DCT
2:26-cv-00414
Computer Protection IP LLP v. Samsung Electronics Co Ltd
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Computer Protection IP, LLP (Georgia)
- Defendant: Samsung Electronics Co., Ltd. (South Korea); Samsung Electronics America, Inc. (New York)
- Plaintiff's Counsel: Hill, Kertscher & Wharton, LLP
- Case Identification: 2:26-cv-00414, E.D. Tex., 05/19/2026
- Venue Allegations: Venue is alleged to be proper as to Samsung Electronics Co., Ltd. because it is a foreign corporation. Venue is alleged to be proper as to Samsung Electronics America, Inc. because it maintains regular and established places of business in the district, including a "flagship campus" in Plano, Texas.
- Core Dispute: Plaintiff alleges that Defendant's Samsung Knox mobile security platform and its OpenStack-based cloud and network products infringe three patents related to secure and distributed computing environments.
- Technical Context: The technology concerns methods for securing computing devices and cloud infrastructure through pre-boot authentication, virtualization, and the creation of isolated environments for sensitive data.
- Key Procedural History: The complaint does not reference any prior litigation, Inter Partes Review (IPR) proceedings, or specific licensing history related to the patents-in-suit.
Case Timeline
| Date | Event |
|---|---|
| 2006-10-13 | Earliest Priority Date for all Asserted Patents |
| 2018-09-13 | Article published describing Samsung's use of OpenStack |
| 2018-11-27 | U.S. Patent No. 10,140,452 Issues |
| 2019-01-01 | Start of Samsung's cloud transition period involving OpenStack |
| 2019-09-03 | U.S. Patent No. 10,402,568 Issues |
| 2020-08-25 | U.S. Patent No. 10,754,957 Issues |
| 2021-07-01 | Samsung Cloud Platform launch date mentioned in presentation |
| 2023-01-01 | End of Samsung's cloud transition period involving OpenStack |
| 2023-01-01 | OpenInfra Summit in Vancouver |
| 2026-05-19 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 10,402,568 - "Protecting Computing Devices From Unauthorized Access"
- Patent Identification: U.S. Patent No. 10,402,568, "Protecting Computing Devices From Unauthorized Access," issued September 3, 2019.
The Invention Explained
- Problem Addressed: The patent addresses the challenge of protecting sensitive corporate or enterprise data stored on mobile computing devices (e.g., smartphones, PDAs) that are often used outside of a secure corporate network and are vulnerable to loss, theft, or unauthorized access ʼ568 Patent, col. 1:51-61
- The Patented Solution: The invention describes a multi-tiered access control system that creates a secure, isolated "partition" or "container" on the mobile device to store enterprise data, separating it from the user's personal data '568 Patent, col. 4:12-20 Access to this enterprise partition is controlled by a remote server that verifies the device's integrity using a device authentication tool, such as a key or digital certificate, creating distinct "modes of operation" for accessing enterprise versus personal data '568 Patent, abstract '568 Patent, Fig. 1
- Technical Importance: This technology provides a framework for the "Bring Your Own Device" (BYOD) model, allowing enterprises to secure corporate assets on employee-owned devices without controlling the entire device.
Key Claims at a Glance
- The complaint asserts infringement of at least independent claim 1 Compl. Ex. B
- The essential elements of independent claim 1 are:
- A multi-tiered access control system comprising a plurality of mobile computing devices and a remote server.
- Each mobile device comprises a CPU, BIOS, memory, a native operating system, an interface to identify a user, and a plurality of access controls.
- The access controls include a program to authenticate the user, a "partition" to separate enterprise data from other data, a first mode permitting access to enterprise data, and a second mode permitting access to other data while excluding access to enterprise data.
- The access controls also include a "device authentication tool" (e.g., key or certificate).
- The remote server is configured to communicate with the mobile devices, attempt to "verify a characteristic or attribute" of the device, and "contemporaneously" "validate" the key or digital certificate.
- The complaint does not explicitly reserve the right to assert dependent claims.
U.S. Patent No. 10,140,452 - "Protecting Computing Devices From Unauthorized Access"
- Patent Identification: U.S. Patent No. 10,140,452, "Protecting Computing Devices From Unauthorized Access," issued November 27, 2018.
The Invention Explained
- Problem Addressed: The patent identifies a need for systems that can provide robust access control and disaster recovery for computing devices, especially those operating outside a secure environment, where the device's primary operating system (OS) cannot be trusted as the root of security '452 Patent, col. 2:30-48
- The Patented Solution: The invention proposes a system where a "virtual machine manager" (such as a hypervisor) is launched between the physical boot-up of a device and the launch of its main operating system '452 Patent, col. 19:4-7 This manager intercepts the boot process and communicates with a remote authentication server to verify the device's integrity before deciding whether to allow the main OS to launch and access secure data '452 Patent, col. 3:44-51 '452 Patent, Fig. 3 This establishes a trusted state before the potentially vulnerable OS is loaded.
- Technical Importance: This pre-boot authentication architecture provides a higher level of security assurance for nodes in a distributed system, a foundational concept for modern cloud computing and trusted execution environments.
Key Claims at a Glance
- The complaint asserts infringement of at least independent claim 1 Compl. Ex. D
- The essential elements of independent claim 1 are:
- A system comprising a distributed computer network, at least one protected computing device, a virtual machine manager, an authentication server, and a control console.
- The protected device has an OS and a virtual machine, and is configured to access secure data from a storage repository.
- The "virtual machine manager" is launched "between boot-up" of the device and "launch of said operating system".
- The manager causes the remote "authentication server" to provide "indicia" for authentication.
- The manager makes a "decision" based on the indicia whether to "launch or not launch" the operating system.
- The manager includes a "hypervisor" configured to control the launch decision.
- The complaint does not explicitly reserve the right to assert dependent claims.
U.S. Patent No. 10,754,957 - "Non-Transitory Computer Readable Medium for Creating a Virtual Machine Manager"
- Technology Synopsis: This patent addresses the secure provisioning of resources in a distributed computing system. It claims a non-transitory computer-readable medium containing instructions that, when executed, create a system that receives a request for a virtual machine (VM), communicates with an authentication server to verify the request, and then makes a decision to provide or deny the VM based on the authentication server's response '957 Patent, claim 6
- Asserted Claims: The complaint asserts infringement of at least independent claim 6 Compl. Ex. F
- Accused Features: The complaint alleges that Samsung's OpenStack platform infringes by its process of using components like the Horizon dashboard to request VMs and Keystone to authenticate those requests before Nova provisions the VM Compl. ¶64 Compl. ¶65
III. The Accused Instrumentality
- Product Identification: The complaint identifies two primary sets of accused instrumentalities:
- The Samsung Knox system, a mobile security platform embedded in Samsung mobile devices Compl. ¶10 Compl. ¶11
- Samsung's implementation of OpenStack, an open-source cloud computing platform, which is used in Samsung's virtualized Radio Access Network (vRAN) products for 5G networks and in the Samsung Cloud Compl. ¶20 Compl. ¶¶22-26
- Functionality and Market Context:
- Samsung Knox is described as a multi-layered security architecture on Samsung mobile devices, including phones and laptops Compl. ¶11 Compl. ¶14 Its key functionality involves creating a secure, isolated "workspace" or "container" to separate enterprise data from personal data, enforced by a hypervisor, secure boot processes, and remote attestation servers that communicate with the mobile devices Compl. ¶12 Compl. ¶15 Compl. ¶16 The complaint alleges Knox is used to secure the mobile devices of Samsung's own employees and is also offered for sale and licensed in the United States Compl. ¶19
- OpenStack is described as a distributed cloud computing platform used by Samsung for its 5G network offerings (vRAN) and its internal cloud infrastructure Compl. ¶20 The complaint details that this system runs network functions on general-purpose servers using virtualization, separating software from hardware Compl. ¶22 The architecture is alleged to comprise multiple computing devices across different network nodes, including controller nodes, compute nodes (e.g., Nova), and storage nodes, which are managed via components like the Horizon dashboard and authenticated via the Keystone identity service Compl. ¶33 Compl. ¶34 Compl. ¶37 Compl. ¶38 A diagram from a Samsung presentation shows its "Global Infrastructure" is based on 17 data centers, including several in the U.S., that support the Samsung Cloud Compl. ¶32
IV. Analysis of Infringement Allegations
'568 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A) a plurality of mobile computing devices... | Samsung's Knox system is alleged to secure over 2 billion Samsung devices, including mobile phones, which constitute a plurality of mobile computing devices Compl. Ex. B, p. 7 | ¶47 | col. 18:64-65 |
| [A7] a partition that separates said enterprise data from other data; | The Samsung Knox Workspace is alleged to be a "container" or "protected partition" that is designed to separate, isolate, and encrypt enterprise and work data from the user's personal data and applications outside the container Compl. Ex. B, p. 18 Compl. Ex. B, p. 19 Compl. Ex. B, p. 20 An included diagram illustrates the separation between the "PERSONAL ENRVIRONMENT" and "KNOX WORKSPACE ENRVIRONMENT" Compl. Ex. B, p. 21 | ¶48 | col. 19:16-17 |
| [A10] a device authentication tool comprising at least one of a key or a digital certificate; and | Samsung Knox allegedly utilizes a "Device Root Key (DRK)," described as a device-unique asymmetric key signed by a Samsung-issued X.509 certificate, which is injected into the device at manufacture and used for device attestation Compl. Ex. B, p. 27 | ¶48 | col. 19:25-26 |
| B) a remote server configured to communicate with each of said plurality of said mobile computing devices... | Samsung Knox is alleged to employ a remote server for system administration, such as an Enterprise Mobility Management (EMM) server, which communicates with and manages the Samsung mobile devices, including through remote attestation Compl. Ex. B, p. 31 Compl. Ex. B, p. 32 | ¶47 | col. 19:27-29 |
| [B1] said server is configured to attempt to verify a characteristic or attribute of said at least one mobile computing device, and | The remote server allegedly uses "Remote Device Health Attestation" to detect unauthorized modifications like rooting. This is based on Trusted Boot, which collects measurement data to verify the integrity of the device platform Compl. Ex. B, p. 33 | ¶48 | col. 19:30-32 |
| [B2] said server is further configured to validate at least one of said key or said digital certificate...contemporaneously with said attempt to verify... | The remote server allegedly validates the device's integrity by verifying the signature of the attestation data, which is signed with an Attestation Certificate that is in turn signed by the Device Root Key (DRK) and a Samsung root key via an X.509 certificate Compl. Ex. B, p. 36 | ¶48 | col. 19:33-38 |
'452 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| (a) a distributed computer network comprising multiple computing devices at multiple locations... | Samsung's OpenStack deployment is alleged to be a distributed network of controller, compute, and storage nodes operating as physical devices at separate locations, as shown in a network diagram Compl. Ex. D, p. 7 A presentation slide shows this infrastructure distributed across 17 global data centers Compl. ¶32 | ¶56 | col. 18:58-60 |
| (b) at least one protected computing device at a first location...to access secure data from a secure data storage repository at a second location; | The OpenStack Nova compute nodes are alleged to be "protected computing devices" that are secured through hardening, network isolation, and access controls. These nodes are configured to communicate with storage controller nodes (e.g., Cinder, Swift) to access data from separate storage repositories Compl. Ex. D, p. 7 Compl. Ex. D, p. 11 | ¶56 | col. 18:61-65 |
| (d) said virtual machine manager...configured to be launched between boot-up of said at least one protected computing device and launch of said operating system; | The "virtual machine manager" is alleged to be the Nova service software stack, including the hypervisor (e.g., KVM). This manager is allegedly launched after the physical boot of the server (the Nova compute node) but before the launch of the guest operating system (OS) running on the virtual machine that Nova provisions Compl. Ex. D, p. 16 | ¶56 | col. 19:4-7 |
| (e) an authentication server located remotely from said at least one protected computing device and configured for authenticating said at least one protected computing device for access to said secure data; | The OpenStack Keystone identity service is alleged to be the "authentication server." It runs on a dedicated controller node, remote from the Nova compute nodes, and is configured to provide authentication tokens that control access to other services and data resources Compl. Ex. D, p. 21 Compl. Ex. D, p. 22 | ¶56 | col. 19:8-11 |
| (h) said virtual machine manager configured to make a decision based on said indicia from said authentication server whether to allow...to either launch or not launch said operating system based upon whether said...device is either authenticated or not... | The Nova service (as the "virtual machine manager") allegedly enforces token-based authentication. If "nova-compute" receives a valid token from Keystone, it proceeds with the API calls to launch the VM/guest OS. If it does not have a valid token, it will not and cannot instantiate the VM/guest OS, thereby making a launch/no-launch decision based on authentication Compl. Ex. D, p. 34 A diagram illustrates the workflow where Keystone authentication (step 3) precedes the launch request to the hypervisor (step 18) Compl. Ex. D, p. 30 Compl. Ex. D, p. 31 Compl. Ex. D, p. 35 | ¶56 | col. 19:19-34 |
- Identified Points of Contention:
- Scope Questions: The case may raise questions about the scope of patent terms originating from a specific architecture ("Kylie™") when applied to general-purpose commercial platforms. For the '568 Patent, a question is whether Samsung's "container" is a "partition" as contemplated by the patent. For the '452 Patent, a core question is whether the collection of distributed OpenStack services (Nova, Keystone, Horizon) collectively functions as the claimed "virtual machine manager" that is launched "between boot-up" and OS launch.
- Technical Questions: An infringement analysis may focus on the specific sequence of operations. For the '452 Patent, a technical question is whether the boot sequence of an OpenStack compute node and the subsequent provisioning of a VM by Nova follows the exact "boot-up -> manager launch -> OS launch" sequence required by claim 1(d), or if there is a technical distinction in the timing and nature of how the components are activated. For the '568 patent, a question is whether the remote server's verification of an attestation signature ("validate at least one of said key") occurs "contemporaneously" with its verification of device measurements ("verify a characteristic"), as required by claim 1[B2].
V. Key Claim Terms for Construction
From U.S. Patent 10,402,568 (Asserted Claim 1)
- The Term: "partition that separates said enterprise data from other data"
- Context and Importance: This term is central to the invention's security model. The definition of "partition" will determine whether a purely logical software construct like a container, which operates within the main OS, meets the claim limitation, or if a more robust, hardware-assisted separation is required.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification of the parent '452 patent, incorporated by reference, describes protected partitions as potentially being "files, protected areas, protected datasets, defined areas within a file system, physical drives, directories, bits, and areas of memory, among others" '452 Patent, col. 4:66-col. 5:2 This language may support a broader, more logical definition.
- Evidence for a Narrower Interpretation: The figures and description in the related patents emphasize technologies like TrustZone and hypervisors, which provide hardware-level isolation '568 Patent, Fig. 1 A party might argue that a true "partition" requires this level of hardware-enforced separation, rather than just a software container running on top of the main OS.
From U.S. Patent 10,140,452 (Asserted Claim 1)
- The Term: "virtual machine manager"
- Context and Importance: This term defines the core component that enforces the pre-boot security check. The complaint maps this term to the distributed OpenStack Nova service. Whether this mapping is correct depends on how broadly the term is construed. Practitioners may focus on this term because the patent's original embodiment appears to be a single, pre-OS hypervisor on a client device, whereas the accused product is a distributed cloud management system.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The abstract states the invention uses "hypervisors and other virtual machine monitors or managers," suggesting the term is not limited to a specific type of hypervisor '452 Patent, abstract The claims define the "manager" by its function-launching pre-OS and making an authentication-based decision-which may support an interpretation covering any set of components that performs this function.
- Evidence for a Narrower Interpretation: The patent's workflow diagrams depict a singular entity ("Kylie™ Hypervisor") being launched "PRE-OS BOOT" on a client device '452 Patent, Fig. 3 This could support a narrower construction requiring a monolithic software component launched at a specific point in a single device's boot sequence, which may not align with the distributed, service-based nature of OpenStack's Nova component.
VI. Other Allegations
- Indirect Infringement: The complaint does not plead separate counts for indirect or contributory infringement. The infringement counts are limited to direct infringement under 35 U.S.C. § 271(a) Compl. ¶47 Compl. ¶56 Compl. ¶64
- Willful Infringement: The complaint does not contain allegations of willful infringement or pre-suit knowledge of the patents.
VII. Analyst's Conclusion: Key Questions for the Case
This dispute appears to center on the application of patent claims, which describe a specific security architecture, to widely-used, general-purpose commercial technologies (Android and OpenStack). The key questions for the court will likely be:
- A central issue will be one of technical mapping: Does the distributed, service-oriented architecture of Samsung's OpenStack implementation, involving components like Nova and Keystone, function as the claimed pre-boot "virtual machine manager" that makes a launch/no-launch decision, or is there a fundamental mismatch between the patent's client-centric architecture and the accused cloud platform?
- A related question is one of claim scope: Can the term "partition" in the '568 patent, rooted in the context of creating a secure zone on a mobile device, be construed to read on the "Knox Workspace" software container, and can "virtual machine manager" in the '452 patent be construed to cover a collection of distributed cloud services rather than a single pre-boot hypervisor?
- An evidentiary question will be one of operational sequence: What evidence will be presented to demonstrate that the accused systems perform the specific, sequential steps required by the claims? For instance, does Samsung's remote attestation process for Knox meet the "verify" and "contemporaneously... validate" steps of claim 1 of the '568 patent, or is there a temporal or functional separation that takes it outside the claim?
Analysis metadata
Loading Complaint
Suggested improvements