CA2683230C

Systems and methods for secure transaction management and electronic rights protection

Abstract

The present invention provides systems and methods for electronic commerce including secure transaction management and electronic rights protection. Electronic appliances such as computers employed in accordance with the present invention help to ensure that information is accessed and used only in authorized ways, and maintain the integrity, availability, and/or confidentiality of the information. Secure subsystems used with such electronic appliances provide a distributed virtual distribution environment (VDE) that may enforce a secure chain of handling and control, for example, to control and/or meter or otherwise monitor use of electronically stored or disseminated information. Such a virtual distribution environment may be used to protect rights of various participants in electronic commerce and other electronic or electronic-facilitated transactions. Secure distributed and other operating system environments and architectures, employing, for example, secure semiconductor processing arrangements that may establish secure, protected environments at each node. These techniques may be used to support an end-to-end electronic information distribution capability that may be used, for example, utilizing the 'electronic highway'.

CA2683230C, drawing sheet 1
Sheet 1 of 148

Term

Term ended

Expired 13 February 2016, 10.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

39 claims: 12 independent, 27 dependent

  1. 1
    CA 02683230 2013-04-29 CLAIMS:1. A distributed electronic rights management system comprising: plural nodes having protected processing environments, characterized in that each node can perform electronic processes in response to receipt and assembly of 5 electronic components, and at least one of the plural nodes authenticates one or more of the electronic components before assembling them, wherein a plurality of the electronic components are assembled to form a component assembly at least in part according to instructions contained in a permissions record, the permissions record identifying the plurality of electronic 10 components for assembly, being received separately from a governed object, and containing assembly instructions specifying one or more relationships between the plurality of electronic components, and wherein at least one of the protected processing environments performs an electronic process to govern use of the governed object in accordance with control 15 structures contained in the permissions record.
  2. 2
    A distributed electronic rights management method comprising:performing, with at least one protected processing environment, electronic processes in response to receipt and assembly of electronic components, and 20 authenticating, within the protected processing environment, each of the electronic components before assembling them, wherein a plurality of electronic components are assembled to form a component assembly at least in part according to instructions contained in a permissions record, the permissions record identifying one or more of the plurality of 921 CA 02683230 2013-04-29 electronic components for assembly, being received separately from a governed object, and containing assembly instructions specifying one or more relationships between the plurality of electronic components, and wherein at least one of the protected processing environments performs 5 an electronic process to govern use of the governed object in accordance with control structures contained in the permissions record.
  3. 4
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that each node can perform electronic processes in response to receipt and assembly of electronic components, and at least one of the plural nodes authenticates each of the electronic components by 15 obtaining a corresponding certificate from a certifying authority, wherein a plurality of the electronic components are assembled to form a component assembly at least in part according to instructions contained in a permissions record, the permissions record identifying the plurality of electronic components for assembly, being received separately from a governed object, and 20 containing assembly instructions specifying one or more relationships between the plurality of electronic components, and wherein at least one of the protected processing environments performs an electronic process to govern use of the governed object in accordance with control structures contained in the permissions record. 922 CA 02683230 2013-04-29
  4. 5
    A distributed electronic rights management system comprising plural nodes having protected processing environments, wherein a certifying authority that issues certificates allowing each node to authenticate electronic components before assembling them to perform and/or control electronic rights management processes, wherein a plurality of electronic components are assembled to form a component assembly at least in part according to instructions contained in a permissions record, the permissions record identifying the plurality of electronic components for assembly, being received separately from a governed object, and containing assembly instructions specifying one or more relationships between the plurality of electronic components, and wherein at least one of the protected processing environments performs an electronic process to govern use of the governed object in accordance with control structures contained in the permissions record.
  5. 6
    In a distributed electronic rights management system comprising plural nodes each having a protected processing environment, a method characterized by the step of issuing certificates allowing each node to authenticate electronic components before assembling them to perform and/or control electronic rights management processes, wherein a plurality of electronic components are assembled to form a component assembly at least in part according to instructions contained in a permissions record, the permissions record identifying the plurality of electronic components for assembly, being received separately from a governed object, and 923 CA 02683230 2013-04-29 containing assembly instructions specifying one or more relationships between the electronic components, and wherein at least one of the protected processing environments performs an electronic process to govern use of the governed object in accordance with control 5 structures contained in the permissions record.
  6. 7
    A programmable component arrangement comprising:a tamper resistant processing environment including a microprocessor, memory, a task manager, memory manager and external interface controller;10 means for loading electronic components at least in part into the memory;means for initiating one or more tasks associated with processing the components;means for certifying the validity, integrity and/or trustedness of the components;means for assembling a plurality of the components to form a component 15 assembly at least in part according to instructions contained in a permissions record, the permissions record identifying the plurality of components for assembly, being received at the processing environment separately from a governed object, and containing assembly instructions specifying one or more relationships between the plurality of electronic components, 20 means for governing use of the governed object in accordance with control structures contained in the permissions record;and means for securely delivering the component assembly. 924 CA 02683230 2013-04-29
  7. 8
    In a programmable component arrangement comprising a tamper resistant processing environment including a microprocessor, memory, a task manager, a memory manager and an external interface controller, a processing method characterized by the following steps:creating electronic components;associating events with the created components;loading the one or more of the components into the memory;initiating one or more tasks associated with processing the components;certifying the validity, integrity and/or trustedness of the created components;assembling a plurality of the components to form a component assembly at least in part according to instructions contained in a permissions record, the permissions record identifying the plurality of components for assembly, being received at the processing environment separately from a governed object, and containing assembly instructions specifying one or more relationships between the plurality of electronic components, means for governing use of the governed object in accordance with control structures contained in the permissions record;and securely delivering the component assembly.
  8. 9
    A secure component-based operating process comprising:(a) retrieving electronic components;(b) retrieving a record that specifies a plurality of the components for assembly into a component assembly;925 CA 02683230 2013-04-29 (c) checking said components and/or said record for validity;(d) using said plurality of components to form said component assembly in accordance with instructions associated with the record, wherein the record is retrieved separately from a governed electronic object, and wherein the instructions specify one 5 or more relationships between the plurality of components;and (e) performing, at a protected processing environment, a process based at least in part on said component assembly, wherein the process controls use of the governed electronic object in accordance with control structures contained in the record. 10
  9. 20
    A method for securely managing at least one operation on a data item performed at least in part by an electronic arrangement, said method comprising:(a) securely delivering a first procedure component to said electronic 20 arrangement;(b) securely delivering, to said electronic arrangement, a second procedure component separable or separate from said first procedure component;(c) assembling the first and second components to form a component assembly at least in part according to instructions contained in a permissions record, the 927 CA 02683230 2013-04-29 permissions record identifying one or both of the first and second components, being securely delivered to the electronic arrangement separately from the data item, and containing assembly instructions specifying one or more relationships between the first and second components;5 (d) performing, at a protected processing environment, at least one operation on said data item, wherein use of or access to the data item is governed in accordance with control structures contained in the permissions record;and (e) securely conditioning at least one aspect of use of said data item based on said delivering steps (a) and (b) having occurred.
  10. 37
    A secure component-based operating system comprising:component retrieving means for retrieving a plurality of components;930 CA 02683230 2013-04-29 record retrieving means for retrieving a record that specifies a component assembly;checking means, operatively coupled to said component retrieving means and said record retrieving means, for checking said component and/or said record for validity;5 using means, coupled to said checking means, for using said component to form said component assembly at least in part in accordance with instructions contained in said record, said record identifying a plurality of components for assembly, being retrieved separately from a governed electronic object, and containing assembly instructions specifying one or more relationships between the plurality of components;10 and performing means, coupled to said using means, for performing a process for governing use of or access to the governed object in accordance with control structures contained in the record, the process being based at least in part on said component assembly.
  11. 38
    A secure component-based operating system comprising:a database manager that retrieves, from a secure database, electronic components and at least one record that specifies a component assembly;an authenticating manager that checks said component and/or said record for 20 validity;a channel manager that uses a plurality of the components to form said component assembly in accordance with instructions contained in said record, the record identifying the plurality of components for assembly, being received separately 931 CA 02683230 2013-04-29 from a governed electronic object, and containing assembly instructions specifying one or more relationships between the plurality of components;and an execution manager that performs a process to govern use of or access to the governed object in accordance with control structures contained in the record, the 5 process being based at least in part on said component assembly.
  12. 39
    An electronic appliance comprising:a processor;and at least one memory device connected to said processor, wherein said processor 10 comprises: retrieving means for retrieving electronic components, and at least one record that specifies a component assembly, from said memory device, checking means coupled to said retrieving means for checking the components and/or said record for validity, 15 using means coupled to said retrieving means for using a plurality of the components to form said component assembly in accordance with instructions contained in said record, the record identifying the plurality of components for assembly, being retrieved separately from a governed electronic object, and containing assembly instructions specifying one or more relationships between the plurality of 20 components, and performing means, coupled to said using means, for performing a process for governing use of or access to the governed object in accordance with control structures contained in the record. 932