2:26-cv-00400
Massachusetts Institute Of Technology v. Microsoft Corp
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Massachusetts Institute of Technology (Massachusetts)
- Defendant: Microsoft Corporation (Washington)
- Plaintiff's Counsel: McKool Smith PC; Holland & Knight LLP
- Case Identification: 2:26-cv-00400, E.D. Tex., 05/15/2026
- Venue Allegations: Venue is based on Defendant Microsoft having regular and established places of business in the Eastern District of Texas, including data centers, Microsoft Windows Stores, and an Azure Front Door "point of presence" in Plano.
- Core Dispute: Plaintiff alleges that Defendant's cloud services and related hardware, such as Azure Sphere and Project Cerberus, infringe patents related to Physical Unclonable Function (PUF) technology for reliably generating and using device-specific cryptographic keys.
- Technical Context: The case concerns Physical Unclonable Functions (PUFs), a hardware security technology that generates unique identifiers or cryptographic keys from inherent, random physical variations in semiconductor chips, providing a "silicon fingerprint" for device authentication.
- Key Procedural History: The complaint notes that the asserted technology, developed by MIT Professor Srinivas Devadas, has received widespread industry recognition and awards. It also states that companies including Intel and Xilinx have licensed the Asserted Patents, and that the accused SRAM PUF technology was developed by Intrinsic ID, a company acquired by Synopsys in 2024, which is described as a partner of Microsoft's suppliers.
Case Timeline
| Date | Event |
|---|---|
| 2002-04-16 | Earliest Priority Date for '569 and '103 Patents |
| 2002-11-01 | Professor Devadas publishes "Silicon Physical Random Functions" paper |
| 2010-03-16 | U.S. Patent No. 7,681,103 is issued |
| 2010-10-19 | U.S. Patent No. 7,818,569 is issued |
| 2016-01-01 | NXP reportedly begins using SRAM PUF from Intrinsic-ID |
| 2020-01-01 | Microsoft research article describes PUF use in Azure Sphere |
| 2024-01-01 | Synopsys acquires Intrinsic ID |
| 2025-03-31 | Date since which Microsoft allegedly maintained a point of presence in the District |
| 2026-05-15 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 7,681,103 - "Reliable generation of a device-specific value"
Issued March 16, 2010
The Invention Explained
- Problem Addressed: The patent addresses the challenge that while a Physical Unclonable Function (PUF) can provide a unique, device-specific value from manufacturing variations, this value is often "noisy" and unreliable for cryptographic purposes because it can change due to factors like measurement error, temperature, or circuit aging Compl. ¶16 '103 Patent, col. 2:20-25 A cryptographic key, however, must be perfectly stable and repeatable Compl. ¶16
- The Patented Solution: The invention proposes a two-phase "fuzzy extractor" method to create a stable value from a noisy PUF. In an initial "enrollment" phase, a first digital value is generated from the PUF, and "redundancy information" (also known as helper data) is computed from it and stored. In a subsequent "reconstruction" phase, a new, potentially noisy digital value is generated and combined with the stored redundancy information to reliably correct any errors and regenerate the exact first digital value '103 Patent, abstract '103 Patent, col. 2:9-19
- Technical Importance: This approach provided a practical method for converting unstable physical characteristics into stable cryptographic keys, enabling the use of PUFs for robust and secure device authentication Compl. ¶¶21-22
Key Claims at a Glance
- The complaint asserts claims 1-11, 20, and 22-26, highlighting independent claim 1 Compl. ¶11 Compl. ¶26
- Independent Claim 1 of the '103 Patent recites:
- A method for repeatedly generating an unpredictable device-specific value comprising:
- in a first component of a device, generating a first digital value that is substantially dependent on fabrication variation among like devices, wherein the first digital value comprises a device-specific function of an input value inputted to a device;
- computing redundancy information based on the first digital value;
- in the first component of the device, generating a subsequent digital value; and
- in a second component of the device, determining the first digital value from the subsequent digital value and the redundancy information.
- The complaint reserves the right to assert additional claims Compl. ¶11
U.S. Patent No. 7,818,569 - "Data protection and cryptographic functions using a device-specific value"
Issued October 19, 2010
The Invention Explained
- Problem Addressed: The patent addresses the security vulnerability of storing cryptographic keys directly on an integrated circuit, where they could be extracted by attackers through physical probing or other means Compl. ¶¶37-38 Traditional systems often required injecting and storing keys, creating a significant security risk '569 Patent, col. 1:50-61
- The Patented Solution: The invention describes a method where a cryptographic key is generated on-demand from a PUF each time it is needed. This key is used to perform a cryptographic function on data stored within the same integrated circuit and is not stored in non-volatile memory. By regenerating the key only when necessary, the invention eliminates the security risk associated with key storage '569 Patent, abstract '569 Patent, col. 2:10-15 Compl. ¶35
- Technical Importance: This invention enabled the creation of highly secure systems where the cryptographic key is inextricably linked to the physical hardware, making it nearly impossible for attackers to extract or clone the key Compl. ¶39
Key Claims at a Glance
- The complaint asserts claims 1-12, highlighting independent claim 9 Compl. ¶11 Compl. ¶34
- Independent Claim 9 of the '569 Patent recites:
- A method comprising:
- applying a key generation function to determine a cryptographic key in an integrated circuit based on an input to the key generation function that includes a first digital value generated in the integrated circuit such that the first digital value depends on circuit parameters that vary due to fabrication variations among like integrated circuits; and
- performing a cryptographic function on information stored in the integrated circuit using the determined cryptographic key;
- wherein the method does not require non-volatile storage of the cryptographic key in the integrated circuit.
- The complaint reserves the right to assert additional claims Compl. ¶11
III. The Accused Instrumentality
Product Identification
The complaint accuses Microsoft's cloud services and related hardware, including the Azure Sphere secure IoT device ecosystem and Project Cerberus, an open-source hardware root-of-trust specification Compl. ¶¶77-78
Functionality and Market Context
The complaint alleges that these Microsoft products utilize PUF technology, sourced from Synopsys/Intrinsic ID, as a core security feature Compl. ¶77 Compl. ¶80 Specifically, Project Cerberus is alleged to use a "Hardware Physically Unclonable Function (PUF)" within its security controller to establish a root of trust for server platforms Compl. ¶78 A block diagram from a Microsoft presentation shows a "PUF" block as a component of the Project Cerberus Controller Compl. p. 28 Similarly, the Azure Sphere ecosystem is alleged to rely on silicon that implements PUF technology for its hardware root of trust Compl. ¶79 The complaint positions these products as crucial for securing a wide range of applications, from IoT devices to government and aerospace systems Compl. ¶43 Compl. ¶60
IV. Analysis of Infringement Allegations
'103 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| in a first component of a device, generating a first digital value that is substantially dependent on fabrication variation... wherein the first digital value comprises a device-specific function of an input value inputted to a device; | The accused technology allegedly generates a "first digital value" (an SRAM PUF response) from a "first component" (the SRAM PUF). This value is dependent on fabrication variations and is generated in response to an input signal that powers on the SRAM. | ¶74 | col. 2:9-12 |
| computing redundancy information based on the first digital value; | Synopsys's technology, allegedly used by Microsoft, generates an "activation code (AC)" or "helper data" from the initial PUF response. This is alleged to be the claimed "redundancy information." | ¶75 | col. 2:12-14 |
| in the first component of the device, generating a subsequent digital value; and | At a later time, a "subsequent digital value" (a new, noisy PUF response) is generated from the same SRAM PUF component when it is powered on again. | ¶75 | col. 2:14-16 |
| in a second component of the device, determining the first digital value from the subsequent digital value and the redundancy information. | Using the stored "activation code" and the new noisy PUF response, a "PUF Algorithm" allegedly reconstructs the original, noise-free "first value." A diagram illustrates this enrollment and reconstruction process. | ¶75; Compl. p. 26 | col. 2:16-19 |
'569 Patent Infringement Allegations
| Claim Element (from Independent Claim 9) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| applying a key generation function to determine a cryptographic key... based on an input... that includes a first digital value generated in the integrated circuit... | The accused technology's "PUF algorithm" is alleged to be the "key generation function." This algorithm allegedly takes the PUF response (the "first digital value") as an input to generate a secret "cryptographic key." | ¶66 | col. 2:35-41 |
| ...such that the first digital value depends on circuit parameters that vary due to fabrication variations among like integrated circuits; | The initial PUF response is generated from the startup values of SRAM cells, which are determined by random, minute variations in the manufacturing process and are unique to each chip. A diagram from Synopsys illustrates this process. | ¶61; Compl. p. 21 | col. 2:39-41 |
| performing a cryptographic function on information stored in the integrated circuit using the determined cryptographic key; | The generated cryptographic key is allegedly used to perform functions such as secure key storage and authentication on data stored on the chip. | ¶69 | col. 2:41-43 |
| wherein the method does not require non-volatile storage of the cryptographic key in the integrated circuit. | The complaint alleges that in the accused technology, keys are "extracted 'from the chip,' only when they are needed" and are not stored in non-volatile memory, making the solution secure. | ¶70 | col. 2:44-46 |
Identified Points of Contention
- Evidentiary Questions: The complaint's infringement theory relies on connecting Microsoft's products to Synopsys's technology, often through third-party articles and partner relationships Compl. ¶80 Compl. ¶82 A primary question will be what direct evidence exists that Microsoft's accused products (e.g., Azure Sphere, Project Cerberus) practice the specific steps of the asserted claims as described in Synopsys/Intrinsic ID marketing materials and white papers.
- Scope Questions: For the '103 patent, a point of contention may be the interpretation of "first component" and "second component." The complaint alleges these can be different algorithms on the same hardware. The court may need to determine if the patent requires physically distinct structures or if software-defined components suffice.
V. Key Claim Terms for Construction
The Term: "redundancy information" '103 Patent, claim 1
Context and Importance: This term is the core of the '103 patent's solution for stabilizing a noisy PUF output. The infringement case depends on the accused "activation code" or "helper data" falling within the scope of this term. Its construction will determine what type of error-correction data is covered by the patent.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The claim itself broadly defines it as information "computed based on the first digital value" that is later used with a subsequent value to determine the first value '103 Patent, claim 1 This language may support an interpretation covering any data that serves this error-correction purpose.
- Evidence for a Narrower Interpretation: The specification provides detailed examples of error-correction schemes, such as using a "modified Hamming code" or a "product code" '103 Patent, col. 11:59-65 '103 Patent, col. 12:54-58 A defendant may argue that the term should be limited to these or structurally similar coding schemes, rather than any generic "helper data."
The Term: "key generation function" '569 Patent, claim 9
Context and Importance: This term defines the mechanism that transforms the raw, device-specific PUF output into a usable cryptographic key. The infringement allegation hinges on the accused "PUF Algorithm" meeting this definition. Practitioners may focus on whether this term implies specific functional requirements, such as cryptographic hardening.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The claim language describes it functionally as a function that is applied "to determine a cryptographic key... based on an input... that includes a first digital value" '569 Patent, claim 9 This may support a broad definition covering any process that achieves this result.
- Evidence for a Narrower Interpretation: The complaint alleges the accused function includes "privacy amplification" to create a uniformly random key Compl. ¶66 The patent specification discusses using one-way random hash functions as part of the process, which could be argued as a necessary component of the "key generation function" to ensure cryptographic security, potentially narrowing its scope '569 Patent, col. 15:20-31
VI. Other Allegations
The complaint does not contain specific counts or factual allegations for indirect infringement or willful infringement.
VII. Analyst's Conclusion: Key Questions for the Case
- A central question will be one of evidentiary linkage: can Plaintiff produce direct evidence that Microsoft's specific implementations within its Azure Sphere and Project Cerberus platforms practice every element of the asserted claims, or will the case depend on a chain of inferences drawn from marketing materials, third-party articles, and partnerships between Microsoft's suppliers and the accused technology provider, Synopsys?
- A key issue of claim construction for the '103 patent will be the scope of "redundancy information." The case may turn on whether this term is construed broadly to cover any "helper data" that enables error correction, as alleged by the Plaintiff, or is limited to the specific error-correcting code structures detailed in the patent's specification.
- The dispute over the '569 patent may hinge on a functional and definitional question: does the accused "PUF algorithm" perform the specific functions of the claimed "key generation function," and does the overall accused process satisfy the negative limitation that the cryptographic key is not stored in "non-volatile storage," as those terms are understood in the context of the patent?