2:26-cv-00782
VeriBase LLC v. Unitech America Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: VeriBase LLC (New Mexico)
- Defendant: Unitech America, Inc. (California)
- Plaintiff's Counsel: Rabicoff Law LLC
- Case Identification: 2:26-cv-00782, E.D. Tex., 09/02/2026
- Venue Allegations: Venue is asserted based on the Defendant allegedly maintaining an established place of business in the Eastern District of Texas and having committed acts of patent infringement within the district.
- Core Dispute: Plaintiff alleges that Defendant's unnamed products infringe a patent related to methods for securing a computer system by selectively controlling an application's ability to write data to a storage medium.
- Technical Context: The technology concerns proactive, behavior-based computer security, which aims to prevent malware infections by controlling fundamental system operations rather than relying on reactive, signature-based detection of known threats.
- Key Procedural History: The complaint does not mention any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the patent-in-suit.
Case Timeline
| Date | Event |
|---|---|
| 2005-12-01 | '661 Patent Application Filing Date (Priority Date) |
| 2017-03-21 | U.S. Patent No. 9,600,661 Issues |
| 2026-09-02 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,600,661 - System and method to secure a computer system by selective control of write access to a data storage medium
- Patent Identification: U.S. Patent No. 9,600,661, System and method to secure a computer system by selective control of write access to a data storage medium, issued March 21, 2017.
The Invention Explained
- Problem Addressed: The patent's background section describes conventional anti-virus software as often being insufficient because it typically acts only after a computer has been infected and can be slow to identify new viral threats '661 Patent, col. 1:10-23
- The Patented Solution: The invention proposes a proactive security method where a background process, called an "interceptor," monitors all attempts by applications to write data to a storage medium like a hard drive '661 Patent, abstract When a write attempt is detected, the interceptor checks a "rules database" to determine if the specific application has permission '661 Patent, col. 2:30-34 Based on the rules, which can specify different access levels, the write operation is either allowed or blocked, thereby preventing unauthorized programs from saving malicious code to the system '661 Patent, abstract '661 Patent, Fig. 1 If no rule exists for a given application, the system can prompt the user for a decision '661 Patent, col. 3:18-24
- Technical Importance: The described technology represents a preventative, rule-based approach to system security, focusing on controlling application behavior at the operating system level rather than reacting to known malware signatures.
Key Claims at a Glance
- The complaint alleges infringement of one or more claims, including "Exemplary '661 Patent Claims" identified in an attached exhibit Compl. ¶11 The following is a breakdown of independent claim 1:
- Independent Claim 1: A method comprising the following essential elements:
- Running a first process in "kernel mode" that monitors accesses to a data storage device.
- Detecting an attempt by a separate application to write data to the storage device.
- Interrogating a "rules database" that contains references to applications and their associated "access level".
- Controlling the write access based on the "access level" found for the application in the rules database.
III. The Accused Instrumentality
Product Identification
- The complaint does not name specific accused products in its main body. It refers to them as the "Exemplary Defendant Products" and states they are identified in charts included as "Exhibit 2" Compl. ¶11 Compl. ¶16 This exhibit was not provided with the complaint.
Functionality and Market Context
- The complaint alleges that the accused products infringe by implementing the technology claimed in the '661 Patent Compl. ¶16 It further alleges that the Defendant distributes product literature and website materials that instruct end users on how to use the products in an infringing manner Compl. ¶14 The complaint does not provide sufficient detail for analysis of the specific functionality or market context of the accused products. No probative visual evidence provided in complaint.
IV. Analysis of Infringement Allegations
The complaint incorporates by reference claim charts in an unprovided "Exhibit 2" to support its infringement allegations Compl. ¶16 Compl. ¶17 As this exhibit was not available for review, a claim chart summary cannot be constructed. The complaint asserts in a conclusory manner that the "Exemplary Defendant Products practice the technology claimed by the '661 Patent" and "satisfy all elements of the Exemplary '661 Patent Claims" Compl. ¶16
- Identified Points of Contention: Based on the language of claim 1 of the '661 Patent and the general nature of the allegations, several points of contention may arise.
- Technical Question: A central factual question will be whether the accused products employ a monitoring process that operates in "kernel mode", as explicitly required by claim 1 '661 Patent, col. 6:12-13 Evidence of the architectural layer in which the accused monitoring process runs will be critical.
- Scope Question: The dispute may turn on the definition of a "rules database" '661 Patent, col. 6:18 The analysis will likely focus on whether the accused products' mechanism for storing permissions constitutes a database with distinct "access level" values associated with specific applications, as described in the patent.
- Evidentiary Question: Plaintiff will need to present evidence demonstrating how the accused products "control" write access in response to a rule lookup. The question will be whether this control mechanism functions in a manner consistent with the patent's teachings of allowing or blocking write attempts '661 Patent, col. 3:15-17
V. Key Claim Terms for Construction
The Term: "kernel mode"
Context and Importance: This term appears in the first limitation of independent claim 1 and defines the operational level of the monitoring process '661 Patent, col. 6:12-13 Practitioners may focus on this term because it is a specific technical requirement; if the accused product's monitoring process operates entirely in "user mode," it may not infringe this element.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent does not provide an explicit definition that deviates from the term's generally understood meaning in computer science, which could support an argument that it should be given its plain and ordinary meaning.
- Evidence for a Narrower Interpretation: The specification states, "In the preferred embodiment, the interceptor module is a kernel mode driver which has a higher level of access to the Windows file system and system resources" '661 Patent, col. 4:38-42 A party could argue this language ties the term to a specific implementation (a "kernel mode driver" in a "Windows" environment), potentially narrowing its scope.
The Term: "rules database"
Context and Importance: This term is central to the claimed invention, as it is the component that stores the permissions used to control write access '661 Patent, col. 6:18-19 The case may depend on whether the defendant's method for managing application permissions qualifies as the claimed "rules database".
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification describes the database in general terms as "a set of entries or references in a data structure where the identity of an application is paired with one or more permission values" '661 Patent, col. 2:35-39, which could support a broad construction covering various data structures.
- Evidence for a Narrower Interpretation: The patent describes a "preferred number of possible write access levels" (e.g., Level 0, 1, 2, 4) and notes the database is "preferably encrypted" '661 Patent, col. 2:34-35 '661 Patent, col. 2:55-68 A party might argue that these specific embodiments inform and limit the meaning of "rules database" to a structure possessing such enumerated levels or security features.
VI. Other Allegations
- Indirect Infringement: The complaint alleges induced infringement, stating that since the service of the complaint, the Defendant has knowingly sold products and distributed "product literature and website materials" that instruct end users to use the products in a manner that infringes the '661 Patent Compl. ¶14 Compl. ¶15
- Willful Infringement: The complaint does not use the term "willful infringement." However, it alleges that the service of the complaint provides Defendant with "Actual Knowledge of Infringement" Compl. ¶13 and that Defendant "continues to make, use, test, sell, offer for sale, market, and/or import" the accused products despite this knowledge Compl. ¶14 These allegations could form the basis for a claim of post-suit willful infringement.
VII. Analyst's Conclusion: Key Questions for the Case
The resolution of this dispute will likely depend on the court's determination of several key technical and legal questions:
- A primary issue will be one of technical implementation: Does the accused products' security architecture include a process that monitors file system access from within the operating system's "kernel mode", or does it operate at a different, non-infringing architectural level?
- A second core issue will be one of definitional scope: Can the term "rules database", as described in the patent with specific access levels, be construed to read on the accused products' system for storing and applying application permissions?
- A key evidentiary question will be what proof Plaintiff can marshall to show the inner workings of the accused products, particularly given the generic allegations in the complaint and the reliance on an unprovided exhibit. The ability to demonstrate, through discovery or reverse engineering, the specific mechanisms for monitoring, rule-checking, and blocking write access will be dispositive.