2:24-cv-00928
AttestWave LLC v. Cortado Mobile Solutions GmbH
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: AttestWave LLC (Delaware)
- Defendant: Cortado Mobile Solutions GmbH (Germany)
- Plaintiff's Counsel: Rabicoff Law LLC
- Case Identification: 2:24-cv-00928, E.D. Tex., 08/12/2026
- Venue Allegations: Plaintiff alleges venue is proper because Defendant is a foreign entity not resident in the United States and therefore may be sued in any judicial district. Plaintiff further alleges that Defendant, through its agents and alter egos, has committed acts of patent infringement within the district.
- Core Dispute: Plaintiff alleges that Defendant's mobile device management products and services infringe a patent related to methods for ensuring the trusted execution of software programs over a computer network through "secure logic interlocking."
- Technical Context: The technology at issue addresses network security by creating a verifiable link between a software program's operational behavior and a unique, unpredictable security signal it generates, allowing a network to trust the traffic from that program.
- Key Procedural History: The filing is a First Amended Complaint. The complaint alleges that the service of the original complaint provided Defendant with actual knowledge of the alleged infringement for the purposes of willfulness. The complaint also includes extensive alter ego allegations aimed at establishing jurisdiction over the German parent company through the actions of its U.S. subsidiary.
Case Timeline
| Date | Event |
|---|---|
| 2002-03-16 | '643 Patent Priority Date |
| 2002-08-14 | '643 Patent Application Date |
| 2011-02-22 | '643 Patent Issue Date |
| 2026-08-12 | First Amended Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
- Patent Identification: U.S. Patent No. 7,895,643, "Secure logic interlocking," issued February 22, 2011 (the "'643 Patent") Compl. ¶¶20-21
The Invention Explained
- Problem Addressed: The patent's background section identifies a fundamental problem in computer networks: unlike traditional telephone networks, it is difficult to ensure that software on an end-user's machine ("end station") operates according to prescribed rules Compl. ¶21 '643 Patent, col. 1:16-28 This lack of "trusted operation" makes networks vulnerable to misbehaving software, leading to problems such as denial-of-service attacks and unstable performance '643 Patent, col. 1:20-28
- The Patented Solution: The invention proposes a system to create a "trusted flow" of communications by "interlocking" different software modules into a single, combined program '643 Patent, abstract '643 Patent, col. 2:8-19 As described in the specification, one module performs an operational task (e.g., sending a data packet), while another module concurrently generates an unpredictable "security signal" '643 Patent, abstract '643 Patent, Fig. 1 A corresponding "checker" component elsewhere on the network, which shares the means to generate the same signal, can then validate the data packet. Because the modules are interlocked, the signal can only be generated correctly if the operational task is also performed correctly, thus assuring the network that the software has not been tampered with and is behaving as trusted '643 Patent, col. 2:8-19
- Technical Importance: This approach aims to create a proactive security mechanism that verifies software integrity during operation, distinguishing it from "reactive" methods like firewalls that typically act only after misbehavior is detected '643 Patent, col. 2:50-60
Key Claims at a Glance
- The complaint alleges infringement of one or more claims of the '643 Patent, referencing "Exemplary '643 Patent Claims" identified in an external exhibit that was not provided with the complaint Compl. ¶23 Compl. ¶28
- As an example, independent claim 1 is a system claim that recites:
- An integrated combination of a computer software program comprised of a software application logic module and an operation assurance logic module.
- Wherein the two modules operate as combined sub-procedures to provide combined computing functions and an integrated concurrent generation of unique security tags from the operation assurance logic module.
- Storage for the program.
- A controller for concurrent execution of the integrated combination.
- Wherein the security tags are only generated when the integrated program is executed without tampering.
- An associated operational checking logic for validating the program's execution was not tampered with, responsive to the unique security tags.
- The complaint does not explicitly reserve the right to assert dependent claims but alleges infringement of "one or more claims" Compl. ¶23
III. The Accused Instrumentality
Product Identification
- The complaint identifies the accused products as "Exemplary Defendant Products" and the "Accused Instrumentality," which appears to refer to Defendant's mobile device management (MDM) solutions, including a product named "Cortado MDM" Compl. ¶7 Compl. ¶9 Compl. ¶23 The complaint also notes that client application components are available on U.S. app storefronts Compl. ¶13
Functionality and Market Context
- The complaint provides limited detail regarding the technical functionality of the accused products. It alleges the products are "[e]ngineered for the cloud, delivered by our team in Denver, Colorado" Compl. ¶10 The complaint focuses extensively on the defendant's corporate structure, sales, and marketing activities in the United States, alleging that a German parent company (*Attestwave LLC v. Cortado Mobile Solutions GmbH*) and a U.S. subsidiary (Cortado Inc.) operate as alter egos to market and sell the accused products in the U.S. Compl. ¶¶7-18
- No probative visual evidence provided in complaint.
IV. Analysis of Infringement Allegations
The complaint incorporates its infringement allegations by reference to an external exhibit (Exhibit 2) that was not provided with the complaint documents Compl. ¶¶28-29 As such, a detailed claim chart summary cannot be constructed. The general infringement theory appears to be that Defendant's MDM system, comprising client-side software on mobile devices and server-side components, practices the claimed invention. The client software would allegedly function as the "first computing element" containing the "integrated combination" of logic modules, while the server infrastructure would perform the function of the "associated operational checking logic" '643 Patent, claim 1
- Identified Points of Contention:
- Scope Questions: A central question may be whether Defendant's MDM system, which manages device policies and security, performs the specific function of assuring "proper execution of a software computer program" by validating a "trusted flow of communications" as described in the patent '643 Patent, col. 1:30-31 The court may need to determine if the patent's scope, seemingly focused on authenticating data traffic, extends to the broader context of mobile device management.
- Technical Questions: The analysis may focus on whether the security architecture of the accused products meets the "interlocking" and "integrated combination" requirements of the claims. A key point of contention could be whether the accused system's security tokens or signals are "concurrently generat[ed]" in an inseparable manner with an "application logic module," as claim 1 requires, or if they are generated by standard, separable security protocols that function independently of the primary application logic.
V. Key Claim Terms for Construction
The Term: "integrated combination of computer software program" (from claim 1)
Context and Importance: This term is foundational to the patent's "interlocking" concept. The required degree of "integration" will be critical. Practitioners may focus on this term because its construction will determine whether a standard software bundle containing separate operational and security components can infringe, or if a more complex, inseparable linkage is required.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: Parties advocating for a broader reading might argue that the plain language of the claim does not specify a particular method of integration, and thus could cover any software product where operational and security modules are designed to work together and are delivered as a single package.
- Evidence for a Narrower Interpretation: Parties advocating for a narrower reading may cite the specification's description of transforming modules into a "single logic program" via an "Obfuscator," "Program Encrypter," or "Hidden Program Generator" '643 Patent, Fig. 12A-12C '643 Patent, col. 4:25-35 This suggests that an "integrated combination" requires a specific technical transformation that makes the constituent modules inseparable, rather than merely bundling them.
The Term: "operational checking logic" (from claim 1)
Context and Importance: This term defines the function of the verifying component in the system (e.g., the server). Its construction will determine what type of validation mechanism falls within the claim scope.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: A broader interpretation could encompass any server-side logic that validates a security credential from a client, such as checking a standard digital certificate or API token, before granting access to a service.
- Evidence for a Narrower Interpretation: A narrower interpretation may be supported by specification language suggesting the checker must be a direct counterpart to the generator. For example, the patent states, "if further the checker has a copy of the pseudo-random generator...the checker concludes that the packet flow is 'trusted'" '643 Patent, col. 2:14-19 This may support an argument that the "checking logic" must be capable of independently reproducing the security signal, implying a coordinated or symmetric process beyond standard credential validation.
VI. Other Allegations
- Indirect Infringement: The complaint alleges that Defendant induces infringement by selling the accused products to customers and providing "product literature and website materials" that instruct end users on how to use the products in an infringing manner Compl. ¶¶26-27 The knowledge element is alleged to have been met upon service of the original complaint Compl. ¶27
- Willful Infringement: The complaint alleges willful infringement based on Defendant's continued infringing conduct after receiving "actual knowledge" of the '643 Patent and the infringement allegations via the service of the original complaint Compl. ¶¶25-26
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of claim scope and technical implementation: Does the security architecture of Defendant's accused MDM products embody the specific "interlocked" and "concurrent" generation of security signals as taught in the '643 Patent, or does it utilize more conventional, separable security protocols that may fall outside the scope of the claims?
- A second central question will revolve around claim construction: Can the term "integrated combination" be interpreted broadly to cover any software suite with linked security and operational functions, or is it limited by the specification's detailed examples of obfuscation and encryption to a technically inseparable program structure? The resolution of this question will likely be a primary determinant of infringement.
- A threshold procedural battle will likely concern jurisdiction: Given the extensive allegations of an alter-ego relationship between the German defendant and its U.S. subsidiary Compl. ¶¶7-18, the court's initial analysis of personal jurisdiction and corporate veil-piercing will be a critical and potentially case-dispositive early issue.