DCT

2:26-cv-00304

Headwater Research LLC v. Amazon.com Services LLC

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:26-cv-00304, E.D. Tex., 04/16/2026
  • Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Amazon has committed acts of infringement, maintains a regular and established place of business (including several warehouse and delivery facilities), and derives substantial revenue within the District.
  • Core Dispute: Plaintiff alleges that Defendant's devices running Fire OS and the associated Amazon Device Messaging service infringe three U.S. patents related to secure mobile device messaging, security techniques for device-assisted services, and adaptable network policies.
  • Technical Context: The technology at issue addresses methods for securing, managing, and monetizing services on mobile and connected devices, a critical area in the modern smartphone, smart device, and cloud services industries.
  • Key Procedural History: The complaint provides an extensive background on the inventor, Dr. Gregory Raleigh, highlighting his contributions to wireless communications technology, including MIMO, and his role in founding companies acquired by Cisco and Qualcomm. No prior litigation, licensing, or post-grant proceedings concerning the Asserted Patents are mentioned in the complaint.

Case Timeline

Date Event
2009-01-28 '464 Patent Priority Date
2009-02-13 '564 Patent Priority Date
2009-03-02 '777 Patent Priority Date
2014-09-09 '777 Patent Issued
2016-11-08 '564 Patent Issued
2024-04-23 '464 Patent Issued
2026-04-16 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 9,491,564 - "Mobile device and method with secure network messaging for authorized components"

The Invention Explained

  • Problem Addressed: The patent does not explicitly state a problem in its background section but implicitly addresses the need for a structured and secure method for various software components on a mobile device to communicate with network services.
  • The Patented Solution: The invention describes a mobile device with an "inter-process software communication (IPC) bus" that facilitates secure communication between a "device link agent" and various software "component processes" (e.g., applications) ʼ564 Patent, col. 2:15-28 The device link agent maintains a secure message link to a network server, and only components identified by "access authorization information" from a secure server are allowed to use the bus ʼ564 Patent, abstract This creates a controlled messaging channel for authorized applications on the device.
  • Technical Importance: This technology provides a centralized and secure architecture for managing communications between applications on a device and backend network services, which is fundamental for operating system security and service management.

Key Claims at a Glance

  • The complaint asserts infringement of at least Claim 1 of the '564 patent Compl. ¶35
  • The essential elements of independent Claim 1 include:
    • A mobile end-user device comprising a wireless modem and an inter-process software communication (IPC) bus.
    • The IPC bus provides secure communication between an executing "device link agent" and executing processes for a plurality of "software components."
    • This secure communication involves receiving "access authorization information" from a "secure server" and allowing bus access only to software components identified by that information.
    • The device link agent is configured to maintain a "secure message link" to a "message link server" and receive "secure messages" from it.
    • The device link agent routes received messages to the specific software components for which they are intended.
  • The complaint also alleges infringement of "the claims of the '564 patent," reserving the right to assert other claims Compl. ¶34

U.S. Patent No. 11,966,464 - "Security techniques for device assisted services"

The Invention Explained

  • Problem Addressed: The patent background describes how the proliferation of mass-market digital communications and high-bandwidth content is straining the capacity of wireless and wireline access networks ʼ464 Patent, col. 1:1-21
  • The Patented Solution: The patent proposes "device assisted services" where a "service profile" is executed within a "secure execution environment" on the device's processor ʼ464 Patent, Abstract This secure environment, shown as a "protected DAS partition" in the patent's figures, monitors and controls the device's use of a service according to policy settings associated with a service plan ʼ464 Patent, Abstract '464 Patent, Fig. 1 This allows for granular, secure, on-device enforcement of network policies.
  • Technical Importance: This on-device enforcement mechanism gives service providers a secure tool to manage network resources and implement complex service plans without relying solely on network-side equipment, directly addressing data demand challenges.

Key Claims at a Glance

  • The complaint asserts infringement of at least Claim 11 of the '464 patent Compl. ¶47
  • The essential elements of independent Claim 11 include:
    • A wireless end-user device comprising a secure modem, a secure execution environment, a secure memory partition, and a processor.
    • The processor is configured to establish a "secure control channel" between the "secure execution environment" and a "network service controller."
    • The processor receives messages from the controller containing "one or more settings."
    • The processor stores these settings in the "secure memory partition," which is accessible only from the "secure execution environment."
    • The processor controls the device using these settings.
  • The complaint also alleges infringement of "the claims of the '464 patent," reserving the right to assert other claims Compl. ¶46

U.S. Patent No. 8,832,777 - "Adapting network policies based on device service processor configuration"

The Invention Explained

  • The patent describes a system for adapting network policies based on the configuration of a "service processor" on an end-user device '777 Patent, abstract A network system receives a device credential, obtains a service policy, and uses authentication information associated with the on-device service processor to facilitate an authentication procedure, allowing the network to verify the device's configuration and adapt its policies accordingly '777 Patent, abstract

Key Claims at a Glance

  • Asserted Claims: The complaint asserts infringement of at least Claim 1 Compl. ¶59
  • Accused Features: The complaint alleges that Amazon's Fire OS devices and ADM services, which involve device registration and account-related settings, practice the methods for adapting network policies claimed in the '777 patent Compl. ¶58

III. The Accused Instrumentality

Product Identification

  • The accused instrumentalities are "Amazon devices that support Fire OS" and the "Amazon Device Messaging ('ADM')" service (Compl. ¶¶2; Compl. ¶22). These include products like Fire TV Sticks, Fire TV Cubes, Fire tablets, and Echo Show devices Compl. ¶2

Functionality and Market Context

  • Fire OS is the operating system for the accused devices, which automatically registers the device to a user's Amazon account and provides access to Amazon's backend services, including app stores, billing, and authentication Compl. ¶2
  • ADM is described as the "only push channel for Fire tablets, Fire TV, Echo Show, and other Amazon-branded devices," which developers must integrate to send real-time push messages Compl. ¶3
  • Amazon allegedly uses ADM to push its own service notifications, such as deal alerts and Prime Video trailers, and to collect behavioral user data, which increases user engagement and generates revenue (Compl. ¶¶4; Compl. ¶6). The complaint alleges that Amazon's revenues from these products and services are in the "billions of dollars" Compl. ¶7
  • No probative visual evidence provided in complaint.

IV. Analysis of Infringement Allegations

The complaint references claim charts attached as exhibits, but those exhibits were not provided with the complaint for this analysis Compl. ¶35 Compl. ¶47 Compl. ¶59 Therefore, the infringement allegations are summarized below in prose.

  • '564 Patent Infringement Allegations: The complaint alleges that Amazon's system of Fire OS devices and the ADM service constitutes infringement. The theory of infringement suggests that the ADM service, which delivers push notifications to applications on Fire OS devices, functions as the claimed "secure network messaging for authorized components." The complaint alleges direct infringement by making, using, and selling these systems, and induced infringement by "instructing users of Defendant's mobile applications to register the Fire OS device to enable push messaging" Compl. ¶34

  • '464 Patent Infringement Allegations: The complaint alleges that Amazon's products infringe by having users register, set up, and use Fire OS devices and their associated account settings Compl. ¶46 The infringement theory appears to be that Fire OS, in conjunction with Amazon's backend services, creates a "secure execution environment" on the device to manage and control "device assisted services" (like ADM) based on policies tied to the user's account, mapping to the patent's claims for "security techniques for device assisted services."

  • Identified Points of Contention:

    • Scope Questions: A central dispute will likely concern whether the terms "authorized components" and "secure network messaging" in the '564 Patent can be interpreted to read on standard applications receiving push notifications via Amazon's ADM service. Similarly, for the '464 Patent, a key question will be whether the standard application environment in Fire OS constitutes a "secure execution environment" that is architecturally distinct from the main application partition, as depicted in the patent's figures.
    • Technical Questions: The complaint's allegations raise the question of what specific technical features of Fire OS and ADM perform the functions required by the claims. For the '564 Patent, a question is whether ADM performs the claimed functions of receiving "access authorization information from a secure server" to specifically authorize component access to the messaging bus, beyond a general application permission to receive notifications. For the '464 Patent, the court may need to determine if Fire OS implements a "service profile" with specific "policy settings" that are stored in a "secure memory partition" accessible only from the alleged "secure execution environment," as required by Claim 11.

V. Key Claim Terms for Construction

'564 Patent

  • The Term: "authorized components"
  • Context and Importance: The definition of this term is critical. If "authorized components" is construed broadly to mean any application a user installs, the claim scope may be quite large. If it is construed narrowly to require a specific, server-driven authorization process beyond user installation, the infringement case may be more difficult to prove. Practitioners may focus on this term because its interpretation will determine whether a general-purpose mobile OS architecture falls within the claim's scope.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The patent does not explicitly define "authorized components" in a narrow way in the main body of the claims, which may support an argument that the term should be given its plain and ordinary meaning.
    • Evidence for a Narrower Interpretation: Claim 1 requires "receiving access authorization information from a secure server" and "allowing access to said bus only for software components identified by said access authorization information" ʼ564 Patent, col. 10:20-25 This language suggests a specific, server-controlled authorization step, potentially narrowing the term to components that have undergone this specific verification, rather than any app on the device.

'464 Patent

  • The Term: "secure execution environment"
  • Context and Importance: This term's construction is central to the infringement analysis of the '464 patent. Whether Amazon's Fire OS infringes may depend on whether its standard application sandboxing or memory protection features meet the definition of a "secure execution environment" as claimed.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification suggests this can be a "virtual execution environment" or rely on operating system features, which could support a broader reading that encompasses modern OS security models '464 Patent, col. 6:15-17
    • Evidence for a Narrower Interpretation: The patent's figures, such as Figure 1, consistently depict the "PROTECTED DAS EXECUTION PARTITION" (114) as architecturally separate from the "APPLICATION EXECUTION PARTITION" (102) '464 Patent, Fig. 1 This visual distinction, along with language about a "separate hardware security function," may support a narrower construction requiring a distinct, hardware-enforced partition beyond standard OS-level process isolation '464 Patent, col. 6:15-17

VI. Other Allegations

  • Indirect Infringement: The complaint alleges inducement of infringement for all asserted patents. The factual basis cited is Amazon's alleged instruction to users to register and use Fire OS devices and enable push messaging, which allegedly causes the infringing acts to occur Compl. ¶34 Compl. ¶46 Compl. ¶58 The complaint also makes general allegations of providing instructions and information to customers Compl. ¶37
  • Willful Infringement: Willfulness is alleged for all three patents, based on Amazon's alleged knowledge of the patents "at least since receipt of this Complaint" Compl. ¶36 Compl. ¶48 Compl. ¶60 This establishes a basis for potential post-suit willfulness.

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue will be one of definitional scope: Can terms rooted in specific security architectures, such as "secure execution environment" and "authorized components," be construed to cover the general-purpose, widely-used features of a modern mobile operating system and its associated push notification service? The outcome may depend on whether the court views these terms as requiring specific structures beyond those common in the industry.
  • A key evidentiary question will be one of technical implementation: What evidence will be presented to show that Amazon's Fire OS and ADM systems actually perform the specific, multi-step processes claimed in the patents-such as using server-sent "access authorization information" to grant bus access on a per-component basis ('564 patent) or storing policy "settings" in a "secure memory partition" accessible only by a "secure execution environment" ('464 patent)? The case will likely turn on a detailed technical comparison of the accused systems against the patent specifications.
Loading Complaint