3:26-cv-01303
BenedorTSE LLC v. Amazon.com Services LLC
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: BenedorTSE, LLC (Delaware)
- Defendant: Amazon.com Services LLC (Delaware); Amazon.com, Inc. (Delaware)
- Plaintiff’s Counsel: Waddey Acheson LLC
- Case Name: BenedorTSE, LLC v. Amazon.com Services LLC and Amazon.com, Inc.
- Case Identification: 3:26-cv-01303, M.D. Tenn., 09/11/2026
- Venue Allegations: Venue is alleged to be proper in the Middle District of Tennessee because Defendants operate a "regular and established place of business" in the district, including a major corporate hub in Nashville and a fulfillment center in Murfreesboro, and have committed alleged acts of infringement in the district.
- Core Dispute: Plaintiff alleges that Defendant’s Amazon Shopping app and its associated authentication and payment systems infringe two patents related to methods for securing electronic transactions.
- Technical Context: The technology involves using a customer's own device as an authentication factor to create and transmit encrypted, single-use credentials for e-commerce transactions, thereby protecting sensitive payment information from the merchant.
- Key Procedural History: The complaint alleges that Defendants had knowledge of the patents-in-suit and their family members due to citations in Defendants' own patent prosecution history, including instances where Defendants submitted the art to the USPTO in Information Disclosure Statements. These allegations form the basis for a claim of willful infringement.
Case Timeline
| Date | Event |
|---|---|
| 2000-12-01 | Priority Date for ’979 and ’713 Patents |
| 2013-06-11 | U.S. Patent No. 8,463,713 Issues |
| 2014-12-01 | Amazon Shopping App becomes available on Google Play |
| 2016-07-26 | U.S. Patent No. 9,400,979 Issues |
| 2018-02-20 | Amazon-owned U.S. Patent 9,898,357 issues, citing the Carrott patent family |
| 2020-01-07 | Amazon-owned U.S. Patent 10,528,931 issues, citing a Carrott patent family publication |
| 2020-08-25 | Amazon-owned U.S. Patent 10,755,323 issues, citing a Carrott patent family publication |
| 2021-05-25 | Amazon-owned U.S. Patent 11,016,954 issues, citing the ’979 Patent |
| 2026-09-11 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,400,979 - "Transactional Security Over a Network" (Issued July 26, 2016)
The Invention Explained
- Problem Addressed: The patent addresses security risks in early e-commerce, where customers had to provide sensitive financial information like credit card numbers directly to merchants, leaving that data vulnerable on merchant servers (Compl. ¶¶10-11; ’979 Patent, col. 2:11-24). Existing solutions were considered cumbersome or insufficient Compl. ¶12
- The Patented Solution: The invention proposes a method where a customer's own device performs two-factor authentication. First, the user is authenticated (e.g., via password), and second, the device itself is authenticated by reading its own unique hardware identifiers (Compl. ¶¶15-16). These two factors—a user identifier and a device hardware identifier—are encrypted together on the user's device to create a secure "encrypted user code" '979 Patent, col. 18:65-19:2 This code is transmitted to a provider for authorization instead of the raw payment credentials, meaning the merchant never sees the customer's sensitive information '979 Patent, col. 2:45-50
- Technical Importance: This approach treats the user's personal device as a security token, a concept the complaint characterizes as unconventional at the time, to create a "person-present" level of verification for card-not-present online transactions without requiring new hardware (Compl. ¶¶14-16).
Key Claims at a Glance
- The complaint asserts independent method claims 13 and 19 (Compl. ¶¶47-48).
- Essential Elements of Independent Claim 13:
- Receiving an entered password from a user via a graphic user interface on the user's device.
- Determining if the password is valid.
- Based on a valid password, reading a hardware identifier from the device's hardware.
- Determining if the hardware identifier is valid.
- Based on both the password and hardware identifier being valid, retrieving a user identifier from the device's storage.
- Creating an encrypted user code by encrypting both the user identifier and the hardware identifier.
- Transmitting the encrypted user code to a provider for a transaction authorization decision.
- Receiving the transaction authorization decision from the provider.
- The user receiving performance of the approved transaction request.
- The complaint does not explicitly reserve the right to assert other claims but states infringement of "one or more claims" Compl. ¶46
U.S. Patent No. 8,463,713 - "Transactional Security Over a Network" (Issued June 11, 2013)
The Invention Explained
- Problem Addressed: As a member of the same patent family sharing a common specification, the '713 Patent addresses the same security vulnerabilities in e-commerce transactions as the '979 Patent Compl. ¶21 '713 Patent, col. 1:26-29
- The Patented Solution: The solution is functionally identical to that of the '979 Patent, involving the creation of an encrypted code on a user's device from user and device identifiers for secure transaction authorization '713 Patent, abstract '713 Patent, col. 2:30-40 The complaint notes the '713 Patent claims the same architecture but with "additional limitations" Compl. ¶24
- Technical Importance: The technology provides a method for secure, device-based, multi-factor authentication in online transactions, aiming to prevent exposure of sensitive customer data Compl. ¶16
Key Claims at a Glance
- The complaint asserts independent method claim 13 Compl. ¶58
- Essential Elements of Independent Claim 13:
- Receiving an entered password from a user.
- Determining if the password is valid.
- Based on a valid password, reading a hardware identifier from the device's hardware.
- Determining if the hardware identifier is valid.
- Based on a valid hardware identifier, retrieving a user agreement identifier from the device's storage.
- Creating an encrypted user code by encrypting the user agreement identifier and the hardware identifier, with the specific limitation that "each such encrypted code being valid only for a single request for an authorization decision."
- Transmitting the encrypted user code to a provider for an authorization decision.
- Receiving the authorization decision from the provider.
- The complaint alleges infringement of "one or more claims" of the '713 Patent Compl. ¶57
III. The Accused Instrumentality
Product Identification
The "Accused Instrumentality" is identified as the Amazon Shopping app operating on customers' mobile devices, in conjunction with Amazon's supporting backend systems for account sign-in, device registration/recognition, and stored-payment checkout and authorization Compl. ¶27
Functionality and Market Context
- The complaint alleges that when a user makes a purchase, the Accused Instrumentality uses a stored payment method without the user re-entering full card details Compl. ¶33 The user authenticates via a password through the app's interface Compl. ¶30 The system is alleged to register and recognize the specific device used for the account Compl. ¶31
- The complaint alleges that the app then transmits an "encrypted, cryptographically authenticated transaction request" derived from customer- and device-identifying information to Amazon's backend systems for authorization Compl. ¶33
- These features are alleged to be technically necessary for stored-payment purchases and to provide significant commercial benefits to Amazon by reducing friction at checkout, thereby increasing customer conversion and retention Compl. ¶35
IV. Analysis of Infringement Allegations
No probative visual evidence provided in complaint.
’979 Patent Infringement Allegations
| Claim Element (from Independent Claim 13) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| received an entered password from the user into a graphic user interface of the user's computerized device | The user enters their Amazon account password into the Amazon Shopping app's sign-in interface. | ¶47(a) | col. 18:65-67 |
| determined... whether the entered password was valid... | The app and Amazon's authentication services determine if the entered password is valid and deny access if not. | ¶47(b) | col. 18:65-67 |
| based on the password being valid, read a device-specific hardware identifier from the hardware of the user's device | The Accused Instrumentality reads a hardware identifier from the user's device to identify the device. | ¶47(c) | col. 17:11-16 |
| determined whether the hardware identifier was valid... | The system determines if the hardware identifier matches a permitted, registered device for the user's account. | ¶47(d) | col. 11:27-34 |
| based on at least one of the password being valid and the hardware identifier being valid, retrieved a user identifier that identified the user... from the storage media of the user's device | The system retrieves a user identifier, such as a customer-account or session identifier, from the device's storage. | ¶47(e) | col. 11:35-39 |
| created an encrypted user code by encrypting the user identifier and the hardware identifier | The system creates an encrypted credential derived from customer-identifying and device-identifying information. | ¶47(f) | col. 11:40-45 |
| transmitted... the encrypted user code to a provider... in a transaction request for a transaction authorization decision | The encrypted code is transmitted to Amazon's retail and payment-processing infrastructure for authorization. | ¶47(g) | col. 12:4-10 |
| received, by the input and output device of the user's device, the transaction authorization decision from the provider | The user's device receives an authorization decision, such as an order confirmation screen in the app. | ¶47(h) | col. 12:35-44 |
| received, by the user, performance of the transaction request from the provider based on the transaction authorization decision approving the transaction | The user receives the completed purchase and fulfillment of the order. | ¶47(i) | col. 12:48-52 |
’713 Patent Infringement Allegations
| Claim Element (from Independent Claim 13) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| received an entered password from the user into a graphic user interface of the user's computerized device | The user enters their Amazon account password into the Amazon Shopping app's sign-in interface. | ¶58(a) | col. 29:50-58 |
| determined, by a processor, whether the entered password was valid... | The system determines if the entered password matches the one established for the customer's Amazon account. | ¶58(b) | col. 29:55-58 |
| based on the password being valid, read a device-specific hardware identifier from the hardware of the user's device | The Accused Instrumentality reads a device-specific hardware identifier from the user's device. | ¶58(c) | col. 29:60-62 |
| determined whether the hardware identifier was valid... | The system determines if the device is registered to and recognized for the customer's account. | ¶58(d) | col. 29:64-67 |
| based on the hardware identifier being valid, retrieved a user agreement identifier from the storage media of the user's device... | The system retrieves a user agreement identifier, alleged to be a stored credential or token associated with the payment method. | ¶58(e) | col. 31:62-67 |
| created an encrypted user code by encrypting the user agreement identifier and the hardware identifier, each such encrypted code being valid only for a single request for an authorization decision | The system creates an encrypted authorization credential, allegedly accompanied by a per-request signature, making it usable only for that single request. | ¶58(f) | col. 35:22-26 |
| transmitted, by the input and output device of the user's device, the encrypted user code to a provider... | The encrypted code is transmitted to Amazon's retail and payment-processing infrastructure for an authorization decision. | ¶58(g) | col. 35:30-37 |
| received, by the input and output device of the user's device, the authorization decision from the provider | The user's device receives an authorization decision, such as an order confirmation displayed in the app. | ¶58(h) | col. 35:38-40 |
- Identified Points of Contention:
- Technical Question: The complaint alleges, "on information and belief," that the accused system creates an encrypted code by encrypting specific user and device identifiers (Compl. ¶47(f)). A central dispute may be the actual technical composition of the transmitted data. The court may need to determine if Amazon's "per-request cryptographic signature" Compl. ¶33 is equivalent to the patents' "encrypted user code" containing specific data elements.
- Scope Question: For the '713 Patent, a key point of contention may be whether the security credential generated by Amazon is "valid only for a single request for an authorization decision" as required by claim 13 Compl. ¶58(f) The analysis will question whether Amazon's use of a "per-request cryptographic signature" meets this specific single-use limitation or if it operates differently (e.g., time-based validity).
V. Key Claim Terms for Construction
The Term: "hardware identifier"
Context and Importance: This term is foundational to the invention's concept of using the device itself as a physical authentication token. The scope of this term will determine what types of device-specific information can satisfy the claim limitation. Practitioners may focus on this term because its construction could either limit the claims to permanent, physical serial numbers or broaden them to cover software-based identifiers common in modern mobile devices.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification provides examples such as "serial numbers from the motherboard, the hard drives, the processor, etc." '713 Patent, col. 17:13-15 The use of "etc." suggests the list is not exhaustive and could encompass other forms of unique device identifiers.
- Evidence for a Narrower Interpretation: The specification consistently refers to physical components like "motherboard," "hard drives," and "processor" when discussing the source of the identifier '713 Patent, col. 17:13-15 This could support an interpretation limited to identifiers tied to immutable physical hardware, potentially excluding resettable or software-derived advertising IDs.
The Term: "encrypted user code"
Context and Importance: This term defines the output of the claimed method's core security process. Infringement will depend on whether the data packet transmitted by the Amazon Shopping app for authorization constitutes an "encrypted user code" as defined by the patent.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The abstract describes encrypting a "customer identifier string" to be transferred from the customer to a merchant '713 Patent, abstract This could be read to cover any encrypted data payload that serves to identify the user for a transaction.
- Evidence for a Narrower Interpretation: The claims explicitly require creating the code "by encrypting the user identifier and the hardware identifier" '979 Patent, claim 13 This language, combined with the specification's description of combining these elements '979 Patent, col. 11:40-45, suggests a specific structure where both identifiers are part of the encrypted payload, potentially distinguishing it from a transaction request that is merely signed but where the identifiers might be in plaintext.
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement under 35 U.S.C. § 271(b), stating that Amazon encourages and instructs customers on how to use the Accused Instrumentality in an infringing manner through its help documentation and user instructions Compl. ¶52 Compl. ¶62 It also alleges contributory infringement under 35 U.S.C. § 271(c), asserting that the app and its integrated components are material parts of the invention, specially made for this use, and are not staple articles of commerce Compl. ¶53 Compl. ¶63
- Willful Infringement: The complaint alleges willful infringement based on Defendants' alleged pre-suit knowledge of the patents-in-suit and their family (Compl. ¶¶37-44). The allegations are supported by specific instances where patents owned by Amazon Technologies, Inc. cited the '979 Patent or its family members during their own prosecution, including applicant-submitted citations in Information Disclosure Statements Compl. ¶39 Compl. ¶41
VII. Analyst’s Conclusion: Key Questions for the Case
A central issue will be one of definitional scope: How will the term "hardware identifier" be construed? The case may turn on whether this term is limited to permanent serial numbers of physical components, or if it can be interpreted to cover the kind of software-based, potentially resettable, unique device identifiers commonly used by modern mobile applications like the Amazon Shopping app.
A key evidentiary question will be one of technical implementation: Does the transaction request transmitted by the Amazon Shopping app constitute an "encrypted user code" that is created "by encrypting" both a user identifier and a hardware identifier, as required by the claims? Resolution will likely depend on forensic analysis of the accused system's data transmissions.
A pivotal question for the '713 Patent will be one of functional specificity: Does the security mechanism in Amazon's checkout process create a credential that is "valid only for a single request for an authorization decision"? The court will need to examine whether the alleged "per-request cryptographic signature" is functionally equivalent to the specific single-use limitation recited in the claim.