DCT

2:25-cv-01121

Congruent Media Resourcing LLC v. Palo Alto Networks Inc

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:25-cv-01121, E.D. Tex., 11/13/2025
  • Venue Allegations: Venue is alleged to be proper as Defendant maintains a place of business in Plano, Texas, within the Eastern District of Texas, and has allegedly committed acts of infringement in the district.
  • Core Dispute: Plaintiff alleges that Defendant's Prisma Cloud Defender, a cloud security product, infringes a patent related to methods for creating secure software applications.
  • Technical Context: The technology involves "application wrapping" or "securitization," a process for adding security features to a pre-compiled software application without modifying its original source code.
  • Key Procedural History: The complaint does not mention any prior litigation, inter partes review proceedings, or licensing history related to the patent-in-suit.

Case Timeline

Date Event
2011-10-10 '418 Patent Priority Date
2015-09-15 '418 Patent Issue Date
2019-05-29 Palo Alto Networks announces Prisma cloud security suite
2025-11-13 Complaint Filing Date

II. Technology and Patent(s)-in-Suit Analysis

  • Patent Identification: U.S. Patent No. 9,135,418 ("System and Method for Creating Secure Applications"), issued September 15, 2015 (the "'418 Patent").

The Invention Explained

  • Problem Addressed: The patent addresses the security risks associated with enterprises allowing employees to use personal mobile devices for work, a trend known as "Bring-Your-Own-Device" or BYOD Compl. ¶11 '418 Patent, col. 1:21-43 Enterprises are hesitant to put corporate data on these devices due to the risk of malware from personal applications and a general lack of control over the device's security posture Compl. ¶11 '418 Patent, col. 1:28-34
  • The Patented Solution: The invention provides a method to take a standard, non-secure "target application" and convert it into a "secure application" without needing access to the original source code '418 Patent, abstract This is achieved by "imposing one or more intercepts" on the target application, which can modify its behavior according to security policies Compl. ¶11 '418 Patent, col. 1:57-61 The modified application is then "repackaged" so that the security intercepts are "integrated" and "inseparable" from the original application, creating what the patent calls an "immutable deployable entity" Compl. ¶12 '418 Patent, col. 2:4-10
  • Technical Importance: This technology allows for the enforcement of enterprise security policies on third-party or existing applications without requiring source code modification, facilitating secure application deployment in diverse environments like BYOD Compl. ¶14

Key Claims at a Glance

  • The complaint asserts independent claim 9 Compl. ¶17
  • The essential elements of Claim 9 are:
    • Receiving a target application that is designed to interact with an operating system;
    • Configuring the target application by imposing one or more intercepts on it, converting it into a secure application that maintains its interaction with the operating system; and
    • Repackaging the secure application such that the intercepts are integrated with and inseparable from the secure application.
  • The complaint does not explicitly reserve the right to assert other claims.

III. The Accused Instrumentality

Product Identification

  • The complaint identifies the "Palo Alto Networks Prisma Cloud Defender" as the Accused Instrumentality Compl. ¶18

Functionality and Market Context

  • Prisma Cloud Defender is a component of Defendant's Prisma Cloud security suite that allegedly leverages "Runtime Application Self-Protection ('RASP')" technology Compl. ¶19 It is designed to be integrated into a target application to secure it, interacting with the host operating system at the process and kernel level Compl. ¶20
  • The complaint alleges there are two types of Defenders, "App-embedded" and "Serverless" Compl. ¶21 The deployment process for an App-embedded Defender is described as "embedding a Defender into the workloads," which "modifies the container's entrypoint" to run the Defender first Compl. ¶22 Compl. p. 15 A flowchart from Defendant's documentation is presented as evidence that this process "convert[s] a target application into a secure application" Compl. ¶21 Compl. p. 10

IV. Analysis of Infringement Allegations

'418 Patent Infringement Allegations

Claim Element (from Independent Claim 9) Alleged Infringing Functionality Complaint Citation Patent Citation
receiving a target application that is designed to interact with an operating system; The Prisma Cloud Defender receives a target application for the purpose of converting it into a secure application. The target application is designed to interact with an operating system via OS facilities like process memory, threads, and file I/O. ¶20 col. 1:47-49
configuring the target application by imposing one or more intercepts on the target application, wherein the imposition of the intercepts converts the target application into a secure application that maintains the interaction with the operating system; and The deployment of a "Defender" agent allegedly imposes intercepts on the target application, converting it into a secure application. The complaint presents a screenshot from Defendant's documentation with a box labeled "generating a secure application" to support this Compl. p. 9 The allegation states that because the Defender uses OS-specific interfaces, it maintains the application's interaction with the OS. ¶21 col. 4:40-42
repackaging the secure application such that the intercepts are integrated with the secure application and are inseparable from the secure application. The Prisma Cloud Defender allegedly secures an application by "embedding a Defender into the workloads." This process is said to modify the container's entrypoint to run the Defender first, allegedly making the security components inseparable from the application. A screenshot from Defendant's documentation explains how this "embed process modifies the container's entrypoint" Compl. p. 15 ¶22 col. 2:4-10
  • Identified Points of Contention:
    • Scope Questions: The case may turn on whether the accused "Defender" agent, which is allegedly "embedded" into a workload Compl. ¶22, qualifies as one or more "intercepts" as the term is used in the patent. The patent defines an intercept as a "replacement of an existing instruction or a new instruction that may interrupt program flow" Compl. ¶11 '418 Patent, col. 1:66-2:3 A question for the court is whether modifying a container's entrypoint constitutes "imposing... intercepts on the target application."
    • Technical Questions: A central technical question will be the meaning of "inseparable." The patent describes creating an "immutable deployable entity" where intercepts are "physically inseparable" from the original files after "repackaging" Compl. ¶12 '418 Patent, col. 2:7-10 The complaint alleges this is met by modifying a container's entrypoint Compl. p. 15 This raises the question of whether a runtime dependency enforced by a container configuration is equivalent to the physical integration described in the patent.

V. Key Claim Terms for Construction

  • The Term: "intercepts"

    • Context and Importance: This term defines the core mechanism of the invention. Whether the Defendant's "Defender" technology is found to be an "intercept" is critical to the infringement analysis.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: The specification provides a broad definition: "an actual replacement of an existing instruction or a new instruction that may interrupt program flow and conditionally return control to the program flow" '418 Patent, col. 1:66-2:3 Plaintiff may argue this functional definition covers any mechanism that alters program execution for security purposes, including the Defender's alleged operation.
      • Evidence for a Narrower Interpretation: The patent's detailed examples focus on "byte code injection" and "link injection" '418 Patent, col. 22:45-51 '418 Patent, col. 24:64-25:17 Defendant may argue the term should be construed more narrowly to cover only these specific forms of direct code modification, as opposed to the alleged modification of a container's runtime configuration.
  • The Term: "inseparable"

    • Context and Importance: This term is key to the final state of the claimed secure application and distinguishes the invention from a simple security add-on. Its construction will determine if the alleged integration of the Defender meets the claim requirement.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: Plaintiff may argue that "inseparable" should be interpreted functionally, meaning the original application cannot operate without the security component. The allegation that the Defender's deployment "modifies the container's entrypoint to run App-Embedded Defender first" supports this, as the original application will not run independently Compl. p. 15
      • Evidence for a Narrower Interpretation: The specification uses strong language, describing the result of repackaging as "physically inseparable from the original files" and an "immutable deployable entity" '418 Patent, col. 2:7-10 Defendant may argue this requires a static, permanent modification of the application's binary files, rather than a configurable runtime dependency established by a container's entrypoint.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges both induced and contributory infringement Compl. ¶23 It claims Defendant provides the Prisma Cloud Defender to customers with knowledge of infringement and provides marketing materials, videos, and instructional user guides (such as those for deploying Defenders) that encourage and instruct customers on how to perform the infringing method Compl. ¶¶23-25
  • Willful Infringement: The complaint does not contain an explicit allegation of willful infringement. However, it alleges that Defendant has knowledge of its infringement "at least as of the date of the service of the original Complaint" and continues to induce and contribute to infringement, which may form the basis for a post-filing willfulness claim Compl. ¶¶24-25

VII. Analyst's Conclusion: Key Questions for the Case

The resolution of this case will likely depend on the court's interpretation of key claim terms as they apply to modern cloud-native security technology. Two central questions emerge:

  • A core issue will be one of definitional scope: Does Palo Alto Networks' "Defender" technology, which is allegedly "embedded" in a containerized workload, constitute the "imposition of... intercepts" as that term is defined and described in the '418 Patent, which focuses on code-level injection?
  • A key evidentiary question will be one of technical implementation: Does the alleged modification of a container's "entrypoint" to run the Defender agent first render the components "inseparable" in the manner required by Claim 9? This will require a factual analysis of whether this runtime configuration achieves the "physically inseparable" and "immutable" state described in the patent's specification.
Loading Complaint