Cosmokey Solutions Gmbh & Co. v. Duo Security LLC

15 F.4th 1091
Court of Appeals for the Federal Circuit·Decided October 4, 2021·No. 20-2043·Published·Cited by 29 cases

Opinion

United States Court of Appeals for the Federal Circuit

COSMOKEY SOLUTIONS GMBH & CO. KG, Plaintiff-Appellant

v.

DUO SECURITY LLC, FKA DUO SECURITY, INC., Defendant-Appellee

2020-2043

Appeal from the United States District Court for the District of Delaware in No. 1:18-cv-01477-CFC, Judge Colm F. Connolly.

Decided: October 4, 2021

SCOTT THOMAS WEINGAERTNER, White & Case LLP, New York, NY, argued for plaintiff-appellant. Also represented by STEFAN MENTZER, GRACE WANG, MATTHEW ROB- ERT WISNIEFF.

MARK A. LEMLEY, Durie Tangri LLP, San Francisco, CA, argued for defendant-appellee. Also represented by BETHANY BENGFORT.

Before O’MALLEY, REYNA, and STOLL, Circuit Judges.

2 COSMOKEY SOLUTIONS GMBH & CO. v. DUO SECURITY LLC

Opinion for the court filed by Circuit Judge STOLL. Concurring opinion filed by Circuit Judge REYNA.

STOLL, Circuit Judge.

CosmoKey Solutions GmbH & Co. KG appeals the United States District Court for the District of Delaware’s entry of judgment on the pleadings holding that the asserted claims of CosmoKey’s U.S. Patent No. 9,246,903 are ineligible under 35 U.S.C. § 101. The district court held that the asserted claims are directed to abstract ideas and fail to provide an inventive concept. We conclude that the claims of the ’903 patent are patent-eligible under Alice step two because they recite a specific improvement to a particular computer-implemented authentication technique . Accordingly, we reverse the decision of the district court.

BACKGROUND

I

The ’903 patent is titled “Authentication Method” and purports to disclose an authentication method that is both low in complexity and high in security. The abstract describes a method of authenticating the identity of a user performing a transaction at a terminal (e.g., a computer), including activating an authentication function on the user’s mobile device. ’903 patent Abstract, col. 2 ll. 35–40.

The patent specification recognizes that when a user communicates with a remote transaction partner (e.g., a bank, a store, or a secured database) via a communication channel like the Internet, “it is important to assure that an individual that identifies itself as an authorized user is actually the person it alleges to be.” Id. at col. 1 ll. 15–19. The specification also describes several conventional authentication methods involving a user’s mobile phone. Id. at col. 1 ll. 30–46. The specification discloses that by using a user’s mobile device for authentication, the prior art

COSMOKEY SOLSUTIONS GMBH & CO. v. DUO SECURITY LLC 3

confirms “that the person carrying the mobile device, e.g., a mobile telephone, is actually present at the location of the terminal from which the transaction has been requested.” Id. at col. 1 ll. 47–50. “Thus, as long as the user is in control of his mobile device, the authentication method assures that no third party can fake the identification data of this user and perform any transactions in his place.” Id. at col. 1 ll. 50–53.

The specification purports to improve on these conventional mobile phone authentication methods in that, according to the invention, the “authentication function is normally inactive and is activated by the user only preliminarily for the transaction, said response from the second communication channel includes the information that the authentication is active, and the authentication function is automatically deactivated.” Id. at col. 1 ll. 58–63. The specification explains the advantages of this method as follows : “In this method, the complexity of the authentication function can be reduced significantly” because all that is required “from the authentication function is to permit the authentication device to detect whether or not this function is active[,]” and “the only activity that is required from the user for authentication purposes is to activate the authentication function [within] a suitable timing.” Id. at col. 1 l. 64–col. 2 l. 3. The specification explains that there is a “predetermined time relation” in that “the authentication function is activated within a certain (preferably short) time window after the transmission of the user identification .” Id. at col. 2 ll. 8–14. The specification also touts the enhanced security provided by this method:

Since the authentication function is normally inactive , the authentication will almost certainly fail when a third party fraudulently identifies itself as the user in order to initiate a transaction. Then, the authentication would be successful only in the very unlikely event that the true user happens to activate the authentication function of his mobile 4 COSMOKEY SOLUTIONS GMBH & CO. v. DUO SECURITY LLC

device just in the right moment. Even in this unlikely case the fraud could be detected . . . . Thus, notwithstanding the low complexity, the method according to the invention offers a high level of security .

Id. at col. 2 ll. 15–32.

The specification thus explains that the claimed invention “provide[s] an authentication method that is easy to handle and can be carried out with mobile devices of low complexity.” Id. at col. 1 ll. 54–56. The specification elaborates that “[i]t is a particular advantage of the invention that the mobile device does not have to have any specific hardware for capturing or outputting information.” Id. at col. 2 ll. 44–46. According to the specification, the mobile device need only be capable of being activated for a certain period of time and connecting to a mobile network where it has an address that is linked to the identification data of the user. Id. at col. 2 ll. 46–50. Then, the authentication device must be “capable of checking whether the authentication function of the mobile device with the associated address is active.” Id. at col. 2 ll. 50–54.

Thus, instead of requiring the user to input multiple authentication factors using multiple communication channels, the user’s identity is verified by transmitting the user identification via a first communication channel and checking via a second communication channel that an authentication function is activated in the user’s mobile device . Id. at col. 1 ll. 3–9. Checking for an activated authentication function replaces the manual entry of information for an authentication factor by the user. For example , the user may activate the authentication function by activating their mobile device, id. at col. 2 ll. 56–60, or by activating an application on a mobile device, see id. at col. 6 ll. 59–62.

Claim 1 is the sole independent claim of the ’903 patent and recites:

COSMOKEY SOLSUTIONS GMBH & CO. v. DUO SECURITY LLC 5

1. A method of authenticating a user to a transaction at a terminal, comprising the steps of: transmitting a user identification from the terminal to a transaction partner via a first communication channel, providing an authentication step in which an authentication device uses a second communication channel for checking an authentication function that is implemented in a mobile device of the user, as a criterion for deciding whether the authentication to the transaction shall be granted or denied, having the authentication device check whether a predetermined time relation exists between the transmission of the user identification and a response from the second communication channel, ensuring that the authentication function is normally inactive and is activated by the user only preliminarily for the transaction, ensuring that said response from the second communication channel includes information that the authentication function is active, and thereafter ensuring that the authentication function is automatically deactivated.

Id. at col. 10 ll. 39–60.

II

In September 2018, CosmoKey sued Duo Security, Inc. 1 for infringement of the ’903 patent. In October 2019, Duo moved for judgment on the pleadings pursuant to Rule 12(c) of the Federal Rules of Civil Procedure, arguing that

Free access — add to your briefcase to read the full text and ask questions with AI

Cosmokey Solutions Gmbh & Co. v. Duo Security LLC, 15 F.4th 1091 (Fed. Cir. 2021).

15 F.4th 1091 (Cosmokey Solutions Gmbh & Co. v. Duo Security LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related