3:26-cv-01339
BenedorTSE LLC v. Bank Of America NA
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: BenedorTSE, LLC (Delaware)
- Defendant: Bank of America, N.A. (North Carolina)
- Plaintiff’s Counsel: Waddey Acheson LLC
- Case Identification: 3:26-cv-01339, M.D. Tenn., 09/18/2026
- Venue Allegations: Venue is alleged to be proper based on Defendant having a regular and established place of business in the district—a financial center in Nashville, Tennessee—and having committed acts of infringement within the district.
- Core Dispute: Plaintiff alleges that Defendant’s mobile banking application and supporting systems infringe three patents related to methods for securely authorizing electronic transactions by generating and transmitting encrypted user and device identifiers.
- Technical Context: The technology relates to the field of secure digital payments and authentication, a foundational component of modern mobile banking and e-commerce.
- Key Procedural History: The three patents-in-suit are members of the same patent family, share a common written description, and all claim priority to a U.S. patent application filed on December 1, 2000. The complaint cites the Federal Circuit’s decision in Akamai v. Limelight to support its theory of direct infringement where method steps are performed by multiple actors.
Case Timeline
| Date | Event |
|---|---|
| 2000-12-01 | Priority Date for ’979, ’713, and ’723 Patents |
| 2012-09-04 | U.S. Patent No. 8,260,723 Issues |
| 2013-06-11 | U.S. Patent No. 8,463,713 Issues |
| 2014-10-20 | Bank of America begins support for Apple Pay at launch |
| 2015-09-15 | Bank of America introduces Fingerprint and Touch ID Sign-in |
| 2016-07-26 | U.S. Patent No. 9,400,979 Issues |
| 2026-09-18 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,400,979 - "Transactional Security Over a Network"
- Issued: July 26, 2016
The Invention Explained
- Problem Addressed: The patent documentation describes a technological environment around the year 2000 where the growth of e-commerce was hampered by insecure and inconvenient payment systems Compl. ¶8 Methods like SSL encrypted data in transit but left it exposed on merchant servers, while more secure protocols like Secure Electronic Transaction (SET) were too cumbersome for widespread consumer adoption Compl. ¶¶9-10 A gap existed for a practical method to cryptographically bind a user’s identity to their specific device for a transaction without exposing sensitive data Compl. ¶14
- The Patented Solution: The invention describes a system where a user’s device generates a unique, encrypted "user code" for each transaction Compl. ¶22 This code is created by encrypting a user-specific identifier along with a device-specific "hardware identifier" read from the device itself ’979 Patent, abstract ’979 Patent, col. 9:1-10:2 This encrypted code is transmitted to a merchant and then to a verification entity (e.g., a bank) for authorization, avoiding the need to transmit sensitive information like a full credit card number over the network ’979 Patent, abstract
- Technical Importance: This approach treated the user's personal device as a security token, enabling device-user binding for what the complaint terms "person-present" verification in an online transaction Compl. ¶¶13-14
Key Claims at a Glance
- The complaint asserts at least independent method claim 19 Compl. ¶37
- Claim 19 of the ’979 Patent includes the following essential elements:
- reading a hardware identifier from the hardware of the customer's mobile device;
- determining whether the hardware identifier was valid;
- based on validity, retrieving a user agreement identifier from the device's storage;
- creating an encrypted user code by encrypting the user agreement identifier and the hardware identifier;
- transmitting the encrypted user code in a transaction request;
- receiving a transaction authorization decision; and
- the customer receiving performance of the requested transaction.
- The complaint does not explicitly reserve the right to assert dependent claims for this patent.
U.S. Patent No. 8,463,713 - "Transactional Security Over a Network"
- Issued: June 11, 2013
The Invention Explained
- Problem Addressed: As with its family members, the patent addresses the need for a secure transaction method that does not require the customer to provide private information directly to a merchant, where it could be vulnerable in a database breach ’713 Patent, col. 2:11-24 The system sought to avoid cumbersome hardware tokens or complex protocols that had failed to gain traction ’713 Patent, col. 1:53-65
- The Patented Solution: The invention discloses a method where a user's device, after validating a password, reads hardware identifiers from the device itself and retrieves a stored user agreement identifier ’713 Patent, col. 33:51-34:2 These elements are encrypted into a single-use "user code" which is sent to a provider for authorization, who then confirms the transaction back to the device ’713 Patent, col. 34:3-34:31 This process binds the transaction to the specific device without exposing underlying credentials.
- Technical Importance: The invention provided a framework for using a consumer's own device as a factor of authentication, a practice the complaint alleges was not conventional or routine at the time of invention Compl. ¶12
Key Claims at a Glance
- The complaint asserts at least independent method claim 13 Compl. ¶45
- Claim 13 of the ’713 Patent includes the following essential elements:
- receiving an entered password;
- determining if the password is valid;
- based on password validity, reading a hardware identifier from the device hardware;
- determining if the hardware identifier is valid;
- based on hardware identifier validity, retrieving a user agreement identifier;
- creating an encrypted user code from the user agreement identifier and hardware identifier, valid for only a single request;
- transmitting the encrypted user code for an authorization decision; and
- receiving the authorization decision at the device.
- The complaint does not explicitly reserve the right to assert dependent claims for this patent.
U.S. Patent No. 8,260,723 - "Transactional Security Over a Network"
- Issued: September 4, 2012
- Technology Synopsis: The patent discloses methods for conducting secure purchase transactions by generating an "encrypted customer code" on an electronic device. This code, created by encrypting a customer identifier string, a plurality of hardware identifiers, and a transaction-specific count value, is transmitted to a merchant instead of raw credit card information, thereby protecting the user's sensitive data while enabling device-bound transaction verification ’723 Patent, abstract ’723 Patent, col. 2:25-39
- Asserted Claims: The complaint asserts at least method claim 1 and non-transitory computer storage medium claim 7 Compl. ¶¶53, 56
- Accused Features: The complaint accuses the process of provisioning Bank of America cards into digital wallets (e.g., Apple Pay) and the subsequent authorization of purchases made with those virtual cards (Compl. ¶¶29-30; Compl. ¶54). This includes the generation of a "device-specific dynamic security code" or "cryptogram" for each purchase Compl. ¶¶54g-h
III. The Accused Instrumentality
Product Identification
The "Accused Instrumentality" is identified as Bank of America’s mobile banking application, "Bank of America Mobile Banking," for iOS and Android devices, along with its supporting back-end computer systems Compl. ¶1 Compl. ¶24
Functionality and Market Context
- The complaint alleges the Accused Instrumentality provides access to financial accounts and transaction authorization Compl. ¶24 Key accused functionalities include:
- Authentication: Requiring user authentication via passcode, password, or biometrics (e.g., fingerprint/Touch ID) Compl. ¶25
- Device Recognition: Employing device-recognition and trusted-device technology, which involves reading device-specific identifiers to validate that the device is enrolled and associated with the customer's profile Compl. ¶26
- Secure Transactions: Providing services like Zelle, Bill Pay, and transfers that require authorization Compl. ¶28
- Digital Wallet Provisioning: Allowing users to add Bank of America credit and debit cards to third-party digital wallets like Apple Pay, Google Pay, and Samsung Pay, a process which itself involves authentication and the creation of a device-specific "virtual card number" or "Device Account Number" Compl. ¶¶29-30 This process is alleged to involve reading a stable hardware identifier from the device Compl. ¶30
- The complaint alleges the Accused Instrumentality is used by tens of millions of customers, with Bank of America reporting approximately 31 million active mobile users at year-end 2020 and processing billions of digital logins and hundreds of billions of dollars in transactions annually Compl. ¶24 Compl. ¶¶31-32
IV. Analysis of Infringement Allegations
’979 Patent Infringement Allegations
| Claim Element (from Independent Claim 19) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a. reading a hardware identifier from the hardware of the customer's mobile device; | The app, including bundled security software, reads device-specific identifying information, including device-unique identifiers, from the customer's mobile device. | ¶37a; ¶26 | col. 8:11-19 |
| b. determining whether the hardware identifier was valid... | The app and supporting systems determine if the device is a recognized, enrolled device associated with the customer's online-banking profile. | ¶37b; ¶26 | col. 11:34-40 |
| c. based on the hardware identifier being valid, retrieving from the device's storage media a user agreement identifier that identifies the customer... | The app retrieves a stored, encrypted customer identifier issued by the bank during enrollment. | ¶37c; ¶26 | col. 11:41-47 |
| d. creating an encrypted user code by encrypting the user agreement identifier and the hardware identifier; | The app uses the retrieved identifiers to generate encrypted, request-specific authorization material. | ¶37d; ¶26 | col. 11:48-54 |
| e. transmitting the encrypted user code from the customer's device to Bank of America in a transaction request... over a computer network; | The app transmits the encrypted authorization material to Bank of America's servers for sign-in, Zelle payment, bill pay, or transfer requests. | ¶37e; ¶26 | col. 9:18-24 |
| f. receiving the transaction authorization decision from Bank of America at the customer's device; and | The customer's device receives the authorization decision from Bank of America's servers. | ¶37f | col. 9:25-29 |
| g. the customer receiving performance of the requested transaction from Bank of America... | The customer's requested sign-in, payment, or transfer is completed based on the approval. | ¶37g | col. 9:25-29 |
’713 Patent Infringement Allegations
| Claim Element (from Independent Claim 13) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a. receiving, into the app's graphical sign-in interface on the customer's mobile device, a password entered by the customer; | The app receives a passcode or password through its sign-in interface. | ¶45a; ¶25 | col. 11:15-18 |
| c. based on the password being valid, reading a hardware identifier from the hardware of the customer's device; | Upon successful authentication, the app reads device-specific identifying information from the customer's mobile device. | ¶45c; ¶26 | col. 11:31-34 |
| d. determining whether the hardware identifier was valid based on whether it matched a permitted hardware identifier... | The system determines if the device is a recognized, enrolled device associated with the customer's online-banking profile. | ¶45d; ¶26 | col. 11:34-40 |
| e. based on the hardware identifier being valid, retrieving from the device's storage media a user agreement identifier... | The app retrieves a stored identifier identifying the agreement arising from the customer's enrollment. | ¶45e; ¶26 | col. 11:41-47 |
| f. creating an encrypted user code by encrypting the user agreement identifier and the hardware identifier, each such encrypted user code being valid for only a single authorization request; | The app uses the device validation and stored identifiers to generate encrypted, request-specific authorization material for a single transaction. | ¶45f; ¶26 | col. 11:48-54 |
| g. transmitting the encrypted user code to Bank of America's provider-facing systems in a request for an authorization decision...; and | The app transmits the encrypted code to Bank of America's systems to request authorization. | ¶45g | col. 12:10-21 |
| h. receiving the authorization decision from Bank of America at the customer's device. | The customer's device receives the authorization decision from Bank of America. | ¶45h | col. 12:45-49 |
No probative visual evidence provided in complaint.
Identified Points of Contention
- Scope Questions: A central question may be definitional: do the modern, often OS-managed, device identifiers allegedly read by the accused app Compl. ¶54c fall within the scope of the term "hardware identifier," which the patents’ common specification describes with examples such as "serial numbers from the motherboard, the hard drives, the processor, etc." ’723 Patent, col. 8:15-17? The complaint itself anticipates this issue by pleading infringement under the doctrine of equivalents for the ’723 patent Compl. ¶57
- Technical Questions: The infringement analysis may turn on whether Bank of America’s process for validating a "recognized, enrolled device" Compl. ¶37b is technically the same as the claimed step of "determining whether said plurality of hardware identifiers are valid... by comparing said read hardware identifiers with a list of permitted hardware identifiers" as recited in claim 1 of the ’723 patent.
- Attribution Questions: The asserted method claims involve steps performed across multiple entities: the customer's device, Bank of America's servers, and potentially third-party wallet providers or merchants. This raises the question of whether Bank of America can be held liable for direct infringement as a single actor under 35 U.S.C. § 271(a) by "directing or controlling" the other actors' performance, a theory the complaint explicitly invokes by citing Akamai Technologies, Inc. v. Limelight Networks, Inc. Compl. ¶58
V. Key Claim Terms for Construction
The Term: "hardware identifier"
- Context and Importance: This term is the linchpin of the patents’ claimed security method, as it cryptographically binds a transaction to a physical device. The infringement case hinges on whether the "device-unique identifiers" and "stable hardware identifier" allegedly read by the Bank of America app Compl. ¶26 Compl. ¶30 meet this definition. Practitioners may focus on this term because its construction will determine whether technology developed for early 2000s PCs reads on modern mobile device architectures.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The claims use the general phrase "a hardware identifier from the hardware of the customer's mobile device" ’979 Patent, cl. 19 An argument could be made that this covers any identifier that is unique and persistently associated with the device hardware, regardless of how it is accessed.
- Evidence for a Narrower Interpretation: The specification provides specific, low-level examples: "unique hardware identifiers (such as serial numbers from the motherboard, the hard drives, the processor, etc.)" ’723 Patent, col. 8:14-17 This language could support an argument that the term is limited to serial numbers physically inscribed on hardware components, as opposed to identifiers assigned and managed by the operating system.
The Term: "user agreement identifier"
- Context and Importance: This identifier is a required input for creating the claimed "encrypted user code." The complaint alleges this element is met by an "encrypted customer identifier issued by Bank of America" Compl. ¶37c or an identifier for the agreement arising from enrollment (Compl. ¶45e). The dispute may focus on whether a generic account number or internal customer ID qualifies as an identifier of a "user agreement."
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification states this identifier "contains or identifies the contractual agreement between the customer and a verification entity" ’713 Patent, col. 5:21-24 This could support a reading where any token or string that the verification entity uses to look up the user's account and its associated terms of service would suffice.
- Evidence for a Narrower Interpretation: An argument could be made that the term requires a specific data string that uniquely represents the agreement itself (e.g., a hash of the agreement text or a unique agreement number), rather than a general-purpose customer account number that primarily identifies the customer.
VI. Other Allegations
Indirect Infringement
The complaint pleads both induced and contributory infringement for all three patents-in-suit. It alleges inducement by asserting Bank of America "actively and knowingly encouraged and instructed its customers" to use the accused app in an infringing manner Compl. ¶39 Compl. ¶47 Compl. ¶59 It alleges contributory infringement on the basis that Bank of America provides the mobile app, which it knows to be "specially made and adapted for use in an infringing manner" and which is not a "staple article of commerce suitable for substantial non-infringing use" Compl. ¶40 Compl. ¶48 Compl. ¶60
Willful Infringement
The complaint does not contain a formal count for willful infringement. However, the prayer for relief requests an award of enhanced damages pursuant to 35 U.S.C. § 284 and a finding that the case is exceptional, warranting attorneys' fees under § 285 Compl. ¶62.C-D These requests suggest that a theory of willful infringement, which typically requires pre-suit knowledge of the patents, may be developed during litigation.
VII. Analyst’s Conclusion: Key Questions for the Case
- Definitional Scope: A core issue will be whether the term "hardware identifier," which the patent specification illustrates with examples from early-2000s PC components like motherboard serial numbers, can be construed to cover the software-accessible, OS-managed device identifiers used in modern smartphones and mobile banking applications.
- Liability for Divided Performance: The case will likely test the boundaries of divided infringement doctrine. A central question for the court will be whether Bank of America "directs or controls" the actions of its customers, their mobile devices, and merchants to such a degree that it can be held liable as a single direct infringer for methods whose steps are performed across this distributed system.
- Technical and Functional Equivalence: An evidentiary question will be whether the accused system's functions are technically equivalent to the claimed steps. For example, does checking for a "recognized, enrolled device" perform substantially the same function, in substantially the same way, to achieve substantially the same result as the claimed step of "comparing... read hardware identifiers with a list of permitted hardware identifiers"?