DCT

2:26-cv-00643

Congruent Media Resourcing LLC v. Silverfort Inc

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:26-cv-00643, E.D. Tex., 07/30/2026
  • Venue Allegations: Venue is alleged to be proper based on Defendant maintaining a place of business within the Eastern District of Texas.
  • Core Dispute: Plaintiff alleges that Defendant's identity security platform infringes a patent related to methods for creating secure applications by modifying a target application to enforce new security behaviors.
  • Technical Context: The lawsuit is situated in the cybersecurity field, specifically concerning the protection of enterprise identity and access management (IAM) systems by modifying application behavior at runtime to prevent unauthorized access.
  • Key Procedural History: The complaint does not mention any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the patent-in-suit.

Case Timeline

Date Event
2011-10-10 '418 Patent Priority Date
2015-09-15 '418 Patent Issue Date
2026-07-30 Complaint Filing Date

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 9,135,418 - "System and Method for Creating Secure Applications"

  • Patent Identification: U.S. Patent No. 9,135,418, "System and Method for Creating Secure Applications," issued September 15, 2015.

The Invention Explained

  • Problem Addressed: The patent's background section describes the security risks enterprises face when employees use personal mobile devices for work, as malware on the device could compromise sensitive corporate data '418 Patent, col. 1:21-42 IT departments are described as having limited means to manage and secure these "Bring Your Own Device" (BYOD) environments '418 Patent, col. 1:31-34
  • The Patented Solution: The invention provides a method for transforming a standard, pre-compiled "target application" into a "secure application" without access to its original source code '418 Patent, col. 1:61-64 This is achieved through a process, sometimes called "wrapping," that programmatically inserts "intercepts" into the application '418 Patent, col. 1:55-57 These intercepts modify the application's behavior to enforce security policies, and the modified application is then "repackaged" as a new, secure entity '418 Patent, col. 2:4-10 '418 Patent, Fig. 10
  • Technical Importance: The described technology offers a way to retroactively apply security controls to existing applications, addressing a key challenge in enterprise security where source code for third-party software is unavailable.

Key Claims at a Glance

  • The complaint asserts independent claim 1 Compl. ¶16
  • The essential elements of Claim 1 are:
    • A method of operating a secure application, comprising: receiving a request to activate the secure application, wherein the secure application was created from a target application with a first behavior and now has a second, imposed behavior.
    • In response to the request, forcing the secure application to override the first behavior with the second behavior, where the second behavior takes priority.
    • Via a processing unit, performing the second application behavior.
  • The complaint does not explicitly reserve the right to assert dependent claims.

III. The Accused Instrumentality

Product Identification

  • The Silverfort Identity Security Platform ("Accused Instrumentality") Compl. ¶16

Functionality and Market Context

  • The Accused Instrumentality is described as a security platform that integrates with a customer's existing Identity and Access Management (IAM) infrastructure to provide "inline protection to each identity" Compl. ¶17
  • It operates by intercepting authentication requests forwarded from the IAM infrastructure, analyzing them for risk, and then triggering security controls (the "second application behavior") such as enforcing multi-factor authentication or blocking the access attempt Compl. p. 7
  • To do this, the platform allegedly builds a "behavioral baseline" for accounts and uses it to detect anomalies and enforce "adaptive policies" that override unexpected or insecure behavior Compl. ¶19 The complaint presents this as a runtime protection solution for enterprise identity systems Compl. ¶17

IV. Analysis of Infringement Allegations

'418 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
receiving a request to activate the secure application through an input device, wherein the secure application was created from a target application having a first set of functions associated with a first application behavior and the secure application has a second set of functions that are imposed on the first set of functions and that are associated with a second application behavior: A user's access request from an IAM infrastructure is alleged to be the "request to activate." The complaint alleges the Silverfort platform is the "secure application," created from the "target application" (the underlying, unsecured authentication process) by imposing a second set of functions (security policies) Compl. p. 7 ¶18 col. 6:20-27
in response to the receipt of the request, forcing the secure application to override the first application behavior with the second application behavior, wherein the second application behavior takes priority over the first application behavior; The platform provides an automated response that "detects, redacts, blocks, or redirects malicious activity." This is alleged to be the override of the first (unsecured) behavior. The complaint points to Silverfort's mechanism of building a baseline and enforcing policies that permit only expected behavior (Compl. p. 9). ¶19 col. 6:27-30
and via a processing unit, performing the second application behavior. The Silverfort platform allegedly performs the second behavior by enforcing "adaptive policies and virtual fences" to block deviations in real-time. The complaint presents a screenshot of authentication logs showing "Silverfort's action" (e.g., "MFA Denied") as evidence of this step being performed (Compl. p. 12). ¶20 col. 6:30-31
  • Identified Points of Contention:
    • Scope Questions: A potential dispute may arise over whether the term "secure application", as described in the patent (e.g., a repackaged, modified software file), can be read to cover the accused Silverfort platform, which is a distributed service that integrates with, but is separate from, a customer's IAM system. The complaint's theory appears to treat the combination of the original authentication system and the Silverfort overlay as the "secure application."
    • Technical Questions: The analysis may turn on what constitutes the "target application" in the context of the accused system. The patent describes a concrete process of decomposing and modifying a specific application '418 Patent, Fig. 11 The court may need to determine if Silverfort's functional integration with an IAM system-without structurally modifying the IAM software itself-satisfies the "created from a target application" limitation.

V. Key Claim Terms for Construction

  • The Term: "secure application"

  • Context and Importance: The definition of this term is central, as the entire method of Claim 1 is directed to "operating a secure application." The infringement case depends on whether the accused Silverfort platform, in whole or in part, qualifies as a "secure application" under the patent's definition.

  • Intrinsic Evidence for Interpretation:

    • Evidence for a Broader Interpretation: The patent mentions the creation of "secure workspaces" and "virtual partitions," which could suggest that "application" is not limited to a single executable file but can encompass a broader secure environment or system '418 Patent, col. 1:17-18 '418 Patent, col. 15:26-30
    • Evidence for a Narrower Interpretation: The specification repeatedly describes the creation process as taking a "target application," modifying it, and "repackaging" it into an "immutable deployable entity" '418 Patent, col. 2:4-10 Detailed examples focus on modifying application files through byte-code injection or linking, which may support a narrower construction limited to a self-contained, modified software package '418 Patent, col. 22:45-59
  • The Term: "created from a target application"

  • Context and Importance: This term defines the required relationship between the original software and the infringing "secure application." Plaintiff's theory appears to be that the Silverfort platform is functionally "created from" the default, unsecured authentication process. Defendant may argue its platform is an independent system that merely interacts with the authentication process, rather than being "created from" it in the manner described by the patent.

  • Intrinsic Evidence for Interpretation:

    • Evidence for a Broader Interpretation: The patent states the modification occurs by "binding one or more intercepts to the target application," which could be interpreted as a functional linkage rather than a purely structural one '418 Patent, col. 1:55-57
    • Evidence for a Narrower Interpretation: The detailed description and figures illustrate a specific technical process of disassembly, code injection, and repackaging '418 Patent, Fig. 10 '418 Patent, Fig. 11 This evidence may support a definition requiring direct structural modification of the target application's files, not merely a functional overlay by an external service.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges both induced and contributory infringement Compl. ¶¶21-23 The factual basis for inducement is Defendant's alleged provision of the Accused Instrumentality to customers along with marketing materials, user guides, and support that instruct on its infringing use, allegedly with knowledge and intent Compl. ¶¶21-22 The platform is also alleged to be a non-staple article of commerce adapted for infringement Compl. ¶23
  • Willful Infringement: The complaint does not contain a separate count for willful infringement but alleges Defendant has knowledge of its infringement "at least as of the date of the service of the Original Complaint" and continues to induce infringement Compl. ¶22 This pleading may form the basis for a claim of post-suit willfulness and a request for enhanced damages under 35 U.S.C. § 284.

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue will be one of definitional scope: can the term "secure application", which the patent repeatedly describes as a single, repackaged software entity, be construed to cover Defendant's distributed security platform that operates in concert with a separate enterprise IAM system?

  • A key evidentiary question will be one of technical mapping: does Silverfort's platform, which monitors and applies policies to authentication requests, meet the "created from a target application" limitation? The case may turn on whether this claim language requires the direct structural modification and repackaging process detailed in the patent's specification, or if a functional overlay is sufficient.

Loading Complaint