1:22-cv-01309
Softex LLC v. Dell Technologies
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Softex LLC (Delaware)
- Defendant: Dell Technologies Inc. and Dell Inc. (Delaware)
- Plaintiff's Counsel: McKOOL SMITH, P.C.
- Case Identification: 1:22-cv-01309, W.D. Tex., 12/14/2022
- Venue Allegations: Plaintiff alleges venue is proper because Defendants maintain a regular and established place of business in the district and have committed acts of patent infringement within the district.
- Core Dispute: Plaintiff alleges that Defendant's computers, tablets, and other devices, which utilize Microsoft's "Find My Device" feature and/or Absolute Software's "Absolute Persistence" technology, infringe seven patents related to persistent, firmware-level device security and anti-theft systems.
- Technical Context: The technology concerns security software embedded in a computer's Basic Input/Output System (BIOS) or other non-user-accessible memory, designed to survive theft, device tampering, hard drive replacement, or operating system reinstallation.
- Key Procedural History: The complaint states that the patents-in-suit were originally assigned to Softex, Inc., which pioneered persistent theft detection technology in the early 2000s, and were transferred to Plaintiff Softex LLC in August 2022. It is also noted that in May 2003, a company associated with the accused "Absolute Functionality" issued a joint press release with Phoenix Technologies announcing an intent to install Softex's "TheftGuard" technology on OEM BIOSs.
Case Timeline
| Date | Event |
|---|---|
| 2003-05-01 | Phoenix and Absolute issue press release regarding TheftGuard technology (approx. date) |
| 2003-08-23 | Earliest Priority Date for all Asserted Patents |
| 2009-09-15 | U.S. Patent No. 7,590,837 Issues |
| 2012-03-06 | U.S. Patent No. 8,128,710 Issues |
| 2012-03-20 | U.S. Patent No. 8,137,410 Issues |
| 2012-03-27 | U.S. Patent No. 8,145,892 Issues |
| 2012-10-16 | U.S. Patent No. 8,287,603 Issues |
| 2013-08-13 | U.S. Patent No. 8,506,649 Issues |
| 2013-08-20 | U.S. Patent No. 8,516,235 Issues |
| 2022-08-05 | Asserted Patents assigned from Softex, Inc. to Softex LLC |
| 2022-12-14 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 7,590,837 - "Electronic Device Security and Tracking System and Method"
- Issued: September 15, 2009 (the "'837 Patent")
The Invention Explained
- Problem Addressed: The patent addresses the ineffectiveness of traditional software-based theft prevention systems, which were easily defeated because the software was stored on viewable parts of a hard drive and could be tampered with or erased by thieves (Compl. ¶24, citing '837 Patent, col. 18:34-37). Physical security measures were also deemed costly and insufficient for post-theft tracking or recovery (Compl. ¶24, citing '837 Patent, col. 1:22-30).
- The Patented Solution: The invention proposes a persistent security system architecture comprising three cooperating components: an OS-level application, a "non-viewable" component, and a Basic Input/Output System (BIOS) component (Compl. ¶25, citing '837 Patent, col. 2:12-17). The BIOS component, stored in a secure, non-volatile area of the device's hardware, is designed to check the integrity of the other two software components during the boot process and restore them from a backup if they have been tampered with or removed (Compl. ¶25, citing '837 Patent, col. 17:64-18:8).
- Technical Importance: This multi-component, BIOS-anchored approach was designed to create a security system that could survive hard drive replacement or reformatting, representing a significant technical advance in device security and recovery Compl. ¶20
Key Claims at a Glance
- The complaint asserts at least independent Claim 1 Compl. ¶73
- The essential elements of Claim 1 include:
- An application component within an OS for sending location data and determining stolen status.
- A non-viewable security component with a validator module to check if the application component is present and has been tampered with.
- A non-volatile storage device with a secure area.
- A BIOS security component in the secure area configured to check the application component's integrity during boot.
- The BIOS component is further configured to restore the application component upon a negative integrity check and to prevent the OS from booting if it receives a stolen notification.
- The application component is configured to notify the BIOS component if the device is reported stolen.
- The application component is "substantially distinct" from the BIOS and validator components.
U.S. Patent No. 8,506,649 - "Electronic Device Security and Tracking System and Method"
- Issued: August 13, 2013 (the "'649 Patent")
The Invention Explained
- Problem Addressed: The patent targets the same general problem as the '837 Patent-the vulnerability of traditional, software-only security systems on mobile devices to tampering by thieves (Compl. ¶30, citing '649 Patent, col. 18:34-37).
- The Patented Solution: The patented solution is a security application for a mobile electronic device that utilizes code stored, at least in part, in a "system area" of memory that "cannot be modified by the user" (Compl. ¶31, citing '649 Patent, col. 3:44-60). When notified of a theft by a remote security service, this persistent application is capable of disabling user functions, copying user data to a server for recovery, and continuing to communicate with the security service (Compl. ¶31, citing '649 Patent, col. 2:16-37).
- Technical Importance: The invention provided a framework for persistent security and data recovery on mobile devices, allowing owners to remotely control and retrieve data from a device even after it has been compromised Compl. ¶31
Key Claims at a Glance
- The complaint asserts at least independent Claim 1 Compl. ¶78
- The essential elements of Claim 1, which claims a mobile electronic device, include:
- A security application operable to:
- Enable registration with a security service.
- Automatically send identifying information to the service.
- Periodically communicate with the service after registration.
- Accept a "loss or requested disabling" notification from the service.
- In response, automatically disable at least one user function while maintaining communication with the service.
- Automatically cause user data to be copied to a server.
- The security application must utilize code residing at least partially in a "system area" that "cannot be modified by the user."
- The application must receive the notification from the server "via the system area."
U.S. Patent No. 8,516,235 - "Basic Input/Output System Read Only Memory Image Integration System and Method"
- Issued: August 20, 2013 Compl. ¶35
- Technology Synopsis: This patent pertains to systems and methods for integrating a security application into a BIOS ROM image Compl. ¶36 The system uses a three-part structure (application, non-viewable, and BIOS components) where the BIOS component validates the presence and integrity of the other components at boot-up and restores them if compromised, ensuring persistence Compl. ¶37
- Asserted Claims: At least independent Claim 8 Compl. ¶82
- Accused Features: The "Absolute Functionality" in Dell's products is alleged to infringe Compl. ¶82
U.S. Patent No. 8,145,892 - "Providing an Electronic Device Security and Tracking System and Method"
- Issued: March 27, 2012 Compl. ¶41
- Technology Synopsis: The patent describes an electronic device with persistent security based on a non-viewable component, an application component, and a BIOS security component Compl. ¶43 After activation of a security service, the non-viewable component and BIOS component cooperate to check the integrity of the application component and restore it automatically if a negative integrity check occurs Compl. ¶43 Compl. ¶44
- Asserted Claims: At least independent Claim 12 Compl. ¶87
- Accused Features: The "Absolute Functionality" in Dell's products is alleged to infringe Compl. ¶87
U.S. Patent No. 8,137,410 - "Electronic Device Disabling System and Method"
- Issued: March 20, 2012 Compl. ¶46
- Technology Synopsis: This patent discloses a security apparatus using a hidden memory partition and an associated application component for tracking and locating a device Compl. ¶48 The system is configured to automatically determine if the hidden partition is valid and, if so, load a non-viewable component from it; this component can then restore the application component from a backup if it failed to load correctly on the previous power-up Compl. ¶¶49-50
- Asserted Claims: At least independent Claim 8 Compl. ¶92
- Accused Features: The "Absolute Functionality" in Dell's products is alleged to infringe Compl. ¶92
U.S. Patent No. 8,287,603 - "Electronic Device With Protection From Unauthorized Utilization"
- Issued: October 16, 2012 Compl. ¶52
- Technology Synopsis: This patent describes a method to prevent a stolen device from booting by using a coordinated system between an application component and a BIOS component Compl. ¶53 Compl. ¶54 The application determines if it is operating correctly and informs the BIOS component; if, on a subsequent boot, the BIOS component does not find this "operating correctly" information, it prevents the boot process from completing Compl. ¶55
- Asserted Claims: At least independent Claim 18 Compl. ¶97
- Accused Features: The "Absolute Functionality" in Dell's products is alleged to infringe Compl. ¶97
U.S. Patent No. 8,128,710 - "Electronic Device Security System and Method"
- Issued: March 6, 2012 Compl. ¶58
- Technology Synopsis: This patent describes a persistent security system with the ability to remotely wipe data from a compromised device Compl. ¶62 The system architecture involves an application component, a non-viewable component, and a BIOS component that work together to check for tampering, restore the application, and facilitate the erasure of the device's non-volatile storage after it is reported stolen Compl. ¶¶60-61
- Asserted Claims: At least independent Claim 2 Compl. ¶102
- Accused Features: The "Absolute Functionality" in Dell's products is alleged to infringe Compl. ¶102
III. The Accused Instrumentality
Product Identification
The complaint identifies two sets of accused functionalities: "Windows Functionality," specifically Microsoft's "Find My Device" feature on Dell computers running Windows 10 and 11, and "Absolute Functionality," which includes a suite of security software such as Absolute Home & Office, Computrace, and LoJack for Laptops Compl. ¶6 Compl. ¶8 Compl. ¶65 Compl. ¶67 The accused products are an extensive list of Dell computers, tablets, and Android devices that incorporate one or both of these functionalities Compl. ¶¶4-8
Functionality and Market Context
- The "Windows Functionality" is a standard OS feature that allows an administrator to use a Microsoft account to locate, lock, or display a message on a lost or stolen device Compl. ¶65 Compl. ¶66
- The "Absolute Functionality" is marketed as a "persistent security solution" that is "embedded in the firmware of every device that leaves the factory floor" Compl. ¶7 Compl. ¶67 Its key technical feature is a "self-heal" capability, where a component in the device's firmware (BIOS) can automatically reinstall the security software agent if it is removed or tampered with Compl. ¶68 This persistence is designed to survive OS reinstalls, hard drive reformats, or even complete hard drive replacement Compl. ¶70 An infographic from Absolute's website, included in the complaint, illustrates this process as "Undeletable Security with Absolute Persistence" Compl. ¶70 at p. 43
IV. Analysis of Infringement Allegations
'837 Patent Infringement Allegations
The complaint alleges that Dell products incorporating "Absolute Functionality" infringe Claim 1 of the '837 Patent Compl. ¶72 Compl. ¶73
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| an application component to execute within an OS environment... | The Accused Products include an "application agent" that is installed in the operating system as a service (Compl. Ex. H, p. 8). | ¶73 | col. 2:14-15 |
| wherein said application component is configured to cause the electronic device to send, to the server system, a message that contains location information... | The application agent makes regularly scheduled calls to the Absolute Monitoring Center (server system) and provides asset and location data (Compl. Ex. H, p. 11). | ¶73 | col. 18:23-28 |
| and wherein said application component is configured to determine whether the electronic device has been reported stolen... | The application agent's contact frequency increases from daily to every 15 minutes when a device is reported stolen, allowing it to determine the device's stolen status from the server (Compl. Ex. H, p. 12). | ¶73 | col. 18:28-33 |
| a non-viewable security component... compris[ing] a validator module capable of determining whether the application component... has been tampered with | A "downloader agent" (rpcnetp.exe) is described as a non-viewable component that is downloaded from the BIOS and can determine if the main application agent is present or has been tampered with Compl. Ex. H, p. 15 | ¶73 | col. 18:38-42 |
| a non-volatile storage device comprising a secure area | The Absolute software is embedded in a secure, non-volatile "Option ROM" within the BIOS PCI or UEFI firmware (Compl. Ex. H, p. 19). A screenshot from a technical analysis illustrates the "PCI Option ROM" as part of the "Core BIOS Flash Image" (Compl. Ex. H, p. 19). | ¶73 | col. 18:43-44 |
| a basic input/output security (BIOS) component stored in the secure area, the BIOS security component configured to check the integrity of the application component during a boot process... | A "Persistence Module" is installed in the BIOS or firmware and its purpose is to check on the software agent, surviving even if the firmware is flashed or the device is reimaged (Compl. Ex. H, p. 20). | ¶73 | col. 18:45-49 |
| automatically cause the electronic device to restore the integrity of the application component in response to a negative integrity check... | The Persistence Module employs "self-healing technology" that "rebuild[s] the Application Agent software even if the service is deleted" (Compl. Ex. H, p. 28). | ¶73 | col. 18:53-57 |
| prevent the electronic device from booting the OS in response to receiving a notification that the... device has been reported stolen. | The accused functionality includes a "remote poison pill" feature that, when a device is reported stolen, "locks down OS and prevents boot" and disables the notebook (Compl. Ex. H, p. 29). | ¶73 | col. 18:58-62 |
Identified Points of Contention
- Architectural Mapping: A primary question may be whether the accused two-part architecture ("Application Agent" and "Persistence Module") maps directly onto the claimed three-part architecture ("application component," "non-viewable security component," and "BIOS security component"). The analysis may focus on whether the single "Persistence Module" performs the distinct functions recited for both the claimed "non-viewable component" and the "BIOS component."
- Scope Questions: The interpretation of "non-viewable" will be significant. The complaint suggests this can be a software agent like "rpcnetp.exe" that runs as a service Compl. Ex. H, p. 15 A dispute may arise over whether such a component, even if hidden from a typical user, meets the claimed level of persistence and inaccessibility.
'649 Patent Infringement Allegations
The complaint alleges that Dell devices with "Windows Functionality" infringe Claim 1 of the '649 Patent Compl. ¶77 Compl. ¶78
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| a mobile electronic device | Dell's laptops and other computers are alleged to be mobile electronic devices Compl. Ex. I, p. 2 | ¶78 | col. 1:57-58 |
| causing the mobile electronic device to periodically communicate with the security service... | The "Find My Device" feature, when enabled, periodically sends the device's location to the Microsoft security service (server) Compl. ¶66, p. 41 | ¶78 | col. 2:16-19 |
| accepting a notification... from the security service... indicating that the owner... has reported a loss or requested disabling... | A user can log into their Microsoft account from another device and select the "Lock" option for the stolen device, which sends a disabling notification to it Compl. Ex. I, p. 13 A screenshot shows the user interface for initiating this lock command Compl. Ex. I, p. 14 | ¶78 | col. 2:20-25 |
| automatically disabling at least one user function... while still allowing the mobile electronic device to communicate with the security service | In response to the lock command, the device is locked. However, it can still communicate its location, and administrators with permissions may still access it Compl. Ex. I, p. 15 Compl. Ex. I, p. 17 | ¶78 | col. 2:26-31 |
| automatically causing at least some user data to be copied from the mobile electronic device to at least one of the servers | When an owner views device details and location from their Microsoft account, this information, including the device's serial number, is sent to the server and paired with user-identifying data Compl. ¶66 at p. 41 Compl. Ex. I, p. 18 | ¶78 | col. 2:32-35 |
| the security application utilizes code residing at least partially in the system area that cannot be modified by the user | The complaint alleges that by "segregating access and not allowing the user access to the administrator area, MSFT provides a system area that cannot be accessed by the user" Compl. ¶66 at p. 42 | ¶78 | col. 2:38-40 |
Identified Points of Contention
- Technical Questions: A significant technical question will be whether the "Find My Device" feature performs the step of "automatically causing at least some user data to be copied from the mobile electronic device." The complaint's theory appears to be that sending device metadata (serial number, location) to a server satisfies this element Compl. Ex. I, p. 18 A counterargument may be that this limitation requires copying of user-generated files (e.g., documents, photos), not just device-identifying data.
- Scope Questions: The construction of "system area that cannot be modified by the user" will be critical. The case may turn on whether this term can be interpreted to cover a standard OS partition with administrator-level privileges, or if the patent's specification limits the term to a more fundamentally immutable memory location, such as a protected region of firmware or flash memory.
V. Key Claim Terms for Construction
"non-viewable security component" ('837 Patent, Claim 1)
- Context and Importance: This term is central to the claimed invention's distinction from prior art. The "non-viewable" nature provides the persistence that pure software solutions allegedly lacked. Practitioners may focus on this term because its definition will determine whether a software agent running as a background service, as alleged for the accused Absolute product, falls within the claim scope, or if the claim requires a component hidden at a deeper hardware or file-system level (e.g., in a host protected area).
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification may describe the component's function more broadly, stating it "may reside in hidden partitions on the hard disk drive" or other non-volatile memory, suggesting its specific location is not limiting as long as it is not easily accessible to a user '837 Patent, col. 2:5-6
- Evidence for a Narrower Interpretation: Specific embodiments described in the patent, such as placing the component in a "Host Protected Area (HPA) of the HDD," could be used to argue for a narrower definition tied to specific, tamper-resistant hardware locations known at the time '837 Patent, col. 2:20-21
"system area that cannot be modified by the user" ('649 Patent, Claim 1)
- Context and Importance: The infringement allegation against Microsoft's "Find My Device" feature hinges on this term. Its construction will determine whether software protected only by operating system user-privilege levels (e.g., administrator vs. standard user) qualifies, or if the claim requires a hardware-level partition that is immutable by any user, including an administrator.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent may not explicitly define "user," which could be argued to mean a "non-administrator user," thereby bringing standard OS privilege controls into scope.
- Evidence for a Narrower Interpretation: The specification, particularly Figure 45, illustrates a "SYSTEM AREA (NON-CHANGEABLE TO NORMAL USER)" in a PDA's flash memory, distinctly separate from the "CHANGEABLE AREA (ACTS LIKE FILE SYSTEM)" '649 Patent, Fig. 45 This figure may support an argument that the "system area" is a fundamentally different type of memory partition, not merely a permissions-restricted folder within the main file system.
VI. Other Allegations
- Indirect Infringement: The complaint alleges active inducement of infringement for all asserted patents. The factual basis for this allegation is that Dell provides, advertises, and distributes its products with instructions, user manuals, and marketing materials that encourage and facilitate customers' activation and use of the accused "Windows Functionality" and "Absolute Functionality" Compl. ¶17 Compl. ¶74 Compl. ¶79
- Willful Infringement: The complaint alleges that Dell has had "actual knowledge of the Asserted Patents at least as early as the filing of this Complaint" and that its infringement is willful Compl. ¶9 The prayer for relief seeks a finding of willfulness and enhanced damages Compl. p. 51, ¶B Compl. p. 51, ¶C The allegation appears to be predicated on continued infringement after the complaint provided notice.
VII. Analyst's Conclusion: Key Questions for the Case
- Architectural Equivalence: A central technical issue will be whether the two-part architecture of the accused "Absolute Functionality" (a BIOS-level "Persistence Module" and an OS-level "Application Agent") meets the three-part architecture recited in claims of the '837 and ''892' patents (a "BIOS component," a "non-viewable component," and an "application component"). The case may turn on whether a single accused component can be shown to perform the distinct functions of two separate claimed components.
- Definitional Scope of "System Area": A key question of claim construction will be the meaning of a "system area that cannot be modified by the user" as claimed in the '649 Patent. The viability of the infringement theory against Microsoft's "Find My Device" will likely depend on whether this term can be construed to cover an administrator-protected area of a standard operating system, or if intrinsic evidence limits its scope to a more fundamentally immutable hardware partition.
- The Nature of "Persistence": Across the asserted patents, the core inventive concept is a security system that persists despite user or thief intervention. A fundamental evidentiary question will be whether the "self-healing" mechanism of the accused Absolute products and the OS-level lock of the accused Windows product function in a manner that is technically congruent with the specific methods of integrity checking, component restoration, and boot prevention recited in the asserted claims.