DCT
2:25-cv-01252
Athena Security LLP v. Hewlett Packard Enterprises Co
Key Events
Amended Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Athena Security, LLP (Nevada)
- Defendant: Hewlett Packard Enterprise Company (Delaware)
- Plaintiff's Counsel: Russ August & Kabat
- Case Identification: 2:25-cv-01252, E.D. Tex., 03/20/2026
- Venue Allegations: Plaintiff alleges venue is proper because Defendant has a regular and established place of business in the Eastern District of Texas, specifically citing an office in Plano, Texas.
- Core Dispute: Plaintiff alleges that Defendant's enterprise networking and security products, including the Juniper SRX Series, Aruba CX Series, and Aruba ClearPass, infringe three patents related to secure network tunneling, packet relaying, and remote network access control.
- Technical Context: The patents-in-suit relate to fundamental technologies for securing and managing enterprise-grade computer networks, a market where performance, security, and scalability are critical.
- Key Procedural History: The complaint alleges that Defendant had pre-suit knowledge of one asserted patent, U.S. Patent No. 9,369,299, because Defendant cited it in an Information Disclosure Statement (IDS) during the prosecution of its own U.S. patent in 2019. This allegation may be used to support a claim of willful infringement.
Case Timeline
| Date | Event |
|---|---|
| 2004-12-03 | U.S. Patent No. 8,250,357 Priority Date |
| 2006-08-11 | U.S. Patent No. 7,969,880 Priority Date |
| 2008-06-10 | U.S. Patent No. 9,369,299 Priority Date |
| 2011-06-28 | U.S. Patent No. 7,969,880 Issued |
| 2012-08-21 | U.S. Patent No. 8,250,357 Issued |
| 2016-06-14 | U.S. Patent No. 9,369,299 Issued |
| 2019-06-03 | Alleged date of Defendant's knowledge of the '299 Patent via IDS filing |
| 2026-03-20 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,250,357 - "Tunnel interface for securing traffic over a network"
- Patent Identification: U.S. Patent No. 8,250,357, "Tunnel interface for securing traffic over a network," issued August 21, 2012 Compl. ¶8
The Invention Explained
- Problem Addressed: The patent addresses the need for a flexible and scalable platform that allows a service provider to deliver internet and security services, such as virtual private networks (VPNs), to a plurality of customers U.S. Patent No. 8,250,357, col. 4:18-25
- The Patented Solution: The invention describes a method for delivering security services by establishing two distinct routing nodes within separate processing systems and creating a secure communication "tunnel" over an IP connection between them. Data packets are received at the first node, forwarded to a service provider router, encrypted, sent through the tunnel to the second node, decrypted, and then sent to their final destination within the second processing system U.S. Patent No. 8,250,357, abstract U.S. Patent No. 8,250,357, col. 21:20-45
- Technical Importance: This architecture allows for the logical separation and secure management of traffic for multiple customers within a shared service provider network, a key enabler for managed security services U.S. Patent No. 8,250,357, col. 1:65-67
Key Claims at a Glance
- The complaint asserts independent claim 1 Compl. ¶13
- The essential elements of independent claim 1 include:
- establishing a first routing node within a first processing system;
- establishing a second routing node within a second processing system;
- establishing an IP connection path between the two systems that connects the first routing node to service provider routers, which are in turn configured to implement a VPN to the second routing node;
- receiving data packets at the first routing node;
- forwarding the packets to a selected service provider router;
- encrypting the packets within that router;
- sending the encrypted packets to the second routing node;
- receiving the encrypted packets at the second routing node;
- decrypting the packets; and
- sending the decrypted packets to a destination in the second processing system.
- The complaint does not explicitly reserve the right to assert dependent claims.
U.S. Patent No. 7,969,880 - "Device and method for relaying packets"
- Patent Identification: U.S. Patent No. 7,969,880, "Device and method for relaying packets," issued June 28, 2011 Compl. ¶17
The Invention Explained
- Problem Addressed: In networks where communication load is distributed across multiple links (e.g., link aggregation), an imbalance can occur, leading to inefficient use of network resources U.S. Patent No. 7,969,880, col. 1:30-36
- The Patented Solution: The patent describes a network relay device that uses a "computational expression," such as a hash function, to distribute packets across multiple physical ports. The expression uses "seed information" from the packet (e.g., source and destination addresses) to calculate a result, which then determines the output port. Crucially, the device includes a "modifying module" that can change the computational expression itself, allowing the load distribution logic to be altered without changing the physical port associations U.S. Patent No. 7,969,880, abstract U.S. Patent No. 7,969,880, col. 2:1-17
- Technical Importance: This method provides a flexible way to manage and optimize traffic load balancing in high-performance network switches, allowing administrators to adapt to changing network conditions U.S. Patent No. 7,969,880, col. 2:47-51
Key Claims at a Glance
- The complaint asserts independent claim 1 Compl. ¶20
- The essential elements of independent claim 1 include:
- an interface module with physical ports to transmit and receive packets;
- a computing module to execute a computational expression using seed information (source/destination info) from a received packet;
- a destination search module that selects an output physical port from a plurality of candidate ports based on the computation's result and pre-set associations; and
- a modifying module configured to modify the computational expression without changing the associations between computation results and output ports.
- The complaint does not explicitly reserve the right to assert dependent claims.
U.S. Patent No. 9,369,299 - "Network access control system and method for devices connecting to network using remote access control methods"
- Multi-Patent Capsule
- Patent Identification: U.S. Patent No. 9,369,299, "Network access control system and method for devices connecting to network using remote access control methods," issued June 14, 2016 Compl. ¶24
- Technology Synopsis: The patent describes a method for out-of-band network access control (NAC). The system authenticates a user device via a remote access device (RAD), applies a restrictive network access filter (NAF) on the RAD, and then directs the user device to run an agent that checks for security compliance U.S. Patent No. 9,369,299, abstract Based on the agent's findings, the NAF can be modified to grant, maintain, or deny broader network access, all while the NAC server remains outside the primary data path U.S. Patent No. 9,369,299, col. 2:56-62
- Asserted Claims: Independent claim 11 Compl. ¶27
- Accused Features: The complaint alleges that the Aruba ClearPass product performs this out-of-band NAC method, using network switches and gateways as the RAD and the ClearPass OnGuard agent to perform compliance checks on user devices Compl. ¶25 Compl. Ex. 6, p. 2 Compl. Ex. 6, p. 28
III. The Accused Instrumentality
Product Identification
The complaint accuses the Juniper SRX Series of infringing the '357 Patent, the Aruba CX Series of infringing the '880 Patent, and Aruba ClearPass of infringing the '299 Patent Compl. ¶11 Compl. ¶18 Compl. ¶25
Functionality and Market Context
- Juniper SRX Series: These are described as "Services Gateways" for managed service providers, designed to deliver scalable and secure network-based services like VPN routing and forwarding (VRF) and multi-tenancy for enterprise customers Compl. Ex. 2, p. 2 Compl. Ex. 2, p. 4 The complaint presents a diagram of a route-based VPN topology to illustrate the accused functionality Compl. Ex. 2, p. 9 This figure shows two SRX devices communicating securely over the internet.
- Aruba CX Series: These are identified as network switches that provide access layer performance using custom ASICs Compl. Ex. 4, p. 2 The complaint alleges these switches perform load balancing using link aggregation groups (LAGs) and computational hashes based on Layer 2, 3, or 4 packet information, such as source and destination addresses Compl. Ex. 4, p. 10
- Aruba ClearPass: This is a Network Access Control (NAC) product that protects business networks by checking credentials and enforcing rules for user devices Compl. Ex. 6, p. 2 It uses protocols like RADIUS to communicate with network infrastructure (e.g., switches, gateways) to control access based on user roles, device condition, or location Compl. Ex. 6, p. 3 A diagram in the complaint illustrates the ClearPass system architecture, showing users connecting to network hardware which then communicates with the ClearPass platform for authentication and policy enforcement Compl. Ex. 6, p. 2
IV. Analysis of Infringement Allegations
U.S. Patent No. 8,250,357 Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| establishing a first routing node within a first processing system; | The Juniper SRX Series allegedly establishes a first routing node within a first processing system, such as a Services Processing Card (SPC). | ¶13; Ex. 2, p. 5 | col. 23:7-8 |
| establishing a second routing node within a second processing system; | The Juniper SRX Series allegedly establishes a second routing node within a second processing system, such as an SRX platform deployed in a separate service-provider location. | ¶13; Ex. 2, p. 7 | col. 23:9-10 |
| establishing an internet protocol (IP) connection communications path between the first processing system and the second processing system... | The accused products allegedly establish an IP connection path, such as a route-based IPsec VPN, between the first and second processing systems. | ¶13; Ex. 2, p. 10 | col. 23:11-18 |
| (ii) configuring one or more of the plurality of service provider routers to implement a virtual private network... | The accused products are allegedly configured to implement a VPN between service provider routers and the second routing node. | ¶13; Ex. 2, p. 13 | col. 23:19-22 |
| encrypting the received plurality of data packets to form encrypted packets within the selected service provider router... | The Juniper SRX Series allegedly encrypts received data packets in tunnel mode to form encrypted packets. | ¶13; Ex. 2, p. 21 | col. 23:28-33 |
| decrypting the received encrypted packets...to form decrypted packets; and | The Juniper SRX Series allegedly decrypts the received encrypted packets using security associations. | ¶13; Ex. 2, p. 31 | col. 24:1-3 |
- Identified Points of Contention:
- Scope Questions: A central question may be the interpretation of "first processing system" and "second processing system." The complaint's theory appears to map these terms to distinct hardware components (e.g., processing cards) or geographically separate devices within a service provider's network Compl. Ex. 2, p. 5 Compl. Ex. 2, p. 7 The defense may argue for a narrower construction that requires more distinct, standalone systems than what is practiced by the accused products.
- Technical Questions: The analysis will question whether the various functions described in the claim (e.g., routing, encrypting, decrypting) are performed by the specific components alleged in the complaint (e.g., "routing node," "service provider router") in the sequence required by the claim.
U.S. Patent No. 7,969,880 Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| an interface module including a plurality of physical ports for connection to lines... | The Aruba CX Series allegedly includes an interface module with physical ports for Ethernet links, configured to transmit and receive packets. | ¶20; Ex. 4, p. 2 | col. 22:20-22 |
| a computing module configured to execute a computing process with a computational expression using seed information... | The Aruba CX Series allegedly includes a computing module that executes a load-balancing calculation using a hash based on packet destination and source information. | ¶20; Ex. 4, p. 9 | col. 22:23-27 |
| a destination search module configured to...select a physical port for transmission...from a plurality of candidate ports... | The Aruba CX Series allegedly includes a search module that selects a physical port for packet transmission based on the result of the hash and associations between results and output ports. A screenshot of the "show forwarding-info" command is provided as evidence Compl. Ex. 4, p. 11 | ¶20; Ex. 4, p. 11 | col. 22:28-35 |
| a modifying module configured to modify the computational expression without modifying the associations... | The Aruba CX Series allegedly includes a modifying module that modifies the computational expression (e.g., the hash algorithm) through a command-line interface command. | ¶20; Ex. 4, p. 12 | col. 22:36-38 |
- Identified Points of Contention:
- Scope Questions: The dispute may focus on whether the accused Aruba CX switches contain structurally distinct "computing," "search," and "modifying" modules as recited in the claim. The defense could argue these functions are performed by a single, integrated processing architecture, which may not map to the claim's modular language.
- Technical Questions: A key question will be whether a user-initiated command to change a hash algorithm (e.g., "hash l2-src-dst") constitutes the claimed "modifying module configured to modify the computational expression" Compl. Ex. 4, p. 13 This raises the question of whether the claim requires an automated or dynamic modification capability versus a static, user-driven configuration change.
V. Key Claim Terms for Construction
Patent: '357 Patent
- The Term: "processing system"
- Context and Importance: Claim 1 requires a "first processing system" and a "second processing system." The infringement case hinges on whether two distinct systems exist in the accused architecture. Practitioners may focus on this term because its construction will determine if the claim reads on a single, geographically distributed service, or if it requires physically separate and independent hardware platforms.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification may describe a "processing system" in functional terms as any collection of hardware capable of executing routing and security services, which could support an argument that different service locations or even different virtualized environments on shared hardware constitute distinct systems U.S. Patent No. 8,250,357, col. 4:34-36
- Evidence for a Narrower Interpretation: The patent figures may depict the "processing systems" as physically separate boxes or chassis, which could support an argument that the term is limited to discrete hardware devices U.S. Patent No. 8,250,357, Fig. 1
Patent: '880 Patent
- The Term: "modifying module"
- Context and Importance: Claim 1 requires a "modifying module configured to modify the computational expression." The infringement allegation relies on a user command changing a hash setting. The case may turn on whether a software interface that accepts user commands meets this limitation. Practitioners may focus on this term because it addresses the level of automation and structural identity required by the claim.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification may describe the purpose of modification broadly as allowing flexibility to alleviate communication load imbalance, which could support an interpretation that any means of changing the expression, including manual configuration, is covered U.S. Patent No. 7,969,880, col. 1:30-39
- Evidence for a Narrower Interpretation: An embodiment in the detailed description might describe the modifying module as an automated component that changes the hash function in response to network monitoring, suggesting the "module" is more than a passive command-line interface U.S. Patent No. 7,969,880, col. 6:50-55
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement for all three asserted patents. The basis for these allegations is that Defendant provides the accused products to customers and encourages their normal and customary use through user manuals and online instruction materials, which allegedly instruct users to perform the infringing methods Compl. ¶12 Compl. ¶19 Compl. ¶26
- Willful Infringement: For the '357 and '880 Patents, the complaint alleges knowledge, and therefore potential willfulness, attaches from at least the filing and service of the complaint Compl. ¶12 Compl. ¶19 For the '299 Patent, the complaint alleges pre-suit knowledge dating back to at least June 3, 2019, when Defendant allegedly cited the '299 Patent in an Information Disclosure Statement (IDS) during the prosecution of its own, unrelated patent Compl. ¶26
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of architectural mapping: for the '357 Patent, can the claim terms "first processing system" and "second processing system" be construed to cover different service provider locations or virtualized systems as alleged by the Plaintiff, or does the patent require physically distinct hardware units that do not exist in the accused architecture?
- A central question for the '299 Patent will be one of pre-suit knowledge and intent: does Defendant's citation of the '299 Patent in an IDS during its own patent prosecution establish "knowledge of the patent and of infringement" sufficient to support a claim for willful infringement, or will it be characterized as a routine, non-substantive disclosure by patent counsel?
- A key technical question for the '880 Patent will be one of functional definition: does a command-line interface that allows a user to manually change a hash setting constitute a "modifying module configured to modify the computational expression," or does the claim require a more automated, structurally distinct component that actively alters the load-balancing logic?
Analysis metadata
Loading Amended Complaint
Suggested improvements