Synopsys, Inc. v. InnoGrit Corp. was a lawsuit in the United States District Court for the Northern District of California, filed on 17 April 2019, in which Synopsys alleged that its licensee InnoGrit, a chip designer licensed to use Synopsys electronic design automation (EDA) software at an office in Shanghai, ran the software at its San Jose office by altering the identifying information of its computers to defeat Synopsys’s licence keys.[2][3] Judge Lucy H. Koh granted a preliminary injunction and later held that manipulating host identifiers to get around a licence key’s host restriction can be circumvention under the Digital Millennium Copyright Act (DMCA), not only a breach of the licence.[2][3] The parties settled in January 2020 on confidential terms that included a permanent injunction.[4]
Background
As described by the court, Synopsys licenses its EDA software under licences that grant “limited rights to install” the software and use specific programs “subject to control by [Synopsys] via its license key system”. A licence key file contains an encrypted control code and “specifies the location(s) where the licensed software is authorized to be used”.[2] Customers supply a “Host ID” for each computer that will run Synopsys licence software, and Synopsys includes it in the key file, which prevents use on other computers.[3]
On 20 January 2017 Synopsys International Ltd., the Synopsys subsidiary responsible for distribution in China, and InnoGrit signed an end user licence and maintenance agreement (EULA) for InnoGrit’s use of the software at an address in Shanghai.[2] According to an earlier order, InnoGrit had represented that it would use the software only at its Shanghai office.[1]
The dispute
Synopsys alleged that from about May 2017 InnoGrit used Synopsys software in San Jose. Its second amended complaint alleged that InnoGrit changed the identifying information of at least 15 computers in San Jose to bypass the Host ID restriction, using the software “without authorization many thousands of times”; that an employee downloaded a “crack file” of counterfeit keys, configuration instructions and unlicensed copies from an Iranian website and spread it to other computers on a USB drive; and that an employee downloaded piracy tools and a key generator from a Chinese website and placed them in a shared folder.[3] Synopsys sued under 17 U.S.C. § 1201(a)(1) (circumvention) and § 1201(a)(2) (trafficking in circumvention technology), and later added copyright infringement and unlawful importation claims over an unlicensed version of its Synplify software.[3]
InnoGrit’s main argument was that using “duly issued, authentic license keys from Synopsys that function precisely as intended” is not covered by the DMCA, so that, at worst, its conduct was a breach of the EULA. It also argued that any copying was de minimis or fair use during an evaluation period.[3] InnoGrit filed counterclaims against Synopsys and its subsidiary, which were later dismissed in the settlement.[4]
Decision or outcome
Temporary restraining order and preliminary injunction
The court refused Synopsys’s request for a temporary restraining order without notice, because Synopsys had not shown irreparable harm before InnoGrit could be heard, but ordered InnoGrit to show cause why a preliminary injunction should not issue and allowed expedited discovery.[1]
On 26 June 2019 the court granted a preliminary injunction. It relied on a forensic examination of InnoGrit’s computers by Synopsys’s consultants that found “forensic artifacts related to counterfeit license keys, counterfeit key generators, and ‘crack’ files”, and confirmed that MAC addresses had been changed manually on 11 computers in the United States, allowing the software to run on unauthorised computers because “software only runs when a software license key matches the MAC address of a computer authorized to run the software”. The court also noted evidence that unauthorised use continued until 26 May 2019, after the suit was filed.[2]
The injunction barred InnoGrit from using Synopsys software, counterfeit keys, key generators or cracked versions in violation of the DMCA, and ordered it to preserve evidence, including USB devices. It expressly did not prevent lawful use “pursuant to the terms of the end user license and maintenance agreement executed on January 20, 2017”.[2]
Motion to dismiss
On 1 October 2019 the court denied InnoGrit’s motion to dismiss. InnoGrit did not dispute that the licence key system was a technological measure controlling access to copyrighted works. On circumvention, the court followed the majority of decisions in the district that unauthorised use of a licence key is circumvention, and distinguished a contrary decision that turned on keys that still “function[ed] precisely as intended”. Altering computers’ identifying information, it held, “prevented the license key system’s Host ID requirement from restricting the use of Synopsys software as it was designed and intended to do”.[3] The court also held that a trafficking claim under § 1201(a)(2) does not require proof that the defendant used the tools it imported, and that de minimis copying and fair use could not be decided on the pleadings. It declined to rely on the EULA, noting that Synopsys itself was not a party to it and asserted no breach-of-contract claim.[3]
Settlement
After a settlement conference before a magistrate judge, the parties filed a stipulated dismissal on 24 January 2020 “in consideration of the payments, promises and mutual undertakings” in a confidential settlement agreement.[5][4] InnoGrit agreed to a permanent injunction against using Synopsys applications or licence key files “without a valid license issued from Synopsys”, which “specifically prohibits” altering identifying information on its licence server computers, including the Host ID it provides to Synopsys, and limits use to the quantity licensed. The court retained jurisdiction to enforce the agreement, and all claims and counterclaims were dismissed with prejudice.[4]
Significance for software licensing and SAM practice
The case is a district court decision at the pleading and preliminary injunction stages, not a final judgment. Its relevance for licence management lies in how a site and host restriction was enforced:
- Site-restricted licences. The licence was tied to a Shanghai address, and use in another country was the core of the dispute.[2]
- Contract or circumvention. The customer argued the dispute was at most a breach of its licence; the court allowed the vendor’s DMCA claims because host identifiers had been altered to defeat the key.[3]
- Forensic discovery. The vendor obtained expedited discovery and a forensic review of the customer’s computers early in the case.[1][2]
- Ongoing obligations. The settlement turned licence terms into a court-enforceable injunction with fee-shifting for later disputes.[4]
A related Synopsys case about counterfeit keys used after evaluation licences is described in Synopsys v. Ubiquiti.
Lessons learned
- Running licensed software outside the licensed site can be more than a breach of contract if the licence key’s host ID check is defeated. The court rejected the argument that the customer’s conduct was at worst a breach of the EULA.[3]
- Changing MAC addresses or other host identifiers to match a licence file is treated as circumvention, not merely use of a valid key. The court held that such changes stopped the key system working as intended.[2][3]
- Downloading crack files or key generators onto company systems can itself support a DMCA trafficking claim. The court held that § 1201(a)(2) does not require proof that the tools were used.[3]
- Control who can install engineering tools and what they download; one employee’s actions were attributed to the company. The allegations about the crack file and key generator concerned downloads by individual employees, placed on a USB drive and a shared folder.[3]