2:26-cv-00744
AAA Internet Publishing Inc v. JPMorgan Chase & Co
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: AAA Internet Publishing Inc., d/b/a WTFast (British Columbia, Canada)
- Defendant: JPMorgan Chase & Co. and JPMorgan Chase Bank, N.A. (Delaware/New York)
- Plaintiff's Counsel: Cole Schotz Dallas.
- Case Identification: 2:26-cv-00744, E.D. Tex., 08/25/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Defendant conducts business, offers products and services, and maintains a regular and established place of business in the district, including a major office campus in Plano, Texas, that employs over 12,000 people.
- Core Dispute: Plaintiff alleges that Defendant's online and mobile banking platforms infringe a patent related to methods for securing online accounts by comparing device-specific identifiers and geographic location data.
- Technical Context: The lawsuit operates in the domain of digital security and multi-factor authentication, a field of critical importance to the financial services industry for protecting customer accounts from unauthorized access and fraud.
- Key Procedural History: The patent-in-suit, RE47,533, is a reissue of U.S. Patent No. 9,087,183. The prosecution history of both the original patent and the reissue proceeding may be relevant to interpreting the scope and validity of the asserted claims.
Case Timeline
| Date | Event |
|---|---|
| 2006-10-04 | '533 Patent Priority Date |
| 2015-07-21 | U.S. Patent No. 9,087,183 (Original Patent) Issued |
| 2017-05-24 | Application for Reissue ('533 Patent) Filed |
| 2019-07-23 | U.S. Patent No. RE47,533 (Reissue Patent) Issued |
| 2026-08-25 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Reissue Patent No. RE47,533 - "Method and System of Securing Accounts"
- Patent Identification: U.S. Reissue Patent No. RE47,533 ("Method and System of Securing Accounts"), issued July 23, 2019 (the "'533 Patent").
The Invention Explained
- Problem Addressed: The patent's background describes weaknesses in then-existing online authentication methods. These methods often forced a trade-off between security and user convenience, requiring users to install special software, accept unwanted cookies, or pre-register every device they wished to use for account access '533 Patent, col. 2:30-3:11
- The Patented Solution: The invention proposes a server-side security system that does not require special client-side software. When a user attempts to log in, the server determines "unique profile identifiers" of the accessing computer (e.g., hardware serial numbers, MAC address) and its "geographic location" (derived from its IP address). It then compares this information to a set of trusted identifiers and locations previously associated with the user's account in a database. A mismatch can trigger a denial of access or a request for further user verification '533 Patent, col. 3:33-47 '533 Patent, col. 4:39-62
- Technical Importance: The described technology sought to enhance security by "binding" an account to a user's specific devices without the friction of requiring users to manually install software or manage device registration lists.
Key Claims at a Glance
- The complaint asserts infringement of "at least claim 13" of the '533 Patent Compl. ¶50 Claim 13 is an independent claim.
- The essential elements of independent Claim 13 include:
- Storing at least one "profile identifier" and a "geographic location" associated with a user account in a database.
- Detecting an access attempt from a computer and determining the computer's own profile identifier and geographic location.
- Comparing the computer's identifier and location with those stored for the account.
- Permitting access if both the identifier and the location match the stored information.
- Communicating with the user to determine if access should be permitted if the computer's identifier is different from the stored identifier.
- Reporting the computer's identifier and location to an administrator if both are different from the stored information.
- Defining the "profile identifier" as being selected from a large group of hardware and software attributes, including CPU serial numbers, MAC addresses, and various unique identifiers (UUIDs/GUIDs).
- The complaint alleges infringement of one or more of Claims 1-19, reserving the right to assert additional claims Compl. ¶48
III. The Accused Instrumentality
Product Identification
- The "Accused System" is identified as the security features of Defendant's "Chase Online Platforms," which include the Chase.com website and the Chase Mobile application Compl. ¶31
Functionality and Market Context
- The complaint alleges the Accused System is designed to protect customer accounts from unauthorized access. The system is described as employing "Safeguards against suspicious activity" and "Additional validation checks" Compl. ¶32 A screenshot from Defendant's website explains that when an "unusual login or account activity" is seen, the system uses "additional validation checks like mobile app notifications or one time code to authenticate" the user Compl. p. 19 The complaint alleges that to do this, the Accused System captures and stores device information (such as IP address, operating system, and browser information) and location data associated with a user's account Compl. ¶36 Compl. ¶37 This functionality is positioned as a critical security measure for protecting customer assets and data Compl. ¶31
IV. Analysis of Infringement Allegations
The complaint alleges that the Accused System performs the steps recited in the asserted claims. A central part of the allegation is that when a user attempts to log in, the Accused System compares the characteristics of the device being used against a profile of trusted devices and locations associated with that user's account.
RE47,533 Patent Infringement Allegations
| Claim Element (from Independent Claim 13) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| storing at least one profile identifier and a geographic location associated with the account on the database; | The Accused System allegedly captures and stores user device information and geographic location in a database when an account is opened or registered. | ¶36 | col. 4:39-44 |
| determining at least one profile identifier associated with the computer and a geographic location associated with the computer; | During a login attempt, the Accused System allegedly collects information from the device, including its IP address, to determine its identifiers and geographic location. | ¶37; ¶39 | col. 7:1-19 |
| comparing the at least one profile identifier associated with the account to the at least one profile identifier associated with the computer; | The Accused System allegedly compares the login device's information with the information previously stored and associated with the account to recognize the device. | ¶37 | col. 4:45-53 |
| comparing the geographic location associated with the account to the geographic location associated with the computer; | The Accused System allegedly compares the geographic location derived from the login device's IP address to the location information associated with the account. | ¶39 | col. 4:54-62 |
| permitting the computer access to the account when 1) the at least one profile identifier... is the same as... and 2) the geographic location... is the same as... | The complaint alleges that when the device and location information match the stored information, the Accused System permits access to the account. | ¶43 | col. 4:50-53 |
| communicating with the user to determine if access to the account should be permitted when the at least one profile identifier associated with the account is different from the at least one profile identifier associated with the computer; | When a login attempt is from an unrecognized device, the system allegedly uses multi-factor authentication, sending a code to the user, to verify if access should be allowed. A screenshot describes this as "Additional validation checks" Compl. p. 19 | ¶38; ¶41 | col. 4:50-53 |
| reporting the at least one profile identifier... and the geographic location... to an administrator... when [they are] different... | The complaint alleges on information and belief that the Accused System "maintains a log of suspicious activity or otherwise alerts administrators" when there is a mismatch. A screenshot titled "Safeguards against suspicious activity" notes that a "temporary hold" may be placed on the account Compl. p. 22 | ¶42 | col. 8:45-49 |
- Identified Points of Contention:
- Scope Questions: A primary question may be whether the types of information the Accused System allegedly collects (e.g., "operating system information and browser information" (Compl. ¶36)) function as a "profile identifier" within the meaning of the patent. The defense may argue that these are general attributes, not the unique, hardware-based identifiers emphasized in parts of the patent specification.
- Technical Questions: The complaint alleges the system "reports... to an administrator" by maintaining a "log of suspicious activity" Compl. ¶42 An issue for the court will be whether passively creating a log entry that an administrator could review satisfies this claim limitation, or if the claim requires a more active, directed notification.
V. Key Claim Terms for Construction
The Term: "profile identifier"
Context and Importance: This term is the technological core of the claim. The infringement analysis will depend entirely on whether the device data collected by the Accused System falls within the court's construction of this term.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: Claim 13 itself defines the term with a very long and varied Markush group, including not only hardware-specific data (e.g., "CPU serial number") but also software-based identifiers (e.g., "admin... UUID provided by the operating system") and network identifiers (e.g., "MAC address") '533 Patent, col. 25:6-26:5 Plaintiff may argue this broad definition explicitly covers the types of OS- and browser-level data allegedly collected by Chase.
- Evidence for a Narrower Interpretation: The patent's abstract focuses exclusively on the "MAC address" as the identifier '533 Patent, abstract A defendant could argue that this, along with repeated references to specific hardware components, indicates the invention is properly focused on unique, persistent hardware identifiers, not more mutable software-level attributes.
The Term: "reporting... to an administrator"
Context and Importance: This is an active step in the claimed method for handling a security exception. Whether the Accused System performs this step as claimed will be a key factual and legal question.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification describes a "logging system, which allows tracking of the activities of unique profile identifiers by a host administrator" '533 Patent, col. 8:45-48 Plaintiff will likely argue that creating such a log constitutes "reporting" because it makes the information available to the administrator for review.
- Evidence for a Narrower Interpretation: The specification also contemplates notifying "law enforcement" in certain scenarios, which suggests a more active, outbound communication '533 Patent, col. 4:64-68 A defendant may argue that "reporting" requires a similar active alert (e.g., an email, a system alert), not merely the passive creation of a log entry.
VI. Other Allegations
- Indirect Infringement: The complaint alleges inducement of infringement under 35 U.S.C. § 271(b), asserting that Defendant provides instructions on its websites that encourage and guide customers to use the Accused System in an infringing manner Compl. ¶52 For example, a provided screenshot details Defendant's "Identity and Device Verification" policy Compl. p. 16
- Willful Infringement: The complaint alleges willfulness based on Defendant's continued infringement after gaining knowledge of the '533 Patent, with knowledge alleged to begin "at least the date of service of this Complaint" Compl. ¶53
VII. Analyst's Conclusion: Key Questions for the Case
The resolution of this case may depend on the court's determination of several key technical and legal questions:
A core issue will be one of definitional scope: Can the term "profile identifier," which is rooted in the patent's description of unique hardware data like MAC addresses, be construed broadly enough to encompass the more general operating system, browser, and network information allegedly used by the Accused System for device recognition?
A second central question will be one of functional equivalence: Does the Accused System's alleged practice of logging suspicious activity satisfy the claim requirement of "reporting" that activity "to an administrator"? The case may turn on whether this claim language requires an active, outbound notification or is met by the passive creation of a data log for potential review.