DCT

2:26-cv-00353

Sunstone Information Defense Inc v. Akamai Tech Inc

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:26-cv-00353, E.D. Tex., 05/01/2026
  • Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Defendant maintains regular and established places of business in the district, pointing to the physical locations of employees and the installation of Defendant's solutions on servers located within the district, such as for the Frisco Independent School District.
  • Core Dispute: Plaintiff alleges that Defendant's computer security products, including its Account Protector service, infringe five U.S. patents related to methods for detecting malicious applications by analyzing and validating communications between servers and client devices.
  • Technical Context: The technology at issue addresses cybersecurity threats, particularly sophisticated malware and bots that can hijack or alter user sessions with web services such as online banking or e-commerce platforms.
  • Key Procedural History: The complaint alleges that Plaintiff's founder, Dr. Ford, was introduced to key individuals within Akamai's Security Business Unit on July 31, 2015, and that subsequent communications regarding Plaintiff's technology occurred, including a follow-up on August 3, 2015. These allegations of pre-suit knowledge are presented to support claims of willful infringement.

Case Timeline

Date Event
1998-08-20 Akamai was founded.
2011-09-21 Earliest Priority Date for '870, '682, '833, '255, '753 Patents.
2015-07-31 SunStone was introduced to key individuals within the Akamai Security Business Unit.
2015-08-03 Akamai followed up on the introduction with SunStone.
2015-09-01 U.S. Patent No. 9,122,870 ('870 Patent) Issued.
2021-03-23 U.S. Patent No. 10,958,682 ('682 Patent) Issued.
2022-03-22 U.S. Patent No. 11,283,833 ('833 Patent) Issued.
2024-03-06 U.S. Patent No. 11,943,255 ('255 Patent) Issued.
2025-07-22 U.S. Patent No. 12,368,753 ('753 Patent) Issued.
2026-05-01 Complaint Filing Date.

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 9,122,870 - "Methods and Apparatus for Validating Communications in an Open Architecture System"

Patent Identification

  • U.S. Patent No. 9,122,870, issued September 1, 2015.

The Invention Explained

  • Problem Addressed: The patent addresses the failure of conventional virus detection algorithms to identify malicious interference in client-server communications. It notes these algorithms typically focus on detecting the malware's source rather than the malicious noise (i.e., the interference) itself, allowing disguised malicious code to alter communications undetected '870 Patent, col. 2:28-42
  • The Patented Solution: The invention proposes a method where a server sends a client device not only "transactional information" (the core data) but also "presentation information" that specifies how that data should be displayed '870 Patent, col. 15:1-12 The server then determines a "prediction" of what the client's response should look like based on this combined information. If the actual response received from the client device does not match the prediction, the system provides an indication of a malicious application '870 Patent, col. 15:13-22 This process is illustrated in network diagrams showing communications between client devices, application servers, and database servers '870 Patent, Fig. 1
  • Technical Importance: This approach provided a method to counter malware that operates "in-session" to alter transactions, a significant threat in fields like online banking where client-server connections must generally be allowed Compl. ¶44

Key Claims at a Glance

  • The complaint asserts independent claim 1 Compl. ¶67
  • The essential elements of independent claim 1 include:
    • selecting transactional information to transmit from a server to a client device.
    • selecting presentation information specifying how the transactional information is to be displayed.
    • transmitting a message with both types of information to the client.
    • determining a prediction of a response message from the client based on the transmitted information and how the client is configured to render it.
    • receiving the actual response message from the client.
    • providing an indication of a malicious application if the response message does not match the prediction.
    • wherein the prediction is further based on estimating locations of rendered features, page geometry, or relative locations of elements.
  • The complaint also asserts claims 2-20 and 37-39 Compl. ¶219

U.S. Patent No. 10,958,682 - "Methods and Apparatus for Varying Soft Information Related to the Display of Hard Information"

Patent Identification

  • U.S. Patent No. 10,958,682, issued March 23, 2021.

The Invention Explained

  • Problem Addressed: This patent, from the same family as the '870 Patent, also addresses the need to validate communications in the presence of malicious noise that conventional antivirus tools fail to detect '682 Patent, col. 2:24-36 It specifically notes that malicious applications can be configured to identify and switch between valid "codewords," thereby defeating traditional error-correction schemes that cannot identify such a switch '682 Patent, col. 2:13-24
  • The Patented Solution: The solution involves using variations of "soft information" (presentation data) to define how "hard information" (transactional data) is rendered on a client device '682 Patent, abstract A security processor predicts how the client will render the information and compares this to the actual response to detect interference. The claims expand on the types of "presentation information" that can be varied, including protocol information, style sheets, and even information that changes a function definition in a code library at the client device '682 Patent, col. 32:5-19 Figure 17 of the patent graphically contrasts messaging with and without this disclosed technology, showing how the invention introduces variability to detect anomalies '682 Patent, Fig. 17
  • Technical Importance: The invention aims to overcome the problem of detecting sophisticated malware by creating dynamic "polymorphs" of a web service, making it difficult for an attacker to predict and mimic legitimate user interactions Compl. ¶46

Key Claims at a Glance

  • The complaint asserts independent claim 10 Compl. ¶96
  • The essential elements of independent claim 10 are largely parallel to claim 1 of the '870 Patent but add further specificity:
    • The steps of selecting, transmitting, determining a prediction, receiving a response, and providing an indication are performed via a processor.
    • The prediction is further determined by "estimating a label of the presentation information."
    • The "presentation information" is defined to include at least one of protocol, formatting, positional, rendering, style, or transmission encoding information, or information changing a function in a code library.
    • The "transactional information" is defined to include at least one of text, data, pictorial, image, authentication, or financial information.
  • The complaint also asserts claims 1-9 and 11-40 Compl. ¶251

Multi-Patent Capsule: U.S. Patent No. 11,283,833 - "Methods and Apparatus for Detecting a Presence of a Malicious Application"

  • Patent Identification: U.S. Patent No. 11,283,833, issued March 22, 2022 Compl. ¶113 Compl. ¶120
  • Technology Synopsis: The patent describes a method for detecting malicious applications by predicting expected human interaction with a website. The system identifies webpage elements for user input, analyzes cursor behavior (e.g., spatial density or velocity vectors), and uses this prediction as a baseline to evaluate interaction data received from a client device, flagging deviations that suggest non-human behavior Compl. ¶127 The method is applied to a first website and a second, different website to create distinct predictions for each Compl. ¶125
  • Asserted Claims: Independent claim 1 is asserted Compl. ¶125
  • Accused Features: The complaint alleges that Akamai's Accused Products utilize a processor and machine learning to access a webpage, predict normal usage patterns, and determine if a user's interaction is human-derived by analyzing user behavior signals, mouse telemetry, and device data across different customer websites (e.g., Washington Post and Sephora) Compl. ¶¶281-284

Multi-Patent Capsule: U.S. Patent No. 11,943,255 - "Methods and Apparatus for Detecting a Presence of a Malicious Application"

  • Patent Identification: U.S. Patent No. 11,943,255, issued March 6, 2024 Compl. ¶142
  • Technology Synopsis: The patent details a method for detecting malicious applications by establishing a baseline during a "first access of a website" and using it for comparison during a "subsequent access." On the first visit, the system sends transactional and presentation information, receives back information on how it was graphically rendered, and stores this as a "predicted response." On a subsequent visit, it repeats the process and compares the new rendered output to the stored prediction, flagging a mismatch as a potential malicious attack Compl. ¶156 Compl. ¶158
  • Asserted Claims: Independent claim 1 is asserted Compl. ¶154
  • Accused Features: The complaint alleges that Akamai's products receive a connection request, transmit a transactional string and presentational information, and then process the client's rendered output (e.g., a hashed image) to create a device profile or "predicted response" for use in evaluating subsequent access attempts Compl. ¶¶307-309

Multi-Patent Capsule: U.S. Patent No. 12,368,753 - "Methods and Apparatus for Detecting a Presence of a Malicious Application"

  • Patent Identification: U.S. Patent No. 12,368,753, issued July 22, 2025 Compl. ¶171
  • Technology Synopsis: The technology described is substantively similar to the '255 Patent, focusing on detecting malicious activity by comparing a webpage rendering from a "subsequent access" to a "predicted response" stored during a prior access. The system first stores information describing a client's rendered output for specific transactional and presentation data, then on a later visit, it transmits new information and compares the new rendered output to the stored prediction to identify interference Compl. ¶181 Compl. ¶183
  • Asserted Claims: Independent claim 1 is asserted Compl. ¶179
  • Accused Features: The complaint alleges Akamai's products utilize a processor and memory to maintain a profile of devices for a user's account, with device identification accomplished by rendering a crafted image and hashing the result. This stored profile ("predicted response") is then used for comparison when the user makes a subsequent request for access from a customer website like the Washington Post Compl. ¶¶331-333

III. The Accused Instrumentality

Product Identification

  • The accused products include Akamai's "Account Protector" service along with "similar offerings" Compl. ¶4 Compl. ¶204

Functionality and Market Context

  • The Accused Products are designed to stop bot-driven attacks by analyzing user behavior to detect threats Compl. ¶201 When a user attempts to log in, Account Protector evaluates the risk by referencing a behavioral profile built from the user's typical devices, IP addresses, and other factors Compl. ¶205 The system is alleged to collect hundreds of signals from client devices, including mouse movement data and user interactions with login prompts Compl. ¶¶206-207 A screenshot in the complaint shows code variables from Akamai's script, including one containing a unique identifying string allegedly used for device fingerprinting Compl. ¶207 Compl. p. 56 This profiling is allegedly achieved in part by rendering a "crafted image that generates a unique fingerprint identifying the device" Compl. ¶206 The complaint alleges these technologies are actively implemented on major corporate websites, such as The Washington Post and Sephora Compl. ¶205

IV. Analysis of Infringement Allegations

'870 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
selecting transactional information to transmit from a server to a communicatively coupled client device based on a request from the client device; The Accused Products provide protected login pages containing transactional prompts for username and password entry. ¶223 col. 5:33-40
selecting presentation information corresponding to the transactional information...specifying how the transactional information is to be displayed; The Accused Products select and transmit styling information for fingerprint imagery, including a unique transactional string and presentational details like font and pixel values. ¶226; ¶227; ¶229 col. 5:41-49
transmitting at least one message including the presentation and transactional information from the server to the client device; The Accused Products transmit the login page, associated styling, and scripts to the client device for rendering. A screenshot shows an Akamai-protected login page for The Washington Post. ¶223; ¶224 col. 5:41-44
determining a prediction of a response message from the client device based on...the selected transactional information, ii) how the client device is configured to render...and iii) predicted response information... The Accused Products use advanced machine learning to create a prediction of normal traffic and user behavior, creating a "choke" point to collect user interactions. ¶228 col. 10:1-10
receiving the response message from the client device; The Accused Products collect user telemetry data, including mouse movement, and canvas information from the user device in an encoded/encrypted request payload. ¶225; ¶229 col. 10:11-14
responsive to information in the response message not matching the prediction, providing an indication there is a malicious application affecting communications... The Accused Products determine an actionable risk classification, and if a security concern is identified, they move to deny the request. A diagram illustrates this deny/allow workflow. ¶230; ¶259 col. 10:15-22
wherein the prediction is further determined based at least in part by at least one of: (a) estimating locations of rendered features... The prediction process is alleged to be sensitive to the layout of the page, the position of transactional login prompts, window zoom, window size, and device rotation, which all impact page layout and element geometry. ¶228 col. 16:26-31

Identified Points of Contention

  • Scope Questions: A central question may be whether the term "prediction of a response message," as defined in the patent, can be construed to cover the behavioral profiles and machine learning models alleged to be used by Akamai. The patent claim links the "prediction" to the specific "presentation information" sent by the server, raising the question of whether a general behavioral model constitutes such a prediction.
  • Technical Questions: The complaint alleges Akamai creates a "prediction of normal traffic" (Compl. ¶228). The infringement analysis may hinge on what technical evidence demonstrates that this prediction is based on the specific factors required by the claim (e.g., "estimating locations of rendered features and functions as displayed by the client device") versus being based on other behavioral biometrics not explicitly tied to the server-sent presentation information.

'682 Patent Infringement Allegations

Claim Element (from Independent Claim 10) Alleged Infringing Functionality Complaint Citation Patent Citation
selecting, via a processor, transactional information to transmit from a server... The Accused Products require the delivery of a login form with user credential prompts. ¶255 col. 3:9-13
selecting, via the processor, presentation information...specifying how the transactional information is to be displayed; The Accused Products transmit JavaScript data collection functionality and styling information that dictates how login prompts and fingerprinting imagery are rendered. ¶255 col. 3:14-17
transmitting, via the processor, at least one message including the presentation and transactional information... The Accused Products deliver the login form and associated scripts to the client device. A screenshot of the Washington Post login page shows mouse data being collected. ¶255; ¶224 col. 3:18-21
determining, via the processor, a prediction of a response message from the client device... An anti-bot detection system decides whether a user's credentials proceed to validation, a process which focuses on behavioral data surrounding the transactional page. ¶256 col. 3:22-30
receiving, in the processor, the response message from the client device; The system harvests data including device configuration information and user-supplied data, which contributes to machine learning identification of webpage elements. ¶257 col. 3:31-32
responsive to information in the response message not matching the prediction, providing...an indication there is a malicious application... After data analysis, the final output of the Accused Product's process is to act against perceived security threats and deny the request. A diagram shows this workflow leading to "access denied." ¶259 col. 3:33-37
wherein the prediction is further determined by the processor based at least in part by estimating a label of the presentation information, The process uses machine learning to identify webpage elements that express human user interaction, analyzing parameters like window size, zoom level, and device orientation. ¶257; ¶231 col. 3:38-41

Identified Points of Contention

  • Scope Questions: Practitioners may focus on the construction of "estimating a label of the presentation information." The analysis will question whether Akamai's behavioral modeling and risk scoring constitutes "estimating a label" in the context of the patent, or if the term requires a more specific, discrete identifier.
  • Technical Questions: Claim 10 requires the "presentation information" to include specific categories, such as "information changing a definition of a function in a code library" '682 Patent, col. 32:15-17 A key factual question will be whether the complaint provides evidence that Akamai's system actually transmits and utilizes these specific, and potentially uncommon, types of presentation information as part of its infringement.

V. Key Claim Terms for Construction

For the '870 Patent

  • The Term: "prediction of a response message"
  • Context and Importance: This term is the central mechanism for detecting divergence from expected behavior. Its construction will determine whether Akamai's use of machine learning-based behavioral profiles falls within the scope of the claims, or if the claims are limited to a more direct prediction of specific return values (like screen coordinates) based on server-sent instructions.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification describes the prediction as a "best guess" and an "estimation" as to how information is displayed, which could support a broader reading to include probabilistic models '870 Patent, col. 5:49-55
    • Evidence for a Narrower Interpretation: The claim itself ties the prediction to being "based on...how the client device is configured to render" the server-sent information and further refines it as being determined by "estimating locations of rendered features" and "page geometry" '870 Patent, col. 15:13-22 '870 Patent, col. 16:26-31

For the '682 Patent

  • The Term: "estimating a label of the presentation information"
  • Context and Importance: This limitation appears to be a key differentiator from the parent '870 Patent. The definition of "label" is critical; if construed broadly as any characteristic, it may read on general fingerprinting, but if construed narrowly as a specific, designated identifier, it could be a significant hurdle for the infringement case.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The patent does not appear to provide an explicit definition of "label," which may allow for it to be given its plain and ordinary meaning, potentially covering any characteristic or classification derived from the presentation information.
    • Evidence for a Narrower Interpretation: The specification discusses the use of "codewords" and how malicious applications can switch between valid ones '682 Patent, col. 2:13-24 A party may argue that "label" should be construed in this context to mean a specific, discrete identifier akin to a codeword, rather than a probabilistic score from a behavioral model.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges that Akamai induces infringement by instructing and encouraging its customers and end users to operate the Accused Products in an infringing manner through advertisements, technical materials, and other instructions Compl. ¶241 Compl. ¶242
  • Willful Infringement: The complaint alleges that Akamai had pre-suit knowledge of SunStone's patents and technology dating back to at least July 31, 2015, through direct business communications between the parties Compl. ¶211 Compl. ¶212 It is alleged that Akamai proceeded to launch its "Bot Manager" service shortly after these communications ceased, suggesting Akamai acted despite knowledge of SunStone's rights Compl. ¶214

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue will be one of technological translation: do the concepts of "varying soft information" and creating a "prediction" based on "presentation information," as described in the patents, map onto the technical reality of Akamai's system, which allegedly uses behavioral biometrics and canvas fingerprinting to generate a device/user profile and compare it against a baseline? The case may turn on whether SunStone's patented method of dynamically altering a webpage's presentation to detect malware is functionally the same as Akamai's method of observing a user's inherent behavioral and device-specific patterns.
  • A second key question will be one of definitional scope, particularly concerning the term "estimating a label" in the '682 Patent. The court's construction of this term will be critical in determining whether Akamai's risk scoring and behavioral analysis falls within the claim language, or if the patent requires the estimation of a more discrete, pre-defined identifier.
  • A third central question will be evidentiary, focused on willfulness. The complaint makes specific allegations of pre-suit meetings and discussions about SunStone's technology. The case will likely involve a deep inquiry into what was disclosed during those 2015 interactions and whether that knowledge can be directly tied to the subsequent development and sale of the Accused Products, potentially exposing Akamai to enhanced damages.
Loading Complaint