DCT

2:25-cv-01195

Stealthpath IP Inc v. Fortinet Inc

Key Events
Amended Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:25-cv-01195, E.D. Tex., 03/03/2026
  • Venue Allegations: Venue is alleged to be proper based on Defendant Fortinet, Inc. having regular and established places of business within the Eastern District of Texas, specifically in Frisco and Plano, and employing engineers in the district who are allegedly responsible for designing and supporting the accused technologies.
  • Core Dispute: Plaintiff alleges that Defendant's Secure SD-WAN products, including its FortiGate and FortiWiFi firewalls, infringe three U.S. patents related to "zero trust" cybersecurity and secure network communications.
  • Technical Context: The lawsuit concerns the field of network security, specifically methods for authenticating and authorizing communications within virtualized environments and between trusted and untrusted networks to prevent the spread of malware.
  • Key Procedural History: The complaint alleges that Fortinet had knowledge of the asserted patents as of December 10, 2025, the service date of the original complaint. It also alleges that on February 9, 2024, the U.S. Patent and Trademark Office cited the application that would become the '803 patent during the prosecution of a Fortinet patent, which may be used to support allegations of pre-suit knowledge.

Case Timeline

Date Event
2017-10-06 Earliest Priority Date for '803, '646, and '143 Patents
2019-08-06 U.S. Patent No. 10,374,803 Issues
2021-03-30 U.S. Patent No. 10,965,646 Issues
2023-08-15 U.S. Patent No. 11,729,143 Issues
2024-02-09 USPTO cites application for '803 patent during prosecution of a Fortinet patent
2025-12-10 Original complaint served on Fortinet
2026-03-03 First Amended Complaint filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 10,374,803 - "Methods for Internet Communication Security" (Issued August 6, 2019)

The Invention Explained

  • Problem Addressed: The patent identifies a "need to address security threats that can arise during hypervisor-mediated communications" Compl. ¶17 It notes that in such environments, malware can target virtual machines directly or through the hypervisor itself, exploiting security shortcomings like holes in memory management Compl. ¶17 '803 Patent, col. 1:34-38
  • The Patented Solution: The invention proposes a "network security layer resident in the hypervisor that authenticates and authorizes incoming communications before transmission to virtualized components" Compl. ¶17 '803 Patent, col. 1:47-51 This involves intercepting a network packet within the hypervisor, decrypting a portion of it to obtain parameters, authorizing the packet by comparing these parameters to expected values, and then passing the authorized packet to a virtual device '803 Patent, col. 2:1-5
  • Technical Importance: The technology provides a security solution specifically for virtualized environments, aiming to protect against attacks that target the hypervisor, which is a critical layer of modern computing infrastructure.

Key Claims at a Glance

  • The complaint asserts infringement of at least Claim 1 Compl. ¶32
  • Independent Claim 1 requires:
    • A product for authorizing network communications in a hypervisor, comprising a non-transitory computer-readable storage medium with computer-readable program code.
    • The program code is executable in a hypervisor to perform communication management operations.
    • The operations comprise: intercepting a first network packet in the hypervisor, the packet comprising a first higher-than-OSI layer three portion.
    • The operations further comprise: decrypting, with a single-use cryptographic key, at least a portion of the first higher-than-OSI layer three portion to obtain one or more first packet parameters.
    • The operations further comprise: authorizing the first network packet in the hypervisor by comparing the one or more first packet parameters with one or more first expected values.
    • The operations further comprise: passing the authorized first network packet to a virtual device.
  • The complaint reserves the right to assert additional claims Compl. ¶29

U.S. Patent No. 10,965,646 - "Methods For Internet Communication Security" (Issued March 30, 2021)

The Invention Explained

  • Problem Addressed: The patent addresses vulnerabilities in networks that contain legacy systems and devices which may not support advanced malware detection techniques Compl. ¶20 It describes a need for "interfaces to immunize, or to at least limit the attendant risks of, communications between protected and unsecure networks" Compl. ¶20 '646 Patent, col. 1:46-50
  • The Patented Solution: The invention claims a product that bridges communications between different networks, such as trusted Ethernet-based systems and unsecure legacy networks '646 Patent, col. 1:51-57 It secures communications by receiving a network packet, establishing a secure pathway with a user-application on another device through an identifier-exchange process, and confirming the packet's payload conforms to a pre-assigned data model before passing it along the secure pathway '646 Patent, col. 308:31-54
  • Technical Importance: This technology aims to provide a method for securely integrating older, less secure devices into a modern network without compromising the security of the overall system.

Key Claims at a Glance

  • The complaint asserts infringement of at least Claim 1 Compl. ¶54
  • Independent Claim 1 requires:
    • A product for securing communications of a plurality of networked computing devices, comprising a non-transitory computer-readable storage medium with computer-readable program code.
    • The program code is executable by a processor to perform communication management operations.
    • The operations comprise: receiving a first port-to-port network packet from a first computing device.
    • The operations further comprise: establishing a secure communication pathway with a user-application at a second computing device, which itself comprises sending an application identifier, receiving a second application identifier in response, and comparing the second identifier with a pre-established value.
    • The operations further comprise: confirming a payload of the first port-to-port network packet conforms to a data model pre-assigned to the pre-established value for the user-application.
    • The operations further comprise: passing the payload to the second computing device via the secure communication pathway.
  • The complaint reserves the right to assert additional claims Compl. ¶29

Multi-Patent Capsule: U.S. Patent No. 11,729,143

  • Patent Identification: U.S. Patent No. 11,729,143, "Methods For Internet Communication Security," issued August 15, 2023 Compl. ¶15
  • Technology Synopsis: As a continuation of the '646 patent, this invention also addresses securing communications between networked devices Compl. ¶15 It claims a product that consumes a network packet to get a payload and destination port, confirms the payload conforms to a data model pre-assigned to that port, forms a new packet containing a new payload and identification codes, and sends the new packet to security software on the destination device Compl. ¶74
  • Asserted Claims: At least Claim 1 Compl. ¶74
  • Accused Features: The complaint alleges that Fortinet's products, with their ability to "recognize network traffic generated by a large number of applications" and use "Application control sensors" to specify actions, infringe this patent Compl. ¶77

III. The Accused Instrumentality

  • Product Identification: Fortinet products supporting Secure SD-WAN, including FortiGate and FortiWiFi products (collectively, the "Accused Products") Compl. ¶26
  • Functionality and Market Context: The Accused Products are described as integrated security appliances that combine "firewalling, SD-WAN, and security in one appliance" Compl. ¶34 A key accused functionality is the virtual version, FortiGate-VM, which is alleged to be "executable in a hypervisor" and runs on platforms like Nutanix Acropolis Hypervisor (AHV) Compl. ¶¶35, 38 The complaint highlights the products' deep packet inspection capabilities, which involve intercepting encrypted traffic (like HTTPS), decrypting it for "Content scanning," and then re-encrypting it before forwarding it to its destination Compl. ¶¶36, 38, 40 A diagram from Fortinet's documentation illustrates this deep inspection process of decryption, scanning, and re-encryption Compl. p. 13 The complaint also points to the products' use of "Protocol enforcement" to manage traffic based on known protocols and ports Compl. ¶41

IV. Analysis of Infringement Allegations

'803 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
A product for authorizing network communications in a hypervisor, the product comprising a non-transitory computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code executable in a hypervisor... The Accused Products include FortiGate-VM, which is alleged to run on hypervisors like Nutanix AHV and Microsoft Hyper-V, and perform communication management operations. ¶¶34-35; ¶38 col. 2:58-62
...intercepting a first network packet in the hypervisor, the first network packet comprising a first higher-than-OSI layer three portion; The Accused Products allegedly intercept encrypted packets, such as over an HTTPS session, which comprises a higher-than-OSI layer three portion. An annotated figure shows a red arrow pointing to the interception of an "Encrypted packet" by a FortiGate appliance. (Compl. p. 12). ¶36 col. 9:10-15
...decrypting, with a single-use cryptographic key, at least a portion of the first higher-than-OSI layer three portion to obtain one or more first packet parameters; The Accused Products allegedly perform "Deep packet inspection" which includes decrypting encrypted traffic. The complaint alleges that Fortinet's documentation states that "[e]very key should only be generated for a specific single-use encrypt/decrypt purpose." ¶¶38-39 col. 9:49-55
...authorizing the first network packet in the hypervisor, comprising: comparing the one or more first packet parameters with one or more first expected values; and The Accused Products allegedly perform "Content scanning" and "Protocol enforcement" on the decrypted packet contents, which involves comparing packet parameters against expected values like allowed protocols for known ports. ¶¶40-41 col. 10:1-14
...passing the authorized first network packet to a virtual device. After authorization, the Accused Products allegedly re-encrypt and pass the packet to its destination, which the complaint alleges is a "virtual device." ¶41 col. 10:15-16
  • Identified Points of Contention:
    • Scope Questions: A central question may be whether the accused FortiGate-VM, which runs on a third-party hypervisor, performs the claimed operations "in a hypervisor" as required by the claim language. The analysis may focus on whether the claimed "network security layer resident in the hypervisor" reads on software operating as a guest virtual machine within that hypervisor.
    • Technical Questions: A technical question is whether the Accused Products use a "single-use cryptographic key" as claimed. While the complaint cites Fortinet's documentation about best practices for single-use keys Compl. ¶39, the actual implementation in the Accused Products will require factual evidence.

'646 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
A product for securing communications of a plurality of networked computing devices...the computer-readable program code executable by a processor to perform communication management operations... The Accused Products are described as security appliances for networked devices that perform communication management, as shown in a product datasheet. (Compl. p. 21). ¶56 col. 27:29-38
...receiving a first port-to-port network packet from a first computing device; The Accused Products are alleged to receive network packets from computing devices, such as an encrypted packet in an HTTPS session from a network user. ¶57 col. 28:1-3
...establishing a secure communication pathway with a user-application at a second computing device...comprising: sending an application identifier...receiving...a second application identifier...and comparing the second application identifier with a pre-established value... This is allegedly met by the TLS handshake process, where the server sends its certificate (the first "application identifier") and the client responds with its own certificate/key (the second "application identifier"), which is then verified. A diagram illustrates this typical TLS exchange. (Compl. p. 24). ¶¶58-60 col. 28:4-16
...confirming a payload of the first port-to-port network packet conforms to a data model pre-assigned to the pre-established value for the user-application; and The Accused Products allegedly perform "Port enforcement check" to confirm that the packet payload from an application conforms to a pre-assigned data model (e.g., that SSH runs on port 22). ¶61 col. 28:17-21
...passing the payload to the second computing device via the secure communication pathway. The Accused Products allegedly pass the payload to the second computing device via the established secure pathway, for example as part of their SD-WAN functionality. ¶62 col. 28:22-24
  • Identified Points of Contention:
    • Scope Questions: A key question will be whether the standard exchange of server and client certificates in a protocol like TLS constitutes the specific, multi-step process of "sending an application identifier," "receiving...a second application identifier," and "comparing" as recited in the claim. The defense may argue that the claim requires a bespoke identification process, not a standard protocol handshake.
    • Technical Questions: The complaint's theory appears to equate a server certificate with the claimed "application identifier" Compl. ¶58 The analysis may hinge on whether the technical function and content of a server certificate in a TLS handshake meet the definition of "application identifier" as understood in the context of the patent's specification.

V. Key Claim Terms for Construction

For U.S. Patent 10,374,803:

  • The Term: "in a hypervisor"
  • Context and Importance: This term is critical because it defines the location where the claimed invention operates. The complaint alleges Fortinet's virtual appliances (FortiGate-VM) are "executable in a hypervisor" Compl. ¶35, but the defense may argue that this is distinct from the claimed functionality being an integral part of the hypervisor itself, as opposed to a guest VM running on it. The patent's focus on solving security issues within the hypervisor makes this distinction central to the infringement analysis.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification discusses applicability to both Type 1 and Type 2 hypervisors '803 Patent, col. 3:39-43, which could support an interpretation that includes software running on top of a hypervisor, not just integrated within its core.
    • Evidence for a Narrower Interpretation: The background explicitly discusses a "network security layer resident in the hypervisor" '803 Patent, col. 1:49-51 and problems of malware exploiting "holes in memory management" in hypervisors '803 Patent, col. 1:36-38, suggesting the invention is intended to operate at a privileged level within the hypervisor architecture, not merely as a guest application.

For U.S. Patent 10,965,646:

  • The Term: "application identifier"
  • Context and Importance: The infringement theory hinges on mapping a standard TLS certificate exchange to the claimed steps of sending, receiving, and comparing "application identifiers" Compl. ¶¶58-60 The definition of this term will determine if a generic server/client certificate qualifies, or if the claim requires a specific, purpose-built identifier as described in the patent's embodiments.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The claims use the general term "application identifier" without specifying its format or content, which may support an argument that any unique code identifying an application, including a standard certificate, falls within its scope.
    • Evidence for a Narrower Interpretation: The detailed description provides examples of an "n-tuple" that includes an "application identifier" alongside other specific codes like user identifiers and data type identifiers, all used to form a secure communication pathway '646 Patent, col. 4:8-15 This context suggests "application identifier" may be a specific component of a proprietary security model, rather than a generic certificate.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges active inducement of infringement by Fortinet, based on providing instructions, support, and "regularly-schedule[d] webinars" that allegedly instruct customers on how to use the Accused Products in an infringing manner Compl. ¶¶44, 65 Contributory infringement is also alleged on the basis that the Accused Products are "especially made and/or adapted for infringement" and are not staple articles of commerce Compl. ¶¶45, 66
  • Willful Infringement: Willfulness allegations are based on Fortinet's alleged knowledge of the patents as of December 10, 2025, from the service of the original complaint Compl. ¶48 The complaint further alleges pre-suit knowledge of the '803 patent based on a USPTO citation during the prosecution of one of Fortinet's own patents Compl. ¶47 The complaint alleges that despite this notice, Fortinet has taken "no remedial action" Compl. ¶49

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue for the '803 patent will be one of operational locus: does Fortinet's virtual appliance, which operates as a guest virtual machine on a hypervisor, meet the claim limitation of a product performing authorization "in a hypervisor"? The case may turn on whether the patented invention is construed to require integration with the hypervisor's privileged core, or if it can read on software running in a virtualized guest environment.
  • A central question for the '646 patent will be one of protocol mapping: does a standard cryptographic handshake, such as the exchange of digital certificates in TLS, constitute the claimed multi-step process of "establishing a secure communication pathway" by exchanging "application identifiers"? The dispute may focus on whether the claim requires a bespoke identification and authorization scheme distinct from the functions inherent in standard, off-the-shelf security protocols.
  • An overarching evidentiary question will be one of functional implementation: for all asserted patents, the complaint relies heavily on marketing materials and high-level diagrams from Fortinet. A key challenge will be for the Plaintiff to prove, with technical evidence, that the accused products' internal operations perform the specific functions as recited in the claims, particularly regarding the use of "single-use" keys ('803 patent) and the comparison of payloads against "pre-assigned" data models ('646 and '143 patents).
Loading Amended Complaint