DCT
2:25-cv-00635
Umbra Tech Ltd Uk v. Palo Alto Networks Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: UMBRA Technologies Ltd. (UK) (British Virgin Islands) & UMBRA Technologies (US) Inc. (Delaware)
- Defendant: Palo Alto Networks, Inc. (Delaware)
- Plaintiff's Counsel: Devlin Law Firm LLC
- Case Identification: 2:25-cv-00635, E.D. Tex., 06/13/2025
- Venue Allegations: Venue is alleged to be proper based on Defendant Palo Alto Networks, Inc. maintaining a regular and established place of business within the Eastern District of Texas.
- Core Dispute: Plaintiff alleges that Defendant's next-generation firewalls and software-defined wide-area networking (SD-WAN) products infringe five U.S. patents related to secure network optimization, virtual networking, and multi-perimeter firewalls.
- Technical Context: The technology relates to software-defined wide-area networking (SD-WAN) and cloud-based security, which are critical for enterprises seeking to optimize and secure network traffic to cloud applications and between geographically distributed locations.
- Key Procedural History: The complaint states that all five patents-in-suit were recently asserted against Fortinet, Inc. in the Eastern District of Texas. The '482, '687, and '328 patents were asserted against Juniper Networks, Inc. in the District of Delaware. The '482 patent was also previously asserted against VMware, Inc. (dismissed) and is currently asserted against Cisco Systems, Inc. (stayed). Notably, a petition for Inter Partes Review of the '482 patent filed by Cisco (IPR2024-00498) was denied institution by the Patent Trial and Appeal Board, a development that may be relevant to the patent's validity.
Case Timeline
| Date | Event |
|---|---|
| 2015-04-07 | Priority Date for '482, '256, '687, '328 Patents |
| 2015-12-07 | Priority Date for '105 Patent |
| 2020-02-25 | '482 Patent Issued |
| 2020-05-19 | '256 Patent Issued |
| 2022-11-15 | '105 Patent Issued |
| 2023-10-24 | '687 Patent Issued |
| 2024-12-03 | '328 Patent Issued |
| 2025-02-18 | Defendant waived service in UMBRA v. Juniper |
| 2025-04-02 | Complaint filed in UMBRA v. Fortinet |
| 2025-06-13 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 10,574,482 - "MULTI-PERIMETER FIREWALL IN THE CLOUD"
The Invention Explained
- Problem Addressed: The patent's background describes the traditional placement of a firewall at the edge between a local network (LAN) and a broader network as a limitation ʼ482 Patent, col. 5:60-65 This rigid, single-perimeter architecture is not well-suited for modern distributed and cloud-based environments Compl. ¶14
- The Patented Solution: The invention proposes a "multi-perimeter firewall" system within a cloud or virtualized network ʼ482 Patent, abstract This system involves multiple firewalls, including stateful packet inspection (SPI) and deep packet inspection (DPI) firewalls, that communicate and share threat information to cooperatively protect the network Compl. ¶14 ʼ482 Patent, col. 5:50-57 This extends the utility of firewalls beyond the traditional network edge into the cloud itself ʼ482 Patent, col. 15:45-67
- Technical Importance: This approach provided a framework for securing decentralized network architectures, such as SD-WAN, which were becoming necessary to provide efficient, low-latency access to cloud applications Compl. ¶¶11-12
Key Claims at a Glance
- The complaint asserts infringement of at least one claim, with the provided infringement chart focusing on independent claim 1 Compl. ¶29 Compl. Ex. 6
- The essential elements of Claim 1 include:
- An egress ingress point device;
- A first access point server;
- A second access point server in communication with the first;
- An endpoint device in communication with the second access point server;
- A first perimeter firewall that performs stateful packet inspection to prevent some traffic from passing from the first to the second access point server; and
- A second perimeter firewall that performs deep packet inspection to prevent some traffic from passing from the second access point server to the endpoint device.
- The complaint reserves the right to amend its analysis, which may include asserting additional claims Compl. ¶29
U.S. Patent No. 10,659,256 - "SYSTEM AND METHOD FOR VIRTUAL INTERFACES AND ADVANCED SMART ROUTING IN A GLOBAL VIRTUAL NETWORK"
The Invention Explained
- Problem Addressed: In traditional internet routing, there is often "little to no control over the routes between two points," as traffic delivery relies on the policies of various intermediary network operators Compl. ¶15 '256 Patent, col. 2:23-26 This can lead to suboptimal performance, particularly for distributed organizations.
- The Patented Solution: The patent describes a system using "virtual interfaces" (VIFs) that act as logical "hook points" for multiple network tunnels Compl. ¶15 ʼ256 Patent, abstract ʼ256 Patent, col. 7:1-6 This VIF structure allows a system to dynamically manage traffic, detect tunnel failures, create new tunnels, and switch traffic between them to optimize performance, reliability, and speed ʼ256 Patent, abstract The system can send unique data streams over multiple tunnels during low packet loss and duplicate streams during high packet loss ʼ256 Patent, col. 2:1-9
- Technical Importance: This method provides a foundation for SD-WAN technology, improving the quality of service for network connectivity over the public internet, thereby enhancing performance and user experience Compl. ¶15 ʼ256 Patent, col. 6:58-62
Key Claims at a Glance
- The complaint asserts infringement of at least one claim, with the provided infringement chart focusing on independent claim 1 Compl. ¶36 Compl. Ex. 7
- The essential elements of Claim 1 include:
- An endpoint device with a tunnel manager and a first virtual interface.
- An access point server with a tunnel listener and a second virtual interface.
- A communication path of one or more tunnels connecting the tunnel listener and manager.
- At least two active tunnels.
- The virtual interfaces providing logical access points to the tunnels.
- A process of detecting a tunnel failure, determining if another tunnel is available, dynamically creating a new tunnel if not, and switching traffic to it.
- Concurrently sending unique data streams during low packet loss and duplicate streams during high packet loss.
- The complaint reserves the right to assert additional claims Compl. ¶36
Multi-Patent Capsule: U.S. Patent No. 11,503,105 - "SYSTEM AND METHOD FOR CONTENT RETRIEVAL FROM REMOTE NETWORK REGIONS"
- Patent Identification: U.S. Patent No. 11,503,105, "SYSTEM AND METHOD FOR CONTENT RETRIEVAL FROM REMOTE NETWORK REGIONS", issued November 15, 2022.
- Technology Synopsis: The patent addresses the problem of slow speeds and low bandwidth when retrieving content from remote servers due to a lack of control over the network path Compl. ¶16 '105 Patent, col. 2:1-13 The invention enhances regional content retrieval by using a combination of smart-routing and point-to-multi-point topology to enable multiple, concurrent, and secure streams from different geographic regions '105 Patent, col. 4:46-58
- Asserted Claims: At least one claim, with Exhibit 8 focusing on independent claim 1 Compl. ¶43
- Accused Features: The complaint accuses PAN's SD-WAN systems and methods, which are allegedly used for receiving and delivering content across different geographic regions via remote access point servers Compl. ¶¶16, 42
Multi-Patent Capsule: U.S. Patent No. 11,799,687 - "SYSTEM AND METHOD FOR VIRTUAL INTERFACES AND ADVANCED SMART ROUTING IN A GLOBAL VIRTUAL NETWORK"
- Patent Identification: U.S. Patent No. 11,799,687, "SYSTEM AND METHOD FOR VIRTUAL INTERFACES AND ADVANCED SMART ROUTING IN A GLOBAL VIRTUAL NETWORK", issued October 24, 2023.
- Technology Synopsis: Belonging to the same family as the '256 Patent, this patent addresses the lack of control over internet routing paths '687 Patent, col. 2:23-26 It discloses using virtual interfaces (VIFs) as "hook points" for network tunnels, allowing for advanced routing and improved quality of service in a global virtual network (GVN) '687 Patent, col. 7:2-8
- Asserted Claims: At least one claim, with Exhibit 9 focusing on independent claim 1 Compl. ¶50
- Accused Features: The complaint targets PAN's SD-WAN products and services that allegedly use virtual interfaces for advanced routing in a global virtual network Compl. ¶¶15, 49
Multi-Patent Capsule: U.S. Patent No. 12,160,328 - "MULTI-PERIMETER FIREWALL IN THE CLOUD"
- Patent Identification: U.S. Patent No. 12,160,328, "MULTI-PERIMETER FIREWALL IN THE CLOUD", issued December 3, 2024.
- Technology Synopsis: Belonging to the same family as the '482 Patent, this patent addresses the limitations of traditional firewalls placed at the network edge '328 Patent, col. 5:62-6:05 The invention describes a multi-perimeter firewall system in a cloud or virtualized network that distributes workload and shares threat information to improve security Compl. ¶14
- Asserted Claims: At least one claim, with Exhibit 10 focusing on independent claim 10 Compl. ¶57
- Accused Features: The complaint targets PAN's systems and methods for network virtualization that allegedly implement a multi-perimeter firewall system Compl. ¶¶14, 56
III. The Accused Instrumentality
Product Identification
- The accused instrumentalities are Palo Alto Networks' systems and methods for network virtualization, including Next-Generation Firewall (NGFW) appliances (e.g., PA-Series), the PAN-OS operating system, and related SD-WAN products and services Compl. ¶¶28, 35, 42, 49, 56 Associated management and security services such as Panorama, Wildfire, and Prisma Access are also implicated Compl. Ex. 6, p. 2 Compl. Ex. 7, p. 2
Functionality and Market Context
- The accused products provide SD-WAN functionality, creating an intelligent and dynamic wide-area network over standard internet services to connect geographically distributed locations Compl. Ex. 7, p. 4 This includes features like dynamic path selection based on application performance, path health monitoring for latency and packet loss, and simplified branch onboarding through Zero Touch Provisioning Compl. Ex. 7, p. 5 Compl. Ex. 7, p. 7 The complaint highlights through marketing materials the ability of the accused products to be deployed in various architectures, including hub-and-spoke and mesh topologies Compl. Ex. 8, p. 7 A diagram from the accused product's documentation shows a "Global Interconnect" architecture connecting branches across a "Global Backbone," illustrating the product's intended use for distributed organizations Compl. Ex. 9, p. 8
- The complaint alleges that these products provide significant advantages and have substantial commercial value, and that Defendant utilizes them in its own and its customers' virtualized network architectures Compl. ¶13
IV. Analysis of Infringement Allegations
'482 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a multi-perimeter firewall system located in a cloud and forming part of a global virtual network, comprising: | The PAN Accused Instrumentalities are described as multi-perimeter firewall systems located in a cloud and forming part of a global virtual network, utilizing NGFWs and services like Wildfire. | ¶¶28-29; Ex. 6, p. 4 | col. 1:1-3 |
| an egress ingress point device; | The PAN PA-7000 Series firewalls are alleged to be the egress ingress point device, including ports for data link and packet forwarding. | Ex. 6, p. 11 | col. 5:35-40 |
| a first access point server...; | The PAN-OS operating system, running on components like the Network Processing Card (NPC) of a PA-7000 series firewall, is alleged to be the first access point server. | Ex. 6, p. 13 | col. 6:1-5 |
| a second access point server...; | The cloud-based Wildfire analysis environment is alleged to be the second access point server, which is in communication with the first access point server. | Ex. 6, p. 16 | col. 6:6-10 |
| an endpoint device...; | The endpoint device is alleged to be a PAN firewall configured with a management interface for communication with the Wildfire cloud service. | Ex. 6, p. 18 | col. 6:11-15 |
| a first perimeter firewall...performs stateful packet inspection to prevent at least some traffic from passing from the first access point server to the second access point server; | The PAN-OS packet flow is alleged to perform stateful packet inspection on the NPC (the first access point server) to prevent known threats from being passed to the Wildfire cloud (the second access point server). A flowchart from PAN's documentation is cited to show this inspection process. | Ex. 6, p. 24; Ex. 6, p. 25 | col. 6:40-50 |
| a second perimeter firewall...performs deep packet inspection to prevent at least some traffic from passing from the second access point server to the end point device, | The Wildfire cloud service (the second access point server) is alleged to perform deep packet inspection (content inspection) and prevent malicious traffic from being passed back to the endpoint device. | Ex. 6, p. 28; Ex. 6, p. 29 | col. 6:51-55 |
- Identified Points of Contention:
- Scope Questions: A primary question will be whether the combination of Defendant's on-premise NGFWs and its separate cloud-based "Wildfire" service can be considered a single "multi-perimeter firewall system" as claimed. The defense may argue these are distinct products, not a single system.
- Technical Questions: The analysis will likely focus on whether the alleged "stateful packet inspection" performed by the "first perimeter firewall" actually serves the claimed function of "prevent[ing] at least some traffic from passing...to the second access point server". The complaint maps this to a general security function, and a court may need to determine if this meets the specific functional language of the claim.
'256 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| an endpoint device comprising at least one tunnel manager and a first virtual interface; | The accused PAN "Branch" device is alleged to be the endpoint device, including a "tunnel manager" and a "first virtual interface" (the "VPN Virtual Interface"). A diagram from PAN's documentation illustrates a branch with a VPN virtual interface. | Ex. 7, p. 7 | col. 1:20-23 |
| and an access point server comprising at least one tunnel listener and a second virtual interface, | The accused PAN hub ("HQ") is alleged to be the access point server, which includes an SD-WAN interface ("second virtual interface") that functions as the "tunnel listener" to monitor tunnel status. | Ex. 7, p. 10 | col. 1:24-27 |
| the at least one tunnel listener being connected to the at least one tunnel manager via a communication path comprising one or more tunnels; | The tunnel listener (on the SD-WAN interface) is alleged to be connected to the tunnel manager via communication paths comprising tunnels such as "Cable Modem," "Fiber," and "MPLS." | Ex. 7, p. 13 | col. 7:1-6 |
| wherein at least one of the first virtual interface or the second virtual interface are configured to: detect a failure of a first tunnel...; | PAN's SD-WAN products are alleged to provide failover protection in the event of a brownout or blackout, which is presented as detecting a tunnel failure. | Ex. 7, p. 23 | col. 1:55-56 |
| determine whether another tunnel among the one or more tunnels is available in response to detecting the failure; | The accused products are alleged to use "failover protection" and choose from available links for "path selection," which is presented as determining if another tunnel is available. | Ex. 7, p. 24 | col. 1:57-59 |
| dynamically create a new tunnel...in response to determining that another tunnel is not available; | The accused products are alleged to be configured for "failover" where "the existing tunnel is torn down, and routing changes are triggered to set up a new tunnel." | Ex. 7, p. 27 | col. 1:60-63 |
| and switch traffic from the first tunnel to the new tunnel; | The system is alleged to "redirect traffic" to a new tunnel when a failover occurs. | Ex. 7, p. 28 | col. 1:64-65 |
| and wherein the at least two tunnels in the active state concurrently send duplicate streams of data...during periods of high packet loss. | PAN's documentation is cited as describing an "Error Correction Profile" that can use "Packet Duplication to duplicate application sessions from one tunnel to another" to reduce packet loss. | Ex. 7, p. 31 | col. 2:5-9 |
- Identified Points of Contention:
- Scope Questions: A central dispute will likely be the definition of "virtual interface". The complaint alleges PAN's software-defined interfaces for managing VPNs and SD-WAN tunnels meet this limitation. The defense may argue that the claimed "VIF" requires a specific structure or functionality not present in the accused products.
- Technical Questions: An evidentiary question will be how PAN's failover and error correction features actually operate. The infringement analysis will turn on whether the accused "failover protection" and "packet duplication" functions meet the specific, multi-step process recited in the claim for detecting failure, determining availability, and creating new tunnels.
V. Key Claim Terms for Construction
'482 Patent, Claim 1:
- The Term: "multi-perimeter firewall system"
- Context and Importance: This term is the central concept of the patent. Its construction will determine whether a distributed collection of security products and services, like PAN's NGFWs and its Wildfire cloud, can be considered a single infringing "system" or are merely separate, non-infringing components.
- Intrinsic Evidence for a Broader Interpretation: The specification may describe the system in functional terms, focusing on the cooperative exchange of information between firewalls, which could support reading the claim on logically connected but physically separate products ʼ482 Patent, col. 5:50-57
- Intrinsic Evidence for a Narrower Interpretation: The abstract and figures may depict the firewalls as components of a more integrated architecture, potentially within a single provider's cloud, which could support a narrower definition that excludes a combination of on-premise hardware and third-party cloud services ʼ482 Patent, Fig. 8 ʼ482 Patent, abstract
'256 Patent, Claim 1:
- The Term: "virtual interface"
- Context and Importance: The "virtual interface" is the core of the claimed invention for managing network tunnels. The infringement case depends on whether PAN's software-based SD-WAN and VPN interfaces meet the definition of the claimed "VIF". Practitioners may focus on this term because it is the "hook point" for the claimed smart routing functionality.
- Intrinsic Evidence for a Broader Interpretation: The patent describes the VIF as a "logical point of access to the one or more tunnels," language that may support a broad construction covering any software abstraction that manages tunnel connections '256 Patent, col. 1:30-36
- Intrinsic Evidence for a Narrower Interpretation: The specification also describes a VIF as a "structure" that allows for "shifting of time and resource intensive operations" '256 Patent, col. 1:20-23 This could be interpreted to require a specific architectural implementation that differs from the accused products.
VI. Other Allegations
- Indirect Infringement: The complaint does not plead separate counts for indirect infringement. However, the infringement allegations for direct infringement rely heavily on Defendant's publicly available product documentation, datasheets, and configuration guides, which allegedly instruct customers on how to configure and use the accused SD-WAN and firewall features in an infringing manner Compl. Ex. 6-10, generally These allegations could form the basis for a future claim of induced infringement.
- Willful Infringement: The complaint does not contain an explicit claim for willful infringement or a request for enhanced damages under 35 U.S.C. § 284. The prayer for relief requests a declaration of an "exceptional case" under § 285 for the purpose of attorneys' fees, but does not allege pre-suit knowledge of the patents or egregious conduct that would typically underpin a willfulness claim Compl. Prayer ¶C
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: can terms like "multi-perimeter firewall system" and "virtual interface", which are rooted in the patent's specific architectural descriptions, be construed broadly enough to read on Palo Alto Networks' allegedly infringing combination of on-premise hardware, cloud services, and software-defined management interfaces?
- A key evidentiary question will be one of functional operation: does the accused SD-WAN functionality, as described in public marketing materials, actually perform the specific, ordered steps of tunnel failure detection, availability determination, dynamic creation, and traffic switching as strictly required by claims like Claim 1 of the '256 patent, or is there a material difference in the underlying technical process?
- A central validity question, particularly for the '482 patent, will be shaped by the prior denial of IPR institution. While not preclusive, the PTAB's decision that Cisco failed to show a reasonable likelihood of prevailing may influence the district court's view of the patent's strength against invalidity challenges based on similar prior art.
Analysis metadata
Loading Complaint
Suggested improvements