DCT
2:26-cv-00795
AAA Internet Publishing Inc v. Palo Alto Networks Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: AAA Internet Publishing Inc., d/b/a WTFast (British Columbia)
- Defendant: Palo Alto Networks, Inc. (Delaware)
- Plaintiff’s Counsel: Cole Schotz P.C.
- Case Identification: 2:26-cv-00795, E.D. Tex., 09/08/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Defendant Palo Alto Networks maintains a "regular and established place of business" in Plano, Texas, where it employs a substantial number of individuals and conducts business.
- Core Dispute: Plaintiff alleges that Defendant’s Prisma Secure Access Service Edge (SASE) platform infringes three U.S. patents related to monitoring network connection quality and optimizing internet traffic routing.
- Technical Context: The technology at issue involves methods for analyzing network performance by comparing data from multiple connection paths and intelligently routing traffic based on its sensitivity to latency, a field relevant to online gaming, VoIP, and enterprise cloud connectivity.
- Key Procedural History: U.S. Patent No. RE49,392 is a reissue of U.S. Patent No. 9,742,646. Reissue proceedings can alter claim scope and may introduce the possibility of intervening rights as a defense for acts of infringement that occurred before the reissue date.
Case Timeline
| Date | Event |
|---|---|
| 2012-10-05 | Priority Date for U.S. Patent No. 11,050,669 |
| 2012-10-29 | Priority Date for U.S. Patent No. 9,571,359 |
| 2013-10-07 | Application filed for U.S. Patent No. 11,050,669 |
| 2013-10-29 | Application filed for U.S. Patent No. 9,571,359 |
| 2017-02-14 | U.S. Patent No. 9,571,359 Issues |
| 2017-08-22 | Original U.S. Patent No. 9,742,646 (related to RE49,392) Issues |
| 2017-11-29 | Reissue Application filed for U.S. Patent No. RE49,392 |
| 2021-06-29 | U.S. Patent No. 11,050,669 Issues |
| 2023-01-24 | U.S. Reissued Patent No. RE49,392 Issues |
| 2026-09-08 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Reissued Patent No. RE49,392 - "System and Method for Monitoring Network Connection Quality by Executing Computer-Executable Instructions Stored on a Non-Transitory Computer-Readable Medium"
- Patent Identification: U.S. Reissued Patent No. RE49,392, issued January 24, 2023.
The Invention Explained
- Problem Addressed: The patent's background section states that conventional "ping meters" in applications like online games are flawed because they typically only display an instantaneous latency value (Compl. ¶22; ’392 Patent, col. 2:45-54). This fails to provide an accurate representation of connection quality over time and ignores other critical performance metrics such as latency deviation, the number of network hops, and packet loss ’392 Patent, col. 2:55-60
- The Patented Solution: The invention proposes a system that simultaneously monitors and compares two different network connections to the same target server: a first connection (e.g., a standard internet path) and a second connection through a private server system ’392 Patent, abstract ’392 Patent, claim 1 It tracks a plurality of quality metrics for both paths (e.g., ping, ping deviation, hops), stores the data, and displays a comparison to the user, thereby providing a more comprehensive tool to diagnose connection health and identify performance issues ’392 Patent, col. 3:39-48 ’392 Patent, FIG. 9
- Technical Importance: This approach provided a more sophisticated method for end-users and administrators to analyze and troubleshoot network performance beyond simple latency values, enabling better-informed decisions on how to correct or bypass connection problems ’392 Patent, col. 2:66-3:11
Key Claims at a Glance
- The complaint asserts independent claim 10 Compl. ¶55
- Essential elements of claim 10 include:
- A system with monitoring software installed on a user computer.
- A first network connection to a target server.
- A second network connection to the target server through a private server system, established simultaneously with the first.
- Monitoring of one or more network quality metrics for both the first and second connections.
- Continually comparing the metrics of the first connection to the metrics of the second connection.
- The comparison is performed "to determine how much each of the first and second network quality metrics has improved or degraded" in either connection.
- The complaint reserves the right to assert other claims Compl. ¶55
U.S. Patent No. 9,571,359 - "System and Method for Monitoring Network Connection Quality By Executing Computer-Executable Instructions Stored on a Non-Transitory Computer-Readable Medium"
- Patent Identification: U.S. Patent No. 9,571,359, issued February 14, 2017.
The Invention Explained
- Problem Addressed: The patent identifies the same problem as the ’392 Patent: that simple ping meters are inadequate for assessing true network quality because they only show instantaneous latency and overlook other important metrics that influence performance, such as latency deviation and packet loss (’359 Patent, col. 2:10-34).
- The Patented Solution: The invention describes a method for monitoring network quality that involves establishing a first connection to a "target server" for an online activity and a second, "additional network connection" to the same target server via a "private server system" ’359 Patent, claim 1 The method involves continually monitoring, storing, and displaying multiple network quality metrics (e.g., ping, hops) for both connections, allowing a user to compare them on a visual display ’359 Patent, abstract ’359 Patent, FIG. 1
- Technical Importance: The invention provides users a direct, real-time benchmark, allowing them to see how their current network connection performs relative to an alternative, potentially optimized path, thereby helping to identify and address performance bottlenecks ’359 Patent, col. 2:41-48
Key Claims at a Glance
- The complaint asserts independent claim 1 Compl. ¶64
- Essential steps of claim 1 include:
- Providing a target server, a database, and a visual display.
- Establishing a first network connection to the target server.
- Establishing an "additional" network connection to the target server through a "private server system."
- Simultaneously and continually monitoring a "first plurality of network quality metrics" for the first connection and a "second plurality of network quality metrics" for the additional connection.
- Continually storing both pluralities of metrics in the database.
- Displaying at least one metric from each plurality on the visual display.
- The complaint reserves the right to assert other claims Compl. ¶64
U.S. Patent No. 11,050,669 - "Method and System for Managing, Optimizing, and Routing Internet Traffic from a Local Area Network (LAN) to Internet Based Servers"
- Patent Identification: U.S. Patent No. 11,050,669, issued June 29, 2021.
- Technology Synopsis: The patent addresses the problem of internet service providers treating all data equally, which is detrimental to latency-sensitive applications like online gaming (’669 Patent, col. 1:40-54). The patented solution involves a gateway computer on a local network that analyzes internet data to classify it (e.g., as latency-sensitive), then routes the latency-sensitive data through a specialized, high-performance private network while sending non-sensitive data through other routes ’669 Patent, abstract ’669 Patent, col. 2:56-62
- Asserted Claims: The complaint asserts independent claim 19 Compl. ¶74
- Accused Features: The complaint alleges that the Prisma SASE platform's function as a branch gateway, its use of App-ID technology to analyze and prioritize applications, and its ability to route traffic through different paths (including the Prisma Access private network) based on performance policies infringe the ’669 Patent Compl. ¶¶43-46
III. The Accused Instrumentality
Product Identification
The accused instrumentality is Defendant's "Prisma SASE" platform, which integrates Prisma Access, Prisma SD-WAN, and Autonomous Digital Experience Management ("ADEM") Compl. ¶31
Functionality and Market Context
- The Prisma SASE platform is described as a unified, cloud-delivered service for enterprise network security and software-defined wide-area networking (SD-WAN) Compl. ¶31 Compl. ¶32
- The ADEM component is alleged to perform "autonomous digital experience monitoring" by collecting network performance metrics such as latency, jitter, and packet loss across network segments, from an endpoint device to a target application Compl. ¶31 It allegedly runs synthetic tests, including ICMP pings, at regular intervals to collect this data Compl. ¶36
- The complaint alleges that the platform monitors performance across multiple paths simultaneously, including a "direct internet path" and an "additional path through PAN's Prisma Access private server system" Compl. ¶37 A screenshot in the complaint shows a dashboard comparing a "Standard VPN" path with a "DIRECT ACCESS" path Compl. ¶37, p. 15 Another visual depicts trend charts for network latency, jitter, and packet loss over time Compl. ¶37, p. 14
- Collected metrics are allegedly stored in the "Strata Cloud Manager" platform and can be retrieved and viewed on visual dashboards Compl. ¶40 Compl. ¶41 The Prisma SD-WAN component uses ION devices at branch locations to route traffic based on application needs and real-time network performance Compl. ¶34
IV. Analysis of Infringement Allegations
U.S. RE49,392 Infringement Allegations
| Claim Element (from Independent Claim 10) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a monitoring software configured to be installed on a user computer | The ADEM agent software is installed on user workstations or on Prisma SD-WAN devices at remote network sites. | ¶35 | col. 4:4-6 |
| a first network connection configured to... connect the router to a target server by the first network connection through the internet | The platform establishes a "direct internet path from the endpoint or site device to the target application server." | ¶37 | col. 3:35-37 |
| a second network connection... configured to... connect the router to the target server by the second network connection through a private server system through the internet, wherein the second network connection and the first network connection are established simultaneously | The platform establishes an "additional path through PAN's Prisma Access private server system," which constitutes the private server system. The complaint alleges simultaneous monitoring across these paths. | ¶37; ¶38 | col. 3:38-42 |
| one or more first network quality metrics for the first network connection... being monitored by the monitoring software on the user computer | ADEM collects metrics such as latency, jitter, packet loss, and hop-by-hop path data for the direct internet path. | ¶31; ¶36; ¶38 | col. 3:5-9 |
| one or more second network quality metrics for the second network connection... being continually monitored by the monitoring software on the user computer | ADEM also collects performance metrics for the path through the Prisma Access private server system. | ¶37; ¶39 | col. 3:5-9 |
| the one or more first network quality metrics... being continually compared to the one or more second network quality metrics... to determine how much each... has improved or degraded in the first or the second network connection | ADEM allegedly uses baselines and enables "continual comparison of network quality metrics across those connections," which "allows determination of how metrics have improved or degraded." | ¶41 | col. 4:30-34 |
- Identified Points of Contention:
- Scope Questions: A central issue may be whether the accused "Prisma Access" network, an enterprise security product, qualifies as the "private server system" contemplated by the patent. The defense may argue the patent's concept is rooted in gaming-optimization networks and is technically distinct from Defendant's SASE architecture.
- Technical Questions: The infringement allegation hinges on whether the accused platform performs the active step of "comparing... to determine how much each... has improved or degraded." The court may need to decide if displaying comparative data on a dashboard, as alleged Compl. ¶41, is sufficient to meet this analytical limitation, or if the claim requires a more explicit computational "determination" performed by the system itself.
U.S. 9,571,359 Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| providing a target server; providing a database; providing a visual display | The accused platform monitors connections to target application servers, stores collected metrics in the Strata Cloud Manager platform (a database), and displays metrics on visual dashboards. | ¶31; ¶36; ¶40; ¶41 | col. 3:3-9 |
| establishing a first network connection to the target server | The platform establishes and monitors a "direct internet path from the endpoint or site device to the target application server." | ¶37 | col. 3:35-37 |
| establishing an additional network connection to the target server through the private server system | The platform establishes and monitors an "additional path through PAN’s Prisma Access private server system." Prisma Access is alleged to be the "private server system." | ¶37; ¶38 | col. 3:60-63 |
| simultaneously... continually monitoring a first plurality of network quality metrics for the first network connection and a second plurality of network quality metrics for the additional network connection | ADEM "continuously monitor[s] network connection quality" including latency, jitter, and packet loss, across multiple paths simultaneously, including via synthetic tests run every 30 seconds. | ¶31; ¶36; ¶37 | col. 3:5-9 |
| continually storing the first plurality of network quality metrics and the second plurality of network quality metrics within the database | ADEM "stores the collected network quality metrics in PAN's Strata Cloud Manager platform," with options for long-term retention. | ¶40 | col. 5:21-24 |
| displaying the at least one of the first plurality of network quality metrics and at least one of the second plurality of network quality metrics on the visual display | ADEM "displays the monitored network quality metrics on visual dashboards," including trend charts and per-path scores. An included screenshot shows a dashboard comparing two paths. | ¶41; ¶37 p. 15 | col. 5:55-61 |
- Identified Points of Contention:
- Scope Questions: As with the ’392 Patent, a key point of contention will likely be whether the accused platform's architecture, particularly the comparison of a "direct access" path to a "standard VPN" or "Prisma Access" path Compl. ¶37, p. 15, is equivalent to the patent's method of comparing a primary connection to a "private server system."
- Technical Questions: The claim requires "simultaneously" monitoring both connections. The defense may scrutinize the evidence to question whether the alleged synthetic tests Compl. ¶36 for different paths are truly simultaneous or are instead performed sequentially in a way that falls outside the claim's scope.
V. Key Claim Terms for Construction
For U.S. RE49,392 and U.S. 9,571,359
- The Term: "private server system"
- Context and Importance: This term is foundational to the infringement allegations for both the ’392 and ’359 patents, as the complaint identifies Defendant’s "Prisma Access" platform as this system Compl. ¶37 Compl. ¶38 The outcome of the case may depend on whether an enterprise SASE platform can be construed as the "private server system" described in patents that appear focused on gaming network optimization.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specifications describe the system as being comprised of "a plurality of servers across the globe" ’359 Patent, col. 3:61-62 This general language could support an interpretation that covers any distributed, privately managed network used as an alternative data path.
- Evidence for a Narrower Interpretation: The patents frequently use the term in the context of a "Global Private Network" or "GPN," with figures depicting its use for "Game Data" ’359 Patent, FIG. 8 A defendant may argue this context limits the term to networks specifically architected for gaming traffic optimization, rather than a general-purpose security and access platform like Prisma SASE.
For U.S. RE49,392
- The Term: "continually compared... to determine how much each... has improved or degraded"
- Context and Importance: This limitation in claim 10 of the ’392 Patent requires an active analytical step, not just passive data presentation. Practitioners may focus on this term because the defense could argue the accused system only displays comparative metrics, leaving the "determination" of improvement or degradation to the human user, thus avoiding infringement.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification states the comparison "provides the user with a great deal of information on the overall quality of the network connection" ’392 Patent, col. 4:32-34 Plaintiff may argue that any system providing the necessary comparative data "determines" the outcome in a functional sense. The patents' own figures include a "% Difference" column, suggesting a direct computational comparison is part of the invention ’392 Patent, FIG. 9
- Evidence for a Narrower Interpretation: The claim language recites that the system performs the comparison "to determine" the result. A defendant might argue this requires an explicit output or conclusion (e.g., an "improved" status flag), rather than simply presenting two sets of numbers and a percentage difference from which a user must draw their own conclusion.
VI. Other Allegations
- Indirect Infringement: The complaint alleges both induced and contributory infringement for all three asserted patents. The inducement allegations are based on Defendant allegedly encouraging and instructing customers to use the Prisma SASE platform in an infringing manner through extensive documentation, training, technical support, and the promotion of customer success stories Compl. ¶¶56-57 Compl. ¶¶66-67 Compl. ¶¶75-76 The contributory infringement allegations assert that components such as the ADEM agent software and Prisma SD-WAN ION devices are material parts of the inventions, are not suitable for substantial non-infringing uses, and are especially adapted for use in the infringing system (Compl. ¶¶58; Compl. ¶¶68; Compl. ¶¶77).
- Willful Infringement: The complaint alleges that Defendant has had knowledge of the asserted patents "since at least the filing date of this Complaint" and that its continued infringement is therefore willful Compl. ¶¶60-61 Compl. ¶¶70-71 Compl. ¶¶79-80 This forms a basis for seeking enhanced damages based on post-suit conduct.
VII. Analyst’s Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: can the term "private server system," which the patents describe in the context of optimizing online gaming connections, be construed to cover an enterprise-grade Secure Access Service Edge (SASE) platform like Prisma Access? The case may turn on whether the function of providing an alternative, monitored data path is sufficient, regardless of the intended market or underlying architecture.
- A key evidentiary question will be one of functional operation: does the accused ADEM platform perform the specific analytical step recited in claim 10 of the ’392 patent—"comparing... to determine how much each... has improved or degraded"—or does it merely present raw comparative data and trend charts for a human user to interpret?
- The litigation will also likely examine the technical overlap between the patents. A central question for the court will be whether the accused platform's alleged simultaneous monitoring of a "direct" path and a "private" path infringes the monitoring-and-comparison claims of the ’392 and ’359 patents, while its alleged traffic classification and routing capabilities separately infringe the intelligent-routing claims of the ’669 patent.
Analysis metadata