7:26-cv-00025
Athena Security LLP v. Dell Tech Inc
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Athena Security, LLP (Nevada)
- Defendant: Dell Technologies Inc. (Delaware)
- Plaintiff's Counsel: Russ August & Kabat
- Case Identification: 7:26-cv-00025, W.D. Tex., 04/20/2026
- Venue Allegations: Plaintiff alleges venue is proper because Defendant Dell Technologies Inc. has a regular and established place of business in the Western District of Texas.
- Core Dispute: Plaintiff alleges that Defendant's security software, servers, and networking switches infringe four patents related to secure code execution, network memory transactions, power management, and packet relaying.
- Technical Context: The patents-in-suit concern foundational technologies in computing and networking, addressing enterprise-level challenges in security, performance, power efficiency, and load balancing.
- Key Procedural History: The complaint notes that U.S. Patent No. 7,698,744 was diligently examined and allowed over prior art. Public records not referenced in the complaint indicate this patent also survived an ex parte reexamination, with the asserted claim remaining unchanged, which may be raised by the plaintiff to suggest the patent's strength.
Case Timeline
| Date | Event |
|---|---|
| 2004-12-03 | '744 Patent Priority Date |
| 2005-01-18 | '742 Patent Priority Date |
| 2006-08-11 | '880 Patent Priority Date |
| 2007-06-25 | '323 Patent Priority Date |
| 2010-04-13 | '744 Patent Issue Date |
| 2010-04-20 | '742 Patent Issue Date |
| 2011-06-28 | '880 Patent Issue Date |
| 2012-07-17 | '323 Patent Issue Date |
| 2026-04-20 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 7,698,744 - "Secure system for allowing the execution of authorized computer program code"
The Invention Explained
- Problem Addressed: The patent describes conventional, signature-based malware detection methods as "ineffective against the next variation of the virus" and thus unable to protect against novel or zero-day threats '744 Patent, col. 1:44-48
- The Patented Solution: The invention proposes a "proactive whitelist approach" that intercepts requests to execute code at the operating system level '744 Patent, col. 1:52-54 '744 Patent, Fig. 1 Before execution is permitted, a content authenticator (e.g., a cryptographic hash) of the code is generated and checked against a multi-level whitelist architecture, which may include local and global databases, to determine if the code is authorized '744 Patent, col. 2:1-12 '744 Patent, abstract
- Technical Importance: This architecture represented a paradigm shift from reactively blocking known malicious software to proactively permitting only known-authorized software, a strategy designed to offer more robust protection against unknown threats.
Key Claims at a Glance
- The complaint asserts independent claim 37 Compl. ¶13
- The essential elements of claim 37, a program storage device claim, require method steps for:
- intercepting a request to create a process associated with a code module;
- determining whether to authorize the request by causing a cryptographic hash value of the code module to be authenticated with reference to a whitelist database remote from the computer system; and
- allowing the code module to be loaded and executed if the cryptographic hash value matches a value within the remote whitelist database.
- The complaint reserves the right to assert other claims Compl. ¶11
U.S. Patent No. 7,702,742 - "Mechanism for enabling memory transactions to be conducted across a lossy network"
The Invention Explained
- Problem Addressed: The patent states that standard commodity networks like Ethernet are "lossy" (i.e., they can drop packets) and do not guarantee packet order, making them unsuitable for remote programmed I/O, which requires absolute reliability and strict ordering '742 Patent, col. 2:5-14
- The Patented Solution: The patent discloses a network interface that enables remote programmed I/O over a lossy network. The interface receives memory transaction messages (MTMs), encapsulates them into network packets, and assigns each packet a sending priority based on the MTM's transaction type '742 Patent, abstract It then uses a system of queues, linked lists, and acknowledgements to manage packet transmission and re-transmission, ensuring that packets are received by the remote node reliably and in the correct sequence '742 Patent, col. 3:1-24 '742 Patent, col. 11:1-17
- Technical Importance: This technology allows for the use of inexpensive, ubiquitous Ethernet networks for high-performance computing tasks that previously required costly, proprietary network hardware to ensure reliability.
Key Claims at a Glance
- The complaint asserts claims of the '742 Patent, referencing a claim chart for independent claim 1 in an exhibit Compl. ¶18 Compl. ¶20
- The essential elements of independent claim 1 include receiving memory transaction messages (MTMs), composing network packets for them, assigning sending priorities based on MTM transaction type and processor bus protocol rules, organizing packets into groups by priority, sending them over a lossy network, and ensuring their sequential and proper receipt at the remote node.
- The complaint reserves the right to assert other claims Compl. ¶18
U.S. Patent No. 8,225,323 - "Control device and control method for reduced power consumption in network device"
- Technology Synopsis: The patent addresses wasted power consumption in network devices during periods of low traffic '323 Patent, col. 1:25-33 The solution is a control device that manages multiple "transfer resources" by setting them to one of several "standby states" which have different power consumption levels and transition times to a fully active state, based on measured or predicted network load '323 Patent, abstract '323 Patent, col. 2:1-9
- Asserted Claims: Independent claim 23 is asserted Compl. ¶27
- Accused Features: The complaint accuses Dell's PowerEdge R750 and PowerEdge XE9680 servers of infringement, implicating their power management technologies Compl. ¶25
U.S. Patent No. 7,969,880 - "Device and method for relaying packets"
- Technology Synopsis: The patent seeks to solve communication load imbalance in networks with redundant pathways, such as those using link aggregation '880 Patent, col. 1:30-41 The invention is a network relay device that uses a modifiable computational expression (e.g., a hash function) on packet header data to distribute traffic across different physical ports or port groups, allowing an administrator to alter the distribution logic to alleviate traffic bottlenecks '880 Patent, abstract '880 Patent, col. 2:1-16
- Asserted Claims: Independent claim 1 is asserted Compl. ¶34
- Accused Features: The complaint accuses a wide range of Dell PowerSwitch devices running SmartFabric OS10, implicating their link aggregation and load-balancing functionalities Compl. ¶32
III. The Accused Instrumentality
The complaint identifies several categories of Dell products as the "Accused Products" Compl. ¶11 Compl. ¶18 Compl. ¶25 Compl. ¶32
Product Identification
- Security Software: Dell Safeguard and Response Compl. ¶11
- Servers: Dell PowerEdge R670, R770, R7715, R7725, R750, and XE9680 product lines Compl. ¶18 Compl. ¶25
- Networking Switches: A broad range of Dell PowerSwitch devices running SmartFabric OS10 Compl. ¶32
Functionality and Market Context
- The complaint alleges that Dell Safeguard and Response implements a proactive, whitelist-based security architecture to prevent unauthorized code execution Compl. ¶9
- The accused Dell PowerEdge servers are high-performance computing platforms. The allegations implicate their underlying network interface technology for enabling reliable, high-speed memory transactions across a network ('742 Patent allegations) and their sophisticated power management features for optimizing energy use based on workload ('323 Patent allegations) Compl. ¶18 Compl. ¶25
- The accused Dell PowerSwitch devices are enterprise-grade network switches. The infringement allegations target their load-balancing and traffic distribution capabilities, particularly in link-aggregated environments Compl. ¶32
No probative visual evidence provided in complaint.
IV. Analysis of Infringement Allegations
'744 Patent Infringement Allegations
The complaint alleges that the "Dell Safeguard and Response" product infringes claim 37 of the '744 Patent by performing a proactive whitelisting process Compl. ¶¶9-11
| Claim Element (from Independent Claim 37) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| intercepting a request to create a process associated with a code module; | The product allegedly performs "interception of process-creation requests at the operating-system level." | ¶9 | col. 15:3-7 |
| determining whether to authorize the request by causing a cryptographic hash value of the code module to be authenticated with reference to a whitelist database remote from the computer system...; | The product allegedly performs "cryptographic hash computation for the intercepted code module" and "authentication of that hash against a remote whitelist database maintained by a trusted service provider." | ¶9 | col. 15:10-16 |
| and allowing the code module to be loaded and executed within the computer system if the cryptographic hash value matches one of the cryptographic hash values of approved code modules within the remote whitelist database. | The product allows execution if the hash is authenticated against the whitelist, which is the functional outcome of the alleged proactive authorization architecture. | ¶10 | col. 16:1-15 |
'742 Patent Infringement Allegations
The complaint alleges that Dell's PowerEdge servers infringe the '742 Patent but refers to an external exhibit (Exhibit 4) for the detailed comparison of the accused products to the elements of claim 1 Compl. ¶20 As this exhibit was not provided, a detailed tabular analysis is not possible from the face of the complaint. The narrative theory is that the network interfaces in these servers implement the patented mechanism for enabling remote memory transactions over a lossy network Compl. ¶17 Compl. ¶18
- Identified Points of Contention:
- Scope Questions ('744 Patent): A central dispute may concern the interpretation of "whitelist database remote from the computer system" and "trusted service provider" Compl. ¶9 The defense may argue that Dell's cloud-based database is an integral part of its own product, not "remote" in the patent's sense, or that Dell itself is not a "trusted third party service provider" relative to its own system.
- Technical Questions ('744 Patent): An evidentiary question will be whether the accused "Dell Safeguard and Response" product performs all three recited steps-interception, cryptographic hashing for remote authentication, and conditional execution-in the specific manner required by the claim.
- Technical Questions ('742, '323, '880 Patents): For the remaining patents, the core of the dispute will likely be a technical one: whether the accused Dell servers and switches, which implement industry-standard features for networking, power management, and load balancing, practice the specific, and potentially non-standard, methods detailed in the patent claims, or if they achieve similar results through different technical means.
V. Key Claim Terms for Construction
'744 Patent
- The Term: "whitelist database remote from the computer system"
- Context and Importance: This term is critical because infringement of claim 37 requires authentication against a database that is "remote." The definition will determine whether a cloud-based service operated by the defendant (Dell) qualifies, or if it requires a database that is physically or administratively separate in a more distinct way. Practitioners may focus on this term because it distinguishes the claim from a purely localized security system.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification suggests "remote" can be relative, noting that in a server context, a "request may originate from either a client system or from the server," implying a flexible client-server architecture rather than a strict physical separation '744 Patent, col. 2:13-16
- Evidence for a Narrower Interpretation: The patent's abstract and detailed description repeatedly refer to a "global whitelist" maintained by a "trusted service provider" and distinguish it from a "local whitelist" '744 Patent, abstract '744 Patent, col. 8:21-34 Figure 1 depicts the "Global Whitelist Server" (125) as a distinct architectural block, separate from the local system's components, which may suggest a requirement for administrative or network separation.
'742, '323, and '880 Patents
The complaint does not provide sufficient detail for analysis of key claim terms for these patents.
VI. Other Allegations
- Indirect Infringement: For all four asserted patents, Plaintiff alleges induced infringement. The factual basis is that Defendant provides "user manuals and online instruction materials on its website" which allegedly "actively encourage and instruct its customers and end users" to use the Accused Products in a manner that directly infringes the patents Compl. ¶12 Compl. ¶19 Compl. ¶26 Compl. ¶33
- Willful Infringement: The complaint does not contain an explicit allegation of willful infringement. However, for each patent, it alleges that Defendant has had knowledge of the patent "Through at least the filing and service of this Complaint" Compl. ¶12 Compl. ¶19 Compl. ¶26 Compl. ¶33 This allegation provides a basis for potential post-filing enhancement of damages but does not allege pre-suit knowledge, which is typically required for a pre-suit willfulness claim.
VII. Analyst's Conclusion: Key Questions for the Case
The resolution of this case will likely depend on the court's findings on the following central questions:
A core issue will be one of definitional scope: Can claim terms rooted in specific technical contexts, such as the '744 patent's "whitelist database remote from the computer system," be construed to cover modern, integrated cloud services operated by the defendant itself? This question of claim construction will be critical in determining the boundary between the patented invention and standard industry practice.
A key evidentiary question will be one of technical specificity: Do Dell's accused products-which implement industry-standard features for security, networking, power management, and load balancing-operate using the particular, detailed mechanisms recited in the asserted claims? Or will discovery reveal a fundamental mismatch in technical operation, suggesting that Dell's products achieve similar goals through non-infringing means?
A central theme will be conventionality versus invention: The case will test whether the Asserted Patents cover specific, non-conventional solutions to technical problems, as Plaintiff alleges Compl. ¶9, or if the claims, when properly construed, are broad enough to read on the conventional and widespread technologies implemented in Dell's enterprise-grade products.