2:25-cv-01201
Athena Security LLP v. Cisco Systems Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Athena Security, LLP (Nevada)
- Defendant: Cisco Systems, Inc. (Delaware)
- Plaintiff's Counsel: Russ August & Kabat
- Case Identification: 2:25-cv-01201, E.D. Tex., 12/09/2025
- Venue Allegations: Plaintiff alleges venue is proper because Defendant Cisco has regular and established places of business within the Eastern District of Texas.
- Core Dispute: Plaintiff alleges that Defendant's endpoint security products, network switches, and wireless access points infringe three patents related to secure code execution, network packet relaying, and wireless network configuration.
- Technical Context: The technologies at issue concern foundational aspects of modern enterprise IT infrastructure: endpoint cybersecurity, data center traffic management, and wireless network optimization.
- Key Procedural History: The complaint does not allege any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the asserted patents.
Case Timeline
| Date | Event |
|---|---|
| 2004-12-03 | Priority Date for U.S. Patent No. 7,698,744 |
| 2006-08-11 | Priority Date for U.S. Patent No. 7,969,880 |
| 2010-04-13 | U.S. Patent No. 7,698,744 Issued |
| 2011-06-28 | U.S. Patent No. 7,969,880 Issued |
| 2014-09-17 | Priority Date for U.S. Patent No. 10,015,791 |
| 2018-07-03 | U.S. Patent No. 10,015,791 Issued |
| 2025-12-09 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 7,698,744 - "Secure system for allowing the execution of authorized computer program code"
- Patent Identification: U.S. Patent No. 7,698,744, titled "Secure system for allowing the execution of authorized computer program code," issued on April 13, 2010 Compl. ¶9
The Invention Explained
- Problem Addressed: The patent describes the ineffectiveness of traditional signature-based antivirus software against new and varied forms of malicious code, such as viruses and spyware '744 Patent, col. 1:36-54
- The Patented Solution: The invention proposes a "multi-level proactive whitelist approach" to secure a computer system by allowing only the execution of authorized code '744 Patent, abstract A kernel-level driver intercepts requests to create processes or load code modules and authenticates them against a hierarchy of whitelists (e.g., a local cache, a local whitelist, and a remote global whitelist) before permitting execution '744 Patent, col. 2:1-11 '744 Patent, Fig. 1
- Technical Importance: This whitelisting or "default-deny" security model offered a more robust defense against novel "zero-day" threats than the traditional signature-based "default-allow" blacklist model prevalent at the time.
Key Claims at a Glance
- The complaint asserts independent claim 37 ('744 Patent, Compl. ¶13).
- The essential elements of independent claim 37 are:
- A program storage device readable by a computer system, tangibly embodying a program of instructions executable by one or more computer processors of the computer system to perform method steps for allowing authorized code to execute on the computer system comprising:
- intercepting a request to create a process associated with a code module;
- determining whether to authorize the request by causing a cryptographic hash value of the code module to be authenticated with reference to a whitelist database remote from the computer system and maintained by a trusted service provider, the remote whitelist database containing cryptographic hash values of approved code modules, which are known not to contain viruses or malicious code; and
- allowing the code module to be loaded and executed within the computer system if the cryptographic hash value matches one of the cryptographic hash values of approved code modules within the remote whitelist database.
- The complaint does not explicitly reserve the right to assert dependent claims, though this is standard practice.
U.S. Patent No. 7,969,880 - "Device and method for relaying packets"
- Patent Identification: U.S. Patent No. 7,969,880, titled "Device and method for relaying packets," issued on June 28, 2011 Compl. ¶17
The Invention Explained
- Problem Addressed: In complex networks, particularly those using link aggregation, communication "load imbalance" can occur, where some network links are over-utilized while others are under-utilized '880 Patent, col. 1:31-37 This problem can be amplified in multi-stage networks as biases from preceding devices accumulate in subsequent devices '880 Patent, col. 1:37-43
- The Patented Solution: The patent describes a network relay device (e.g., a switch) that uses a "computational expression," such as a hash function, to distribute packets across a group of physical ports. The invention includes a "modifying module" that can change this computational expression. This allows an administrator to alter the packet distribution pattern to alleviate load imbalances without reconfiguring the physical network topology or the fixed associations between computation results and output ports '880 Patent, abstract '880 Patent, col. 2:15-21
- Technical Importance: The invention provides a flexible, software-based method for dynamically tuning and balancing traffic loads in sophisticated networks, improving overall efficiency and throughput.
Key Claims at a Glance
- The complaint asserts independent claim 1 ('880 Patent, Compl. ¶21).
- The essential elements of independent claim 1 are:
- A network relay device for relaying packets, comprising:
- an interface module including a plurality of physical ports for connection to lines, and configured to transmit and receive packets through the lines;
- a computing module configured to execute a computing process with a computational expression using seed information including at least one of destination information and source information associated with a received packet;
- a destination search module configured to, based on the result of the computation and with reference to associations between computation results and output physical ports, select a physical port for transmission of the received packet...; and
- a modifying module configured to modify the computational expression without modifying the associations between computation results and output physical ports.
- The complaint does not explicitly reserve the right to assert dependent claims.
U.S. Patent No. 10,015,791 - "Wireless radio access point configuration"
- Patent Identification: U.S. Patent No. 10,015,791, titled "Wireless radio access point configuration," issued on July 3, 2018 Compl. ¶25
- Technology Synopsis: The patent addresses the problem of co-channel interference in dense wireless deployments, which is particularly acute in the 2.4 GHz band due to the limited number of non-overlapping channels '791 Patent, col. 2:14-24 The patented solution is a network architecture composed of multiple "dual concurrent" wireless access points (APs), where each AP has two radios configured to operate in the same frequency band (e.g., 5 GHz) but on different channels, arranged in a cell pattern to maximize channel utilization and minimize interference '791 Patent, abstract
- Asserted Claims: The complaint asserts independent claim 1 Compl. ¶29
- Accused Features: The complaint accuses Cisco Catalyst 9100 Access Points of infringement Compl. ¶26 Specifically, the allegations target the products' ability to operate in modes where multiple radios serve clients in the same frequency band (e.g., "dual 5-GHz mode") and to be deployed in a cellular fashion with specific channel allocation schemes Compl. Ex. 6, p. 8 Compl. Ex. 6, p. 11 The complaint provides a diagram illustrating a cellular deployment of access points with overlapping coverage areas to ensure a "Minimum of 20% Overlap" Compl. Ex. 6, p. 11
III. The Accused Instrumentality
Product Identification
The complaint identifies three categories of accused products:
- Endpoint security software: Cisco Secure Endpoint (formerly AMP for Endpoints) and Cisco Talos File Reputation (accused of infringing the '744 Patent) Compl. ¶10
- Network switches: Cisco Nexus 9000 Series (accused of infringing the '880 Patent) Compl. ¶18
- Wireless access points: Cisco Catalyst 9100 Access Points (accused of infringing the '791 Patent) Compl. ¶26
Functionality and Market Context
- The accused Cisco Secure Endpoint products provide malware protection by monitoring endpoint activity, such as file execution Compl. Ex. 2, p. 6 The products use a filter driver to intercept these events and leverage a cloud-based database (Cisco Talos) to analyze files via cryptographic hashes, determining their reputation as "good, bad or unknown" and taking protective action accordingly Compl. Ex. 2, p. 10 Compl. Ex. 2, p. 13
- The accused Cisco Nexus 9000 Series switches are high-performance data center switches that manage packet traffic. They employ load-balancing techniques such as Equal-Cost Multi-Path (ECMP) and port-channeling, which use hashing algorithms on packet header data (e.g., IP addresses, MAC addresses) to distribute traffic across multiple available links Compl. Ex. 4, p. 6 The complaint alleges these switches contain ASICs to perform this function and offer configurable load-balancing options Compl. Ex. 4, p. 5 Compl. Ex. 4, p. 8
- The accused Cisco Catalyst 9100 Access Points are enterprise-grade wireless APs that support Wi-Fi 6. The complaint highlights features like Flexible Radio Assignment (FRA), which allows the APs to operate in a "tri-radio mode" with two radios in the 5 GHz band, serving different user groups on different channels Compl. Ex. 6, p. 5 Compl. Ex. 6, p. 8 These products are designed for deployment in high-density cellular patterns Compl. Ex. 6, p. 11
IV. Analysis of Infringement Allegations
'744 Patent Infringement Allegations
| Claim Element (from Independent Claim 37) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| intercepting a request to create a process associated with a code module; | The Cisco Secure Endpoint products allegedly use a filter driver (Immunet Protect Driver) to intercept and monitor file system operations, including process execution events. | ¶13 | col. 3:9-14 |
| determining whether to authorize the request by causing a cryptographic hash value of the code module to be authenticated with reference to a whitelist database remote from the computer system... | The accused products allegedly calculate a SHA256 hash of a file and query a remote, cloud-based database (Cisco Talos File Reputation) to determine the file's disposition. | ¶13 | col. 2:19-34 |
| allowing the code module to be loaded and executed within the computer system if the cryptographic hash value matches one of the cryptographic hash values of approved code modules within the remote whitelist database. | If the remote cloud lookup returns a "clean" disposition, the accused products allegedly allow the file to execute and terminate the analysis progression. | ¶13 | col. 2:6-11 |
A flowchart in the complaint illustrates the process flow, starting with an "IMMUNET Protect Driver" detecting an I/O operation and culminating in a cloud lookup or analysis by "Tetra" Compl. Ex. 2, p. 8
Identified Points of Contention
- Scope Question: A central issue may be whether Cisco's cloud-based reputation service, which can return a disposition of "good, bad or unknown" Compl. Ex. 2, p. 10, constitutes a "whitelist database" as required by the claim. The defense may argue that a true whitelist, by definition, contains only approved items, whereas the accused system is a more general reputation or threat intelligence database.
- Technical Question: The claim requires authentication "with reference to a whitelist database... maintained by a trusted service provider." The court may need to consider whether Cisco, as the provider of the accused endpoint software, can also be the "trusted service provider" maintaining the "remote" database in the manner contemplated by the patent.
'880 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| an interface module including a plurality of physical ports... | The accused Cisco Nexus switches are modular and include line cards with numerous physical ports for network connections. | ¶21 | col. 2:1-4 |
| a computing module configured to execute a computing process with a computational expression using seed information... | The switches' ASICs allegedly execute a hashing process on packet header information (seed information) to perform load balancing. | ¶21 | col. 2:4-9 |
| a destination search module configured to... select a physical port for transmission... | The switches' NX-OS software allegedly uses the hash result to select an output link from a port channel or ECMP group. | ¶21 | col. 2:9-15 |
| a modifying module configured to modify the computational expression without modifying the associations between computation results and output physical ports. | The complaint alleges that the Nexus switches provide commands to configure the load-balancing hash algorithm (e.g., using a "universal-id" or "rotate" option), which constitutes modifying the computational expression. | ¶21 | col. 2:15-18 |
The complaint includes a diagram depicting Equal-Cost Multi-Path (ECMP) routing, showing a packet being distributed among several possible paths to the cloud Compl. Ex. 4, p. 7
Identified Points of Contention
- Scope Question: The dispute may focus on whether providing user-selectable hashing options (e.g., different algorithms or seeds) meets the limitation of "a modifying module configured to modify the computational expression." The patent describes this modification as a means to alter a "trend of bias" in traffic distribution '880 Patent, col. 2:18-21 A key question is whether the configuration options in the Cisco switches serve the same purpose and function in the same way.
- Technical Question: Claim 1 requires modifying the expression "without modifying the associations between computation results and output physical ports." The analysis will likely scrutinize whether changing the hash algorithm or its seed in the accused switches is merely a change to the "computational expression" itself, or if it also inherently "modif[ies] the associations" between the hash results and the ports, which could be a basis for a non-infringement argument.
V. Key Claim Terms for Construction
For the '744 Patent
- The Term: "whitelist database"
- Context and Importance: The infringement case for the '744 Patent hinges on whether the accused Cisco Talos File Reputation service, which provides "good, bad or unknown" dispositions, can be considered a "whitelist database." Practitioners may focus on this term because its construction could be dispositive.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification describes the global whitelist as "a list of all known approved code modules" '744 Patent, col. 8:25-27, which could be argued to encompass any database used for checking authorization, regardless of its internal structure or other possible dispositions.
- Evidence for a Narrower Interpretation: The patent's abstract describes a system for allowing "only the execution of authorized computer program code" '744 Patent, abstract This language, along with the common technical meaning of "whitelist," may support a narrower construction limited to a database containing exclusively known-good or approved items.
For the '880 Patent
- The Term: "modify the computational expression"
- Context and Importance: This term is the core of the asserted inventive concept in the '880 Patent. Whether the user-configurable hashing options in the accused Cisco switches meet this limitation will be a central point of contention.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent states that the "modifying module is configured to modify the computational expression" ('880 Patent, col. 2:15-16) and that this can be done based on "an instruction by a user" '880 Patent, col. 2:55-57 This could support an interpretation where selecting a different pre-set algorithm or seed via a command qualifies as modification.
- Evidence for a Narrower Interpretation: The specification frames the purpose of the modification as altering "the trend of bias in physical port selection" to "alleviate communication load imbalance" '880 Patent, col. 7:2-5 A narrower reading might require that the "modification" be a dynamic or responsive change aimed at this specific goal, rather than a static configuration choice.
VI. Other Allegations
Indirect Infringement
The complaint alleges inducement of infringement for all three asserted patents. The basis for these allegations is that Defendant Cisco provides "user manuals and online instruction materials on its website" that allegedly instruct customers on how to use the accused products in an infringing manner Compl. ¶12 Compl. ¶20 Compl. ¶28
Willful Infringement
Willfulness is alleged for all three patents. The complaint bases this on knowledge of infringement "at least as early as when this Complaint was filed" Compl. ¶12 Compl. ¶20 Compl. ¶28 This allegation appears to be directed at post-suit conduct, as no facts supporting pre-suit knowledge of the patents or infringement are alleged.
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: Can the term "whitelist database", rooted in a security model of permitting only known-good software, be construed to cover a modern, cloud-based threat intelligence service that provides multi-faceted dispositions like "good, bad or unknown"?
- A second central question will be one of functional operation: Does providing a user with static configuration options to select a load-balancing hash algorithm in a network switch perform the same function as the patent's claimed "modifying module," which is described as a tool to actively alter traffic distribution and "alleviate communication load imbalance"?
- A key evidentiary question will be whether the accused wireless access points are, in practice, configured by users into the specific "dual concurrent" radio architecture operating in the same frequency band and arranged in the "cell pattern" required by the claims of the '791 patent.