2:25-cv-01132
Congruent Media Resourcing LLC v. Cisco Systems Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Congruent Media Resourcing LLC (Texas)
- Defendant: Cisco Systems, Inc. (Delaware)
- Plaintiff's Counsel: Direction IP Law
- Case Identification: 2:25-cv-01132, E.D. Tex., 11/18/2025
- Venue Allegations: Plaintiff alleges venue is proper because Defendant maintains a regular and established place of business within the Eastern District of Texas and has allegedly committed acts of infringement in the district.
- Core Dispute: Plaintiff alleges that Defendant's Cisco Secure Application infringes a patent related to methods for creating secure software applications by modifying them without access to their source code.
- Technical Context: The technology addresses the enterprise security challenge of adding security policies and controls to compiled, off-the-shelf applications, a process often called "application wrapping" or "securitization."
- Key Procedural History: The complaint does not mention any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the patent-in-suit.
Case Timeline
| Date | Event |
|---|---|
| 2011-10-10 | U.S. Patent No. 9,135,418 Earliest Priority Date |
| 2015-09-15 | U.S. Patent No. 9,135,418 Issued |
| 2025-11-18 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,135,418 - System and Method for Creating Secure Applications
- Patent Identification: U.S. Patent No. 9,135,418, "System and Method for Creating Secure Applications," issued September 15, 2015 (the "'418 Patent").
The Invention Explained
- Problem Addressed: The patent's background section describes the security risks enterprises face when employees use personal mobile devices for work, as corporate data may be exposed to malware or other vulnerabilities from personal applications on the same device '418 Patent, col. 1:21-41
- The Patented Solution: The invention provides a method to transform a standard, non-secure application into a secure one without access to its original source code '418 Patent, abstract This is achieved by programmatically modifying the application's compiled code, binding "intercepts" to it that enforce security policies, and then "repackaging" the modified application into a new, "immutable deployable entity" '418 Patent, col. 2:4-10 An "intercept" is defined as a replacement or new instruction that can interrupt and conditionally control the program's flow '418 Patent, col. 1:66-col. 2:3
- Technical Importance: This approach allows an organization to apply its security and management policies to third-party applications, which is a key technical capability for enabling secure "Bring Your Own Device" (BYOD) environments.
Key Claims at a Glance
- The complaint asserts independent claim 9 '418 Patent, col. 41:19-32 Compl. ¶17
- The essential elements of claim 9 are:
- Receiving a target application designed to interact with an operating system.
- Configuring the target application by imposing one or more intercepts on it, converting it into a secure application that maintains its interaction with the operating system.
- Repackaging the secure application so the intercepts are integrated with and inseparable from it.
- The complaint does not explicitly reserve the right to assert other claims.
III. The Accused Instrumentality
Product Identification
- The Cisco Secure Application, which is available as a standalone product or as part of the Cisco Observability Platform Compl. ¶19
Functionality and Market Context
- The complaint alleges that the Cisco Secure Application "protects applications at runtime, detects and block attacks in real-time" by embedding security directly into an application's runtime environment Compl. ¶19 It allegedly utilizes an AppDynamics Agent and a "Bytecode Transformer" (BCI) engine to "inject interceptors" into a target application to perform application monitoring and security functions Compl. ¶21
- The product is marketed to Application and Security teams to provide visibility into runtime vulnerabilities, prioritize remediation based on business context, and create a shared context between teams Compl. ¶19
IV. Analysis of Infringement Allegations
- '418 Patent Infringement Allegations
| Claim Element (from Independent Claim 9) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| receiving a target application that is designed to interact with an operating system; | The Cisco Secure Application operates on a target application to secure it at runtime, which by nature interacts with an operating system. A provided diagram shows the AppDynamics Agent architecture receiving a target application. | ¶20 | col. 4:22-24 |
| configuring the target application by imposing one or more intercepts on the target application, wherein the imposition of the intercepts converts the target application into a secure application that maintains the interaction with the operating system; | The Cisco Secure Application allegedly uses a Bytecode Transformer (BCI) engine to "inject interceptors" into the target application. The complaint includes a screenshot from Cisco's documentation stating, "The BCI engine is used to inject interceptors." | ¶21 | col. 4:25-29 |
| and repackaging the secure application such that the intercepts are integrated with the secure application and are inseparable from the secure application. | Plaintiff alleges that the injection of interceptors creates an integrated and secure application. The complaint quotes marketing material stating the security becomes "part of the application" to support the "integrated" and "inseparable" limitations. | ¶22 | col. 4:30-32 |
- Identified Points of Contention:
- Scope Questions: A primary issue may be the construction of "repackaging." The patent's figures and description of a "repackager" creating a new "deployable entity" could suggest a static, pre-deployment modification process '418 Patent, Fig. 11 '418 Patent, col. 2:4-10 The court will need to determine if this term can be construed to cover the accused product's alleged runtime instrumentation via an agent.
- Technical Questions: The complaint's evidence for the "inseparable" limitation may become a point of contention. The allegation rests on marketing language describing the security as "part of the application" Compl. ¶22 A key factual question will be whether the injected "intercepts" are technically inseparable from the target application's code, or if the agent-based security can be disabled or detached in a way that would suggest it is not "inseparable" as required by the claim. The complaint includes a diagram illustrating the "AppDynamics Agent Architecture" which could be analyzed to determine how the agent and target application interact. Compl. ¶20, p. 9
V. Key Claim Terms for Construction
The Term: "repackaging"
Context and Importance: This term is central to the dispute, as it distinguishes between a pre-deployment modification of an application binary and a runtime modification by an agent. The definition will determine whether the accused product's architecture falls within the claim's scope.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent describes the process as occurring during a "reconstruction phase" performed by a "repackager" '418 Patent, col. 24:3-7 Plaintiff may argue this language is broad enough to cover any process that reconstructs the application's executable behavior, including runtime instrumentation.
- Evidence for a Narrower Interpretation: Figure 11 of the patent depicts a distinct "Repackager" module (1130) that produces a "Secure Application" (1135), which is then made available to a "Computing Device" (100). This may support an interpretation that "repackaging" is a discrete, offline step that creates a new, standalone application file before it is ever run on a device.
The Term: "inseparable"
Context and Importance: Tied directly to "repackaging", the meaning of "inseparable" will be critical. If the intercepts injected by the Cisco agent can be disabled or the agent detached, Defendant may argue this limitation is not met.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent states that as a result of repackaging, "the intercepts may be considered to be physically inseparable from the original files...which can result in an immutable deployable entity" '418 Patent, col. 2:6-10 Plaintiff may argue that "inseparable" should be interpreted functionally during runtime-if the application cannot run securely without the agent, they are functionally inseparable.
- Evidence for a Narrower Interpretation: The same passage's reference to "physically inseparable" and an "immutable deployable entity" '418 Patent, col. 2:6-10 provides strong evidence for a narrower construction requiring that the intercept code be permanently woven into the application's binary file, not just linked at runtime by a separate agent process.
VI. Other Allegations
- Indirect Infringement: The complaint alleges both induced and contributory infringement Compl. ¶¶23, 25 The allegations are based on Defendant providing the Accused Instrumentality along with marketing materials, videos, and user guides that allegedly instruct and encourage customers to use the product in a manner that directly infringes claim 9 Compl. ¶23
- Willful Infringement: The complaint does not plead willfulness as a separate count, but it alleges that Defendant has had knowledge of the '418 Patent and its infringement at least since the date of service of the complaint, forming a potential basis for post-filing willfulness allegations Compl. ¶¶24, 25
VII. Analyst's Conclusion: Key Questions for the Case
A core issue will be one of temporal scope in claim construction: Does the term "repackaging," which the patent illustrates as a pre-deployment creation of an "immutable deployable entity," cover the Cisco Secure Application's alleged method of injecting "intercepts" via an agent into an application at runtime?
A key evidentiary question will be one of technical implementation: Can Plaintiff provide sufficient technical evidence to demonstrate that the "intercepts" imposed by the accused agent are "inseparable" from the target application, or will discovery show that the agent and its modifications can be detached or disabled, potentially placing the accused system outside the scope of the claim?