents |
| 2020-03-06 | Priority Date (Provisional App. 62/986,255) |
| 2020-04-30 | Defendant allegedly received copy of provisional application |
| 2021-07-20 | Alleged earliest launch date of Accused Product |
| 2022-04-26 | U.S. Patent No. 11,317,285 Issues |
| 2025-02-18 | U.S. Patent No. 12,231,884 Issues |
| 2025-06-13 | Plaintiff allegedly sent infringement notice letter to Defendant |
| 2026-09-24 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 11,317,285
- Patent Identification: U.S. Patent No. 11,317,285 (“Wireless Network Provisioning Using a Pre-shared Key”), issued April 26, 2022. Compl. ¶9
The Invention Explained
- Problem Addressed: The patent's background section describes the challenges of enabling wireless network access, noting that conventional systems using a single pre-shared key (PSK) for all users can be insecure and difficult to manage, especially when access for a specific user needs to be revoked Compl. ¶15 ’285 Patent, col. 1:44-58 It also notes the infeasibility of credential-entry systems for devices lacking a user interface, such as many Internet-of-Things (IoT) devices Compl. ¶19 ’285 Patent, col. 1:20-29
- The Patented Solution: The invention proposes a centralized, cloud-based system that manages unique PSKs for individual users or devices. A wireless device attempts to connect by sending a value derived from its unique PSK to a local access point (AP). The AP, which does not store the PSK, forwards this value to the cloud-based provisioning system. The cloud system then identifies a matching user profile, generates a pairwise master key (PMK), and sends it to the AP, which uses the PMK to establish an encrypted session and grant network access Compl. ¶18 ’285 Patent, abstract ’285 Patent, Fig. 1
- Technical Importance: This approach centralizes authorization decisions, allowing for scalable and individualized management of network access in large, multi-user environments without requiring complex on-site hardware or insecure shared credentials Compl. ¶18 ’285 Patent, col. 8:54-57
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶36
- The essential elements of independent claim 1 include:
- Creating, at a "cloud-based provisioning system", a plurality of wireless network access profiles that indicate PSKs, bandwidth restrictions, and time periods for access.
- Receiving, at an "access point", a "first value" from a wireless device that is based on the PSK.
- Transmitting the "first value" from the access point to the cloud-based system via the Internet.
- Creating and identifying, by the cloud-based system, a matching value based on its stored PSKs.
- Providing, from the cloud-based system to the access point, a "pairwise master key (PMK)" based on the matching profile's PSK.
- Providing, by the access point, network access to the wireless device using the received PMK, subject to the profile's time and bandwidth restrictions. Compl. ¶43
- The complaint notes infringement of "one or more claims," reserving the right to assert additional claims Compl. ¶36
U.S. Patent No. 12,231,884
- Patent Identification: U.S. Patent No. 12,231,884 (“Wireless Network Provisioning Using a Pre-shared Key”), issued February 18, 2025. Compl. ¶10
The Invention Explained
- Problem Addressed: As a continuation of the application leading to the '285 Patent, the '884 Patent addresses the same problems of insecure and unmanageable shared-key Wi-Fi networks Compl. ¶15 ’884 Patent, col. 1:47-62
- The Patented Solution: This patent details a more specific method for the authentication handshake. It describes the wireless device sending a message integrity code (MIC) and a station nonce (SNonce) to the access point. The AP then transmits the MIC, SNonce, and its own AP nonce (ANonce) to the cloud-based system. The cloud system iteratively calculates MICs for its stored profiles using the received nonces to find a match, and upon finding one, transmits a PMK to the AP to grant access Compl. ¶22 ’884 Patent, abstract ’884 Patent, claim 1
- Technical Importance: This patent claims a specific, ordered cryptographic process that improves upon conventional authentication methods by offloading the computationally intensive key-matching process from the local access point to a remote cloud server Compl. ¶23
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶80
- The essential elements of independent claim 1 include:
- Storing, by a "cloud-based provisioning system", profiles comprising a PSK and SSID.
- Receiving, at an "access point", a "message integrity code (MIC)" and a "station announcement message (SNonce)" from a wireless device.
- Transmitting the "MIC", "SNonce", and an "access point announcement message (ANonce)" to the cloud-based system.
- Receiving these values at the cloud-based system.
- Calculating, by the cloud system, MICs for its stored profiles and determining which one matches the received MIC.
- Transmitting a "PMK" for the matching profile to the access point.
- Receiving the PMK at the access point, establishing an encrypted session, and granting network access. Compl. ¶87
- The complaint notes infringement of "one or more claims," reserving the right to assert additional claims Compl. ¶80
III. The Accused Instrumentality
- Product Identification: Defendant’s cloud-based system known as “ElevenOS,” which includes the “Personal Pass Key” feature (collectively, the "Accused Product") Compl. ¶25
- Functionality and Market Context:
- The Accused Product is described as "enterprise-grade Wi-Fi management software" primarily for the hotel and multifamily housing industries Compl. ¶26 Compl. ¶46
- It allows property managers to use a web application, "Site Manager," to create unique "Personal Pass Keys" for residents or guests, controlling access parameters like duration and bandwidth Compl. ¶27 Compl. ¶49 Compl. ¶50
- The complaint alleges that when a user attempts to connect, the on-premise hardware sends an "encrypted key" to Eleven's cloud-based "Key Matching Service (EKMS)," which "checks the key against a list of authorized keys, granting access only when a match is found" Compl. ¶48 Compl. ¶28 The complaint includes a diagram from Defendant's marketing materials illustrating the "Magic of Key Matching" feature. Compl. ¶139 This diagram describes a "purpose-built service that stores all keys enabled for an SSID and checks that the key entered by a user" is valid, noting it is a "cloud-based solution" Compl. ¶139
IV. Analysis of Infringement Allegations
'285 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| [1a] creating, at a cloud-based provisioning system, a plurality of wireless network access profiles that indicate: 1) a plurality of PSKs; 2) a plurality of bandwidth restrictions; and 3) a plurality of time periods for which network access is permitted... | ElevenOS is a cloud-based system that allows property managers to create unique passkeys (PSKs) for residents with defined attributes like bandwidth speeds and access end dates. | ¶¶47-50 | col. 4:58-6:5 |
| [1b] receiving, by an access point... from a wireless device, a first value that is based at least in part on the PSK; | When a user's device asks to join the network, the on-premise access point receives an "encrypted key." | ¶¶51-52 | col. 5:48-6:2 |
| [1c] transmitting, by the access point, the first value to the cloud-based provisioning system via the Internet; | The on-premise hardware sends the "encrypted key" to Eleven's cloud-native Key Matching Service (EKMS). | ¶¶53-54 | col. 6:2-10 |
| [1d] creating, by the cloud-based provisioning system, a plurality of values based on the plurality of PSKs... [1e] identifying... a second value... that matches the transmitted first value; | The EKMS "checks the key against a list of authorized keys." The complaint cites Defendant's own '407 Patent, which allegedly describes generating MICs from PSKs to find a match. | ¶¶55-60 | col. 6:26-44 |
| [1f] providing, by the cloud-based provisioning system to the access point via the Internet, a pairwise master key (PMK) based on the PSK of the wireless network access profile... | The complaint cites Defendant's '407 patent as evidence that the system generates and uses a PMK based on the PSK to enable the connection. | ¶¶61-64 | col. 7:1-9 |
| [1g] providing, by the access point, network access to the wireless device using the PMK... for a time period indicated by the wireless network access profile... in accordance with a bandwidth restriction... | ElevenOS automatically onboards and off-boards residents based on their access end dates and allows administrators to define bandwidth speeds for users. | ¶¶65-68 | col. 7:1-9 |
'884 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| [1a] storing, by a cloud-based provisioning system, a plurality of wireless network access profiles, wherein each... comprises: a pre-shared key (PSK); and an SSID... | ElevenOS is a cloud-based system that stores unique Wi-Fi passwords (PSKs) and the associated SSID for each resident. | ¶¶91-93 | col. 10:11-14 |
| [1b] receiving, by an access point, from a wireless device, a message integrity code (MIC) and a station announcement message (SNonce)... | The complaint alleges this step is performed by pointing to a diagram in Defendant's own '407 patent, which illustrates the handshake process including Frame 2 containing "SNonce, MIC, etc." | ¶¶94-95 | col. 12:2-8 |
| [1d] transmitting, by the access point, the MIC, the SNonce, and an access point announcement message (ANonce) to the cloud-based provisioning system... | The on-premise hardware sends the connection data ("encrypted key") to Eleven's cloud-native EKMS. The complaint again cites Defendant's '407 patent. | ¶¶98-100 | col. 12:8-15 |
| [1f] calculating, by the cloud-based provisioning system, calculated MICs for multiple wireless network access profiles... [1g]... a first calculated MIC... does not match... [1h]... a second calculated MIC... matches the received MIC; | Defendant's cloud EKMS "checks the key against a list of authorized keys." The complaint alleges this is done by generating MICs for each potential PSK and matching them, as described in Defendant's '407 patent. | ¶¶104-109 | col. 12:25-44 |
| [1i] transmitting, by the cloud-based provisioning system, a pairwise master key (PMK)... to the access point in response to determining that the calculated MIC... matches... | The complaint provides a diagram from Defendant's '407 patent showing the Key Matching Service sending a "Match: (PMK/PSK)" message back to the access point. | ¶¶111-112 | col. 12:55-63 |
| [1j] receiving, by the access point, the PMK... [1k] establishing... an encrypted communication session... [1l] granting... network access... | Defendant's marketing materials state that its system uses "WPA2 Personal encryption with multiple PSKs" and that once a user enters their PSK, they "get connected." | ¶¶113-120 | col. 12:60-67 |
- Identified Points of Contention:
- Evidentiary Questions: The infringement allegations for both patents, and particularly for the specific handshake steps of the '884 Patent, rely heavily on descriptions from the Defendant's own patent (U.S. Patent No. 11,917,407) and marketing materials, rather than on direct technical evidence from the Accused Product itself (Compl. ¶¶56, 95). A central question will be whether the Plaintiff can prove that the Accused Product actually operates in the manner described in those documents.
- Scope Questions: The '285 Patent claims receiving a "first value that is based at least in part on the PSK" Compl. ¶43 The complaint alleges this is an "encrypted key" Compl. ¶48 The analysis may turn on whether the data transmitted by a user's device in the Accused Product's system meets the definition of this claim term, or if there is a technical or legal distinction.
V. Key Claim Terms for Construction
For the '285 and '884 Patents:
- The Term: "cloud-based provisioning system"
- Context and Importance: This term appears in the independent claims of both patents and defines the location where the core authentication logic is performed, distinct from the local "access point". Practitioners may focus on this term because the specific architecture of Defendant's "ElevenOS" and "EKMS" services will be compared against the patent's description of this system. The dispute may center on whether Defendant's system is sufficiently "distinct" from the access points and performs the claimed functions.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent states the system is "an internet-connected server system" that is "remotely located from the access point" and communicates "via the Internet," suggesting any remote server performing the functions could qualify ’285 Patent, claim 1 ’884 Patent, claim 1
- Evidence for a Narrower Interpretation: Figure 1 depicts the "cloud-based provisioning system 110" as a specific arrangement that includes a "PMK database 112", a "profile database 114", and communicates with a "registration system 120" ’285 Patent, Fig. 1 ’285 Patent, col. 4:8-12 This could support an argument that the term requires this specific set of components.
For the '285 Patent:
- The Term: "a first value that is based at least in part on the PSK"
- Context and Importance: This term in claim 1 of the '285 Patent is the data transmitted from the access point to the cloud for matching. Its interpretation is critical to determining infringement. The complaint alleges this is an "encrypted key" Compl. ¶48, but Defendant may argue for a more specific definition.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The claim language "based at least in part on" is facially broad and could encompass any data cryptographically derived from the PSK. The abstract uses similar general language ’285 Patent, abstract
- Evidence for a Narrower Interpretation: The specification describes the generation of a message integrity code (MIC) as part of a WPA handshake procedure ’285 Patent, col. 5:58-6:2 This could be used to argue that the "first value" should be construed more narrowly as a MIC, potentially aligning it more with the claims of the '884 Patent.
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement under 35 U.S.C. § 271(b). The factual basis is that Defendant supplies the Accused Product to its customers (e.g., hotel operators) and provides instructions on how to deploy and operate the infringing functionality through materials such as "Site Manager, its Resource Center, datasheets, and case studies" Compl. ¶40 Compl. ¶84 Plaintiff alleges Defendant does so with knowledge of the patents and with the specific intent to cause its customers to infringe Compl. ¶40
- Willful Infringement: The complaint alleges willful infringement, asserting that Defendant had pre-suit knowledge of the patents. This allegation is based on Defendant's alleged receipt of a provisional application on April 30, 2020, and an infringement notice letter on June 13, 2025 Compl. ¶¶31-32 Compl. ¶71 The complaint also pleads willful blindness, arguing Defendant was on notice of the technology and "took deliberate actions to avoid learning of the '285 Patent" Compl. ¶72 Continued alleged infringement after the filing of the complaint is also cited as a basis for willfulness Compl. ¶41
VII. Analyst’s Conclusion: Key Questions for the Case
A central evidentiary issue will be one of technical proof: The complaint's infringement theory relies heavily on Defendant's own patent and marketing materials to explain the operation of the Accused Product. A key question for the court will be whether Plaintiff can produce sufficient evidence to demonstrate that the Accused Product's actual, real-world operation precisely mirrors the steps claimed in the '285 and '884 patents, particularly the specific MIC and nonce-based handshake of the '884 patent.
The case will also involve a critical question of claim construction: The viability of the infringement allegations against the '285 patent may depend on the scope given to the term "a first value that is based at least in part on the PSK". Whether this term is construed broadly to cover any "encrypted key" or more narrowly to mean a specific cryptographic output like a MIC could be dispositive for that patent.
Finally, a significant question for damages will be one of willfulness: The allegations of pre-suit notice, based on receipt of a provisional application years before the patents issued, will raise the question of when Defendant’s duty to investigate potential infringement began, and whether its subsequent actions constituted willful blindness or objective recklessness.