Fed. Cir.

Dynapass IP Holdings LLC v. Bank of America Corporation

June 11, 2026 ·25-1222 ·Panel Decision ·Moore · By Maria Santos

The United States Court of Appeals for the Federal Circuit affirmed a district court dismissal of a patent infringement claim. The court held that the patent claims required receiving a combined password, not separate passcode and token components.

Listen to this decision 0:00 / 1:05

Background

Dynapass IP Holdings LLC sued Bank of America Corporation and Bank of America, N.A. for infringing U.S. Patent No. six, nine, nine, three, six, five, eight. The patent covered systems for user authentication using a password derived from a passcode and a token. Dynapass alleged that Bank of America’s two-factor authentication feature infringed claims one through seven. The parties filed a joint stipulation of non-infringement based on the district court’s construction of the phrase receiving the password. The district court dismissed the case with prejudice, and Dynapass appealed.

The court’s reasoning

The court reviewed the district court’s claim construction de novo. Dynapass argued that the phrase receiving the password should include embodiments where the passcode and token are submitted separately. The court disagreed, stating that the claim language unambiguously required generating a password from the passcode and token before receiving it. The court noted that the written description repeatedly juxtaposed the password with its separate components, confirming that separate receipt of the passcode and token does not constitute receiving the password. The court cited TIP Systems, LLC v. Phillips & Brooks/Gladwin, Inc. and GPNE Corp. v. Apple Inc. to support the view that claim language controls over alternative embodiments disclosed in the patent.

What it means going forward

The ruling reinforces that patent claim language must be strictly construed according to its text and the patent’s written description, even when alternative embodiments are disclosed. It limits the scope of authentication patents to methods where a combined password is received, excluding methods where passcode and token components are submitted separately.