DCT
1:25-cv-00514
Security First Innovations LLC v. IBM Corp
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Security First Innovations, LLC (Virginia)
- Defendant: International Business Machines Corporation (New York)
- Plaintiff’s Counsel: The Law Offices of Charles B. Molster, III PLLC; Kaleo Legal; Sullivan & Cromwell LLP
- Case Identification: 1:25-cv-00514, E.D. Va., 03/24/2025
- Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Virginia because IBM maintains a regular and established place of business in the district, including multiple offices and at least five data centers in cities such as Ashburn and Chantilly. The complaint asserts that these data centers play a critical role in the operation of the accused infringing systems.
- Core Dispute: Plaintiff alleges that Defendant’s IBM Cloud Object Storage System infringes three patents related to methods for securely storing, splitting, and retrieving encrypted data in a distributed computing environment.
- Technical Context: The technology concerns securing "Data At-Rest" in cloud storage systems by combining data encryption with information dispersal techniques (slicing or sharding data across multiple physical locations) to enhance security and fault tolerance.
- Key Procedural History: The complaint alleges a long-term business relationship between Plaintiff's predecessor-in-interest, Security First Corporation (SFC), and IBM, beginning in the early 2000s. This history includes multiple alleged disclosures of SFC's patent portfolio to IBM starting in 2005, joint development agreements, and a notice in 2006 that a third-party company, Cleversafe, might be infringing SFC's patents. IBM subsequently acquired Cleversafe in 2015. The complaint alleges that IBM continued to use the patented technology after cancelling its last contract with SFC in 2019, forming the basis for allegations of pre-suit knowledge and willful infringement.
Case Timeline
| Date | Event |
|---|---|
| 2004-10-25 | Priority Date for ’456, ’194, and ’802 Patents |
| 2007-01-01 | IBM allegedly began offering cloud-related services |
| 2011-01-01 | IBM launched SmartCloud services |
| 2012-09-18 | U.S. Patent No. 8,271,802 Issued |
| 2013-01-01 | IBM acquired SoftLayer Technologies |
| 2014-12-02 | U.S. Patent No. 8,904,194 Issued |
| 2015-09-15 | U.S. Patent No. 9,135,456 Issued |
| 2015-10-01 | IBM acquired Cleversafe |
| 2025-03-24 | Complaint Filing Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 9,135,456 - Secure Data Parser Method and System
- Issued: September 15, 2015
The Invention Explained
- Problem Addressed: The patent's background section describes the security flaws of prior art cryptographic systems, which were highly user-reliant. These flaws included poor private key management by unsophisticated users, security vulnerabilities from "key migration" across multiple devices via backup systems, and the risk of complete data loss if a physical device storing biometric credentials was lost or stolen (Compl. ¶29-31; ’194 Patent, 1:50-2:26).
- The Patented Solution: The invention proposes a method to secure data that reduces user reliance by combining encryption with data dispersal. A first data set is encrypted using an encryption key. Then, in a counter-intuitive step, the system "logically combines" a portion of that encrypted data with the key itself to create a "resultant." This resultant is then packaged with the encrypted data to form a second data set, which is split into multiple "shares." These shares, along with redundancy information, are stored in separate locations, enabling recovery from a subset of the total shares (Compl. ¶32; ’456 Patent, claim 1). This method obfuscates the key and stores information indicative of it alongside the data it protects (Compl. ¶33).
- Technical Importance: This approach provided a method for secure, fault-tolerant data storage suitable for distributed cloud environments, reducing the risks associated with individual users managing their own cryptographic keys (Compl. ¶33; ’456 Patent, 3:10-14).
Key Claims at a Glance
- The complaint asserts independent Claim 1 (Compl. ¶71).
- The essential elements of Claim 1 include:
- A method performed by a computer system for securing a first data set.
- Processing the first data set to produce a second data set, which comprises:
- Encrypting the first data set with an encryption key to produce an encrypted data set.
- Logically combining at least a portion of the encrypted data set with the encryption key to produce a resultant.
- The second data set comprises the encrypted data set and the resultant, where the encrypted data is required to recover the key from the resultant.
- Producing redundancy information based on the second data set.
- Producing a plurality of "n" shares from the second data set.
- Storing the "n" shares and redundancy information, with at least some shares in separate locations, such that the first data set is recoverable using a threshold number of shares that is less than "n".
- The complaint does not explicitly reserve the right to assert dependent claims for this patent.
U.S. Patent No. 8,904,194 - Secure Data Parser Method and System
- Issued: December 2, 2014
The Invention Explained
- Problem Addressed: As noted in the complaint, the specification of this patent is substantially identical to the '456 Patent and addresses the same problems of user-reliant and vulnerable prior art security systems (Compl. ¶26, fn. 9; ’194 Patent, 1:22-29).
- The Patented Solution: This patent focuses on an efficient method for retrieving and reconstructing data that has been split into shares and stored across a plurality of storage devices. The claimed solution involves identifying a set of the "fastest-responding storage devices" necessary to retrieve the minimum number of shares required for reconstruction. The identification is based at least in part on the "response time" of the storage devices (Compl. ¶36, 119; ’194 Patent, claim 1).
- Technical Importance: In a geographically distributed cloud storage system, this method improves the speed and reliability of data retrieval by prioritizing the quickest responding data sources, ensuring reconstruction can occur efficiently even if some storage nodes are slow or offline (Compl. ¶39; ’194 Patent, 18:47-19:5).
Key Claims at a Glance
- The complaint asserts independent Claim 1 (Compl. ¶109).
- The essential elements of Claim 1 include:
- A method for securely storing and retrieving data.
- Generating a plurality of shares by performing a cryptographic operation on a data set and distributing the data set among the shares, such that reconstruction is possible from a subset of shares.
- Storing the plurality of shares at a plurality of storage devices.
- Receiving a request to retrieve the data set.
- Identifying from the storage devices a set of "fastest-responding storage devices" necessary to retrieve the minimum number of shares, based at least in part on response time.
- Retrieving the minimum number of shares from that set.
- Reconstructing the data set using the retrieved shares.
- Sending the data set responsive to the request.
- The complaint does not explicitly reserve the right to assert dependent claims for this patent.
U.S. Patent No. 8,271,802 - Secure Data Parser Method and System
- Issued: September 18, 2012
- Technology Synopsis: The ’802 Patent is directed to a method of splitting an encrypted data set. The invention involves creating "data splitting information" (e.g., a set of equations) that determines how units of the encrypted data are placed into a plurality of shares, and then including data indicative of the encryption key and integrity information within those shares before they are stored (Compl. ¶34, 153, 158; ’802 Patent, claim 1).
- Asserted Claims: Independent Claim 1 (Compl. ¶144).
- Accused Features: IBM's Information Dispersal Algorithm (IDA) technology is accused of generating the "data splitting information," and its "SecureSlice AONT encryption process" is accused of including data indicative of the encryption key and integrity information with the encrypted data before it is split into shares (Compl. ¶151-158).
III. The Accused Instrumentality
Product Identification
- IBM Cloud Object Storage System, a service within the IBM Cloud suite (Compl. ¶1, 43).
Functionality and Market Context
- The accused product is a cloud storage service designed to store large volumes of unstructured data (Compl. ¶73). It uses a technology called "Information Dispersal Algorithms (IDA)" to encrypt data, separate it into "unrecognizable 'slices'," and create redundancy using erasure codes (Compl. ¶44, 73). These slices are then distributed across multiple geographic locations, disks, or storage nodes (Compl. ¶44, 46). The complaint contains a diagram from an IBM white paper illustrating this three-step process of slicing, dispersing, and retrieving data from a subset of slices (Compl. ¶76, p. 16). The system's "SecureSlice" technology combines the IDA with an "All-or-Nothing-Transform (AONT)" to encrypt the data (Compl. ¶78). For data retrieval, a feature called "SmartRead" allegedly ranks storage nodes ("Slicestors") by "real-time performance" to determine the optimal and fastest combination of slices to request for data reconstruction (Compl. ¶120).
IV. Analysis of Infringement Allegations
9,135,456 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) | Alleged Infringing Functionality - | Complaint Citation | Patent Citation |
|---|---|---|---|
| processing the first data set to produce a second data set... comprising: encrypting the first data set using an encryption key to produce an encrypted data set... | IBM's Cloud Object Storage System uses an "all-or-nothing-transform (AONT) to encrypt the data," which involves generating and using a random encryption key. - | ¶79-80 | col. 3:1-4 |
| logically combining at least a portion of the encrypted data set with the encryption key to produce a resultant... | IBM's system calculates a hash of the encrypted data and then calculates the exclusive-OR (XOR) of that hash and the encryption key. This XOR output is the alleged "resultant." The process is depicted in a diagram from an IBM document (Compl. p. 26). - | ¶81-82 | col. 75:7-21 |
| wherein the second data set comprises the encrypted data set and the resultant, and wherein all of the at least a portion of the encrypted data set is required to recover the encryption key based on the resultant... | The system appends the "resultant" (the XOR output) to the encrypted data to create an "AONT package," which constitutes the second data set. The key is recoverable only by reversing the XOR operation, which requires the resultant and the hash of the encrypted data set. - | ¶84-85 | col. 75:22-39 |
| producing redundancy information based on information in the second data set... | The system uses Information Dispersal Algorithms (IDAs), which employ erasure codes on the AONT package to create redundant "parity" slices in addition to the data slices. This redundancy is shown in a diagram from an IBM document (Compl. p. 28). - | ¶87-88 | col. 4:26-30 |
| producing a plurality of n shares from the second data set, wherein each of the n shares comprises at least some of the second data set... | The AONT package (the second data set) is sliced into a threshold number of data slices, and erasure coding creates additional encoded slices, resulting in a total of "n" shares (or slices). - | ¶90-91 | col. 4:31-33 |
| storing the plurality of n shares and the redundancy information, wherein at least some of the n shares are stored in separate storage locations and the first data set is recoverable using at least a threshold number, less than n... | The "n" slices (shares) are distributed to "Slicestor nodes," which can be separate disks, storage nodes, or geographic locations. Data is retrieved from a "subset of slices," which is a threshold number less than the total number created. - | ¶92-94 | col. 3:5-9 |
- Identified Points of Contention:
- Scope Questions: The complaint alleges that IBM’s process of calculating an XOR of a hash of the encrypted data with the encryption key satisfies the "logically combining" limitation (Compl. ¶82). A central dispute may be whether a hash of the data constitutes "at least a portion of the encrypted data set" as required by the claim. The complaint anticipates this by pleading infringement under the doctrine of equivalents (Compl. ¶83, 86).
- Technical Questions: What evidence demonstrates that "all of the at least a portion of the encrypted data set is required to recover the encryption key"? (Compl. ¶84). The infringement theory relies on the hash being derived from the encrypted data, but the factual basis for how this hash is calculated and used in key recovery will be a key technical point.
8,904,194 Patent Infringement Allegations
| Claim Element (from Independent Claim 1) - | Alleged Infringing Functionality - | Complaint Citation | Patent Citation |
|---|---|---|---|
| generating...a plurality of shares by performing a cryptographic operation on a data set and distributing the data set in the plurality of shares such that the data set can be reconstructed using any subset of the shares that includes at least a minimum number less than all of shares... | The accused system virtualizes, transforms (using AONT), slices, and disperses data using IDAs. Slices are distributed to separate locations, and the data is retrieved from a subset of those slices. - | ¶112-113 | col. 1:35-40 |
| storing the plurality of shares at a plurality of storage devices... - | Slices are distributed to Slicestor nodes, which can be configured in "SD Mode" (one slice per node) or "CD Mode" (multiple slices per node, but on different drives). These nodes and drives constitute the plurality of storage devices. - | ¶114-115 | col. 2:45-48 |
| receiving, at the electronic computing system, request to retrieve the data set... - | A client application issues a "read request" that is sent to an "Accesser node" in the accused system. This is alleged to be the claimed request. | ¶116-118 | col. 18:47-49 |
| identifying from the plurality of storage devices a set of fastest-responding storage devices necessary to retrieve the minimum number of shares, wherein the set of fastest-responding storage devices are identified based at least in part on the response time... | The "SmartRead" feature "ranks Slicestor nodes by real-time performance and requests the optimal combination (read threshold number) of slices to re-create the data." This real-time performance ranking is alleged to be the identification based on response time. This process is illustrated in a diagram provided in the complaint (Compl. p. 37). - | ¶119-122 | col. 18:50-57 |
| retrieving from the set of fastest-responding storage devices, the minimum number of shares... - | The SmartRead feature explicitly "requests slices from the...fastest available Slicestors" to meet the minimum read threshold. - | ¶123-124 | col. 18:58-61 |
| reconstructing the data set using the minimum number of shares... - | After the minimum "read threshold number of slices" is received, the Accesser node decodes the object and verifies its integrity to reassemble the data. - | ¶125-127 | col. 18:62-65 |
- Identified Points of Contention:
- Scope Questions: Does the term "fastest-responding storage devices" read on a system that uses "real-time performance" to rank nodes and requests an "optimal combination" of slices? The analysis may turn on whether "optimal combination" is synonymous with "fastest-responding," as the former could imply factors beyond pure response time (e.g., network cost, load balancing).
- Technical Questions: What specific metrics constitute the "real-time performance" used by IBM's SmartRead feature (Compl. ¶120)? The complaint alleges this is based "at least in part, on the response time" (Compl. ¶122), but the degree to which other factors influence the selection of the "optimal combination" could be a point of dispute.
V. Key Claim Terms for Construction
- The Term: "logically combining at least a portion of the encrypted data set with the encryption key" (’456 Patent, Claim 1)
- Context and Importance: This term is critical because IBM's accused system allegedly combines the encryption key with a hash of the encrypted data, not the encrypted data itself (Compl. ¶82). The case may turn on whether a hash, which is derived from the data but is not the data itself, constitutes "a portion of the encrypted data set." Practitioners may focus on this term because it represents a potential mismatch between the claim language and the accused operation.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent specification's summary of the invention describes a method for securing data by "parsing, splitting and/or separating the data...into two or more parts or portions" and also "encrypting the data" ('194 Patent, col. 1:36-40). This general language about data manipulation could be cited to support a broader view that a hash, being a mathematical representation of the data, is intrinsically linked to it.
- Evidence for a Narrower Interpretation: Claim 1 distinguishes between the "encrypted data set" and the "resultant" created by the logical combination. An argument could be made that if the inventors had intended for a derivative work like a hash to be used, they would not have specified "the encrypted data set" itself. The complaint's reliance on the doctrine of equivalents for this element suggests an anticipation of a narrow construction (Compl. ¶83).
- The Term: "fastest-responding storage devices" (’194 Patent, Claim 1)
- Context and Importance: The infringement allegation for the ’194 Patent hinges on mapping this term to IBM's "SmartRead" feature, which selects an "optimal combination" of slices based on "real-time performance" (Compl. ¶120). The definition will determine if "optimal" is equivalent to "fastest."
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The detailed description discusses the advantage of reconstructing data faster when shares are geographically separated, even when some locations are offline (Compl. ¶39; ’194 Patent, 18:47-19:5). This focus on overall speed and efficiency could support a construction where "fastest-responding" encompasses a holistic "performance" metric that yields the quickest overall result, not just the lowest latency.
- Evidence for a Narrower Interpretation: The term "response time" has a common meaning in computer science related to latency. A defendant might argue that "fastest-responding" implies identifying devices with the lowest raw response time (e.g., via a ping) and retrieving from them, whereas a system selecting an "optimal combination" based on broader "performance" metrics is technically different.
VI. Other Allegations
- Indirect Infringement: The complaint alleges inducement of infringement by IBM's customers through the provision of "instructions, manuals, technical assistance, and promotional materials relating to the installation, use, operation, and maintenance of the IBM Cloud Object Storage system" (Compl. ¶99, 134, 167). It also alleges contributory infringement by selling components that are a material part of the claimed inventions and are not staple articles of commerce (Compl. ¶100, 135, 168).
- Willful Infringement: Willfulness is alleged based on a long history of interactions between IBM and Plaintiff's predecessor, SFC. The complaint alleges that IBM had actual knowledge of the asserted patents and their technology for more than six years prior to the suit, stemming from multiple disclosures of SFC's patent portfolio beginning in 2005, joint development agreements, and discussions regarding potential infringement by Cleversafe, a company IBM later acquired (Compl. ¶53-63).
VII. Analyst’s Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: does the claim term "logically combining at least a portion of the encrypted data set," which suggests a direct operation on the data, read on the accused process of combining the key with a cryptographic hash derived from the data? The outcome may depend on whether this difference is merely semantic or represents a fundamental technical distinction.
- A key evidentiary question will be one of functional equivalence: does the accused "SmartRead" feature, which determines an "optimal combination" of data slices based on "real-time performance," operate in substantially the same way as the claimed method of identifying and retrieving from the "fastest-responding storage devices"? The analysis will likely focus on the specific factors that constitute "real-time performance" and "optimal combination" in the accused system.
- A central question for damages will be scienter: given the extensive history of alleged disclosures, joint development agreements, and the acquisition of a company previously identified as a potential infringer, what was IBM's state of mind regarding the asserted patents both before and after the suit was filed? This will be critical for the determination of willfulness.
Analysis metadata
Loading Complaint
Suggested improvements