7:26-cv-00316
Taasera Licensing LLC v. Open Text Corp
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Taasera Licensing LLC (Texas)
- Defendant: Open Text Corporation (Canada) and Open Text Inc. (Delaware)
- Plaintiff’s Counsel: Dematteo Law LLC; Truelove Law Firm, PLLC
- Case Identification: 7:26-cv-00316, W.D. Tex., 10/08/2026
- Venue Allegations: Venue is alleged to be proper for Open Text Corporation as a foreign corporation that may be sued in any judicial district. Venue for Open Text Inc. is based on allegations that it has a regular and established place of business within the Western District of Texas, including physical offices in Austin and San Antonio.
- Core Dispute: Plaintiff alleges that Defendant’s endpoint security, threat detection, and threat intelligence products infringe four U.S. patents related to runtime application security, risk assessment, and threat remediation.
- Technical Context: The technology at issue addresses methods for identifying and mitigating advanced cybersecurity threats by analyzing the runtime behavior, context, and event sequences of software applications on computing devices.
- Key Procedural History: This First Amended Complaint follows an original complaint, with the plaintiff alleging Defendant had knowledge of the patents at least as of the date of the original filing. Notably, U.S. Patent No. 7,673,137, one of the patents-in-suit, was the subject of an Ex Parte Reexamination (Certificate US 7,673,137 C1, issued Jan. 28, 2025), which resulted in the cancellation of claims 6-29. The complaint asserts claim 14 of this patent, which falls within the cancelled range, raising a threshold question about the viability of this infringement count.
Case Timeline
| Date | Event |
|---|---|
| 2002-01-04 | ’137 Patent Priority Date |
| 2010-03-02 | ’137 Patent Issue Date |
| 2011-02-17 | ’441 Patent Priority Date |
| 2012-05-01 | ’616 Patent Priority Date |
| 2012-12-04 | ’441 Patent Issue Date |
| 2013-01-15 | ’517 Patent Priority Date (Filing Date) |
| 2014-09-30 | ’517 Patent Issue Date |
| 2015-07-28 | ’616 Patent Issue Date |
| 2025-01-28 | ’137 Patent Reexamination Certificate Issued |
| 2026-10-08 | First Amended Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,327,441 - "System and Method for Application Attestation"
The Invention Explained
- Problem Addressed: The patent addresses security challenges arising from the trend towards cloud computing and software-as-a-service models, where traditional security measures may be insufficient ʼ441 Patent, col. 1:15-24
- The Patented Solution: The invention proposes an "attestation service" that evaluates the trustworthiness of a running application. A "runtime monitor" on a target platform inspects the application's "execution context" (e.g., files, processes) and provides this information, along with an "introspection based security context" from external "collaboration services," to an "attestation broker" ʼ441 Patent, col. 6:45-56 This broker then generates an "application artifact" and "application statements" that attest to the application's security posture at runtime, allowing access control decisions to be made based on this dynamic attestation ʼ441 Patent, abstract ʼ441 Patent, FIG. 1
- Technical Importance: This approach moves beyond static, topology-based security to enable context-aware access control based on the verified, real-time behavior and state of an application ʼ441 Patent, col. 2:42-49
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶23
- Essential elements of claim 1 include:
- receiving, by a remote attestation server, a runtime execution context (including executable file binaries and loaded components) from a computing platform;
- receiving, by the attestation server, a security context (including an execution analysis of those binaries and components);
- generating, by the attestation server, a report indicating security risks based on the received runtime and security contexts, as an attestation result; and
- sending the attestation result from the attestation server.
- The complaint does not explicitly reserve the right to assert dependent claims for the ’441 Patent.
U.S. Patent No. 8,850,517 - "Runtime Risk Detection Based on User, Application, and System Action Sequence Correlation"
The Invention Explained
- Problem Addressed: The patent notes that traditional security programs are often unable to detect "advanced persistent threats" (APTs), which can remain hidden while causing damage ʼ517 Patent, col. 1:25-34
- The Patented Solution: The invention describes a method for assessing runtime risk by monitoring for and identifying an "action sequence," which is a series of at least two performed actions, such as a user action, application action, or system action ʼ517 Patent, abstract The system stores a database of rules identifying various action sequences and a database of assessment policies that use these rules. By correlating observed actions against these policies, the system can identify a runtime risk and generate a corresponding "behavior score" for the application or device ʼ517 Patent, col. 2:1-9 ’517 Patent, FIG. 2
- Technical Importance: This method aims to predict threats by analyzing the contextual sequence of events rather than just isolated actions, allowing for the identification of sophisticated, multi-step attacks ʼ517 Patent, col. 8:1-9
Key Claims at a Glance
- The complaint asserts at least independent claim 1 Compl. ¶33
- Essential elements of claim 1 include:
- storing a plurality of rules, each identifying an "action sequence";
- storing a plurality of assessment policies, each including at least one rule;
- identifying, using an assessment policy, a "runtime risk" for an application program, which indicates a threat of the identified action sequence; and
- identifying, by a runtime monitor, a "behavior score" based on the identified runtime risk, where an action sequence comprises at least two performed actions (user, application, or system).
- The complaint does not explicitly reserve the right to assert dependent claims for the ’517 Patent.
Multi-Patent Capsule: U.S. Patent No. 9,092,616
- Patent Identification: U.S. Patent No. 9,092,616, "Systems and Methods for Threat Identification and Remediation," issued July 28, 2015.
- Technology Synopsis: The invention describes a system for providing runtime operational integrity. A "trust orchestration server" receives a "dynamic context" (including endpoint events) from a monitored device, receives third-party "network endpoint assessments," generates "temporal events" from those assessments, correlates the endpoint and temporal events, and generates an "integrity profile" for the system Compl. ¶18 ’616 Patent, abstract
- Asserted Claims: At least independent claim 1 Compl. ¶43
- Accused Features: The complaint accuses OpenText's products that provide threat identification and remediation by collecting and correlating endpoint events, network assessments, and other data to create an integrity profile or risk score for a system Compl. ¶¶18, 20
Multi-Patent Capsule: U.S. Patent No. 7,673,137
- Patent Identification: U.S. Patent No. 7,673,137, "System and Method for the Managed Security Control of Processes on a Computer System," issued March 2, 2010.
- Technology Synopsis: The technology provides security for a computing device by first determining if a new program is an "allowed program." If it is, execution is permitted. If not, the system suspends the program, determines whether to permit it to run, and if so, monitors its execution at the operating system kernel level to detect malicious activity Compl. ¶19 ’137 Patent, abstract As noted in Section I, the asserted claim 14 of this patent was cancelled during reexamination.
- Asserted Claims: At least independent claim 14 Compl. ¶53
- Accused Features: The complaint accuses OpenText's products that identify allowed programs (e.g., via whitelists), receive signals about new programs, and monitor new programs at the operating system kernel level Compl. ¶¶19, 20
III. The Accused Instrumentality
Product Identification
The complaint identifies a broad suite of OpenText products, including but not limited to the OpenText Endpoint Protection System (formerly Webroot® SecureAnywhere® Business Endpoint Protection), OpenText Core Endpoint Detection and Response (Core EDR), OpenText Core Managed Detection and Response (Core MDR), the OpenText/Webroot Security cloud console, the OpenText Threat Intelligence platform (formerly Webroot® BrightCloud®), OpenText DNS Protection, and OpenText Network Detection and Response (formerly Bricata®) Compl. ¶20
Functionality and Market Context
The Accused Instrumentalities are described as a comprehensive cybersecurity portfolio providing endpoint protection, antivirus, network detection and response (NDR), threat intelligence, and behavioral monitoring functionalities Compl. ¶20 The complaint alleges these products operate by performing functions such as runtime risk identification, action-sequence correlation, file and script execution analysis, and reputation scoring to protect customer systems from threats Compl. ¶20 The complaint positions these products as successors to technologies from Webroot, BrightCloud, and Bricata, suggesting they serve a significant market for enterprise security Compl. ¶20
IV. Analysis of Infringement Allegations
The complaint references preliminary claim charts attached as Exhibits A-D but does not include them in the filing (Compl. ¶¶28, 38, 48, 58). As such, a detailed tabular analysis is not possible. The narrative infringement theories for the lead patents are summarized below.
U.S. Patent No. 8,327,441 Infringement Allegations
The complaint alleges that the Accused Instrumentalities practice the invention by operating a system where a cloud-based component (e.g., the OpenText/Webroot Security cloud console) functions as the claimed "attestation server" Compl. ¶¶16, 20 This server allegedly receives a "runtime execution context" and a "security context" from endpoint agents running on customer devices. Based on this information, the server is alleged to generate an "attestation result," such as a reputation score, which reflects the security risks of a running application Compl. ¶16
U.S. Patent No. 8,850,517 Infringement Allegations
The complaint alleges that the Accused Instrumentalities, particularly those with "action-sequence-correlation" functionality, infringe by implementing the claimed method for assessing runtime risk Compl. ¶¶17, 20 The infringement theory is that the products use a set of "rules" and "assessment policies" to identify "action sequences"—combinations of user, application, and system actions. By correlating these observed sequences, the products allegedly identify a "runtime risk" and generate a "behavior score" reflecting that risk, as claimed in the patent Compl. ¶17
- Identified Points of Contention:
- Scope Questions: A central question for the '441 Patent will be whether OpenText's cloud-based management consoles and threat intelligence platforms meet the specific definition of an "attestation server" that generates an "attestation result," or if they perform a more general security analysis. For the '517 Patent, a key dispute may be whether the behavioral monitoring in the accused products constitutes the specific "action sequence" correlation required by the claims.
- Technical Questions: For the '441 Patent, a technical question is what evidence demonstrates that the accused products generate a report based on the combination of both a "runtime execution context" and a separate "security context" as the claim requires. For the '517 Patent, the case may turn on evidence showing that a "behavior score" is generated based on policies that identify specific, multi-step "action sequences," as opposed to being derived from general heuristics or single-event analysis.
No probative visual evidence provided in complaint.
V. Key Claim Terms for Construction
- The Term: "attestation server" (’441 Patent, claim 1)
- Context and Importance: This term is the central component of claim 1. The dispute will likely focus on whether OpenText's cloud infrastructure, which provides threat intelligence and management, qualifies as an "attestation server." The definition will determine if the accused architecture maps onto the claimed system.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification describes the component in functional terms as a service or broker that generates artifacts and statements based on received context, which could support an argument that any server performing this function infringes ʼ441 Patent, col. 7:6-14
- Evidence for a Narrower Interpretation: The detailed description and figures show a specific "Attestation Broker" architecture that interacts with a "Runtime Monitor" and "Collaboration Services" in a particular manner ʼ441 Patent, FIG. 1 This could support a narrower construction tied to this disclosed structure.
- The Term: "action sequence" ’517 Patent, claim 1
- Context and Importance: This term defines the core inventive concept of correlating multiple events. Practitioners may focus on this term because its construction will determine whether the general behavioral analysis performed by the accused products is the same as the specific multi-step sequence correlation claimed by the patent. The claim requires the sequence to comprise "at least two performed actions."
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The claim broadly defines an action as "a user action, an application action, or a system action," which could support construing any combination of two such events as an "action sequence" ʼ517 Patent, col. 10:15-18
- Evidence for a Narrower Interpretation: The specification provides specific examples of action sequences, such as a user action followed by a system action, or a user action followed by an application action and then a system action ʼ517 Patent, col. 7:29-51 ’517 Patent, FIG. 3B This may support an argument that the term requires a causally or logically linked series of events, not just any two chronologically proximate actions.
VI. Other Allegations
- Indirect Infringement: The complaint alleges both induced and contributory infringement for all patents-in-suit. Inducement is based on allegations that OpenText provides instructions, documentation, marketing materials, and technical support that encourage and guide customers to use the Accused Instrumentalities in an infringing manner Compl. ¶26 Compl. ¶36 Compl. ¶46 Compl. ¶56 Contributory infringement is based on allegations that the accused components are material to the inventions, are not staple articles of commerce, have no substantial non-infringing uses, and are known by OpenText to be especially adapted for infringement Compl. ¶27 Compl. ¶37 Compl. ¶47 Compl. ¶57
- Willful Infringement: Willfulness is alleged for all patents-in-suit. The basis for willfulness is the allegation that OpenText had knowledge of the patents "at least as of the date of the original Complaint" and acted with intent or willful blindness Compl. ¶26 Compl. ¶36 Compl. ¶46 Compl. ¶56 The prayer for relief explicitly requests a declaration that infringement is willful Compl. p. 17, ¶b
VII. Analyst’s Conclusion: Key Questions for the Case
- A threshold legal issue will be the viability of the claim for the ’137 Patent. Given that the asserted claim 14 was cancelled in an ex parte reexamination, the court will have to address whether this count can proceed.
- A central question of claim scope will permeate the case: do OpenText’s general-purpose cybersecurity platforms, which perform functions like behavioral analysis and reputation scoring, fall within the specific architectural and functional requirements of the asserted claims? For example, does OpenText’s cloud console function as the claimed "attestation server" (’441 Patent), and does its behavioral analysis engine implement the claimed "action sequence" correlation ’517 Patent?
- A key evidentiary challenge for the plaintiff will be one of technical proof: can Taasera demonstrate that the accused products operate in the precise manner claimed, as opposed to using other, more conventional methods common in the cybersecurity field? The case will likely require a deep technical dive into how the accused products analyze data, correlate events, and generate risk scores, compared to the specific steps recited in the patent claims.