DCT

3:26-cv-01340

BenedorTSE LLC v. JPMorgan Chase Bank NA

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 3:26-cv-01340, M.D. Tenn., 09/18/2026
  • Venue Allegations: Venue is alleged to be proper in the Middle District of Tennessee because Defendant JPMorgan Chase Bank, N.A. has committed alleged acts of infringement in the district and maintains a regular and established place of business there, including numerous physical retail bank branches.
  • Core Dispute: Plaintiff alleges that Defendant’s mobile banking applications and associated authentication systems infringe three U.S. patents related to technology for securing electronic transactions over a network.
  • Technical Context: The technology at issue involves methods for authenticating users and authorizing transactions by binding a user's identity to a specific hardware device and generating encrypted, single-use codes, a key function in the mobile banking and payment security market.
  • Key Procedural History: The complaint alleges a detailed history of pre-suit knowledge by the Defendant, including a presentation of the technology to JPMorgan Chase leadership between 2006 and 2010. Crucially, it also alleges that the U.S. Patent and Trademark Office cited the parent application of the patents-in-suit as prior art against Defendant's own patent applications during prosecution, with a specific rejection noted in a December 2019 Office Action, allegedly resulting in Defendant's actual knowledge of the patents-in-suit by early 2020. This history is central to the Plaintiff's claims of willful infringement.

Case Timeline

Date Event
2000-12-01 Priority Date for '979, '713, and '723 Patents
2006-01-01 Approximate start of period Plaintiff alleges technology was introduced to JPMC's CEO
2009-11-30 Plaintiff's predecessor allegedly presented its "SecurPay" system to JPMC
2012-09-04 U.S. Patent No. 8,260,723 Issued
2013-06-11 U.S. Patent No. 8,463,713 Issued
2014-10-20 JPMC becomes a participating issuer for Apple Pay at its launch
2016-07-26 U.S. Patent No. 9,400,979 Issued
2019-12-17 JPMC opens its first Nashville-area retail branch
2019-12-20 USPTO Final Office Action in JPMC application allegedly citing Plaintiff's prior art
2020-01-01 Approximate date Plaintiff alleges JPMC gained actual knowledge of the patents-in-suit
2026-09-18 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 9,400,979 - "Transactional Security Over a Network"

  • Patent Identification: U.S. Patent No. 9,400,979, "Transactional Security Over a Network," issued July 26, 2016 (Compl. ¶22).

The Invention Explained

  • Problem Addressed: The patent family's background description details the risks of conducting e-commerce prior to the invention (Compl. ¶¶12-14). Conventional systems required customers to transmit private information (e.g., credit card numbers) to merchants and third parties, exposing that information in multiple databases vulnerable to theft ('723 Patent, col. 1:56-2:22). Existing security measures like SSL were insufficient because they did not protect data once it was decrypted on a server (Compl. ¶13).
  • The Patented Solution: The invention proposes a system where sensitive customer information is encrypted into a "customer code" and stored on the user's own device ('723 Patent, col. 2:29-32). For a transaction, this encrypted code—not the underlying sensitive data—is transmitted to a merchant, who forwards it to a verification entity (e.g., a financial institution) for decryption and authorization ('723 Patent, abstract). This process ties the transaction to a specific user device by incorporating unique hardware identifiers, providing security without exposing confidential data to the merchant (Compl. ¶20; '723 Patent, col. 7:12-18).
  • Technical Importance: The technology aimed to fill a "technological gap" by enabling secure, convenient electronic transactions that could bind a user's identity to a specific device, a foundational concept for modern mobile banking and payment systems (Compl. ¶18).

Key Claims at a Glance

The complaint asserts at least independent claim 19 (Compl. ¶61). The complaint alleges infringement of "one or more claims" (Compl. ¶60). Claim 19 recites a method with the following essential elements:

  • reading, by a processor, a hardware identifier from hardware of a computerized device;
  • determining, by said processor, whether said hardware identifier is valid;
  • based on said hardware identifier being valid, retrieving, by said processor, a user agreement identifier that identifies a user from a storage media of said computerized device;
  • creating, by said processor, an encrypted user code by encrypting said user agreement identifier and said hardware identifier;
  • transmitting, by an input and output device of said computerized device, said encrypted user code to a provider in a transaction request for a transaction authorization decision over a computer network;
  • receiving, by said input and output device, said transaction authorization decision from said provider; and
  • receiving, by said user, performance of said transaction request from said provider, based on said transaction authorization decision approving said transaction request.

U.S. Patent No. 8,463,713 - "Transactional Security Over a Network"

  • Patent Identification: U.S. Patent No. 8,463,713, "Transactional Security Over a Network," issued June 11, 2013 (Compl. ¶23).

The Invention Explained

The ’713 Patent is a member of the same patent family as the '979 Patent and shares a common written description (Compl. ¶25). The technical problem, patented solution, and importance are therefore the same as described above for the ’979 Patent.

Key Claims at a Glance

The complaint asserts at least independent claim 13 (Compl. ¶70). The complaint alleges infringement of "one or more claims" (Compl. ¶69). Claim 13 recites a method with the following essential elements:

  • receiving, into a graphic user interface of a computerized device, an entered password from a user;
  • determining, by a processor, whether said entered password is valid;
  • based on said password being valid, reading, by said processor, a hardware identifier from hardware of said computerized device;
  • determining, by said processor, whether said hardware identifier is valid;
  • based on said hardware identifier being valid, retrieving, by said processor, a user agreement identifier from a storage media, which identifies an agreement between the user and a verification entity;
  • creating, by said processor, an encrypted user code by encrypting said user agreement identifier and said hardware identifier, with each code being valid only for a single request;
  • transmitting said encrypted user code to a provider, which in turn sends it to the verification entity for an authorization decision; and
  • receiving said authorization decision from said provider.

U.S. Patent No. 8,260,723 - "Transactional Security Over a Network"

  • Patent Identification: U.S. Patent No. 8,260,723, "Transactional Security Over a Network," issued September 4, 2012 (Compl. ¶24).

Technology Synopsis

As a member of the same patent family, the '723 patent addresses the problem of insecure online transactions by proposing a method to protect a user's sensitive information (Compl. ¶25). The solution involves using a processor on the user's device to read hardware identifiers, generate a unique encrypted code based on those identifiers and other data (like a customer identifier and a transaction counter), and transmit that code for authorization without exposing the underlying credit card information (Compl. ¶78; '723 Patent, claim 1).

Asserted Claims

The complaint asserts at least method claim 1 and non-transitory computer storage medium claim 7 (Compl. ¶¶78-79; Compl. ¶81).

Accused Features

The complaint alleges infringement through the use of Chase cards provisioned to digital wallets like Apple Pay and Google Pay, or through the former Chase Pay service (Compl. ¶79). The accused features include validating a user via password or biometrics, reading device hardware identifiers, retrieving a customer identifier (payment token), incrementing a transaction counter, creating an encrypted code (cryptogram) from this data, and transmitting it to a merchant for authorization (Compl. ¶¶79.a-h).

III. The Accused Instrumentality

Product Identification

The "Accused Instrumentality" is identified as Defendant's "Chase Mobile" and "J.P. Morgan Mobile" applications, in conjunction with supporting authentication, device-trust, transaction-authorization, and payment-provisioning systems (Compl. ¶1).

Functionality and Market Context

The complaint alleges the accused applications are mobile banking platforms that enable customers to access accounts, deposit checks, transfer funds, and make payments (Compl. ¶38). The allegedly infringing functionality involves a multi-step security process where the applications:

  • Bind a customer's account to a "recognized, registered device" or "trusted device" (Compl. ¶40).
  • Read device-specific hardware identifiers from the customer's device and assemble them into a persistent device identifier and signature (Compl. ¶42).
  • Store an encrypted "customer identifier" on the device after the user accepts the relevant service agreements (Compl. ¶44).
  • Assemble the stored identifiers into an encrypted, single-use code that is transmitted to Defendant's systems to request authorization for sign-in or transactions (Compl. ¶45).
  • Enable provisioning of Chase cards to third-party digital wallets (e.g., Apple Pay), which use a similar tokenization process for purchase transactions (Compl. ¶¶49-50).

The complaint asserts that these applications are widely used, with the Chase Mobile app having over 50 million downloads from the Google Play store and Defendant reporting tens of millions of active mobile customers (Compl. ¶38; Compl. ¶51).

No probative visual evidence provided in complaint.

IV. Analysis of Infringement Allegations

'979 Infringement Allegations

Claim Element (from Independent Claim 19) Alleged Infringing Functionality Complaint Citation Patent Citation
reading, by a processor, a hardware identifier from hardware of a computerized device; The accused applications read a device-specific identifier and hardware make/model, assembling them into a persistent device identifier and fingerprint signature. ¶62.a col. 11:3-4
determining, by said processor, whether said hardware identifier is valid; Defendant's systems evaluate the transmitted device identifier to determine if the device is a recognized, trusted device for the customer before allowing access. ¶62.b col. 11:5-9
based on said hardware identifier being valid, retrieving, by said processor, a user agreement identifier that identifies a user from a storage media of said computerized device; The applications retrieve a stored, encrypted customer identifier that was created upon the customer's acceptance of Defendant's EULA and Digital Services Agreement. ¶62.c col. 11:13-17
creating, by said processor, an encrypted user code by encrypting said user agreement identifier and said hardware identifier; The applications assemble the encrypted customer identifier, device identifier, and device signature into a single encrypted sign-in or transaction request. ¶62.d col. 11:18-22
transmitting... said encrypted user code to a provider in a transaction request for a transaction authorization decision over a computer network; The applications transmit the encrypted sign-in or transaction request to Defendant's authentication and transaction-authorization systems. ¶62.e col. 11:23-28
receiving... said transaction authorization decision from said provider; The customer's device receives an authorization decision, which the application maps to an approved, denied, or step-up-required result. ¶62.f col. 12:44-48
receiving, by said user, performance of said transaction request from said provider... Upon approval, the customer receives protected access to their accounts or completion of the requested payment or transfer. ¶62.g col. 12:50-54

'713 Infringement Allegations

Claim Element (from Independent Claim 13) Alleged Infringing Functionality Complaint Citation Patent Citation
receiving, into a graphic user interface of a computerized device, an entered password from a user; The applications receive a password, passcode, or biometric credential through their graphical sign-in interface. ¶71.a col. 30:59-62
determining, by a processor, whether said entered password is valid...; The applications determine if the password is valid by matching it against the permitted password for the customer's account. ¶71.b col. 30:63-64
based on said password being valid, reading, by said processor, a hardware identifier from hardware of said computerized device; After password validation, the applications read the device-specific identifier and hardware make/model, assembling them into a persistent device identifier. ¶71.c col. 30:65-31:1
determining, by said processor, whether said hardware identifier is valid...; Defendant's systems compare the transmitted device identifier against registered trusted devices to determine validity. ¶71.d col. 31:2-5
based on said hardware identifier being valid, retrieving, by said processor, a user agreement identifier...identifying an agreement between said user and a verification entity; The applications retrieve a stored, encrypted customer identifier created upon the customer's acceptance of Defendant's Digital Services Agreement. ¶71.e col. 31:6-10
creating, by said processor, an encrypted user code by encrypting said user agreement identifier and said hardware identifier, each said encrypted code being valid only for a single request...; The applications assemble the identifiers into a single, encrypted, request-specific sign-in or transaction request that bears a per-request transaction identifier to prevent replay. ¶71.f col. 31:11-15
transmitting...said encrypted user code to a provider...said encrypted user code being sent by said provider to said verification entity for an authorization decision; The applications transmit the encrypted user code to Defendant's systems (the alleged provider), which then pass the code to the device-trust and authorization systems (the alleged verification entity). ¶71.g col. 31:16-25
receiving...said authorization decision from said provider. The customer's device receives the authorization decision from the provider. ¶71.h col. 31:26-28

Identified Points of Contention

  • Scope Questions: The infringement theory relies on mapping patent terms from the year 2000 onto modern mobile banking technology. A potential point of contention is whether a "hardware identifier" as described in the patent (e.g., a motherboard serial number) can be interpreted to read on the identifiers the complaint alleges are used, such as a "device-fingerprint signature" assembled by software or an operating-system-assigned "android_id" (Compl. ¶¶62.a, 79.c).
  • Technical Questions: Claim 19 of the '979 Patent requires "creating an encrypted user code by encrypting said user agreement identifier and said hardware identifier." The complaint alleges the accused applications "assembled the encrypted customer identifier together with the device identifier and device signature into a single encrypted sign-in or transaction request" (Compl. ¶62.d). The analysis may turn on whether "assembling" multiple components (some already encrypted) into a single encrypted payload is functionally and legally the same as "encrypting" the claimed identifiers together to create the code.

V. Key Claim Terms for Construction

"hardware identifier"

  • Context and Importance: This term appears in the independent claims of all three patents-in-suit and is fundamental to the invention's goal of tying a transaction to a specific device. The complaint alleges this term covers a "device-specific identifier," "hardware make and model," and a "device-fingerprint signature" (Compl. ¶62.a), as well as identifiers like "android_id" (Compl. ¶79.c). The construction of this term will be critical to determining whether modern, often software-accessible, device identifiers fall within the scope of claims written in an era of more direct hardware access.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification provides examples of hardware identifiers "such as serial numbers from the motherboard, the hard drives, the processor, etc." ('723 Patent, col. 7:15-18). The use of "such as" and "etc." suggests the list is not exhaustive, which may support an interpretation that includes any unique and persistent identifier associated with the device's hardware, even if accessed via the operating system.
    • Evidence for a Narrower Interpretation: The explicit examples provided are all physical, immutable serial numbers of core hardware components. This could support a narrower construction limited to identifiers fixed to the physical hardware itself, potentially excluding identifiers that are generated or assigned by software or the operating system. Claim 1 of the '723 Patent requires "reading a plurality of hardware identifiers from hardware of said electronic device," which could be argued to imply a direct reading from the component.

"user agreement identifier"

  • Context and Importance: This term, present in independent claims of the '979 and '713 patents, is a key piece of data used to create the encrypted transaction code. Claim 13 of the '713 Patent requires it to identify "an agreement between said user and a verification entity." The complaint maps this to a "stored, encrypted customer identifier created upon the customer's acceptance of JPMorgan Chase's end-user license agreement and Digital Services Agreement" (Compl. ¶62.c). Practitioners may focus on whether this "customer identifier" actually "identifies an agreement" as required, or if it is merely a user ID whose creation is conditioned on accepting an agreement.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification refers generally to "a customer agreement identifier that contains or identifies the contractual agreement" ('723 Patent, col. 5:10-13). This language may support a broad reading where any identifier that is inextricably linked to the formation of a user agreement could be considered to "identify" it.
    • Evidence for a Narrower Interpretation: The phrasing "identifies an agreement" could be construed more narrowly to require the identifier to contain or directly point to the specific terms of the agreement itself, rather than just being an arbitrary user ID. The specification discusses creating "a storable version of a consumer's encrypted individual agreement identifiers" ('723 Patent, col. 4:42-43), which could imply the identifier itself embodies or represents the agreement in a more direct way than alleged.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges both induced and contributory infringement. The inducement theory is based on allegations that Defendant, with knowledge of the patents, actively encourages and instructs customers to use the infringing functionalities through its user agreements, application onboarding flows, and support materials (Compl. ¶¶64, 73, 84). The contributory infringement theory alleges that Defendant's mobile applications and backend systems are specially adapted components that are a material part of the invention and have no substantial non-infringing use (Compl. ¶¶65, 73, 84).
  • Willful Infringement: The complaint makes detailed allegations of willful infringement based on Defendant's alleged pre-suit knowledge of the patents-in-suit. This knowledge is alleged to have been acquired through multiple channels: an introduction of the technology to Defendant's CEO between 2006-2008 (Compl. ¶29); a formal presentation in 2009 identifying the patent family (Compl. ¶¶30-31); and, most specifically, through Defendant's own patent prosecution activities, where the parent application of the patents-in-suit was cited as prior art against Defendant's own applications, allegedly providing actual knowledge by "no later than early 2020" (Compl. ¶¶32-34; Compl. ¶66).

VII. Analyst’s Conclusion: Key Questions for the Case

  • A core issue will be one of definitional scope: can patent claim terms conceived in the 2000s PC-era, such as "hardware identifier" (contemplating physical serial numbers), be construed to cover modern mobile device identifiers, such as software-assembled fingerprints or OS-provided IDs, as alleged in the complaint? The outcome of this claim construction battle will likely be determinative for infringement.
  • A second central issue will be willfulness and knowledge. The complaint presents a detailed, multi-source narrative alleging Defendant's pre-suit knowledge, focusing heavily on Defendant's interactions with the patent office regarding its own patent applications. A key question for the court will be whether this evidence is sufficient to prove that Defendant acted despite a subjective belief that it was infringing a valid patent, particularly in the period after it allegedly learned of the patents in early 2020.
  • A third question will relate to divided infringement. For transactions involving third parties like Apple Pay or the Zelle network, the court will need to analyze whether Defendant's control over the end-to-end system—via its applications, user agreements, and backend authorization—is sufficient under the Akamai standard to attribute all steps of the claimed methods to Defendant as a single direct infringer.