DCT
2:25-cv-01196
Stealthpath IP Inc v. Zscaler Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: StealthPath IP Inc. (Delaware)
- Defendant: Zscaler, Inc. (Delaware)
- Plaintiff's Counsel: LATHAM AND WATKINS LLP
- Case Identification: StealthPath IP Inc. v. Zscaler, Inc., 2:25-cv-01196, E.D. Tex., 12/08/2025
- Venue Allegations: Plaintiff alleges venue is proper because Defendant Zscaler has a regular and established place of business in the Eastern District of Texas and has committed acts of patent infringement in the district, including through the actions of employees at its Plano, Texas office.
- Core Dispute: Plaintiff alleges that Defendant's Zscaler Zero Trust Exchange platform and associated cybersecurity products infringe three U.S. patents related to secure network communications.
- Technical Context: The lawsuit concerns the field of "zero trust" cybersecurity, a security model that shifts defenses from static, network-based perimeters to focus on users, assets, and resources, and assumes that no user or device is trusted by default.
- Key Procedural History: The complaint notes that U.S. Patent No. 11,729,143 is a continuation of the application that issued as U.S. Patent No. 10,965,646, suggesting a shared specification and prosecution history between the two patents.
Case Timeline
| Date | Event |
|---|---|
| 2017-10-06 | Priority Date for '803, '646, '143 Patents |
| 2019-08-06 | '803 Patent Issued |
| 2021-03-30 | '646 Patent Issued |
| 2023-08-15 | '143 Patent Issued |
| 2025-12-08 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 10,374,803: Methods for Internet Communication Security
- Patent Identification: U.S. Patent No. 10,374,803, "Methods for Internet Communication Security," issued on August 6, 2019.
The Invention Explained
- Problem Addressed: The patent addresses security threats that can arise in virtualized computing environments where communications are mediated by a hypervisor (Compl. ¶17, citing '803 Patent, col. 1:31-36). Traditional security approaches are vulnerable to malware that targets applications within virtual machines either directly or by exploiting security shortcomings in the hypervisor itself '803 Patent, col. 1:36-40
- The Patented Solution: The invention describes a "network security layer resident in the hypervisor" that authenticates and authorizes incoming communications before they are transmitted to the virtualized components Compl. ¶17 '803 Patent, col. 1:45-52 This security layer intercepts network packets, decrypts a portion using a single-use key to obtain packet parameters, compares these parameters to expected values for authorization, and only then passes the authorized packet to a virtual device '803 Patent, col. 2:1-5
- Technical Importance: This approach aims to improve security in virtualized environments by creating an authorization checkpoint within the hypervisor layer, thereby preventing malware from compromising virtual machines or spreading across a network (Compl. ¶18, citing '803 Patent, col. 22:49-61).
Key Claims at a Glance
- The complaint asserts independent Claim 1 of the '803 patent Compl. ¶32
- The essential elements of Claim 1 include:
- A product for authorizing network communications in a hypervisor comprising a non-transitory computer-readable storage medium with program code.
- The program code is executable in a hypervisor to perform communication management operations.
- The operations comprise: intercepting a first network packet in the hypervisor, the packet comprising a first higher-than-OSI layer three portion.
- The operations further comprise: decrypting, with a single-use cryptographic key, at least a portion of the first higher-than-OSI layer three portion to obtain one or more first packet parameters.
- The operations further comprise: authorizing the first network packet in the hypervisor by comparing the one or more first packet parameters with one or more first expected values.
- The operations further comprise: passing the authorized first network packet to a virtual device.
- The complaint notes that additional claims of the '803 patent may be asserted Compl. ¶19
U.S. Patent No. 10,965,646: Methods For Internet Communication Security
- Patent Identification: U.S. Patent No. 10,965,646, "Methods For Internet Communication Security," issued on March 30, 2021.
The Invention Explained
- Problem Addressed: The patent recognizes that network vulnerabilities can exist due to "legacy systems and devices that might not be able to support advanced techniques for detection and remediation of malware" Compl. ¶20 This creates a need for interfaces to "immunize, or to at least limit the attendant risks of, communications between protected and unsecure networks" (Compl. ¶20, citing '646 Patent, col. 1:30-50).
- The Patented Solution: The invention describes a method of "bridging network communications between device networks sharing protected, trusted Ethernet-based communications with the large body of relatively unsecure legacy devices and networks" (Compl. ¶21, citing '646 Patent, col. 1:51-56). This involves establishing a secure pathway between devices, exchanging application identifiers to verify authorization, confirming that the data payload conforms to a pre-assigned data model, and then passing the payload through the secure pathway (Compl. ¶22, citing '646 Patent, col. 27:2-46).
- Technical Importance: The technology provides a specific solution for securely integrating legacy systems with modern, protected networks without requiring wholesale replacement of the legacy devices Compl. ¶21
Key Claims at a Glance
- The complaint asserts independent Claim 1 of the '646 patent Compl. ¶54
- The essential elements of Claim 1 include:
- A product for securing communications of a plurality of networked computing devices, comprising a non-transitory computer-readable storage medium with program code.
- The program code is executable by a processor to perform communication management operations.
- The operations comprise: receiving a first port-to-port network packet from a first computing device.
- The operations further comprise: establishing a secure communication pathway with a user-application at a second computing device, which itself comprises sending, receiving, and comparing application identifiers.
- The operations further comprise: confirming a payload of the first port-to-port network packet conforms to a data model pre-assigned to the pre-established value for the user-application.
- The operations further comprise: passing the payload to the second computing device via the secure communication pathway.
- The complaint notes that additional claims of the '646 patent may be asserted Compl. ¶23
Multi-Patent Capsule
- Patent Identification: U.S. Patent No. 11,729,143, "Methods For Internet Communication Security," issued August 15, 2023.
- Technology Synopsis: This patent, a continuation of the '646 patent, also claims techniques for securing communications between networked devices (Compl. ¶¶15; Compl. ¶21). The claimed method involves consuming a network packet to obtain its payload and destination port, confirming the payload conforms to a pre-assigned data model, forming a new packet with identification codes, and sending it to the destination via a secure pathway (Compl. ¶24, citing '143 Patent, col. 27:5-24).
- Asserted Claims: Independent Claim 1 Compl. ¶78
- Accused Features: The complaint alleges that the Zscaler Zero Trust Exchange and its components, such as the Zscaler Client Connector, perform the claimed operations (Compl. ¶¶26; Compl. ¶80).
III. The Accused Instrumentality
- Product Identification: The complaint accuses the "Zscaler Zero Trust Exchange" and its various constituent modules, including Zscaler Zero Trust SASE, Zscaler Zero Trust SD-WAN, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Zero Trust Firewall, and various Zscaler Connectors (collectively, the "Accused Products") Compl. ¶26
- Functionality and Market Context: The Accused Products are described as a "direct-to-cloud architecture" that connects users, devices, and applications through the Zscaler Zero Trust Exchange (ZTE) Compl. ¶35 The complaint alleges this architecture eliminates lateral threat movement by inspecting all traffic and applying identity-based access control policies Compl. ¶¶35-36 The complaint includes a marketing diagram describing Zscaler's platform as brokering all communications through the Zero Trust Exchange to provide security services like cyberthreat protection and data protection Compl. p. 12 The system is alleged to operate in part through virtual machines running in hypervisors like VMware vCenter or Microsoft Hyper-V Compl. ¶39 Compl. p. 14
IV. Analysis of Infringement Allegations
'803 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A product for authorizing network communications in a hypervisor...the computer-readable program code executable in a hypervisor... | The Accused Products allegedly include components, such as the Zscaler Branch Connector, that operate as a virtual machine within a "VMware vCenter or vSphere Hypervisor" to manage network communications. | ¶39 | col. 1:45-52 |
| intercepting a first network packet in the hypervisor, the first network packet comprising a first higher-than-OSI layer three portion; | Zscaler's Secure Internet and SaaS Access (ZIA) feature allegedly intercepts network traffic, including applications defined in Layer 7 of the OSI model, which is a higher-than-OSI layer three portion. | ¶40 | col. 1:59-62 |
| decrypting, with a single-use cryptographic key, at least a portion of the first higher-than-OSI layer three portion to obtain one or more first packet parameters; | The Zscaler Zero Trust Exchange is alleged to perform SSL inspection, which involves intercepting and decrypting SSL/TLS traffic between a user and a destination server. A diagram in the complaint illustrates this two-tunnel decryption and re-encryption process. Compl. p. 16 | ¶41 | col. 1:63-65 |
| authorizing the first network packet in the hypervisor, comprising: comparing the one or more first packet parameters with one or more first expected values; and | Zscaler's firewall functionality is alleged to use a series of logical operators to compare traffic parameters (e.g., users, locations, applications, source/destination IP) against policy rules to authorize or block traffic. | ¶42 | col. 2:1-3 |
| passing the authorized first network packet to a virtual device. | Once authorized, the Accused Products allegedly "Allow" network traffic to pass through the firewall to its destination, which can be a virtual device or component within Zscaler's architecture. | ¶43 | col. 2:4-5 |
'646 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| receiving a first port-to-port network packet from a first computing device; | The Accused Products allegedly receive inbound web traffic, such as an HTTPS request from a destination server, which is described as a port-to-port network packet. A diagram depicts this as step 2 in an SSL inspection process. Compl. p. 22 | ¶¶58-59 | col. 27:3-6 |
| establishing a secure communication pathway with a user-application at a second computing device...comprising: sending an application identifier...receiving...a second application identifier...and comparing the second application identifier with a pre-established value... | The complaint alleges Zscaler's SSL inspection process establishes separate SSL tunnels between Zscaler and the user's browser, and Zscaler and the destination server. This process allegedly involves sending and receiving identifiers like server and client certificates to establish a secure pathway. | ¶¶60-64 | col. 27:7-19 |
| confirming a payload of the first port-to-port network packet conforms to a data model pre-assigned to the pre-established value for the user-application; and | Zscaler's Client Connector allegedly uses an "Allowlist" of specified file paths for trusted processes. The complaint alleges this functionality confirms that the payload from a given application conforms to a data model of allowed processes. Compl. p. 28 | ¶65 | col. 27:20-24 |
| passing the payload to the second computing device via the secure communication pathway. | Once authorized, the Accused Products allegedly pass the payload to the second computing device, such as through the Zscaler Zero Trust Exchange, which is described as a "secure communication pathway." | ¶66 | col. 27:25-27 |
- Identified Points of Contention:
- Scope Questions: A central question for the '803 patent will be whether Zscaler's distributed, cloud-based "Zero Trust Exchange" architecture can be considered a "hypervisor" as that term is used in the patent. The complaint alleges some Zscaler components run on hypervisors like VMware Compl. ¶39, but the core infringement theory appears to map the entire Zscaler Exchange to the claimed "hypervisor" Compl. ¶34, which may raise a scope question for the court.
- Technical Questions: For the '646 patent, a key technical question is whether the Accused Products' SSL inspection process Compl. ¶¶57-64 performs the specific three-part sub-sequence of "establishing a secure communication pathway" recited in Claim 1, which requires sending, receiving, and comparing application identifiers. The court will need to determine if Zscaler's exchange of SSL certificates and keys is functionally and structurally equivalent to the claimed sequence.
V. Key Claim Terms for Construction
Term from '803 Patent: "hypervisor"
- The Term: "hypervisor"
- Context and Importance: This term is critical because the asserted claim is explicitly for a "product for authorizing network communications in a hypervisor" Compl. ¶32 The infringement theory appears to equate Zscaler's cloud-native, distributed "Zero Trust Exchange" with the claimed "hypervisor". Practitioners may focus on this term because its construction could determine whether a distributed cloud service falls within the scope of a patent that the specification appears to describe in the context of virtual machines on a single host computer.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent does not appear to provide an explicit, limiting definition of "hypervisor". The term is used generally to describe a layer that mediates communications for virtual machines, which could arguably be applied to a cloud-based service that performs a similar logical function for distributed applications '803 Patent, col. 1:31-36
- Evidence for a Narrower Interpretation: The specification repeatedly discusses the hypervisor in the context of "virtual machines" and "virtualization" on a "host computer," and the provided figures depict architectures consistent with traditional on-premise virtualization (e.g., a single machine with multiple VMs) '803 Patent, FIG. 1 '803 Patent, FIG. 2 '803 Patent, col. 1:36-44 The complaint itself notes that accused components run on specific, named hypervisors like "VMware vCenter or vSphere Hypervisor" Compl. ¶39, which may suggest a narrower, more conventional meaning.
Term from '646 Patent: "establishing a secure communication pathway"
- The Term: "establishing a secure communication pathway...comprising: sending an application identifier...receiving...a second application identifier...and comparing the second application identifier with a pre-established value"
- Context and Importance: This term is a multi-step functional limitation at the heart of Claim 1. The infringement case for the '646 patent hinges on whether Zscaler's SSL inspection process, which involves exchanging certificates, meets this specific claimed sequence for "establishing" the pathway. Practitioners may focus on this term because the comparison of Zscaler's real-world security protocol against the precise sequence of steps recited in the claim will be a primary point of contention.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent describes the overall goal as bridging communications between secure and unsecure networks '646 Patent, col. 1:51-56 A party could argue that any multi-step handshake protocol that achieves this secure bridge by exchanging and verifying credentials falls within the general scope of the claim.
- Evidence for a Narrower Interpretation: The claim recites a specific sequence of "sending," "receiving," and "comparing" application identifiers '646 Patent, col. 27:10-19 A party could argue this requires a specific query-response-comparison sequence that is structurally different from a standard SSL/TLS handshake, which involves a more complex, multi-stage negotiation of ciphers, keys, and certificates. The patent's detailed description of this process will be critical for determining the required structure and order of operations.
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement for all asserted patents, stating that Zscaler provides instructions, support, and "regularly schedules webinars to instruct users regarding operation of the Accused Products" in a way that directly infringes Compl. ¶46 Compl. ¶70 Compl. ¶88 The complaint also alleges contributory infringement, stating Zscaler's products are "especially made and/or adapted for infringement" and are not staple articles of commerce Compl. ¶47 Compl. ¶71 Compl. ¶89
- Willful Infringement: Willfulness is alleged for all asserted patents based on Zscaler's purported "full knowledge of StealthPath's patent rights and full knowledge of infringement" Compl. ¶49 Compl. ¶73 Compl. ¶91 The complaint bases this knowledge on the date of service of the complaint itself, indicating a theory of post-suit willfulness Compl. ¶28
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: can the term "hypervisor", which the '803 patent describes in the context of virtual machines on a host computer, be construed to read on a distributed, cloud-native "zero trust" security platform as alleged in the complaint? The outcome of this question may significantly impact the infringement analysis for the '803 patent.
- A second central question will be one of operational equivalence: does the accused SSL inspection process, which involves a multi-stage certificate and key exchange, perform the specific sequence of "sending," "receiving," and "comparing" application identifiers required by Claim 1 of the '646 patent to establish a "secure communication pathway"? The court's analysis will likely focus on whether there is a fundamental match or mismatch in the technical operation and sequence of steps.
- A third issue concerns the relationship between patents: given that the '143 patent is a continuation of the '646 patent, the court will likely examine the shared specification and prosecution history to determine if claim limitations, particularly those construed for the '646 patent, apply with equal force to the infringement allegations against the '143 patent.
Analysis metadata
Loading Complaint
Suggested improvements