DCT

7:26-cv-00316

Taasera Licensing LLC v. Open Text Corp

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 7:26-cv-00316, W.D. Tex., 08/14/2026
  • Venue Allegations: Venue for Open Text Corporation, a Canadian entity, is alleged to be proper in any U.S. judicial district as it is not a resident of the United States. Venue for Open Text Inc., a Delaware corporation, is alleged to be proper based on its "regular and established place of business" within the Western District of Texas, specifically citing office locations in Austin and San Antonio, and alleged acts of infringement within the district.
  • Core Dispute: Plaintiff alleges that Defendant's endpoint and network security products infringe three patents related to runtime application attestation, risk detection, and threat identification.
  • Technical Context: The technology at issue falls within the cybersecurity domain, focusing on the dynamic analysis of software applications at runtime to assess their trustworthiness and identify security risks in complex environments like data centers and cloud computing.
  • Key Procedural History: The complaint does not mention any prior litigation, Inter Partes Review (IPR) proceedings, or licensing history related to the patents-in-suit.

Case Timeline

Date Event
2011-02-17 Priority Date for '441 Patent
2012-05-01 Priority Date for '616 Patent
2012-12-04 Issue Date for U.S. Patent No. 8,327,441
2013-01-15 Priority Date for '517 Patent
2014-09-30 Issue Date for U.S. Patent No. 8,850,517
2015-07-28 Issue Date for U.S. Patent No. 9,092,616
2026-08-14 Complaint Filing Date

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 8,327,441

  • Patent Identification: U.S. Patent No. 8,327,441, entitled "System and Method for Application Attestation," issued on December 4, 2012 (the '441 Patent). Compl. ¶10

The Invention Explained

  • Problem Addressed: The patent's background section describes the difficulty of attesting to the security of applications at runtime, particularly in data center and cloud computing environments where software is often provided as a service by third parties. '441 Patent, col. 1:15-25
  • The Patented Solution: The invention proposes an "attestation service" that evaluates an application while it is running. '441 Patent, abstract This service receives a "runtime execution context" (describing the application's current attributes and behavior) and a "security context" (providing security information, such as an analysis of the application's code). '441 Patent, abstract By combining these inputs, the service generates an "attestation result" indicating the application's current security risk, which can then be used to make access control decisions. '441 Patent, col. 7:1-13 '441 Patent, Fig. 1
  • Technical Importance: This approach enables security decisions to be based on the dynamic, real-time behavior of an application rather than on static, pre-configured rules, which is crucial for securing virtualized environments. '441 Patent, col. 2:40-49

Key Claims at a Glance

  • The complaint asserts independent claim 1. Compl. ¶21
  • The essential elements of independent claim 1 include:
    • Receiving, by an attestation server, a "runtime execution context" (including executable file binaries and loaded components) and a "security context" (including an execution analysis of those binaries and components).
    • Generating, by the attestation server, a report indicating security risks based on the received contexts.
    • Sending the attestation result from the attestation server.
  • The complaint reserves the right to assert additional claims. Compl. ¶21

U.S. Patent No. 8,850,517

  • Patent Identification: U.S. Patent No. 8,850,517, entitled "Runtime Risk Detection Based on User, Application, and System Action Sequence Correlation," issued on September 30, 2014 (the '517 Patent). Compl. ¶11

The Invention Explained

  • Problem Addressed: The patent addresses the challenge of detecting threats that manifest as a sequence of actions over time, which may appear benign when viewed in isolation. '517 Patent, col. 1:21-27
  • The Patented Solution: The invention describes a method for assessing runtime risk by correlating sequences of user, application, and system actions. '517 Patent, abstract The system uses a "rules database" to define specific "action sequences" of interest and an "assessment policy" database to evaluate them. By identifying a risky action sequence, the system can determine a "runtime risk" and generate a "behavior score" for the application or device. '517 Patent, col. 5:1-24 '517 Patent, Fig. 2
  • Technical Importance: This method allows for the detection of more sophisticated and subtle threats by analyzing the relationship and timing between different events, rather than just the events themselves. '517 Patent, col. 7:1-9

Key Claims at a Glance

  • The complaint asserts independent claim 1. Compl. ¶31
  • The essential elements of independent claim 1 include:
    • Storing rules that each identify an "action sequence" in a rules database.
    • Storing assessment policies that include at least one rule in a policy database.
    • Identifying a "runtime risk" for an application program using an assessment policy, where the risk relates to an identified action sequence.
    • Identifying a "behavior score" for the application based on the runtime risk, where an action sequence comprises at least two performed actions (user, application, or system).
  • The complaint reserves the right to assert additional claims. Compl. ¶31

Multi-Patent Capsule: U.S. Patent No. 9,092,616

  • Patent Identification: U.S. Patent No. 9,092,616, entitled "Systems and Methods for Threat Identification and Remediation," issued on July 28, 2015 (the '616 Patent). Compl. ¶12
  • Technology Synopsis: The '616 Patent describes a system for assessing the operational integrity of a computing environment. The invention centers on a "trust orchestration server" that receives a "dynamic context" (including endpoint events and actions) from an "endpoint trust agent" on a monitored device, correlates this information with third-party network assessments, and generates a comprehensive "integrity profile" for the system. '616 Patent, abstract Compl. ¶17
  • Asserted Claims: The complaint asserts independent claim 1. Compl. ¶41
  • Accused Features: The complaint alleges that OpenText's endpoint protection and network detection products, which include endpoint agents and a central "trust orchestration server" for analysis and correlation, practice the claimed invention. Compl. ¶¶17-18

III. The Accused Instrumentality

Product Identification

The complaint identifies a broad suite of products collectively termed the "Accused Instrumentalities." Compl. ¶18 This includes the OpenText Endpoint Protection System and products from companies OpenText acquired, such as Webroot, BrightCloud, and Bricata. Compl. ¶18 Specific products named include OpenText™ Core Endpoint Protection, Core Endpoint Detection and Response (EDR), Core Managed Detection and Response (MDR), the OpenText/Webroot Security cloud console, the OpenText™ Threat Intelligence platform, and OpenText™ Network Detection and Response (NDR). Compl. ¶¶18, 6-7

Functionality and Market Context

The complaint alleges the Accused Instrumentalities provide a wide range of security functions, including endpoint protection, antivirus, behavioral monitoring, runtime risk identification, action-sequence correlation, threat prevention, and network traffic inspection. Compl. ¶18 The system is described as operating through a combination of endpoint agents (e.g., OpenText/Webroot Endpoint Protection agent), cloud-based management and analysis consoles, and network sensors. Compl. ¶¶18, 6-7 The breadth of the accused product line suggests it represents a significant part of OpenText's security portfolio.

IV. Analysis of Infringement Allegations

The complaint alleges infringement of claim 1 of each of the three patents-in-suit but refers to preliminary claim charts in external Exhibits A, B, and C for detailed mapping, which were not provided with the complaint. Compl. ¶26 Compl. ¶36 Compl. ¶46 The following summarizes the narrative infringement theories presented in the complaint.

No probative visual evidence provided in complaint.

  • '441 Patent Infringement Allegations: The complaint alleges that the Accused Instrumentalities, particularly the cloud-based components like the OpenText/Webroot Security cloud console, function as the claimed "attestation server." Compl. ¶¶15, 18 These systems are alleged to receive a "runtime execution context" (data about running applications from endpoint agents) and a "security context" (results from static, dynamic, and heuristic file analysis). Compl. ¶¶15, 18 The complaint contends that based on this information, the server generates and sends an "attestation result," such as a reputation score or threat analysis, which reflects the security risks of the application at runtime. Compl. ¶15

  • '517 Patent Infringement Allegations: The complaint alleges that the Accused Instrumentalities perform the claimed method of assessing runtime risk by correlating sequences of actions. Compl. ¶16 This is allegedly accomplished through features labeled as "behavioral-monitoring," "runtime-risk-identification-and-scoring," and "action-sequence-correlation." Compl. ¶18 The complaint posits that these systems use underlying "rules" and "assessment policies" to identify risky "action sequences" and thereby generate a "behavior score" reflecting the identified risk. Compl. ¶16

  • Identified Points of Contention:

    • Scope Questions: The infringement analysis for the '441 Patent may raise the question of whether the data streams collected by the accused products can be discretely mapped to the claimed "runtime execution context" and "security context." For the '517 Patent, a potential issue is whether the accused system's architecture includes structures that a court would construe as the claimed "rules database" and "policy database."
    • Technical Questions: A key technical question for the '441 Patent is what evidence shows that the accused system's "security context" is generated from the specific "execution analysis of the executable file binaries and the loaded components" required by the claim. For the '517 Patent, a central question will be whether the threat scores generated by the accused system are functionally equivalent to the claimed "behavior score," which must be based on the risk of a multi-part "action sequence."

V. Key Claim Terms for Construction

  • Term: "attestation server" ('441 Patent, claim 1)

    • Context and Importance: This term defines the central component of the claimed method. Its construction will be critical in determining whether the accused cloud-based architecture, which provides security analysis, falls within the scope of the claim.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: The specification describes the component functionally as a service that receives context information and generates an attestation result, which may support an interpretation covering any back-end system that performs these functions. '441 Patent, col. 7:1-13
      • Evidence for a Narrower Interpretation: Figure 1 of the patent depicts the "Attestation Broker" (109) as a discrete architectural block, separate from other components. This could support an argument that the term requires a distinct, identifiable server component rather than a collection of distributed cloud functions. '441 Patent, Fig. 1
  • Term: "action sequence" '517 Patent, claim 1

    • Context and Importance: The invention is premised on detecting risk by correlating a sequence of actions, making the definition of this term fundamental to the infringement analysis.
    • Intrinsic Evidence for Interpretation:
      • Evidence for a Broader Interpretation: The claim itself defines the term broadly as "a sequence of at least two performed actions," where each action is a user, application, or system action. '517 Patent, claim 1 This language may support a view that any two such actions in chronological order could constitute a sequence.
      • Evidence for a Narrower Interpretation: The specification notes that runtime risk can be based on the "time proximity and natural affinity" of actions, and that rules in a database identify these sequences. '517 Patent, col. 6:18-20 This may support a narrower construction requiring a predefined, meaningful relationship between the actions, not just their occurrence in time.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges both induced and contributory infringement. Inducement is based on allegations that OpenText provides customers with instructions, documentation, and technical support that encourage use of the Accused Instrumentalities in an infringing manner. Compl. ¶24 Compl. ¶34 Compl. ¶44 Contributory infringement is based on allegations that the accused products are not staple articles of commerce, have no substantial non-infringing uses, and are known by OpenText to be especially adapted for use in an infringing way. Compl. ¶25 Compl. ¶35 Compl. ¶45
  • Willful Infringement: Willfulness is alleged based on knowledge of the patents "at least as of the date of this Complaint." Compl. ¶24 Compl. ¶34 Compl. ¶44 The prayer for relief explicitly seeks a judicial declaration that the infringement is willful, which would primarily apply to post-filing conduct. Compl. prayer b

VII. Analyst's Conclusion: Key Questions for the Case

  • A central issue will be one of architectural mapping: can the plaintiff demonstrate that the architecture of OpenText's security suite, which evolved through multiple acquisitions, maps onto the specific, structured components recited in the claims, such as the distinct "attestation server" of the '441 Patent or the "rules database" and "policy database" of the '517 Patent?
  • The case will also likely turn on a question of functional equivalence: does the accused system's process of collecting diverse endpoint data and generating threat scores perform the specific, multi-step functions required by the patent claims, or is there a fundamental mismatch in technical operation? For example, does the system receive distinct "runtime" and "security" contexts as claimed in the '441 Patent, or simply a generalized stream of data?
  • A third key area of dispute may be definitional scope: can terms rooted in the patents' specific embodiments, such as "security context" or "action sequence," be construed broadly enough to read on the functionality of the accused products, or will the court find that the claim language, when read in light of the specification, imposes narrower technical requirements that the accused products do not meet?
Loading Complaint