DCT
2:26-cv-00224
Privatetag Innovations LLC v. O'Reilly Group LLC
Key Events
Amended Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: PrivateTag Innovations LLC (Texas)
- Defendant: O'Reilly Group, LLC (Texas)
- Plaintiff's Counsel: Hill, Kertscher & Wharton, LLP; Capshaw DeRieux, LLP
- Case Identification: 2:26-cv-00224, E.D. Tex., 07/10/2026
- Venue Allegations: Plaintiff alleges venue is proper because Defendant has committed acts of infringement and maintains regular and established places of business (McDonald's restaurant locations) within the Eastern District of Texas.
- Core Dispute: Plaintiff alleges that Defendant's use of the McDonald's contactless payment system, which leverages customer iOS devices with Apple Pay, infringes four patents related to secure radio-frequency identification (RFID) and financial transaction architectures.
- Technical Context: The patents address security vulnerabilities in RFID and near-field communication (NFC) systems, a technology domain critical for enabling fast and secure contactless payments in the retail and quick-service restaurant industries.
- Key Procedural History: This Second Amended Complaint follows an original complaint filed on March 12, 2026, for which Plaintiff alleges it provided pre-suit notice. The complaint asserts that the asserted patents were allowed by the U.S. Patent and Trademark Office over prior art (specifically, "Sugiyama") that disclosed more generalized RFID encryption systems, suggesting the patents' specific technical architectures were considered novel during prosecution.
Case Timeline
| Date | Event |
|---|---|
| 2006-03-21 | Earliest Priority Date for all Patents-in-Suit |
| 2007 | McDonald's acquires NewPOS NP6 system |
| 2010-10-18 | Applicant Response during ''481' patent prosecution |
| 2011-05-31 | U.S. Patent No. 7,952,481 Issues |
| 2015-01-25 | Applicant Response during ''926' patent prosecution |
| 2015-08-11 | U.S. Patent No. 9,104,926 Issues |
| 2017-04-18 | U.S. Patent No. 9,628,466 Issues |
| 2019-11-18 | Applicant Response during ''392' patent prosecution |
| 2020-04-14 | U.S. Patent No. 10,623,392 Issues |
| 2026-03-12 | Original Complaint Filed |
| 2026-03-27 | Original Complaint Served on Defendant |
| 2026-07-10 | Second Amended Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 7,952,481 - "Systems and Methods for RFID Security"
Issued May 31, 2011
The Invention Explained
- Problem Addressed: The patent's background describes a security problem arising from the proliferation of low-cost RFID tags in financial and identity applications. Unauthorized readers could "surreptitiously read the information stored on the card" to perform fraudulent transactions, yet adding robust security features to tags increases their cost, creating a "conflict between security... and ubiquity" Compl. ¶15 Compl. ¶16 '481 Patent, col. 1:49-67
- The Patented Solution: The patent proposes a distributed security architecture where the RFID tag, reader, and server cooperate. The RFID tag receives information from the reader, uses that information to encrypt its identification data, and transmits the now-encrypted data back to the reader. The reader acts as a simple conduit, forwarding the encrypted data to a backend server, which is the only component that performs decryption Compl. ¶¶19-20 '481 Patent, abstract '481 Patent, col. 8:1-18 This architecture secures the wireless communication without requiring the low-cost tag to perform complex cryptographic or decryption tasks.
- Technical Importance: The invention provided a method to implement transaction-specific security for inexpensive, intermittently powered RFID tags, a key challenge for deploying secure RFID in mass-market financial applications at the time Compl. ¶17 Compl. ¶24
Key Claims at a Glance
- The complaint asserts independent claim 1 Compl. ¶87
- Essential elements of claim 1 include:
- At an RFID tag, receiving information from an RFID reader that enables encryption of identification data according to a predetermined scheme used by a server.
- At the RFID tag, encrypting the identification data using the received information to produce encrypted RFID data.
- The encrypted data is for the RFID reader to transmit to the server, which then decrypts it to produce the identification data.
- The complaint notes that Plaintiff has also accused dependent claims 2, 3, 4, and 10 in its Preliminary Infringement Contentions Compl. ¶27, fn 17
U.S. Patent No. 9,628,466 - "Systems and Methods for Performing Secure Financial Transactions"
Issued April 18, 2017
The Invention Explained
- Problem Addressed: The complaint describes the problem of protecting a user's sensitive financial identity, specifically the account number, as it traverses the payment ecosystem from a mobile device, through a potentially untrusted point-of-sale (POS) terminal, to a backend server Compl. ¶42 Compl. ¶50
- The Patented Solution: The invention describes a method where an electronic device (e.g., a mobile phone) stores financial data that "does not comprise an account number" (i.e., a token). The device encrypts this data and sends it to the POS terminal. The POS terminal acts only as a conduit, forwarding the encrypted data to a backend server. Only the server decrypts the data, resolves the token to the actual account number, and processes the payment (Compl. ¶41; Compl. ¶42, Compl. ¶claim 15).
- Technical Importance: This architecture improves payment security by ensuring the actual account number is never transmitted from the mobile device or exposed at the POS terminal, with the sensitive data being resolved only within a trusted backend environment Compl. ¶44
Key Claims at a Glance
- The complaint asserts independent claim 15 Compl. ¶108
- Essential elements of claim 15 include:
- A method for use by an electronic device with memory storing financial data that "does not comprise an account number."
- Encrypting the data using the device's processor to generate encrypted data.
- Sending the encrypted data to the POS terminal for communication to a server, which will decrypt the data to identify an account number and charge the user's bank account.
- Displaying a successful communication acknowledged by the server on the device's display.
- The complaint notes that Plaintiff has also accused dependent claims 18-20 in its Preliminary Infringement Contentions Compl. ¶43, fn 28
- Multi-Patent Capsule: U.S. Patent No. 10,623,392
- Patent Identification: U.S. Patent No. 10,623,392, "Systems and Methods for RFID Security," issued April 14, 2020.
- Technology Synopsis: This patent refines the secure RFID architecture by requiring an "activation-gated" sequence. An RFID tag must first be activated (e.g., by a switch or biometric input) before it can use a subsequent communication from an RFID reader to determine an encryption key Compl. ¶29 Compl. ¶31 This sequence ties the cryptographic operation to a specific, intentional user action, which is particularly relevant for low-cost or intermittently powered tags Compl. ¶34 '392 Patent, claim 1
- Asserted Claims: Independent claim 1 and dependent claim 10 Compl. ¶133 Compl. ¶32, fn 22
- Accused Features: The accused system's use of an iOS device, which is activated via Face ID or Touch ID before it receives communication from the POS terminal to generate a transaction-specific cryptogram Compl. ¶¶135-136
- Multi-Patent Capsule: U.S. Patent No. 9,104,926
- Patent Identification: U.S. Patent No. 9,104,926, "Systems and Methods for Performing Secure Financial Transactions," issued August 11, 2015.
- Technology Synopsis: This patent describes the secure transaction architecture from the perspective of the point-of-sale (POS) device. The POS device receives encryption information, which includes a "pointer to one of a plurality of encryption keys," from a server. It transmits this information to a mobile device, obtains the resulting encrypted data from the mobile device, and forwards it to the server for decryption and authorization, all without decrypting the data itself Compl. ¶¶36-37 '926 Patent, claim 5
- Asserted Claims: Independent claim 5 Compl. ¶153
- Accused Features: The Defendant's NP6 POS terminal, which allegedly acts as a conduit by receiving transaction-specific information from backend servers, transmitting it to the customer's iOS device, receiving encrypted data back, and forwarding it to the server for processing Compl. ¶¶156-160
III. The Accused Instrumentality
- Product Identification: The "McDonald's Contactless Payment System" Compl. ¶57 This system is alleged to comprise three components: (1) a customer's iOS device (e.g., an iPhone) running the McDonald's App with Apple Pay enabled; (2) Defendant's in-store "NewPOS NP6" (NP6 POS) terminal equipped with an RFID reader; and (3) a backend payment platform, such as Adyen, for processing and authorization Compl. ¶57 Compl. ¶69 Compl. ¶72
- Functionality and Market Context:
- The system facilitates "tap-and-go" payments. A customer authenticates a payment on their iPhone (e.g., using Face ID), which causes the device's Secure Element to generate a tokenized Device Account Number (DAN) and a transaction-specific cryptogram Compl. ¶61 Compl. ¶64 This encrypted information is transmitted via NFC from the iPhone to the Defendant's NP6 POS terminal Compl. ¶65 The POS terminal then transmits this data to the backend payment platform, which detokenizes the information, processes the payment with the card issuer, and returns an authorization to the POS Compl. ¶72 The complaint emphasizes that the customer's actual credit card number is not transmitted from the iPhone or exposed to the merchant's POS system Compl. ¶61 A screenshot in the complaint illustrates how Apple Pay is presented as a payment option within the McDonald's app when a card is registered to the Apple Wallet Compl. p. 24
- The complaint alleges this technology is commercially important to restaurant operators like the Defendant because it accelerates service speeds, reduces errors, enhances security, and improves operational efficiency Compl. ¶58
IV. Analysis of Infringement Allegations
- '7,952,481 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| at the RFID tag, receiving information from an RFID reader that enables encryption of identification data according to a predetermined encryption scheme used by the server, the identification data identifying the RFID tag | The customer's iPhone (the "RFID tag") receives an Unpredictable Number (UN) from the Defendant's NP6 POS terminal (the "RFID reader") during a payment transaction. | ¶80 | col. 8:1-4 |
| at the RFID tag, encrypting the identification data according to the predetermined encryption scheme using the received information to produce encrypted RFID data for the RFID reader to transmit to the server... | Based on the received UN and other keys, the iPhone generates a unique session key and uses it to create a cryptogram, which is the "encrypted RFID data." This cryptogram is then transmitted via the POS terminal to the backend server for decryption. | ¶80 | col. 8:4-18 |
- '9,628,466 Patent Infringement Allegations
| Claim Element (from Independent Claim 15) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a method for use by an electronic device for making a purchase transaction...the electronic device having...a memory storing data relating to a financial information of a user, wherein the data does not comprise an account number | The accused method is performed by the customer's iPhone, which stores a tokenized payment data (DAN) that is derived from, but is not, the user's actual credit or debit card account number. | ¶111 | col. 14:43-52 |
| encrypting, using the processor, the data to generate an encrypted data | The iPhone's processor is used to create a transaction-specific cryptogram, which constitutes the "encrypted data." | ¶112 | col. 14:53-54 |
| sending the encrypted data...to the POS terminal for communicating the encrypted data and the purchase transaction to the server and for the server to decrypt the encrypted data to obtain the data, to use the data to identify an account number...and to charge the bank account... | The iPhone sends the cryptogram to the Defendant's POS terminal, which communicates it to the backend server. The server then decrypts the data to identify the underlying account and authorize the charge. | ¶114 | col. 14:55-63 |
| displaying a successful communication acknowledged by the server on the display of the electronic device | The iPhone allegedly displays a success confirmation on its screen after the server acknowledges and approves the transaction. | ¶118 | col. 14:64-66 |
- Identified Points of Contention:
- Scope Questions: A central issue may be whether the term "RFID tag", as used in the '481 and '392 patents, can be construed to read on a complex, general-purpose computing device like an Apple iPhone. The patents' background sections describe RFID tags as "small low cost electronic devices," which may support a narrower construction Compl. ¶14 For the '466 patent, a question is whether a tokenized Device Account Number (DAN) satisfies the negative limitation "data does not comprise an account number," as it functionally identifies an account to the server.
- Technical Questions: The infringement theory for the '481 patent hinges on whether the "Unpredictable Number" sent from the POS terminal to the iPhone truly "enables encryption" as required by the claim, or if it merely acts as a nonce in a cryptographic process where the essential key material is already self-contained within the iPhone's Secure Element. For the '466 patent, an evidentiary question may be whether the "successful communication" displayed on the iPhone is, in fact, "acknowledged by the server," or if it is a local confirmation generated by the device or POS terminal before final server-side settlement.
V. Key Claim Terms for Construction
The Term: "RFID tag" (from '481 Patent, claim 1)
- Context and Importance: The construction of this term is critical, as the accused device is an Apple iPhone, a sophisticated smartphone, while the patent specification repeatedly refers to "small low cost electronic devices" Compl. ¶14 '481 Patent, col. 1:21-22 Practitioners may focus on this term to dispute whether the accused product falls within the patent's scope.
- Intrinsic Evidence for a Broader Interpretation: The claims themselves do not limit the "RFID tag" by cost or complexity. The patent's title is "Systems and Methods for RFID Security," and an argument could be made that any device performing the claimed RFID communication and encryption functions within such a system is an "RFID tag."
- Intrinsic Evidence for a Narrower Interpretation: The patent's background explicitly discusses the "conflict" between the "security of RFID tag information and ubiquity of RFID tag deployment," which is driven by the cost of adding security to "small, inexpensive tags" '481 Patent, col. 1:62-67 This context may support an interpretation limited to the simple, low-cost devices that were the focus of the stated problem.
The Term: "information... that enables encryption" (from '481 Patent, claim 1)
- Context and Importance: This term defines the nature of the data transfer from the reader to the tag, a core step of the invention. The dispute will likely center on whether the data sent by the accused POS terminal (an "Unpredictable Number") performs the function of "enabling" encryption, or merely triggering it.
- Intrinsic Evidence for a Broader Interpretation: The specification provides several examples of such information, including "timing information," "pointer information," or a "server-generated key" passed through the reader '481 Patent, col. 10:4-11:31 This suggests the term is not limited to the key itself but can include various inputs that contribute to the cryptographic process.
- Intrinsic Evidence for a Narrower Interpretation: The word "enables" could be construed to require that the information is a necessary precondition for the tag to perform encryption at all (e.g., by providing a key or a direct seed for a key). An argument could be made that if the tag already possesses all necessary keying material, any data from the reader is merely a nonce that does not "enable" the fundamental cryptographic capability.
VI. Other Allegations
- Indirect Infringement: The complaint alleges that Defendant induces its customers to infringe by actively encouraging them to use the accused contactless payment system Compl. ¶103 Compl. ¶128 The alleged acts of inducement include advertising the McDonald's App, providing checkout prompts for contactless payment, and offering assistance on how to use the system Compl. ¶85 The complaint provides a screenshot of a Facebook advertisement as an example of Defendant encouraging customers to download and use the App Compl. p. 27
- Willful Infringement: Willfulness is alleged based on Defendant's purported knowledge of the patents and the alleged infringement. The complaint asserts that this knowledge stems from both pre-suit notice and the filing and service of the original complaint on March 27, 2026, after which Defendant allegedly continued its infringing activities Compl. ¶¶82-84 Compl. ¶97
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: can the term "RFID tag," which the patent specifications frame in the context of "small low cost electronic devices," be construed to cover a sophisticated, multi-purpose computing device like the Apple iPhone that serves as the primary accused instrumentality?
- A second central question will be one of attribution in a distributed system: for the purposes of direct infringement, can the actions performed by a customer's privately-owned iPhone and a third-party backend payment server be legally attributed to the Defendant, a McDonald's franchisee, merely because the Defendant operates the POS terminal that sits in the middle of the transaction?
- A key evidentiary question will be one of technical mechanism: does the data transmitted from the Defendant's POS terminal to the customer's iPhone functionally "enable" encryption in the manner required by the '481 patent, or does it merely trigger a self-contained cryptographic process within the iPhone's Secure Element, presenting a potential mismatch with the claim language?
Analysis metadata
Loading Amended Complaint
Suggested improvements