DCT

2:26-cv-00490

Arc Link LLC v. Sophos Ltd

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:26-cv-00490, E.D. Tex., 06/18/2026
  • Venue Allegations: Venue is alleged to be proper because the Defendant is not a resident of the United States and may therefore be sued in any judicial district.
  • Core Dispute: Plaintiff alleges that Defendant's networking and cybersecurity products, including wireless access points, virtual firewalls, and threat detection platforms, infringe four U.S. patents covering technologies for network optimization, virtualized network monitoring, and AI-based risk identification.
  • Technical Context: The technologies at issue relate to the management and security of modern IT infrastructure, spanning Wi-Fi performance optimization, cloud network virtualization, and AI-driven cybersecurity threat analysis.
  • Key Procedural History: The complaint does not allege any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the patents-in-suit.

Case Timeline

Date Event
2006-02-08 '592 Patent Priority Date
2012-06-12 U.S. Patent No. 8,200,592 Issued
2013-04-11 '328 Patent Priority Date
2016-07-01 '548 Patent Priority Date
2017-01-17 U.S. Patent No. 9,549,328 Issued
2017-01-24 U.S. Patent No. 9,552,548 Issued
2020-04-28 '655 Patent Priority Date
2023-01-24 U.S. Patent No. 11,563,655 Issued
2025-01-14 Accused Product (Sophos Firewall) Documentation Date
2025-03-04 Accused Product (Sophos Firewall) Documentation Date
2026-06-11 Accused Product (Sophos Email Security) Documentation Date
2026-06-18 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 9,549,328 - "Method to Optimize the Communication Parameters Between an Access Point and at Least One Client Device"

The Invention Explained

  • Problem Addressed: In dense wireless environments, numerous Wi-Fi networks must share a limited radio spectrum, causing interference that degrades performance, while default channel settings are often suboptimal ʼ328 Patent, col. 1:16-30
  • The Patented Solution: The patent describes a decentralized method for a wireless access point (AP) to automatically optimize its channel selection. The AP monitors interference on its current channel, temporarily samples a potential new channel (defined by a different center frequency and/or bandwidth), compares the interference levels of the two channels, and decides whether to switch to the new channel or even switch back to the original one ʼ328 Patent, abstract ʼ328 Patent, col. 7:30-49 This process is designed to run online without disrupting network traffic.
  • Technical Importance: The invention provides a practical, decentralized mechanism for commodity Wi-Fi hardware to self-organize in crowded radio environments, thereby improving overall network capacity and fairness without requiring a central controller ʼ328 Patent, col. 2:6-14

Key Claims at a Glance

  • The complaint asserts at least independent claim 1 Compl. ¶22
  • The essential elements of independent claim 1 include:
    • Establishing a connection on a first channel with a first center frequency and bandwidth.
    • Exchanging data on the first channel.
    • Monitoring a first interference level on the first channel.
    • Reviewing compatibility levels of client devices to determine their ability to switch channels.
    • Instructing client devices to switch to a second channel only if they are all compatible.
    • Determining a second interference level on the second channel.
    • Comparing the first and second interference levels.
    • Deciding whether to switch back to the first channel based on the comparison.
  • The complaint does not explicitly reserve the right to assert dependent claims but makes broad allegations against "one or more claims" Compl. ¶21

U.S. Patent No. 11,563,655 - "Network Monitoring Apparatus and Method Thereof in Programmable Network Virtualization"

The Invention Explained

  • Problem Addressed: In a virtualized network environment where multiple virtual networks (VNs) from different tenants operate on a single shared physical network, it is difficult to monitor the performance of each individual VN. Standard monitoring tools typically provide statistics for the entire physical infrastructure, not for each isolated tenant network '655 Patent, col. 3:31-41 '655 Patent, col. 4:26-30
  • The Patented Solution: The patent discloses a "network hypervisor" containing a "statistics virtualization module." This module is designed to receive requests for statistics for a specific VN, determine which physical resources are shared, and then "isolatedly provide individual physical resource consumption statistics" to that VN. This allows each tenant to see performance data (like flow and port statistics) for its own virtual network, separate from others sharing the same hardware '655 Patent, abstract '655 Patent, col. 5:10-26
  • Technical Importance: This technology enables effective multi-tenancy in cloud computing and data centers by providing each network tenant with the necessary visibility to manage, troubleshoot, and optimize its own slice of the virtualized network '655 Patent, col. 4:56-65

Key Claims at a Glance

  • The complaint asserts at least independent claim 1 Compl. ¶41
  • The essential elements of independent claim 1 include:
    • A computing apparatus with a network hypervisor for SDN-based network virtualization.
    • A statistics virtualization module configured to:
    • Receive a request for statistics for a first virtual network.
    • Determine if a physical resource is shared between the first virtual network and another.
    • "Isolatedly provide" individual statistics to the first virtual network based on that determination.
    • The module provides both "virtual flow entry statistics" and "virtual port statistics" for the first virtual network.
  • The complaint does not explicitly reserve the right to assert dependent claims but makes broad allegations against "one or more claims" Compl. ¶40

U.S. Patent No. 8,200,592 - "System and Method for Modeling Multilabel Classification and Ranking"

  • Technology Synopsis: The patent describes a method for creating a detection model used in machine condition monitoring. The model addresses scenarios where an event can have multiple labels by ranking the labels and inserting a "zero-point" to create a calibrated cutoff between what is considered a "relevant" state (e.g., an actionable alert) and a "non-relevant" state (e.g., background noise) '592 Patent, abstract '592 Patent, col. 2:6-11
  • Asserted Claims: At least claim 20 Compl. ¶54
  • Accused Features: The Sophos Central XDR platform is accused of using a "calibrated label ranking model" to monitor telemetry from various sensors, evaluate machine conditions, and separate actionable security incidents from non-actionable ones, thereby allegedly practicing the "zero-point" method Compl. ¶¶55-57

U.S. Patent No. 9,552,548 - "Using Classified Text and Deep Learning Algorithms to Identify Risk and Provide Early Warning"

  • Technology Synopsis: The technology involves a system that uses deep learning for early risk detection within an enterprise. The system is first trained using datasets of classified text (e.g., documents from prior lawsuits). It then applies the trained algorithms to scan internal electronic communications (e.g., employee emails) to identify and report potential risks, such as litigation risk, before they escalate into actual harm '548 Patent, abstract '548 Patent, col. 1:40-52
  • Asserted Claims: At least claim 17 Compl. ¶68
  • Accused Features: Sophos Email Security products are accused of infringing by using trained AI and deep learning algorithms to analyze enterprise emails. The complaint alleges these products are trained on threat intelligence data ("training datasets") and then applied to emails to identify risks like phishing and malware ("threats or risks of interest") Compl. ¶¶69-72

III. The Accused Instrumentality

Product Identification

The accused instrumentalities are grouped into four categories corresponding to the asserted patents:

  1. Wireless Networking: Sophos AP6 and APX Series access points, managed by Sophos Central Wireless and related firmware Compl. ¶21
  2. Virtual Firewalls: Sophos Firewall (v21.0 and later) deployed as virtual, cloud, or software appliances, particularly the Sophos Firewall Virtual Appliance for VMware ESXi Compl. ¶40
  3. Threat Detection & Response: Sophos Central XDR, Sophos Intercept X with XDR, and related platforms Compl. ¶53
  4. Email Security: Sophos Email Security, Sophos Email Advanced, and related products Compl. ¶67

Functionality and Market Context

The complaint alleges these products form a significant part of Defendant's portfolio for enterprise and cloud networking and security. The wireless products provide Wi-Fi connectivity with automated channel management features designed to optimize performance in congested environments (Compl. ¶¶21; Compl. ¶23). The complaint includes a screenshot from Sophos documentation illustrating automatic channel width selection options like "Auto 80/40/20 MHz" Compl. p. 7 The virtual firewall products provide network security for virtualized environments, such as those running on VMware ESXi, and are managed via the Sophos Central platform Compl. ¶42 A screenshot provided in the complaint shows that the Sophos Firewall virtual appliance can be deployed in a VMware ESX or ESXi environment Compl. p. 13 The XDR and Email Security products use AI and machine learning to analyze data from across an enterprise network to detect, classify, and report on security threats Compl. ¶¶55-57 Compl. ¶¶69-70 A screenshot of the Sophos XDR "Detections" dashboard shows a bar chart and list of threats classified by severity Compl. p. 20

IV. Analysis of Infringement Allegations

'328 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
establishing by the access point a connection with the client devices on a first channel having a first center frequency and a first bandwidth The Sophos AP6 840E access point establishes a connection with Wi-Fi client devices on a selected wireless channel for an SSID, which has a selected radio band, channel, and bandwidth. ¶23 col. 17:40-45
monitoring by the access point a first interference level on the first channel The Sophos AP6 840E performs wireless-channel monitoring, channel-selection logic, and interference-based channel-width selection to evaluate channel conditions. ¶25 col. 17:49-50
reviewing compatibility levels to the access point from the client devices, a compatibility level for a client device defining whether the client device is able to dynamically switch... The access point reviews client-device wireless capabilities, supported radio bands, and supported channel behavior to determine if a client can operate on a target wireless band or channel. ¶26 col. 17:51-61
instructing the client devices to switch to a second channel... only if all compatibility levels for all client devices indicate that all client devices are able to dynamically switch... The access point causes an automatic channel change or wireless-radio channel reselection, causing compatible client devices to operate on a different selected channel. ¶27 col. 17:62-18:2
determining by the access point a second interference level on the second channel The access point assesses or monitors wireless-channel conditions associated with an alternative selected channel or channel width. ¶28 col. 18:3-5
comparing by the access point the first interference level with the second interference level The access point uses load balancing, band steering, or automatic channel-selection logic to compare wireless-channel conditions to identify a preferred channel. ¶29 col. 18:6-8
deciding by the access point whether to switch back to the first channel based on the comparison The access point's wireless-radio channel-management logic evaluates whether to remain on the current channel, switch to another channel, or return to a prior channel based on monitored conditions. ¶30 col. 18:9-12
  • Identified Points of Contention:
    • Technical Question: Claim 1 requires a specific decision step to "switch back to the first channel." The complaint alleges this is met by logic that evaluates whether to "return to a prior channel" Compl. ¶30 A central question for the court will be whether the accused "Auto channel" feature Compl. p. 8, which appears to periodically select the "best channel," performs this specific "switch back" function, or if it simply re-runs its optimization algorithm without a memory of the "first channel" as distinct from any other potential channel.
    • Scope Question: The claim recites "reviewing compatibility levels" that define "whether the client device is able to dynamically switch." The complaint maps this to a general review of "client-device wireless capabilities" Compl. ¶26 It will be a point of dispute whether this general capability review meets the claim's more specific functional requirement of a level that "defin[es]" the ability and willingness to switch.

'655 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
A computing apparatus implemented with a network hypervisor implementing software defined network (SDN)-based network virtualization... A Sophos Firewall virtual appliance deployed as a virtual machine within a VMware ESXi, NSX, and/or vSphere environment, where the VMware environment provides virtualized network resources. ¶42 col. 1:19-25
a statistics virtualization module configured to... determine whether the at least one physical resource is shared between the first virtual network and at least one other... The module determines whether resources like shared ESXi host hardware, shared CPU, shared memory, or shared physical NICs are used by multiple virtual interfaces, zones, or subnets. ¶42 col. 13:53-57
and isolatedly provide individual physical resource consumption statistics to the first virtual network based on the determination whether the at least one physical resource is shared The module provides per-interface, per-zone, per-VLAN, or per-rule statistics associated with a particular virtualized context, rather than statistics for the underlying physical server as a whole. A screenshot shows Sophos marketing material for its AI-powered email protection (Compl. p. 24). ¶42 col. 13:58-62
wherein the statistics virtualization module provides respective virtual flow entry statistics to the first virtual network... and provision of virtual port statistics... for the first virtual network The module provides flow-related telemetry (e.g., connection and session information, firewall-rule logs) and virtual port statistics (e.g., virtual-interface traffic counters) for a specific virtual network, zone, or port group. ¶43 col. 14:1-23
  • Identified Points of Contention:
    • Scope Question: Claim 1 recites a "computing apparatus implemented with a network hypervisor." The complaint accuses a Sophos virtual appliance that runs as a guest on a third-party hypervisor (VMware ESXi) Compl. ¶42 A primary legal question will be whether a guest application can be considered an "apparatus implemented with a network hypervisor," or if this claim language requires the accused apparatus to be the hypervisor itself.
    • Technical Question: The claim requires the module to actively "determine whether the at least one physical resource is shared." The complaint alleges this occurs Compl. ¶42 but does not provide details on how the Sophos product performs this determination. The court may need to consider whether the accused product actively makes this determination or merely reports on conditions established and managed by the underlying VMware platform, which may not satisfy the claim element.

V. Key Claim Terms for Construction

'328 Patent

The Term

"deciding by the access point whether to switch back to the first channel"

Context and Importance

This final step of claim 1 is critical because it suggests a specific, stateful decision process beyond simple, periodic optimization. Practitioners may focus on this term because standard "auto channel" features typically find the "best" channel at a given moment, whereas the claim implies a memory of a prior state ("the first channel") and a specific decision to "switch back" to it.

Intrinsic Evidence for Interpretation

  • Evidence for a Broader Interpretation: The specification discusses a Metropolis sampler, which involves accepting or rejecting a new state based on a probability function '328 Patent, col. 7:1-12 This could be argued to encompass any decision-making process that compares a current state to a potential new state.
  • Evidence for a Narrower Interpretation: The plain language of the claim, "switch back to the first channel," suggests a three-part process: (1) operate on channel A, (2) move to channel B, (3) decide whether to return specifically to channel A. This is more specific than a generic algorithm that, while on channel B, simply decides to move to channel C, which might happen to be the same as A.

'655 Patent

The Term

"isolatedly provide"

Context and Importance

This term captures the essence of the invention-providing per-tenant statistics. The infringement case hinges on whether the accused firewall's per-interface or per-zone reporting Compl. ¶42 meets the claimed "isolatedly provide" function, which is explicitly linked to a "determination" about shared resources.

Intrinsic Evidence for Interpretation

  • Evidence for a Broader Interpretation: The patent's abstract describes the invention as providing "individual statistics to each of created virtual networks." This might support an argument that any non-aggregated, per-tenant reporting satisfies the limitation.
  • Evidence for a Narrower Interpretation: Claim 1 recites "isolatedly provide...based on the determination whether the at least one physical resource is shared." This language suggests a direct causal link. A narrower construction would require proof that the accused product first performs the "determination" step and, as a result of that determination, then provides the statistics in an "isolated" manner. Simply providing segregated reports may not be sufficient without this logical connection.

VI. Other Allegations

Indirect Infringement

The complaint alleges both induced and contributory infringement for all four patents-in-suit. The inducement allegations are based on claims that Sophos provides instructions, product literature, and websites that encourage and facilitate infringing use by customers and end-users Compl. ¶34 Compl. ¶47 Compl. ¶61 Compl. ¶77 The contributory infringement allegations assert that the accused components are material to the inventions, are not staple articles of commerce, and are known by Sophos to be specially made or adapted for infringing use Compl. ¶35 Compl. ¶48 Compl. ¶62 Compl. ¶78

Willful Infringement

The complaint alleges willful infringement based on a theory of willful blindness. It asserts that Sophos has a policy of not reviewing the patents of others in its industry, and therefore remained willfully blind to the patents-in-suit starting from their issue dates Compl. ¶33 Compl. ¶46 Compl. ¶60 Compl. ¶76 Knowledge is also alleged as of the date of the complaint.

VII. Analyst's Conclusion: Key Questions for the Case

  1. An Architectural Mismatch Question: A core issue for the '655 patent will be one of architectural scope: can the Sophos Firewall, a virtual appliance that operates as a guest on a third-party hypervisor, be construed as a "computing apparatus implemented with a network hypervisor" as required by the claim?
  2. A Functional Equivalence Question: For the '328 patent, a key evidentiary question will be whether the accused products' "Auto channel" optimization feature, which appears to periodically select a "best" channel, performs the specific, state-aware "deciding...whether to switch back" function recited in the claim, or if there is a fundamental mismatch in their technical operation.
  3. A Specificity vs. Generality Question: For the '592 and '548 patents, the case will likely turn on claim construction: do the claims, which recite a "calibrated label ranking model predicting a zero-point label" and a method of training deep learning algorithms on classified text, cover the specific implementations in Sophos's security products, or are the claims written at a level of generality that they read on now-conventional uses of AI/ML in the cybersecurity field?
Loading Complaint