1:26-cv-01981
Kmizra LLC v. Portnox Security LLC
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Kmizra LLC (Delaware)
- Defendant: Portnox Security LLC (Delaware)
- Plaintiff's Counsel: Scheef & Stone, LLP; Sheridan Ross P.C.
- Case Identification: 1:26-cv-01981, W.D. Tex., 07/17/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Western District of Texas because Defendant Portnox Security LLC resides in the district, maintains a regular and established place of business there, and has committed acts of infringement in the district.
- Core Dispute: Plaintiff alleges that Defendant's Zero Trust Network Access products infringe a patent related to isolating and remediating potentially infected computers attempting to connect to a protected network.
- Technical Context: The technology addresses network security by assessing the health of endpoint devices (e.g., laptops) before granting them access to a protected network, thereby preventing the spread of malware or "contagion."
- Key Procedural History: The complaint notes that the asserted patent, U.S. Patent No. 8,234,705, has been the subject of prior litigation resulting in confidential license agreements. It also states the patent survived an Inter Partes Review (IPR) proceeding where the Patent Trial and Appeal Board (PTAB) found the claims were not unpatentable, a decision that was later appealed to the Federal Circuit, remanded on procedural grounds, and ultimately dismissed with prejudice by the PTAB.
Case Timeline
| Date | Event |
|---|---|
| 2004-09-27 | Priority Date for U.S. Patent No. 8,234,705 |
| 2012-07-31 | U.S. Patent No. 8,234,705 Issued |
| 2025-06-01 | Alleged Pre-Suit Notice of Infringement Sent to Defendant (stated as "no later than June 2025") |
| 2025-09-29 | Prior Ruling in Kmizra LLC v. Citrix Systems Inc. cited |
| 2026-07-17 | Complaint Filed |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,234,705 - "Contagion Isolation and Inoculation," Issued July 31, 2012 ('705 Patent)
The Invention Explained
- Problem Addressed: The patent's background describes the threat posed by mobile systems like laptops that connect to unsecured public networks (e.g., the internet) and may become infected with viruses, worms, or other malware. When these potentially compromised devices later reconnect to a protected corporate network, they can infect or harm other resources on that network before any preventative measures can be taken ʼ705 Patent, col. 1:14-41
- The Patented Solution: The invention proposes a system for automatically detecting an insecure condition on a host computer attempting to connect to a protected network. This is achieved by contacting a "trusted computing base" on the host to get a "digitally signed attestation of cleanliness" ʼ705 Patent, col. 21:58-65 If the host cannot prove it is "clean," it is "quarantined" with limited network access, allowing it only to connect to a "remediation host" to download necessary patches or updates to fix the insecure condition before being granted full access ʼ705 Patent, col. 22:4-49 Figure 10A of the patent provides a high-level overview of this process: detect vulnerability (1001), quarantine (1002), and provide remediation access (1003) ʼ705 Patent, Fig. 10A
- Technical Importance: The invention describes a method for automated network access control that moves beyond simple firewalls by actively assessing the security posture of an endpoint device before it joins the network, a foundational concept in "zero trust" security architectures ʼ705 Patent, col. 1:34-41
Key Claims at a Glance
- The complaint asserts infringement of at least independent Claim 19 Compl. ¶26 Compl. ¶43
- Claim 19 is a computer program product embodied in a non-transitory medium with instructions for:
- Detecting an insecure condition on a first host connecting to a protected network.
- This detection includes contacting a "trusted computing base" associated with a "trusted platform module" within the host, receiving a response, and determining if it includes a "valid digitally signed attestation of cleanliness."
- The attestation must confirm the host is not infested and/or has a specific patch level.
- If the attestation is not valid, "quarantining the first host" by preventing it from sending data to other hosts.
- This quarantining process involves intercepting web server or DNS requests and serving a "quarantine notification page" or the IP address of a quarantine server.
- Permitting the first host to communicate with a "remediation host" to fix the insecure condition.
- The complaint reserves the right to assert additional claims Compl. ¶26
III. The Accused Instrumentality
Product Identification
- The complaint identifies Defendant's "Portnox Zero Trust Network Access ('ZTNA')" products and services as the Accused Instrumentalities Compl. ¶38
Functionality and Market Context
- The complaint alleges the Portnox ZTNA product is a cloud-native security platform that provides "360-degree access control coverage for all critical IT assets" Compl. ¶45
- Functionally, it is alleged to perform "endpoint posture assessments" to ensure devices meet security policies before connecting to the network Compl. ¶46 This involves monitoring device risk posture by looking at factors like the status of antivirus software and firewalls Compl. ¶46 The complaint includes a screenshot of the Portnox user interface for "Endpoint Risk Posture Assessment," which shows a risk score that can trigger "Allow," "Alert," or "Block" actions Compl. ¶46
- The complaint alleges that the Portnox ZTNA products integrate with Microsoft's Intune service, which utilizes a device's Trusted Platform Module (TPM), to obtain device information through digitally-signed certificates and determine if the device is secure Compl. ¶47 Compl. ¶48
IV. Analysis of Infringement Allegations
The complaint provides a detailed theory of infringement for Claim 19 of the '705 Patent.
'705 Patent Infringement Allegations
| Claim Element (from Independent Claim 19) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| [A] detecting an insecure condition on a first host that has connected or is attempting to connect to a protected network, | The Portnox ZTNA product delivers endpoint posture assessments to ensure endpoints meet security and compliance policies before connecting to the network. The complaint provides a marketing graphic showing Portnox Cloud performing "Risk Mitigation" and "Compliance" checks. | ¶46 | col. 1:34-38 |
| [B1] contacting a trusted computing base associated with a trusted platform module within the first host, | The accused product allegedly meets this element through its integration with Microsoft's Intune service, which uses Trusted Platform Module (TPM) technology to enhance device security. A screenshot shows the Portnox interface for setting up the "MS INTUNE INTEGRATION SERVICE." | ¶47 | col. 22:20-22 |
| [B2] receiving a response, and determining whether the response includes a valid digitally signed attestation of cleanliness, | The Portnox ZTNA product, via its Intune integration, allegedly receives information from the host computer through digitally-signed certificates to determine if the host is secure and can be trusted. The complaint includes a diagram illustrating the flow of device attestation between a Windows device, Azure Entra, and Intune. | ¶48 | col. 22:23-25 |
| [C] wherein the valid digitally signed attestation of cleanliness includes at least one of an attestation that the trusted computing base has ascertained that the first host is not infested, and an attestation that the trusted computing base has ascertained the presence of a patch or a patch level associated with a software component on the first host; | The Portnox product allegedly checks endpoint compliance by matching configuration parameters, such as the status of antivirus programs, against device profile attributes. A screenshot shows a policy setting that increases a device's risk score if it lacks supported antivirus software. | ¶49 | col. 22:26-32 |
| [D] when it is determined that the response does not include a valid digitally signed attestation of cleanliness, quarantining the first host, including by preventing the first host from sending data to one or more other hosts associated with the protected network, | The Portnox product allegedly quarantines non-compliant devices, restricting them to a "quarantine zone" with limited network access. | ¶50 | col. 22:33-38 |
| [E] wherein preventing the first host from sending data... includes [E1] receiving a service request... serving a quarantine notification page... [E2] and in the event the service request comprises a DNS query, providing in response an IP address of a quarantine server... | The Portnox product allegedly delivers a quarantine message or "Access Denied" message when a device does not meet policy requirements. The complaint alleges Portnox can redirect a user to a support page or display a custom message, which serves as the quarantine notification. | ¶51; ¶52 | col. 22:39-49 |
| [F] permitting the first host to communicate with the remediation host. | The Portnox product allegedly allows a quarantined device to access remediation resources, such as software update servers, to become compliant. | ¶53 | col. 22:48-49 |
- Identified Points of Contention:
- Scope Questions: A central question may be whether the system described in the complaint, which relies on an integration with a third-party service (Microsoft Intune), constitutes "contacting a trusted computing base" as claimed by the patent. The dispute may center on whether the claimed invention can be practiced by combining separate products in this manner.
- Technical Questions: The infringement allegation relies heavily on the functionality provided by Microsoft Intune being attributable to the Portnox product. A key question will be what evidence demonstrates that the Portnox product itself performs the claimed steps of "contacting," "receiving," and "determining," rather than simply consuming the result of a process performed entirely by Intune.
V. Key Claim Terms for Construction
The Term: "trusted computing base"
Context and Importance: This term is the core of the security verification process in Claim 19. The complaint alleges this limitation is met via integration with Microsoft Intune and its use of the Trusted Platform Module (TPM) Compl. ¶47 The definition of this term will be critical to determine if a system that relies on a third-party cloud service for attestation falls within the scope of the claims.
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent specification does not appear to provide an explicit definition of "trusted computing base," nor does it limit the invention to a specific hardware implementation. A party could argue that any system, hardware or software, that provides a reliable attestation of cleanliness could meet the definition.
- Evidence for a Narrower Interpretation: The claim itself explicitly links the "trusted computing base" to a "trusted platform module" ʼ705 Patent, col. 22:20-22 A party may argue that this linkage requires a specific hardware-based root of trust, as described in the complaint's own exhibits regarding TPM technology Compl. ¶47, potentially limiting the term's scope to systems with such hardware.
The Term: "quarantining the first host"
Context and Importance: The definition of "quarantining" is central to the infringement analysis, as it describes the primary action taken against a non-compliant device. The complaint alleges that blocking a device and displaying a notification message satisfies this element Compl. ¶50 Compl. ¶51
Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent describes quarantining as providing "only limited access to the protected network" ʼ705 Patent, abstract This could be argued to encompass a range of restrictive actions, including completely blocking access to the protected network while allowing remediation access.
- Evidence for a Narrower Interpretation: The claims and specification describe a specific set of actions for quarantining, including "preventing the first host from sending data to one or more other hosts" and redirecting service requests to a "quarantine server" ʼ705 Patent, col. 22:33-47 A party may argue that a simple "block" action without the specific redirection mechanism for both web and DNS requests does not meet the full scope of this limitation.
VI. Other Allegations
- Indirect Infringement: The complaint alleges that Portnox induces infringement by "promoting, advertising, and instructing customers and potential customers to use" the accused products in an infringing manner Compl. ¶54
- Willful Infringement: Willfulness is alleged based on Portnox's purported actual knowledge of the '705 Patent. The complaint claims this knowledge stems from a notice letter sent "no later than June 2025" and, alternatively, from the filing of the complaint itself Compl. ¶39 Compl. ¶55 The plaintiff requests enhanced damages as a result Compl., Prayer C
VII. Analyst's Conclusion: Key Questions for the Case
A central issue will be one of claim scope and attribution: Can the functionality of a third-party service (Microsoft Intune), which is merely integrated with the accused product, satisfy claim elements requiring active steps like "contacting" and "determining"? The court will need to decide whether Portnox's product is merely a passive recipient of a security status or an active participant in the claimed process.
A second key issue will be one of definitional scope: What technical actions constitute "quarantining" under the patent? The case may turn on whether the accused product's method of blocking access and displaying a notification page performs the same function in the same way as the patent's more detailed description of intercepting and redirecting both web and DNS traffic to a specific quarantine server.
Finally, a critical question will be the interpretation of "trusted computing base". The dispute will likely focus on whether this term, as linked to a "trusted platform module" in the claim, requires a specific hardware-based security component on the host device, or if it can be construed more broadly to cover software or cloud-based attestation services.