DCT
2:25-cv-01063
Umbra Tech Ltd Uk v. Zscaler Inc
Key Events
Amended Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: UMBRA TECHNOLOGIES LTD. (UK) (British Virgin Islands) & UMBRA TECHNOLOGIES (US) INC. (Delaware)
- Defendant: Zscaler, Inc. (Delaware)
- Plaintiff's Counsel: Devlin Law Firm LLC
- Case Identification: 2:25-cv-01063, E.D. Tex., 07/24/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Defendant Zscaler has committed acts of infringement in the district and maintains a regular and established place of business in Plano, Texas.
- Core Dispute: Plaintiff alleges that Defendant's network security and access products infringe four patents related to secure network optimization, multi-perimeter firewalls, content retrieval, and virtual network management.
- Technical Context: The lawsuit concerns technology in the software-defined wide area networking (SD-WAN) and secure access service edge (SASE) markets, which are critical for providing secure, optimized network connectivity for distributed organizations and remote users.
- Key Procedural History: The complaint notes that the lead patent, U.S. Patent No. 10,574,482, has been asserted in several other pending lawsuits against competitors including Palo Alto Networks, Fortinet, and Cisco Systems. A petition for Inter Partes Review (IPR) filed by Cisco Systems against the '482 patent was denied by the Patent Trial and Appeal Board (PTAB). Additionally, the complaint mentions that an ancestor patent to the '192 patent had its patentability upheld by the PTAB in IPR2024-00270.
Case Timeline
| Date | Event |
|---|---|
| 2014-12-08 | U.S. Patent No. 12,335,329 Priority Date |
| 2015-04-07 | U.S. Patent No. 10,574,482 Priority Date |
| 2015-04-07 | U.S. Patent No. 12,432,161 Priority Date |
| 2015-04-07 | U.S. Patent No. 12,452,192 Priority Date |
| 2019-01-28 | Plaintiff filed Response to Non-Final Office Action for '482 patent |
| 2019-08-21 | Plaintiff filed Response distinguishing prior art for '482 patent |
| 2020-02-25 | U.S. Patent No. 10,574,482 Issued |
| 2025-02-18 | Defendant Juniper Networks waived service in related litigation involving '482 patent |
| 2025-04-02 | Plaintiff filed suit against Fortinet, Inc. asserting the '482 patent |
| 2025-05-08 | Zscaler filed Response to Non-Final Office Action for its own patent application |
| 2025-06-13 | Plaintiff filed suit against Palo Alto Networks, Inc. asserting the '482 patent |
| 2025-06-17 | U.S. Patent No. 12,335,329 Issued |
| 2025-07-17 | Examiner issued Non-Final Rejection for '161 patent based on double patenting |
| 2025-07-30 | PTAB issued corrected Notice of Allowability for '192 patent |
| 2025-08-11 | Plaintiff filed Response and terminal disclaimer for '161 patent |
| 2025-08-28 | USPTO issued Notice of Allowance for '161 patent |
| 2025-09-30 | U.S. Patent No. 12,432,161 Issued |
| 2025-10-21 | U.S. Patent No. 12,452,192 Issued |
| 2026-07-24 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 10,574,482: MULTI-PERIMETER FIREWALL IN THE CLOUD (Issued Feb. 25, 2020)
The Invention Explained
- Problem Addressed: The patent describes the limitations of traditional network firewalls, which are typically placed at a single edge between a private network (like a LAN) and a public network (the Internet) '482 Patent, col. 5:61-64 This single-point architecture forces all traffic through a centralized gateway, increasing latency and creating a single point of failure, and is ill-suited for modern, distributed cloud networks '482 Patent, col. 1:55-2:8
- The Patented Solution: The invention proposes a distributed, multi-perimeter firewall system within a global virtual network (GVN) '482 Patent, abstract It uses a first perimeter firewall to perform a fast but less-thorough "stateful packet inspection" (SPI) at an ingress point, filtering out bulk attack traffic '482 Patent, col. 13:7-15 A second, independent perimeter firewall then performs a slower, more resource-intensive "deep packet inspection" (DPI) on the remaining traffic, potentially on a cloned copy, to detect more sophisticated threats '482 Patent, col. 14:49-65 '482 Patent, col. 13:37-42 This architecture is illustrated in figures like FIG. 11, which shows separate SPI and DPI firewalls operating in a cloud-based network '482 Patent, FIG. 11
- Technical Importance: This two-tiered inspection approach aims to improve the efficiency and security of network firewalls by applying the right level of inspection at the right place, conserving computational resources and reducing latency in a distributed environment Compl. ¶20
Key Claims at a Glance
- The complaint asserts independent claims 1 and 13 Compl. ¶41
- Independent Claim 1 breaks down into essential elements:
- A multi-perimeter firewall system in a cloud, part of a global virtual network.
- An egress ingress point device, a first access point server, a second access point server, and an endpoint device.
- A first perimeter firewall at the first access point server performing stateful packet inspection to prevent some traffic from passing to the second access point server.
- A second perimeter firewall at the second access point server performing deep packet inspection to prevent some traffic from passing to the endpoint device.
- The deep packet inspection is performed on a cloned copy of traffic that flows through the second perimeter firewall.
- The complaint does not explicitly reserve the right to assert dependent claims but refers to infringement of "at least one claim" Compl. ¶87
U.S. Patent No. 12,335,329: SYSTEM AND METHOD FOR CONTENT RETRIEVAL FROM REMOTE NETWORK REGIONS (Issued Jun. 17, 2025)
The Invention Explained
- Problem Addressed: The patent identifies problems with traditional methods of accessing geo-restricted content, which often rely on public proxy servers '329 Patent, col. 2:7-12 These methods are described as slow, insecure, and cumbersome, requiring users to manually reconfigure connections for each different geographic region and preventing concurrent viewing of content from multiple regions '329 Patent, col. 2:13-21 '329 Patent, col. 2:27-29
- The Patented Solution: The invention describes a content delivery network device that maintains simultaneous, secure connections to a network of trusted devices in different "target regions" '329 Patent, abstract '329 Patent, col. 4:55-67 When a client sends a secure request that includes an "indication of a desired target region," the device automatically initiates a delivery request to the correct region-specific network device on the client's behalf '329 Patent, col. 13:1-38 This allows a user to pull content from multiple regions concurrently without manual reconfiguration Compl. ¶46
- Technical Importance: This system is designed to improve the speed, security, and user experience of accessing geo-restricted content by creating an integrated, trusted network that handles regional content requests automatically Compl. ¶51
Key Claims at a Glance
- The complaint asserts independent claims 1 and 15 Compl. ¶43
- Independent Claim 1 breaks down into essential elements:
- A content delivery network device with one or more processors.
- Securely connecting to client devices and to two or more second network devices, each serving a target region.
- Receiving a secure request from a client device with an "indication of a desired target region."
- Initiating a delivery request on behalf of the client to a selected one of the second network devices that is "serving the desired target region."
- The delivery request indicates a network source from which to retrieve content.
- Accepting and addressing the delivered content back to the requesting client.
- The complaint does not explicitly reserve the right to assert dependent claims but refers to infringement of "at least one claim" Compl. ¶94
Multi-Patent Capsule: U.S. Patent No. 12,432,161
- Patent Identification: U.S. Patent No. 12,432,161, MULTI-PERIMETER FIREWALL IN THE CLOUD, issued September 30, 2025.
- Technology Synopsis: The patent addresses the limitations and high latency of traditional single-perimeter firewalls by describing a control node for a secure virtual network Compl. ¶18 Compl. ¶23 This control node dynamically determines and instantiates a variable number of virtual firewalls at a cloud location to form a first firewall perimeter, which operates in coordination with a second firewall perimeter to inspect traffic routed toward a remote endpoint '161 Patent, col. 26:34-38
- Asserted Claims: The complaint asserts at least independent claim 1 Compl. ¶41
- Accused Features: The complaint alleges that Zscaler's products, as part of a virtual overlay network, implement a multi-perimeter firewall architecture that infringes the '161 patent Compl. ¶101 Compl. ¶15
Multi-Patent Capsule: U.S. Patent No. 12,452,192
- Patent Identification: U.S. Patent No. 12,452,192, SYSTEMS AND METHODS FOR PROVIDING A GLOBAL VIRTUAL NETWORK (GVN), issued October 21, 2025.
- Technology Synopsis: The patent addresses problems in configuring and managing secure virtual overlay networks, particularly the difficulty of dynamically adjusting connections to outperform the underlying physical network Compl. ¶53 The invention describes a system with control servers that maintain a central registry of all network devices, establish secure management tunnels to each, and dynamically compute and distribute a "ranked list" of peer access point servers for each endpoint device, enabling automated and optimized tunnel configuration '192 Patent, col. 32:61-33:38
- Asserted Claims: The complaint asserts at least independent claim 1 Compl. ¶68
- Accused Features: The complaint alleges that Zscaler's products utilize a virtual network system that infringes by, among other things, using control servers to maintain a device registry and dynamically determine ranked lists of peer access point servers for endpoint devices Compl. ¶55 Compl. ¶108
III. The Accused Instrumentality
- Product Identification: The accused instrumentalities are Zscaler's network security products and services, including Zscaler Internet Access, Zscaler Private Access, Zscaler Zero Trust Branch, Zero Trust Exchange, ThreatLabz, Zscaler Advanced Threat Protection, Zscaler Cloud Sandbox, and Zscaler Cloud Firewall Compl. ¶74
- Functionality and Market Context: The complaint alleges these products form a "virtual overlay network architecture" Compl. ¶15 This architecture is accused of implementing a distributed, multi-perimeter firewall system by using a first firewall to perform stateful packet inspection and a second firewall for deep packet inspection (Compl. ¶17; Compl. ¶18; Compl. ¶19; Compl. ¶20). The system is also accused of providing secure, optimized access to content from different geographic regions by using a network of trusted devices to handle requests based on a user's desired target region Compl. ¶43 Compl. ¶44 Finally, the architecture is alleged to use control servers to dynamically manage network configuration by creating ranked lists of access point servers for endpoints Compl. ¶55 The complaint asserts that these features provide significant commercial value Compl. ¶15
IV. Analysis of Infringement Allegations
U.S. Patent No. 10,574,482 Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a multi-perimeter firewall system located in a cloud and forming part of a global virtual network | The accused Zscaler products allegedly create a "virtual overlay network" that functions as a distributed multi-perimeter firewall system. | ¶15; ¶16 | col. 11:1-7 |
| a first access point server... a second access point server... an endpoint device | The Zscaler architecture is alleged to use a coordinated arrangement of access point servers and an endpoint device to form a virtual overlay network. | ¶17; ¶25 | col. 25:63-26:2 |
| a first perimeter firewall... performs stateful packet inspection to prevent at least some traffic from passing from the first access point server to the second access point server | The complaint alleges Zscaler's system uses a first perimeter firewall at an ingress point to perform stateful packet inspection, thwarting bulk attack traffic before it consumes network bandwidth. | ¶20 | col. 13:7-15 |
| a second perimeter firewall... performs deep packet inspection to prevent at least some traffic from passing from the second access point server to the end point device | The accused system allegedly uses a second, independent perimeter firewall to perform deep packet inspection on traffic that has passed the first firewall. | ¶20 | col. 13:37-42 |
| wherein the deep packet inspection is performed on a cloned copy of traffic that flows through the second perimeter firewall | The complaint alleges the accused deep packet inspection operates on a cloned copy of traffic, functioning as a "trailing indicator" that does not impede the main traffic flow. | ¶17; ¶20 | col. 13:1-5 |
U.S. Patent No. 12,335,329 Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A content delivery network device... configured to securely connect through... to client devices, and securely communicate with each of two or more second network devices... each... serving at least one corresponding target region | The accused Zscaler products allegedly act as a content delivery network device that communicates with a network of trusted devices serving different target regions. | ¶43 | col. 4:55-67 |
| receive, from any given requesting device... a secure request for content delivery, and an indication of a desired target region | The complaint alleges the Zscaler system receives secure requests from clients that specify a desired target region for content. | ¶44 | col. 13:14-16 |
| initiate a delivery request from the content delivery network device... on behalf of the given requesting device, to a selected one of the two or more second network devices that is serving the desired target region | The accused system allegedly solves the technical problem by automatically initiating a delivery request to the device serving the client's specified target region, without manual user intervention. | ¶46 | col. 13:17-30 |
| the delivery request indicating a network source from which the selected one of the second network devices is to retrieve delivery content | The complaint alleges the accused system's delivery requests include a designation of a network source from which to retrieve content. | ¶47 | col. 13:30-33 |
| accept any respective delivery content... and address the respective delivery content back to the respective given requesting device | The accused system allegedly passes the retrieved content back through the content delivery network device to the requesting client. | ¶48 | col. 4:62-65 |
No probative visual evidence provided in complaint.
- Identified Points of Contention:
- Scope Questions ('482 Patent): A central dispute may concern whether Zscaler's architecture constitutes the specific "multi-perimeter firewall system" claimed. The defense may argue its system does not have the distinct "first perimeter firewall" and "second perimeter firewall" operating in the specific, ordered manner required by the claim (SPI first, then DPI on a "cloned copy" second). The complaint's emphasis on distinguishing prior art single-firewall modules suggests this structural arrangement will be a key battleground Compl. ¶21
- Technical Questions ('329 Patent): The infringement analysis for the '329 patent may turn on whether the accused Zscaler products "initiate a delivery request... on behalf of the given requesting device" as claimed '329 Patent, col. 13:21-25 The defense might argue its system merely relays or forwards a user's request to a conventional proxy, rather than initiating a new request to one of multiple, simultaneously-available devices based on a "target-region indication," as the complaint alleges is the patented technical solution Compl. ¶46
V. Key Claim Terms for Construction
For U.S. Patent No. 10,574,482:
- The Term: "a first perimeter firewall... and a second perimeter firewall"
- Context and Importance: The definition of these terms is critical, as the patent's asserted novelty hinges on this specific two-tiered, distributed architecture. The complaint emphasizes that this is not a generic recitation of firewalls but a "claimed distribution of two different, specifically-ordered inspection mechanisms across two independent network perimeters" Compl. ¶17 Prosecution history cited in the complaint shows the applicant distinguished prior art by arguing for a required arrangement filtering traffic across at least three components (two servers and an endpoint), suggesting the structural relationship between the firewalls is a key limitation Compl. ¶21
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: A party might argue the term should be read broadly to cover any two logically separate inspection functions in a distributed network, pointing to specification language that describes the invention as extending firewalls "into a virtual overlay network and/or cloud" '482 Patent, col. 6:4-7
- Evidence for a Narrower Interpretation: A party could argue for a narrower construction requiring two physically or logically distinct hardware or software modules, citing claim language that recites the first firewall "in communication with the first access point server" and the second firewall "in communication with the second access point server" '482 Patent, col. 25:67-26:12 The abstract also separately lists "a first firewall" and "a second firewall" as distinct components '482 Patent, abstract
For U.S. Patent No. 12,335,329:
- The Term: "initiate a delivery request... on behalf of the given requesting device"
- Context and Importance: This term is central to the dispute over whether the accused system performs the patented solution or merely conventional request relaying. The complaint argues the claimed "initiation of a delivery request" is a specific mechanism for selecting among multiple, simultaneously available region-specific devices, which is not equivalent to forwarding a request to a single, pre-configured destination Compl. ¶46 The case may turn on whether Zscaler's system is found to be "initiating" a new request or simply passing one along.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: A party could argue "initiate" should be construed broadly to cover any action that causes a request to be sent, including forwarding or relaying. They might cite general descriptions of the system retrieving content from remote servers '329 Patent, abstract
- Evidence for a Narrower Interpretation: A party would likely argue that "initiate... on behalf of" requires the device to act as a new origin for the request, not just a pass-through. They would point to claim language requiring the device to "select" the correct second network device based on the "target-region indication" '329 Patent, col. 13:25-30, suggesting an active, decision-making role beyond simple relaying, as well as specification language distinguishing the invention from prior art manual proxy configurations '329 Patent, col. 2:7-21
VI. Other Allegations
- Indirect Infringement: The complaint does not plead specific facts supporting indirect infringement for any of the four asserted patents. It makes only conclusory allegations that Zscaler infringes by "making, using, and causing to be used Zscaler systems and methods" Compl. ¶87 Compl. ¶94 Compl. ¶101 Compl. ¶108
- Willful Infringement: The complaint does not explicitly use the word "willful," but it requests an award of damages for "past infringement... and any continuing or future infringement," and also seeks a declaration that the case is "exceptional" under 35 U.S.C. § 285, which is often associated with findings of willful infringement or litigation misconduct Compl. p. 35, Prayer B Compl. p. 36, Prayer C The basis for knowledge appears to be post-suit, stemming from the filing of the complaint itself.
VII. Analyst's Conclusion: Key Questions for the Case
- A central issue will be one of claim scope and prosecution history estoppel: For the '482 patent, did the patentee, in distinguishing prior art during prosecution, limit the claims to a specific three-component architecture (first server, second server, endpoint device)? The court will need to determine if Zscaler's accused system, which the plaintiff alleges is infringing, falls within the scope of that potentially narrowed definition Compl. ¶21
- A key question will be one of technical operation: For the '329 patent, does the accused Zscaler system merely relay user requests to a pre-configured proxy, or does it perform the claimed function of "initiating a delivery request on behalf of the... device" by actively selecting from multiple, simultaneously available regional devices based on a "desired target region" indication? The outcome will likely depend on evidence showing the precise technical functionality of the accused products Compl. ¶46
- An overarching evidentiary question will concern the impact of prior litigation and PTAB decisions: How will the denial of an IPR against the '482 patent and the upholding of an ancestor to the '192 patent by the PTAB influence the court's view on validity? While not binding on the district court, these administrative findings may be presented to frame the patents as having survived scrutiny Compl. ¶66 Compl. ¶83
Analysis metadata
Loading Amended Complaint
Suggested improvements