DCT
3:26-cv-00728
BenedorTSE LLC v. Samsung Electronics Co Ltd
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: BenedorTSE, LLC (Delaware)
- Defendant: Samsung Electronics Co., Ltd. (Republic of Korea) and Samsung Electronics America, Inc. (New York)
- Plaintiff's Counsel: Waddey Acheson LLC
- Case Identification: 3:26-cv-00728, M.D. Tenn., 05/29/2026
- Venue Allegations: Venue is alleged based on Samsung Electronics America, Inc. operating a regular and established place of business in the district (an American Distribution Center in Mt. Juliet, TN) and committing acts of infringement therein.
- Core Dispute: Plaintiff alleges that Defendant's Samsung Pay / Samsung Wallet mobile payment service infringes three patents related to methods and systems for securing electronic transactions over a network.
- Technical Context: The technology concerns methods for authenticating a user and a device during an electronic payment transaction to prevent fraud, without exposing the user's underlying financial account information to the merchant.
- Key Procedural History: The complaint alleges that Defendant had pre-suit knowledge of the patents-in-suit as early as January 2016, based on direct communications between Plaintiff's principal and a senior executive at Samsung Pay, which may form the basis for the willful infringement claim.
Case Timeline
| Date | Event |
|---|---|
| 2000-12-01 | Priority Date for '713, '979, and '723 Patents |
| 2012-09-04 | U.S. Patent No. 8,260,723 ('723 Patent) Issued |
| 2013-06-11 | U.S. Patent No. 8,463,713 ('713 Patent) Issued |
| 2015-09-28 | Samsung Pay launched in the United States |
| 2016-01-20 | Alleged date of Samsung's pre-suit knowledge of the patent portfolio |
| 2016-07-26 | U.S. Patent No. 9,400,979 ('979 Patent) Issued |
| 2026-05-29 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,400,979, Transactional Security Over a Network, issued July 26, 2016
The Invention Explained
- Problem Addressed: Prior to the invention, electronic commerce was hampered by payment systems that were either insecure or overly cumbersome Compl. ¶¶10-11 Protocols like SSL encrypted data in transit but left sensitive information like credit card numbers exposed on merchant servers, while more robust solutions like Secure Electronic Transaction (SET) were too complex for widespread adoption Compl. ¶¶11-12 A technological gap existed for a practical system that could protect customer data from the merchant while binding a transaction to a specific user and device Compl. ¶16
- The Patented Solution: The invention describes a method where a user's device generates a unique, encrypted, single-use code for each transaction Compl. ¶18 This code is created by combining a user's password, a unique identifier read from the device's hardware, and a user agreement identifier stored on the device '979 Patent, col. 35:1-12 This encrypted code is transmitted to the merchant and then to a verification entity for authorization, which avoids exposing the customer's actual payment details to the merchant '979 Patent, abstract
- Technical Importance: This approach provided a framework for multi-factor authentication in e-commerce that used the customer's own device as a security token, enhancing security without requiring the user to enroll in a complex digital certificate infrastructure Compl. ¶¶14-16
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶60
- Essential elements of independent claim 1 include:
- Receiving an entered password from a user via a graphical user interface.
- Determining if the password is valid.
- Reading a hardware identifier from the device's hardware.
- Determining if the hardware identifier is valid.
- Retrieving a user agreement identifier from the device's storage media.
- Creating an encrypted user code by encrypting the user agreement identifier and the hardware identifier.
- Transmitting the encrypted user code to a provider for a transaction authorization decision.
- The complaint does not explicitly reserve the right to assert dependent claims for this patent but alleges infringement of "one or more claims" Compl. ¶59
U.S. Patent No. 8,463,713, Transactional Security Over a Network, issued June 11, 2013
The Invention Explained
- Problem Addressed: The patent addresses the same security and convenience issues in e-commerce as the '979 Patent, namely the risk of exposing sensitive customer financial data to merchants during online transactions Compl. ¶¶10-12
- The Patented Solution: The patent discloses a system and non-transitory computer-readable medium storing instructions to secure transactions '713 Patent, abstract The instructions cause a user's device, upon password entry, to read hardware identifiers, retrieve a user agreement identifier, and create a single-use encrypted code for transmission to a provider, which then returns an authorization decision '713 Patent, col. 31:1-32:15 '713 Patent, Fig. 11 This process validates both the user and the device without transmitting the underlying payment card number to the merchant Compl. ¶18
- Technical Importance: The invention's focus on a non-transitory computer-readable medium provided a basis for claiming the software product itself, not just the method of its use, which was significant for asserting infringement against distributors of software Compl. ¶1 Compl. ¶68
Key Claims at a Glance
- The complaint asserts at least independent method claim 13 and independent non-transitory computer-readable storage medium claim 25 Compl. ¶¶68-69
- Essential elements of independent claim 25 include instructions for a device's processor to perform a method comprising:
- During account establishment: storing a permitted password, user identifier string, permitted hardware identifiers, and a user agreement identifier, and transmitting some of this information to a verification entity.
- During an authorization request: receiving a password, validating it, reading and validating a hardware identifier, retrieving the user agreement identifier, creating an encrypted user code "valid only for a single request," transmitting the code to a provider, and receiving an authorization decision.
- The complaint alleges infringement of "one or more claims" Compl. ¶67
Multi-Patent Capsule: U.S. Patent No. 8,260,723
- Patent Identification: U.S. Patent No. 8,260,723 ("'723 Patent"), Transactional Security Over a Network, issued September 4, 2012 Compl. ¶22
- Technology Synopsis: The '723 Patent, part of the same family as the other patents-in-suit, discloses a method for securing transactions by combining multiple data points on a user's device to create a unique payment credential Compl. ¶18 Compl. ¶22 The invention adds a "count value" (incremented with each transaction) to the combination of user and device identifiers, creating a one-time-use encrypted code that prevents replay attacks and protects the user's real account information from the merchant '723 Patent, col. 31:49-65
- Asserted Claims: The complaint asserts at least independent method claim 1 and independent non-transitory computer storage medium claim 7 Compl. ¶¶76-77
- Accused Features: The complaint alleges that Samsung Wallet infringes by using an Application Transaction Counter (ATC) as the claimed "count value," a device-bound UID as the "hardware identifier," and a tokenized payment identifier as the "customer identifier string" to generate a transaction-specific cryptogram Compl. ¶76
III. The Accused Instrumentality
- Product Identification: The Accused Instrumentality is identified as "Samsung's mobile payment service, Samsung Pay / Samsung Wallet, in conjunction with its supporting hardware and software on compatible Galaxy smartphones, foldable phones, and smart watches, and in conjunction with Samsung's supporting tokenization, attestation, and payment-authorization systems" Compl. ¶1
- Functionality and Market Context: The complaint describes the Accused Instrumentality as a mobile wallet that uses tokenization to replace a user's actual payment card number with a device-specific token Compl. ¶42 Compl. ¶50 To make a payment, a user must authenticate with a fingerprint or PIN Compl. ¶42 The device then uses hardware-backed security features, such as Samsung Knox and the TrustZone-based Integrity Measurement Architecture (TIMA), to perform integrity checks and attest to its trusted state Compl. ¶47 The system reads device-specific identifiers, such as a Unique Device Identifier (UID) derived from a Samsung Device Root Key, to bind the transaction to the specific device Compl. ¶45 The complaint alleges that within its first year, Samsung Pay processed nearly 100 million transactions, indicating significant market adoption Compl. ¶37
No probative visual evidence provided in complaint.
IV. Analysis of Infringement Allegations
'979 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| receiving, into a graphic user interface of a computerized device, an entered password from a user | The Samsung Pay / Samsung Wallet system receives a user-entered Samsung Wallet PIN or other device unlock credential via a graphical interface. | ¶60(a) | col. 15:27-31 |
| determining, by a processor of said computerized device, whether said entered password is valid | The system checks the entered credential against a credential stored on the device or bound to the device's authentication framework to determine its validity. | ¶60(b) | col. 15:56-62 |
| based on said password being valid, reading, by said processor, a hardware identifier from hardware of said computerized device | After validation, the system reads a device-specific identifier, such as a Samsung Device Root Key UID or certificate UID, from the device's secure hardware. | ¶60(c) | col. 7:13-18 |
| determining, by said processor, whether said hardware identifier is valid | The system determines the validity of the hardware identifier through security processes including attestation and integrity checks performed by Samsung-authored framework code. | ¶60(d) | col. 9:8-19 |
| retrieving, by said processor, a user agreement identifier that identifies said user from a storage media of said computerized device | The system retrieves a tokenized payment identifier, such as a token reference identifier or transaction token identifier, stored on the device. | ¶60(e) | col. 15:3-9 |
| creating, by said processor, an encrypted user code by encrypting said user agreement identifier and said hardware identifier | The system creates a transaction-specific cryptographic payment credential derived from the retrieved tokenized identifier and the hardware identifier. | ¶60(f) | col. 17:1-9 |
| transmitting... said encrypted user code to a provider in a transaction request for a transaction authorization decision | The system transmits the encrypted credential to a provider, which includes the payment network, tokenization infrastructure, and/or issuing bank, to request authorization. | ¶60(g) | col. 15:1-9 |
- Identified Points of Contention:
- Scope Question: A primary issue may be whether a "token reference identifier" or "transaction token identifier" Compl. ¶60(e), which is a substitute for a primary account number (PAN) for a specific device or transaction, constitutes a "user agreement identifier" as that term is used in the patent. The defense may argue the patent contemplates an identifier for the user's master agreement with the verification entity, not a transient payment token.
- Technical Question: The claim requires reading a "hardware identifier from hardware of said computerized device" Compl. ¶60(c) The complaint alleges this is a "Samsung Device Root Key UID" or "certificate UID." A question for the court will be whether a cryptographically-derived unique identifier, which is read via software from secure memory, is equivalent to reading an identifier from hardware, which may imply a more direct reading of a physical serial number as contemplated by the patent's examples.
'713 Patent Infringement Allegations
| Claim Element (from Independent Claim 25) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| when establishing an account: storing at least one permitted password, at least one user identifier string, permitted hardware identifiers, and a user agreement identifier... and transmitting the user identifier string, the permitted hardware identifiers, and the user's personal payment information to a verification entity | The complaint alleges that during account setup, Samsung's software stores credentials (PIN/fingerprint), user/hardware identifiers (e.g., Device Root Key UID), and an agreement identifier (e.g., token reference identifier), and transmits required information to Samsung's Token Service or other entities. | ¶68 | col. 27:35-51 |
| when requesting an authorization decision: receiving an entered password... determine whether the entered password matches... read a hardware identifier... determine whether that hardware identifier matches... retrieve the user agreement identifier | During a payment, the software receives a PIN/fingerprint, validates it against stored credentials, reads a hardware identifier (e.g., Root Key UID), and validates it using Knox-based attestation. It then retrieves the user agreement identifier (token). | ¶68 | col. 29:59-30:2 |
| create an encrypted user code by encrypting the user agreement identifier and the hardware identifier (each encrypted user code being valid only for a single request for an authorization decision) | The software creates a transaction-specific cryptogram by encrypting the token and hardware identifier, consistent with the single-use architecture of EMVCo-compliant tokenized payments. | ¶68 | col. 31:49-56 |
| transmit the encrypted user code to a provider... and receive the authorization decision from the provider | The encrypted cryptogram is transmitted to the payment network or merchant terminal, and an authorization decision is received back from the provider. | ¶68 | col. 31:5-10 |
- Identified Points of Contention:
- Scope Question: The claim recites instructions for a "verification entity." The complaint alleges this role is filled by a combination of Samsung's systems, card-network systems, and the issuing bank Compl. ¶40 A central question will be whether this distributed collection of services provided by different corporate entities can be construed as a single "verification entity" under the patent.
- Technical Question: The claim requires creating an encrypted code "valid only for a single request." The complaint alleges this is met by the "single-use-cryptogram architecture of EMVCo-compliant tokenized payment" Compl. ¶68 The factual analysis may turn on whether the technical implementation of the EMVCo cryptogram strictly aligns with the "valid only for a single request" limitation, or if there are operational differences a court could find meaningful.
V. Key Claim Terms for Construction
The Term: "hardware identifier"
- Context and Importance: This term is foundational to the invention's goal of binding a transaction to a specific device. Its construction will determine whether modern security methods, like using cryptographic keys stored in a secure enclave, fall within the scope of claims that provide examples like physical serial numbers.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification lists examples such as "serial numbers from the motherboard, the hard drives, the processor, etc." '979 Patent, col. 7:15-18 Plaintiff may argue this is an illustrative, non-limiting list and that any unique, unchangeable, hardware-rooted value, including a cryptographic one, serves the same identifying function.
- Evidence for a Narrower Interpretation: The defense may argue that all explicit examples are physical identifiers of components. A cryptographic key, even if provisioned at manufacture and stored in secure hardware, may be characterized as data stored on hardware, rather than an identifier of the hardware itself, suggesting a narrower scope.
The Term: "verification entity"
- Context and Importance: The identity of the "verification entity" is critical because it is the trusted third party that decrypts the secure code and authorizes the transaction. The complaint alleges a distributed system of actors fulfills this role Compl. ¶40 The case may depend on whether a single claim term can read on a multi-party, decentralized system.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent often refers to the entity in functional terms, such as the entity that "decrypts the customer code and returns a purchase authorization decision" '713 Patent, col. 3:23-26 Plaintiff may argue that any collection of actors that collectively performs this function meets the claim limitation.
- Evidence for a Narrower Interpretation: The patent figures consistently depict the "Verification Entity" as a single, unitary box (e.g.,'713 Patent, Fig. 4, item 420), distinct from the "Financial Institution" and "Merchant." The defense may argue this structure implies a single, integrated entity is required, not a loose confederation of services from different companies.
VI. Other Allegations
- Indirect Infringement: The complaint alleges Samsung induced infringement by actively instructing and encouraging users, merchants, and developers to use the Accused Instrumentality in an infringing manner through its Terms of Service, SDKs, developer documentation, and support materials Compl. ¶62 Compl. ¶71 It further alleges contributory infringement by providing non-staple components specially made for infringement, such as the Samsung Wallet client software, Knox attestation services, and device-bound cryptographic keys, which allegedly have no substantial non-infringing use Compl. ¶63 Compl. ¶71
- Willful Infringement: Willfulness is alleged based on Samsung's purported actual knowledge of the patent portfolio no later than January 20, 2016, through direct communications from Plaintiff's principal to a Samsung Pay executive Compl. ¶¶26-28 The complaint alleges that despite this knowledge, Samsung continued to make, use, and sell the Accused Instrumentality without taking a license or designing around the patents Compl. ¶64 Compl. ¶72 Compl. ¶81
VII. Analyst's Conclusion: Key Questions for the Case
This case will likely center on fundamental questions of claim scope and technical implementation as mobile payment technology evolved beyond the concepts described in the 2000-era priority patent applications.
- A core issue will be one of definitional scope: can key patent terms from the early 2000s, such as "hardware identifier" and "user agreement identifier," be construed to cover modern, token-based security constructs like device-bound cryptographic keys and single-use payment tokens?
- Another central question will be one of architectural mapping: does the distributed, multi-party system of tokenization involving Samsung, card networks (e.g., Visa, Mastercard), and issuing banks collectively function as the singular "verification entity" described and depicted in the patents-in-suit, or is this a fundamental structural mismatch?
- A key evidentiary question will be one of functional implementation: does the Accused Instrumentality's use of an "Application Transaction Counter" and EMVCo-compliant cryptograms perform the specific steps and functions required by the claims for a "count value" and a code "valid only for a single request," or do the technical details of their operation diverge from the claimed invention?
Analysis metadata
Loading Complaint
Suggested improvements