CA2373508C

Systems and methods for secure transaction management and electronic rights protection

Abstract

The present invention provides systems and methods for electronic commerce including secure transaction management and electronic rights protection. Electronic appliances such as computers employed in accordance with the present invention help to ensure that information is accessed and used only in authorized ways, and maintain the integrity, availability, and/or confidentiality of the information. Secure subsystems used with such electronic appliances provide a distributed virtual distribution environment (VDE) that may enforce a secure chain of handling and control, for example, to control and/or meter or otherwise monitor use of electronically stored or disseminated information. Such a virtual distribution environment may be used to protect rights of various participants in electronic commerce and other electronic or electronic- facilitated transactions. Secure distributed and other operating system environments and architectures, employing, for example, secure semiconductor processing arrangements that may establish secure, protected environments at each node. These techniques may be used to support an end-to-end electronic information distribution capability that may be used, for example, utilizing the "electronic highway".

CA2373508C, drawing sheet 1
Sheet 1 of 164

Term

Term ended

Expired 29 August 2017, 9.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

18 claims: 2 independent, 16 dependent

  1. 1
    CA 02373508 2006-01-27 CLAIMS 1. A Virtual distribution environment comprising:a first host processing environment, said first host processing environment comprising a registry containing one or more installation keys;a second host processing environment comprising: a central processing unit;an operating system;main memory operatively connected to said central processing unit;mass storage operatively connected to said central processing unit and said main memory;a communications port;and secure software, said secure software including: encrypted operational materials and installation materials said installation materials including: encrypted installation materials, said encrypted installation materials including: programming which causes at least certain portions of said operational materials to be decrypted, and confounding algorithm programming which uses at least one confounding algorithm to create critical values required for correct operation of said operational materials on said second host processing environment;at least one of said confounding algorithms constituting the MD5 algorithm, and unencrypted installation materials, said unencrypted installation materials including: programming which causes the decryption of said encrypted installation materials, programming which uses said communications port to establish communication with said first host processing environment, 995 CA 02373508 2006-01-27 programming which includes a secure key exchange protocol, programming which receives an installation key from said registry, and programming which uses said installation key to decrypt at least a portion of said encrypted installation materials;and one or more storage locations including one or more memory locations allocated by an operating system to a boot record file, but not used by such file, said memory locations being located after the end of said file but before the end of the memory sector allocated by said operating system to said file, said one or more storage locations storing variables used as inputs to said confounding algorithm, said one or more storage locations including a storage location on a writeable, non-volatile semiconductor memory device, which storage location is normally allocated for firmware;whereby, said installation materials are decrypted and installed and cause said operational materials to be decrypted and installed.
  2. 2
    The virtual distribution environment of Claim 1, in which at least one of the critical values constitutes a cryptographic key.
  3. 3
    The virtual distribution environment of Claim 1, in which at least one of the critical values includes a plurality of fields;and in which the confounding algorithm programming includes critical value creation programming that uses the confounding algorithm to generate a different value for each field of the plurality of fields and combines the plurality of fields to create the critical value.
  4. 4
    The virtual distribution environment of Claim 1, in which the at least one confounding algorithm includes a multiplicity of algorithms, each of said algorithms being operable to terminate with a different value stored in a predefined register.
  5. 5
    The virtual distribution environment of Claim 1, in which the confounding algorithm programming uses at least one different input variable in the generation of each of the different values.
  6. 6
    The virtual distribution environment of Claim 1, further comprising:996 CA 02373508 2006-01-27 one or more storage locations storing cryptographic keys.
  7. 7
    The virtual distribution environment of Claim 1, wherein at least one of the one or more storage locations comprises:a disk sector marked as damaged.
  8. 8
    The virtual distribution environment of Claim 1, wherein at least one of the one or more storage locations comprises:a disk sector designated as an alternative disk sector to be used to replace disk sectors marked as damaged.
  9. 9
    The virtual distribution environment of Claim 1, wherein at least one of the one or more storage locations comprises:a disk sector reserved for non-general purpose use.
  10. 10
    The virtual distribution environment of Claim 9, wherein the disk sector further comprises:a disk sector reserved for firmware storage.
  11. 11
    The virtual distribution environment of Claim 9, wherein the disk sector further comprises:a disk sector reserved for storage of information generated during testing.
  12. 12
    The virtual distribution environment of Claim 1, wherein the one or more storage locations comprise:at least one storage location on a writeable, non-volatile semiconductor memory device, the storage location being allocated for configuration data.
  13. 13
    The virtual distribution environment of Claim 1, wherein the one or more storage locations comprise:at least one storage location on a writeable, non-volatile semiconductor memory device, the storage location being allocated for BIOS. 997 CA 02373508 2006-01-27
  14. 14
    The virtual distribution environment of Claim 1, wherein the one or more storage locations comprise:one or more memory locations allocated by an operating system to a file, but not used by such file.
  15. 15
    The virtual distribution environment of Claim 1, wherein the one or more storage locations comprise:at least one unused storage location allocated to a file allocation map.
  16. 16
    The virtual distribution environment of Claim 1, wherein the one or more storage locations comprise:at least one unused storage location allocated to a directory.
  17. 17
    The virtual distribution environment of Claim 1, further comprising:one or more secure containers comprising secure contents and one or more rules governing the use of said secure contents.
  18. 18
    A virtual distribution environment comprising:a first host processing environment said first host processing environment comprising a registry containing one or more installation keys;a second host processing environment comprising: a central processing unit;a clock, main memory operatively connected to said central processing unit;mass storage operatively connected to said central processing unit and said main memory;a communications port;and secure software, said secure software including: encrypted operational materials and installation materials, said installation materials including: 998 CA 02373508 2006-01-27 encrypted installation materials, said encrypted installation materials comprising: programming which causes at least certain portions of said operational materials to be decrypted, and trusted server time programming comprising programming which controls said communications port to contact a trusted server and programming which obtains a time value from said trusted server, and clock initialization programming which synchronizes said clock to said time value obtained from said trusted value, said clock initialization programming determining whether said time value specified by said clock is the same or within a specified range as the time value obtained from said trusted server, if said determination results in an affirmative conclusion, said clock initialization programming setting an indication indicating that said clock has been synchronized with said time value obtained from said trusted server, and if said determination results in a negative conclusion, said clock initialization programming performing at least one of the following actions: setting said time value specified by said clock to be the same as or within a specified range of the time value obtained from said trusted server, or storing a time offset value indicating the difference between said time value specified by said clock and the time value obtained from said trusted server;and unencrypted installation materials said unencrypted installation materials including: programming which causes the decryption of said encrypted installation materials, programming which uses said communications port to establish communication with said first host processing environment;programming which includes a secure key exchange protocol;programming which receives an installation key from said registry;and programming which uses said installation key to decrypt at least a portion of said encrypted installation materials;999 CA 02373508 2006-01-27 whereby, said installation materials are decrypted and installed and cause said operational materials to be decrypted and installed. 1000
Independent claims18