DCT

2:24-cv-00855

QPrivacy USA LLC v. Cisco Systems Inc

Key Events
Amended Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:24-cv-00855, E.D. Tex., 02/03/2026
  • Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Defendant Cisco has a regular and established place of business in the District, including physical facilities in Richardson and Allen, authorized sales representatives, and a work-from-home policy that constitutes an aggregate network of business locations.
  • Core Dispute: Plaintiff alleges that Defendant's server and networking devices that implement Encrypted Traffic Analytics (ETA) technology infringe patents related to the dynamic management of private data during network communications.
  • Technical Context: The technology involves analyzing encrypted network traffic metadata to identify threats and manage data sharing without decrypting the content, a significant capability in an era of increasing data privacy concerns and sophisticated cyberattacks.
  • Key Procedural History: The complaint alleges that Plaintiff's CEO introduced the patented technology to Cisco representatives in a meeting on March 6, 2018. The original complaint was filed on October 21, 2024, putting Cisco on notice of the patents for the purposes of willfulness allegations. Plaintiff also states it has served Infringement Contentions on Defendant, including citations to Defendant's source code.

Case Timeline

Date Event
2017-04-09 Priority Date for '824 and '249 Patents
2018-03-06 Meeting between QPrivacy CEO and Cisco representatives
2021-08-31 U.S. Patent No. 11,106,824 Issued
2023-11-14 U.S. Patent No. 11,816,249 Issued
2024-10-21 Original Complaint Filed
2026-02-03 First Amended Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 11,106,824

  • Patent Identification: U.S. Patent No. 11,106,824, "System and Method for Dynamic Management of Private Data," issued August 31, 2021 (the "'824 Patent"). Compl. ¶21

The Invention Explained

  • Problem Addressed: The patent addresses the problem of data being "automatically (and uncontrollably) shared" from a user's device to external remote servers, often without the user's knowledge or explicit consent, creating privacy and security risks. Compl. ¶31 '824 Patent, col. 1:22-29
  • The Patented Solution: The invention describes a system that acts as a gatekeeper for data leaving a user's device. The system determines the "data type" of a packet requested by a remote server by analyzing its characteristics, checks it against a "privacy preference" list, and if the request is for a non-allowed data type, it can modify the data packet before sharing it. '824 Patent, abstract This process is performed without reading the actual content of the packet in real time, thereby preserving confidentiality while enforcing privacy rules. '824 Patent, cl. 17 The system architecture shown in Figure 4 illustrates this interaction between a server, a user's device, and the managing processor and databases. '824 Patent, Fig. 4
  • Technical Importance: This technology provides a method to enforce data sharing policies on network traffic without requiring decryption, which is computationally expensive and can break end-to-end security models. Compl. ¶31

Key Claims at a Glance

  • The complaint asserts independent claim 17. Compl. ¶34
  • The essential elements of claim 17 include:
    • A system comprising a memory, a communication data type database, a privacy preference database, a communication module, and a processor.
    • The processor is configured to instruct a remote server to determine a data type for a data packet based on its "characteristics."
    • This determination is used to check compatibility with a "list of allowed patterns of data packets for sharing."
    • Critically, "the content of the at least one data packet is not read by the remote server for continued operation by the user's device in real time."
  • The complaint reserves the right to assert additional claims. Compl. ¶29

U.S. Patent No. 11,816,249

  • Patent Identification: U.S. Patent No. 11,816,249, "System and Method for Dynamic Management of Private Data," issued November 14, 2023 (the "'249 Patent"). Compl. ¶22

The Invention Explained

  • Problem Addressed: As with the '824 Patent, the '249 Patent addresses the problem of unintentional and uncontrolled sharing of data with external remote servers during network communications. Compl. ¶49 '249 Patent, col. 1:25-28
  • The Patented Solution: The '249 Patent claims a method for managing encrypted data. The method involves a remote server that receives encrypted data packets, determines the "content" of a packet "in accordance with [its] characteristics" and without decrypting it, compares this determined content to a "preference list," and then decides whether to modify the packet before sharing the (potentially modified) communication. '249 Patent, cl. 1 The determination is performed in real time during the communication session. '249 Patent, cl. 1
  • Technical Importance: The claimed method enables the management of encrypted data flows to improve security, a capability the complaint describes as a "non-abstract improvement" to data communications technology. Compl. ¶49

Key Claims at a Glance

  • The complaint asserts independent claim 1. Compl. ¶52
  • The essential elements of claim 1 include:
    • A method comprising: receiving encrypted data packets at a remote server.
    • Determining, by the remote server, a "content" of a data packet based on its "characteristics," without decryption and in real time.
    • Storing, by the remote server, a "preference list."
    • Determining, based on a comparison of the determined content and the preference list, whether to modify the data packet.
    • If so, modifying the data packet and sharing the modified communication.
  • The complaint reserves the right to assert additional claims. Compl. ¶29

III. The Accused Instrumentality

Product Identification

The complaint identifies the Accused Products as Cisco server and networking devices, including specific series of Ethernet switches, routers, and wireless controllers, along with software that implements "Encrypted Traffic Analytics (ETA) technology." Compl. ¶3 Compl. ¶25 Key components of the ETA technology include Cisco Secure Network Analytics (formerly Stealthwatch) and Cisco Identity Services Engine (ISE). Compl. ¶24

Functionality and Market Context

  • The Accused Products are alleged to implement ETA to "monitor activity and detect malicious threats in encrypted traffic without decrypting the traffic." Compl. ¶23
  • The technology functions by collecting and analyzing network telemetry-metadata exported from Cisco's network devices. Compl. ¶24 This telemetry includes elements such as the Sequence of Packet Lengths and Times (SPLT), data from the Initial Data Packet (IDP), and TLS-specific features. Compl. ¶36 A diagram in the complaint shows how four main data elements are extracted from traffic for analysis. Compl. ¶36
  • Cisco Secure Network Analytics is alleged to use a "multi-layer machine-learning engine" to analyze this telemetry, create a baseline of normal network behavior, and detect anomalies. Compl. ¶24 Compl. ¶37 The complaint includes a diagram illustrating this process of collecting telemetry, creating a behavioral baseline, and alarming on anomalies. Compl. ¶37
  • Based on this analysis, the system can take actions to enforce security policies, which the complaint alleges includes modifying network traffic. Compl. ¶26

IV. Analysis of Infringement Allegations

'824 Patent Infringement Allegations

Claim Element (from Independent Claim 17) Alleged Infringing Functionality Complaint Citation Patent Citation
a memory; The Accused Products, such as Cisco Catalyst 9400 Series Switches, contain memory components including DRAM, Flash, and SSD storage. A product data sheet in the complaint shows these specifications. ¶39 col. 5:1-9
a communication data type database, comprising at least one communication data type corresponding to sharing of at least one data packet from the user's device; The ETA technology analyzes network telemetry to identify and classify different types of traffic (e.g., malware, policy violations), which allegedly functions as a database of communication data types. ¶37 col. 8:25-33
a privacy preference database, comprising a list of allowed types of data packets for sharing...; The Accused Products establish a "baseline of normal behavior" and use security policies to define allowed and disallowed network activity. This allegedly functions as the claimed privacy preference database. ¶37 col. 8:34-44
a communication module, to allow communication between the remote server and the at least one user's device; The Accused Products are networking devices (routers, switches) that are inherently designed to facilitate network communication. A diagram in the complaint shows telemetry flowing from routers and switches to the analytics platform. ¶37 col. 11:15-18
a processor... configured to... determine at least one data type for sharing... compatible with the list of allowed patterns... wherein the at least one data type is determined in accordance with characteristics of the communication data packet... Cisco's devices use processors and ASICs to perform analysis on traffic characteristics (e.g., SPLT, IDP) via machine learning to determine the traffic type and compare it against policies. ¶¶36-39 col. 8:46-52
and wherein the content of the at least one data packet is not read by the remote server for continued operation by the user's device in real time... Cisco's marketing materials, cited in the complaint, state that ETA analyzes encrypted traffic "without any decryption" and provides "real-time analysis." ¶¶36, 38 col. 17:40-44

'249 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
receiving, by the remote server, a communication comprising encrypted data packets; The Accused Products, operating as the "remote server," are designed to receive and process encrypted network traffic as their primary function. ¶54 col. 13:15-19
determining, by the remote server, a content of at least one data packet... in accordance with characteristics of the at least one data packet, and wherein the content... is not decrypted by the remote server, and the determination... is performed by the remote server in real time...; The ETA technology allegedly determines the nature ("content") of encrypted traffic by analyzing its characteristics (metadata such as packet size, timing, and TLS features) "without decryption" and in "real time." ¶¶54, 57 col. 17:40-44
storing, by the remote server, a preference list; The Accused Products use machine learning to "create a baseline of normal behavior" and apply security policies, which allegedly functions as the storing of a preference list against which traffic is compared. ¶55 col. 13:21-25
determining, by the remote server, based on a comparison of the determined content, whether to modify the at least one data packet, and if so, modifying the at least one data packet; Cisco Secure Network Analytics compares observed traffic behavior to the baseline and policies and can take remedial actions, such as to "quarantine the suspected host," which is alleged to constitute a modification. ¶¶26, 56 col. 13:14-18
and sharing, by the remote server, the modified communication. When the system takes an action like quarantining a host, the resulting modified state of network communication is effectively "shared" across the network. ¶56 col. 13:18-20
  • Identified Points of Contention:
    • Architectural Mapping: A potential point of dispute is whether the architecture of Cisco's ETA system, where analytics platforms and network devices may reside within the same enterprise network, aligns with the patent's description of communication "between a remote server and at least one user's device," which could be interpreted as a more traditional client-server model over the internet.
    • Definition of "Content": The infringement theory for the '249 Patent hinges on the interpretation of "determining... a content." A key question will be whether analyzing metadata characteristics (like packet size and timing) constitutes a determination of "content," or if the term is limited to the substantive payload of the packet, which the accused ETA technology does not decrypt.
    • Function of "Privacy Preference Database": For the '824 Patent, a question arises as to whether the accused system's use of security policies and a machine-learned "baseline of normal behavior" meets the claim requirement of a "privacy preference database," which the patent specification suggests may be a user-configured list of preferences for personal data.

V. Key Claim Terms for Construction

  • The Term: "remote server" (from '824 claim 17; '249 claim 1)

    • Context and Importance: The complaint alleges that components of Cisco's system, such as the Secure Network Analytics platform, function as the claimed "remote server" relative to other network devices. The viability of the infringement case depends on whether this intra-network relationship fits the patent's architectural language.
    • Evidence for a Broader Interpretation: The claims themselves do not geographically or topologically limit the location of the "remote server." The term could be argued to mean any server that is logically separate from the originating "user's device."
    • Evidence for a Narrower Interpretation: The patent's background describes communication "with external remote servers" like "social network service providers," suggesting an architecture where the server is external to the user's local network. '824 Patent, col. 1:22 '824 Patent, col. 1:39-41 The patent figures also depict a clear separation between the "server" and the "user's device." '824 Patent, Fig. 4
  • The Term: "determining... a content" [without decryption] (from '249 claim 1)

    • Context and Importance: This term is central to the novelty of the claimed method. The dispute will focus on whether analyzing metadata is sufficient to "determine a content."
    • Evidence for a Broader Interpretation: The claim specifies that the determination is made "in accordance with characteristics of the... data packet." '249 Patent, cl. 1 This language may support an interpretation where "content" refers to the inferred nature or purpose of the communication (e.g., malware command-and-control) derived from those characteristics, not just the literal payload.
    • Evidence for a Narrower Interpretation: A defendant may argue that "content" in its plain and ordinary meaning refers to the substance of the communication (the data payload). Because the accused ETA technology is advertised as not decrypting the traffic, it could be argued it cannot determine the actual "content."

VI. Other Allegations

  • Indirect Infringement: The complaint alleges induced infringement, stating that Defendant provides "user manuals and online instruction materials" that encourage and instruct customers to use the Accused Products in an infringing manner. Compl. ¶42 Compl. ¶60 It also pleads contributory infringement, alleging the products are especially made to infringe and are not staple articles of commerce. Compl. ¶43 Compl. ¶61
  • Willful Infringement: Willfulness is alleged based on both pre-suit and post-suit knowledge. Pre-suit knowledge is alleged to stem from a meeting between QPrivacy's CEO and Cisco representatives on March 6, 2018. Compl. ¶28 Post-suit knowledge is based on the filing of the original complaint on October 21, 2024. Compl. ¶46 Compl. ¶64

VII. Analyst's Conclusion: Key Questions for the Case

This case presents several critical questions for the court, revolving around claim construction and the mapping of a commercial security product onto patent claims.

  • A core issue will be one of definitional scope: can the term "content" be construed to cover the inferred nature of encrypted traffic derived from metadata analysis, as the accused products allegedly perform, or is it limited to the data payload, which is not decrypted?

  • A second key question will be one of architectural equivalence: does Cisco's integrated enterprise security architecture, where analytics platforms and network hardware operate within a single organizational network, embody the "remote server" and "user's device" structure described in the patents?

  • Finally, a central evidentiary question will be one of functional mapping: do the accused products' administrator-defined security policies and machine-learned "baselines of normal behavior" perform the role of the claimed "privacy preference database," which the patent specification suggests is a user-centric tool for managing personal data types?

Loading Amended Complaint