EP0861461A2

Systems and methods for secure transaction management and electronic rights protection

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 13 February 2016, 10.6 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

526 claims: 437 independent, 89 dependent

  1. 1
    Claims of equivalent WO 9627155 A2 WE C LAI M; 1. A method for secure content dehvery including:a) encapsulating digital information within one or more digital containers;b) encrypting at least one portion of said digital information;c) associating at least partiaUy secure control information for managing interaction with said encrypted digital information and/or the digital container;d) dehvering one or more of said one or more digital containers to a digital information user;e) employing a protected processing environment for securely controlling decryption of at least a portion of said digital information.
  2. 2
    A system for secure content dehvery including:encrypting means for encrypting at least one portion of digital information;container processing means for encapsulating digital information within one or more digital containers and for associating at least partially secure control information for managing interaction with said encrypted digital information;dehvery means for dehvering one or more of said one or more digital containers to a digital information user;and at least one protected processing environment for securely controlling decryption of at least a portion of said digital information.
  3. 3
    A method for secure digital information dehvery characterized by the steps of:(a) encrypting at least a portion of said digital information through the use of a first at least one VDE node, (b) creating and encrypting, through the use of said first at least one VDE node, control information to control use of at least a portion of said digital information by plural, users, (c) securely providing said control information to said plural users, and (d) employing at least one VDE node different from said first at least one VDE node to process at least portions of said control information and to control use of said encrypted digital information by said users.
  4. 4
    A system for secure digital information dehvery characterized by:a first at least one VDE node for encrypting at least a portion of said digital information, means for creating and encrypting, through the use of said first at least one VDE node, control information to control use of at least a portion of said digital information by plural, users, means for securely providing said control information to said plural users, and at least one VDE node different from said first at least one VDE node for processing at least portions of said control information and to control use of said encrypted digital information by said users.
  5. 5
    A method for secure content dehvery wherein at least partiaUy encrypted content is encapsulated within at least one digital container and the digital container is dehvered to a digital information user, the method characterized by the steps of:associating, with the encapsulated content and/or the digital container, at least partiaUy secure control information for managing interaction with the container and or the content;and employing a protected processing environment for securely controlling decryption of at least a portion of the encrypted content based at least in part on the control information.
  6. 6
    A system for secure content dehvery wherein at least partiaUy encrypted content is encapsulated within at least one digital container and the digital container is dehvered to a digital information user, the system characterized by:a data structure that associates, with the encapsulated content and or the digital container, at least partiaUy secure control information for managing interaction with the information;and a protected processing environment for securely controlling decryption of at least a portion of the encrypted content based at least in part on the control information.
  7. 7
    A method for secure digits! information dehvery characterized by the steps of:(a) encrypting at least a portion of said digital information, (b) associating protected control information to at least a portion of said digital information, and c) providing at least a portion of said encrypted digital information to a first user and at least in part controlling use of at least a portion of said encrypted digital information through the use of at least a portion of said protected control infonnation, wherein said first user further provides at least one of (a) a copy of said at least a portion of said encrypted digital information , or (b) said encrypted digital information, to a second user, and wherein said second user associates further control information with said encrypted digital information for use in controlling use of said encrypted digital information by a third user.
  8. 8
    A system for secure digitεd information dehvery characterized by:means for encrypting at least a portion of said digital information, means for associating protected control information to at least a portion of said digital information, means for providing at least a portion of said encrypted digital information to a first user means for at least in part controlling use of at least a portion of said encrypted digital information through the use of at least a portion of said protected control information, means for εdlowing the first user to provide at least one of (a) a copy of said at least a portion of said encrypted digital information, or (b) said encrypted digital information, to a second user, and means for allowing said second user to associate further control information with said encrypted digital information for use in controlling use of said encrypted digital information by a third user.
  9. 9
    A method for secure digital transaction management including:a) encrypting digital information at a first location;b) enabling a first party to securely associate at least one control with said information for use in ensuring at least one consequence of use of said information;c) enabling one or more additional parties to securely associate at least one further control with said information for use in ensuring at least one consequence of use of said information;d) distributing at least a portion of said information to a party other than the first and additional parties at a location different from the locations of the first and additional locations;and f) decrypting at least a portion of said information at said third location, and ensuring said consequences of use of said information.
  10. 10
    A system for secure digital transaction management including interconnected structures for performing the foUowing functions:a) encrypting digital information;b) enabling a first party to securely associate at least one control with said information for use in ensuring at least one consequence of use of said infoπnation;c) enabling one or more additional parties to securely associate at least one further control with said information for use in ensuring at least one additional consequence of use of said information;d) distributing at least a portion of said information to a further party;and e) decrypting at least a portion of said information;and f) securely ensuring said consequences.
  11. 11
    A system for secure digital transaction management wherein digital information is encrypted by a first party at a first location and distributed, characterized by:a first protected processing environment for enabling the first party to securely εissociate at least a first control with said information, a further protected processing environment for enabling the further party to securely associate at least a further control with said information, and a stUl further protected processing environment for decrypting at least a portion of said information whUe controlling at least one consequence of use of the information based at least in part on the first and further controls.
  12. 12
    A method for secure digit U transaction management wherein digital information is encrypted by a first party at a first location and distributed, characterized by the foUowing steps:enabling the first party to securely associate at least a first control with said information, enabling a further party to securely associate at least a further control with said information, and transmitting the first and further controls;εmd decrypting at least a portion of said information whUe controlling at least one consequence at least in part on the transmitted controls.
  13. 13
    A method for securely automating distributed electronic processes including:a) providing secure, interoperable, general purpose rights management processing means to multiple, parties;b) establishing secure process management controls for automaticaUy, at least partiaUy remotely, and securely supporting requirements related to electronic events;c) securely distributing process management controls to party sites;d) securely maintaining at least a portion of said process management controls under the control of party processing means at said party sites;e) automaticaUy managing electronic processes at said party sites to enforce interests related to said electronic content.
  14. 14
    A system for securely automating distributed electronic processes including:interoperable rights management processing means disposed at multiple parties' sites;control establishing means for establishing secure process management controls;for remotely, automaticaUy, and securely supporting requirements related to electronic events;and for securely distributing process mεmagement controls to party sites;security means for securely maintaining at least a portion of said process management controls under the control of processing means at said party sites;and managing means for automaticaUy managing electronic processes at plural party sites to enforce interests related to said electronic events.
  15. 15
    A method for automating distributed electronic processes using interoperable processors at multiple sites, characterized by the foUowing steps:securely distributing, to the processors, process management controls for automaticaUy, and securely supporting requirements related to electronic events;securely maintaining at least a portion of said process management controls under the control of the processors;and automaticaUy managing, in a distributed manner with the processors, electronic processes at the multiple sites to enforce interests related to electronic events.
  16. 16
    A system for automating distributed electronic processes using interoperable processors at multiple sites, characterized by the foUowing:distributing means connected to the processors for securely distributing, to the processors, process management controls for remotely, automaticaUy, and securely supporting requirements related to electronic events;process control means for securely maintaining at least a portion of said process management controls under the control of the processors;and management means for automaticaUy managing, in a distributed manner with the processors, electronic processes at the multiple sites to enforce the interests related to the electronic events.
  17. 17
    A method of securely enforcing a rights seniority system characterized by the steps of:aUowing a first user to create at least one control over electronic content;and aUowing a second user to contribute at least one further control over electronic content and/or alter the control in place, the second control being subject to the first control.
  18. 18
    A system for securely enforcing a rights seniority system characterized by:a first secure environment for εiUowing a first user to contribute at least one control over electronic content;and a second secure environment for aUowing a second user to contribute at least one further control over electronic content εmd/or alter the control in place, the second control being subject to the first control.
  19. 19
    A method of securely enforcing a rights seniority system characterized by the step of aUowing a first user to create at least one electromc control that at least in part dictates the rights a second user has to create further electronic controls over the use of and/or access to electronic content.
  20. 20
    A system for securely enforcing a rights seniority system characterized by at least one means for aUowing a first user to create at least one electronic control that at least in part dictates the rights a second user has to create further electronic controls over the use of and/or access to electronic content.
  21. 21
    A method for employing protected processing environments including:a) distributing interoperable protected processing environments to plural parties;b) providing a first interoperable protected processing environment for use by a first party to enable said party to (a) encrypt digital information, and (b) create control information for managing at least one aspect of use of said digital information;c) encrypting said digital information in response to one or more instructions from said first party;d) making said digital information avaUable to a second party;e) through the use of a second interoperable protected processing environment, satisfying requirements enforced by said control information and aUowing said second party to use at least a portion of said digital information;f) through the use of said second interoperable protected processing environment securely reporting information reflecting at least one aspect of said second party use of said digital information.
  22. 22
    A system for employing protected processing environments including:interoperable protected processing environments distributed to plural parties, including a first interoperable protected processing environment for use by a first party to enable said party to (a) encrypt digital information, and (b) create control infoπnation for managing at least one aspect of use of said digital information, and further including a second interoperable protected processing environment;meεins for encrypting said digital information in response to one or more instructions from said first party, and for making said digital information avaUable to a second party;means for a second interoperable protected processing environment to satisfy requirements enforced by said control information and to aUow said second party to use at least a portion of said digital information;and to securely report information reflecting at least one aspect of said second party's use of said digital information.
  23. 23
    A method for employing protected processing environments distributed to plural parties characterized by the foUowing steps:using a first protected processing environment to encrypt digital infoπnation, and control information specifying requirements for managing at least one aspect of use of said digital information;using a second protected processing environment interoperable with the first protected processing environment to enforce the requirement specified by said control information and conditionaUy aUowing use of at least a portion of said digital information;and using the second protected processing environment to report information reflecting at least one aspect of use of said digital information.
  24. 24
    A system for employing protected processing environments distributed to plural parties characterized by:a first protected processing environment to encrypt digital information, and for handling control information specifying requirements for manε-ging at least one aspect of use of said digital information;a second protected processing environment interoperable with the first protected processing environment for enforcing at least one requirement specified by said control information and conditionεdly aUowing use of at least a portion of said digital information;and for reporting information reflecting at least one aspect of use of said digital infonnation.
  25. 25
    A secure network architecture comprising multiple cooperating interconnected nodes having protected processing environments, at least a portion of said nodes being able to intercommunicate, characterized in that VDE-protected information can be moved from a source node to a destination node and processed at least in part by the destination node.
  26. 26
    In a secure network architecture comprising multiple cooperating interconnected nodes having protected processing environments, the nodes being able to intercommunicate, a method comprising the step of moving VDE-protected information from a source node to a destination node and processed at least in part by the destination node.
  27. 27
    A secure local area network topology comprising multiple cooperating interconnected nodes, characterized in that at least some of the nodes comprise network workstations with software defining protected processing environments, and at least one of the nodes comprises a secure database server that provides information in protected form for processing by the network workstation protected processing environments.
  28. 28
    In a secure local area network topology comprising multiple cooperating interconnected nodes, a method characterized by the steps of:executing, at least in part with network workstations, software defining protected processing environments, and providing, with a secure database server, information for processing by the network workstation protected processing environments.
  29. 29
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that at least one of the plural nodes provides a protected processing environment that performs a server function for a chent comprising at least a portion of the protected processing environment of at least one other node.
  30. 30
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by providing, with at least one of the plural nodes, a protected processing environment;εind performing, with the protected processing environment, a server function for a chent comprising at least a portion of the protected processing environment of at least one other node.
  31. 31
    A method for securely managing electronic negotiations related to electronic commerce value chain activities including:a) employing a protected processing environment by a first party to securely specify rules and/or controls for managing an electronic commerce process;b) securely making said specified rules and/or controls avaUable to a second party;c) employing a protected processing environment different from said first protected processing environment to further securely specify rules εind/or controls for managing at least one commerce process related to the common commercial interests of said first party and said second party;d) employing said protected processing environment to securely electronicεiUy negotiate at least one aggregate rules and/or controls set representing the electronic interests of both said first party and said second party;e) employing a protected processing environment to manage said electronic commerce process consistent with at least a portion of said aggregate rules and/or controls set.
  32. 32
    A system for securely managing electronic negotiations related to electronic commerce value chain activities including:a first party's protected processing environment for securely specifying rules ε-nd/or controls for managing an electronic commerce process, and for securely making said specified rules and/or controls avaUable to a second party;a second party's protected processing environment different from said first party's protected processing environment to further securely specify rules and/or controls including means for managing at least one commerce process related to the common commercial interests of said first party and said second party;at least one of the first party's and the second party's protected processing environment for securely electronicaUy negotiating at least one aggregate rules and/or controls set representing the electronic interests of both said first party and said second party;and at least one of the first party's and the second party's protected processing environment including means for managing said electronic commerce process consistent with said at least a portion of said aggregate rules and/or controls set.
  33. 33
    A method for securely managing electronic negotiations related to electronic commerce value chain activities through use of first and second protected processing environment chεiracterized by:using the first environment, securely specifying rules and/or controls for managing an electronic commerce process;using the second environment, further securely specifying rules and/or controls for managing at least one commerce process related to the commercial interests of a first and a second party;employing at least one of the first and second protected processing environments to securely electronicaUy negotiate at least one aggregate rules and/or controls set representing the electronic interests of the first party and said second party;and employing at least one of the first and second protected processing environment to manage said electronic commerce process consistent with at least a portion of said aggregate rules and controls set.
  34. 34
    A system for securely managing electronic negotiations related to electronic commerce value chain activities through use of first εmd second protected processing environment characterized by:the first environment including means for securely specifying rules for managing an electronic commerce process;the second environment including means for further securely specify rules for mεmaging at least one commerce process related to the commercial interests of first and second pεirties;at least one of the first εmd second protected processing environments including means for securely electronicaUy negotiating at least one aggregate rules set at least partiaUy representing the electronic interests of said first party and said second party;and at least one of the first and second protected processing environment including means for managing said electronic commerce process consistent with said at least a portion of said aggregate rules set.
  35. 35
    A method for managing a distributed electronic commerce environment including:a) establishing a secure, certificate authority for authenticating a user identity for an electronic commerce participant wherein said identity includes one or more user class parameters;b) certifying said user identity through the use of one or more certificates enabled by said certificate authority;c) controlling the use of distributed electronic information based at least in part on class parameter information included in such certified identity.
  36. 36
    A system for securely managing a distributed electronic commerce environment including:means for establishing a user identify for an electronic commerce participant wherein said identity includes one or more user class parameters;a certificate authority for authenticating such user identity by certifying said user identity through the use of one or more certificates enabled by said certificate authority;and means for controlling the use of distributed electronic information based at least in part on class parameter information included in such certified identity.
  37. 37
    A method for securely managing a distributed electronic commerce environment to aUow interaction with an electronic commerce participant having a user identity that is certified by a certificate authority, characterized by:establishing a user identity;certifying the user identity and the user class parameter;and associating, with the user identity, at least one user class parameter, wherein said certified class parameter, at least in part, is used to control use of distributed electronic information.
  38. 38
    A system for managing a distributed electronic commerce environment to aUow interaction with an electronic commerce participant having a certified user identity, characterized by:means for associating at least one user class parameter with an estabhshed user identity;means for ascertaining the authenticity of the user identity and/or the user class parameter;and means for controlling use of distributed electronic information based at least in part on said status.
  39. 40
    A method of securely establishing user identity through use of certificates, the method characterized by:presenting an electronic token reflecting at least one user class characteristic;determining whether an electronic certificate authenticates the user class characteristic reflected by the token;and using the token as a basis for granting rights.
  40. 41
    A system for identifying a user through use of certificates, the system characterized by:means presenting an electronic token reflecting at least one user class characteristic;means for obtaining an electronic certificate;means for determining whether the electronic certificate authenticates the user class characteristic reflected by the token;and means for using the certified, authenticated token as a basis for granting rights.
  41. 42
    A system for securely managing a distributed electronic commerce environment including:means for identifying an electronic commerce participant by specifying at least one user category;means for authenticating such user identity;and means for controlling the use of distributed electronic information based at least in part on the user category.
  42. 43
    A method for securely managing a distributed electronic commerce environment to aUow interaction with an electronic commerce participant, characterized by:establishing a user identity and an associated user class parameter;and using the class parameter to, at least in part, control use of distributed electronic information.
  43. 44
    A system for managing a distributed electronic commerce environment to aUow interaction with an electronic commerce participant, characterized by:means for associating at least one user class parameter with a user identity;means for authenticating the user identity and/or the user class parameter;and means for controlling use of distributed electronic information based at least in pεirt on said status.
  44. 46
    A method of securely establishing user identity, the method characterized by:presenting an electronic token reflecting at least one user class characteristic;determining the user class characteristic reflected by the token is authentic;and using the token as at least a partial basis for granting rights.
  45. 47
    A system for securely establishing user identity characterized by:means presenting an electronic token reflecting at least one user class characteristic;authenticating the user clεiss characteristic reflected by the token;and means for using the authenticated token as a basis for grεmting rights.
  46. 48
    A method of authenticating a user identity, the method characterized by:receiving a certificate request and associated user identity;and issuing an electronic certificate for use in authenticating at least one user class characteristic associated with the user identity for granting rights based on the user class characteristic.
  47. 49
    A system for authenticating user identity, characterized by:means for receiving a certificate request and associated user identity;and means for issuing an electronic certificate for use in authenticating at least one user class characteristic associated with the user identity for granting rights based on the user class characteristic.
  48. 50
    A method of securely establishing user identity, the method characterized by:receiving a certificate request;and issuing an electronic certificate specifying at least one user class characteristic.
  49. 51
    A system for securely establishing user identity through use of certificates, characterized by:means for receiving a certificate request and associated user identity;and means for issuing an electronic certificate specifying at least one user class characteristic.
  50. 52
    A method or system of managing rights characterized in that a cryptographicaUy signed token is used to certify membership in a class, the token is authenticated, and the class membership represented by the token is used as a basis for granting and/or withholding rights and/or permissions.
  51. 53
    A method or system of managing rights characterized in that a cryptographicaUy signed token is used to certify membership in a class, the status of such token is ascertained, and the class membership represented by the token is used εis a basis for aUowing a user presenting the token to create electronic rules.
  52. 54
    A method or system of managing rights characterized in that a cryptographicaUy signed token is used to certify membership in a class, the token is vahdated, and the class membership represented by the token is used as a basis for aUowing a user presenting the token to exercise rights under electronic rules.
  53. 55
    A method for enabling a distributed electronic commerce electronic agreement system including:a) enabling distributed, interoperable secure chent protected processing environment nodes;b) establishing at least one system wide secure communications key;c) employing pubhc key encryption for communications between plural chent nodes;d) supporting the dehvery of electronic control information by individuεd chents wherein said control information at least in part specifies their respective electronic commerce εigreement rights;e) supporting at least one protected processing environment for determining the respective and/or coUective rights of said chents by establishing one or more electromc agreements based at least in part on said secure dehvery of electronic control information;f) employing a secure software container data control structure for ensuring persistent maintenance of the electronic rights of the chents;g) using secure software containers which provide for data structures that support rules and/or controls coπesponding to electronic commerce model agreement enforcement.
  54. 56
    A distributed electronic agreement system including:plural distributed, interoperahle secure chent protected processing environment nodes for supporting dehvery of electronic control information by individual chents wherein said control information at least in part specifies said chent's respective electronic commerce model -igreement rights, and for employing pubhc key encryption and authentication for communications between said plural chent nodes;means coupled to said nodes for establishing at least one system wide secure communications key;and at least one protected processing environment for: (a) determining the respective and or coUective rights of electronic commerce model chents by establishing one or more electronic agreements based at least in part on said secure dehvery of electronic control information;(b) employing a secure software container data control structure for ensuring persistent maintenance of the electronic rights of commerce model chents;and (c) using secure softwεire containers which provide for data structures that support controls corresponding to electronic commerce model agreement enforcement.
  55. 57
    A method for enabling a distributed electronic commerce electronic agreement system including distributed, interoperable secure chent protected processing environment nodes employing at least one system wide secure communications key, employing pubhc key encryption and authentication for communications between plural chent nodes, and employing an certification authority for establishing chent identity, the method characterized by:supporting the , secure dehvery of electronic commerce model agreement rights control information;determining the respective and or coUective rights of electromc commerce model c ents by establishing one or more electronic agreements based at least in part on said secure dehvery of the electronic control infonnation;employing a secure software container data control structure for ensuring remote, persistent maintenance of the electronic rights of commerce model chents;and using secure software containers which provide for data structures supporting rules and controls corresponding to electronic commerce model εigreement enforcement.
  56. 58
    A distributed electronic commerce electronic agreement system including:distributed, interoperable secure chent protected processing environment nodes employing at least one system wide secure communications key, employing pubhc key encryption and authentication for communications between plural chent nodes, employing an certification authority for establishing chent identity, and supporting the, secure dehvery of electronic commerce model agreement rights control infonnation;meεms disposed in at least one node for determining the respective and or coUective rights of electronic commerce model chents by establishing one or more electronic εigreements based at least in part on said secure dehvery of the electronic control information;and means disposed in at least one node for employing a secure software container data control structure for ensuring remote, persistent maintenεmce of the electronic rights of commerce model chents, and for using secure software containers which provide for data structures supporting rules and controls corresponding to electronic commerce model agreement enforcement.
  57. 59
    A method of securely handling electronic currency characterized by the foUowing steps:packaging electronic currency within a software container, and dehvering the software container as payment for goods or services.
  58. 60
    A system for securely handling electronic currency characterized by:means for packaging electronic currency within a software container, and means for dehvering the software container as payment for goods or services.
  59. 61
    A method or system for managing rights within an organization characterized in that electromc containers are distributed within the organization, the electronic containers having controls εissociated therewith, the controls enforcing, at least in part, an organizational hierarchy relating to the use of the containers and/or the contents thereof.
  60. 62
    A method of organizational rights management characterized by the steps of:distributing an electronic container within an organization and restricting usage, access and/or further distribution of the electronic container or the contents thereof within or outside of the organization based on electronic controls associated with the electronic container.
  61. 63
    A system for organizational rights management characterized by:means for distributing an electronic container and means for restricting usage, access and/or further distribution of the electronic container or the contents thereof within or outside of the organization based on electronic controls associated with the electronic container.
  62. 64
    A method of organizational rights management characterized by the steps of:distributing electronic containers within an organization, and using the electronic containers, at least in part, to administer content usage by persons within the organization.
  63. 65
    A system for organizational rights management characterized by:means for distributing electromc containers within εin organization, and means for using the electronic containers, at least in part, to administer content usage by persons within the organization.
  64. 66
    A method of organizational rights management characterized by the steps of:distributing electronic containers within an organization, and using the electronic containers, at least in part, to administer use of money within the organization.
  65. 67
    A system for organizational rights management characterized by electronic containers distributed within εm organization for, at least in part, administering use of money within the organization.
  66. 68
    A method of organizational rights management characterized by the steps of:distributing protected processing environments within an organization, and using the environments to, at least in part, to administer content usage by persons within the organization.
  67. 69
    A system for organizational rights management characterized by protected processing environments distributed vΛthin an organization, for, at least in part, administering content usage within the organization.
  68. 70
    A method of organizational rights management characterized by the steps of:distributing protected processing environments within an organization, and using the processing environments to, at least in part, to administer use of money by persons within the organization.
  69. 71
    A system for organizational rights management characterized by plural protected processing environments distributed within an organization for, at least in part, administering use of money within the org-mization.
  70. 72
    A rights management apphance including:a user input device, a user display device, at least one processor, and at least one element defining a protected processing environment, characterized in that the protected processing environment stores and uses permissions, methods, keys, programs and/or other information to electronicaUy manage rights.
  71. 73
    In a rights mεm-igement apphance including:a user input device, a user display device, at least one processor, and at least one element defining a protected processing environment, a method of operating the apphance characterized by the step of storing εmd using permissions, methods, keys, programs and/or other information to electronicaUy manage rights.
  72. 74
    A rights management apphance including at least one processor element at least in part defining a protected processing environment, characterized in that the protected processing environment stores and uses permissions, methods, keys, programs and/or other information to electronicaUy manage rights.
  73. 75
    In a rights management apphance including at least one processor element at least in part defining a protected processing environment, a method comprising storing and using permissions, methods, keys, programs and/or other infonnation to electronicaUy manage rights.
  74. 76
    A method of electronicεiUy storing information in a repository and distributing it on request, characterized in that the information is protected by associating electronic controls with the information, the electronic controls serving to enforce rights in the information.
  75. 77
    A system for electronicaUy storing information in a repository and distributing it on request, characterized by means for protecting information by associating electronic controls with the information, and further including means for using the electronic controls to enforce rights in the information.
  76. 78
    A self-protecting electronic container comprising:an electronic container structure for containing digital information, and an electronic protection mechanism that protects or destroys the digital information in the event of tampering.
  77. 79
    A method for a self-protecting electronic container comprising an electronic container structure for containing digital information, the method characterized by detecting an attempt at tampering and protecting or destroying the digital information in the said attempt.
  78. 80
    A method of creating a self-protecting container system comprising:providing at least one property, providing at least one attribute, providing at least one cryptographic key, providing at least one organizational structure relating the key to the property and/or attribute, and encapsulating the property, the attribute, the cryptographic key and the organizational structure, either exphcitly or by reference, into an electronic container structure.
  79. 81
    A self-protecting contε-iner system comprising:at least one property, at least one attribute, at least one cryptographic key, and at least one organizational structure relating the key to the property and/or attribute.
  80. 82
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that each node can perform self- administering processes in response to electronic components.
  81. 83
    A self-administering electronic component comprising:at least one method for performing at least a portion of a transaction, at least one method for generating audit information, and at least one method for securely receiving and interpreting administrative information.
  82. 84
    A self-administering electronic component performing the foUowing methods:at least one method for performing at least a portion of a transaction, at least one method for generating audit information, and at least one method for securely receiving and interpreting administrative information.
  83. 85
    A self-describing electronic component defining at least one parameter and or function, characterized in that the component includes at least one secure, descriptive portion used to create a human readable interface describing the parameter and/or function.
  84. 86
    A method for processing a self-describing electronic component defining at least one parameter and/or function, characterized by the step of creating, at least in part with the component, a human readable interface describing the parameter and/or function based at least in part on at least one secure, descriptive portion of the component.
  85. 87
    A method of performing an electronic transaction comprising:receiving plural components, electronically detecting the occuπence of an event, deteπriining, based on the event, a subset of the plural received components to process the event, and performing, in response to the event, at least one electronic process based on the component subset.
  86. 88
    A system for performing an electronic transaction comprising:means for receiving plural components, means for electronicaUy detecting the occurrence of an event, means for determining, bεised on the event, a subset of the plural received components to process the event, and means for performing, in response to the event, at least one electronic process based on the component subset.
  87. 89
    A distributed transaction processing method characterized by the foUowing steps:receiving a first electronic component at a first location, receiving a second electronic component at a second location, electronicaUy detecting occurrence of an event at the first location, processing, in response to the event detection, a first portion of an electronic transaction at the first location based at least in part on the first electronic component, securely transmitting at least one signal from the first location to the second location, and processing at least a second portion of the electronic transaction at the second location based at least in part on the second electronic component.
  88. 91
    A distributed transaction processing system characterized by:means at a first location for receiving a first electronic component, for electronicaUy detecting occurrence of an event, for processing, in response to the event detection, a first portion of an electronic transaction at the first location based at least in part on the first electronic component, and for securely transmitting at least one signal from the first location to a second location;and means at the second location for receiving a second electronic component, and for processing at least a second portion of the electronic transaction based at least in part on the second electronic component.
  89. 93
    A distributed electronic rights management system comprising plural nodes having protected processing environments, chεiracterized in that each node can perform electronic processes in response to receipt and assembly of electronic components, and the node authenticates each of the electronic components before assembling them.
  90. 94
    A distributed electronic rights management method comprising:performing, with at least one protected processing environment, electronic processes in response to receipt and assembly of electronic components, and authenticating, within the protected processing environment, each of the electronic components before assembling them.
  91. 96
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that each node can perform electronic processes in response to receipt and assembly of electronic components, and the node authenticates each of the electronic components by obtaining a corresponding certificate from a certifying authority.
  92. 97
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a certifying authority that issues certificates aUowing each node to authenticate electronic components before assembling them to perform and/or control electronic rights management processes.
  93. 98
    In a distributed electronic rights management system comprising plural nodes each having a protected processing environment, a method characterized by the step of issuing certificates aUowing each node to authenticate electronic components before assembling them to perform and/or control electronic rights management processes.
  94. 99
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that said nodes enforce usage and or access controls and is capable of electronicaUy obtaining compensation from a user and/or other processing of usage information for subsequent transfer to rights holders.
  95. 100
    In a distributed electronic rights management system comprising plural nodes having a protected processing environment, a method characterized by the step of enforcing usage and or access controls and electronicaUy obtaining compensation from a user and/or other processing of usage information for subsequent transfer to rights holders.
  96. 101
    A distributed electronic rights management system comprising plurεd nodes each having a protected processing environment, characterized in that each node enforces usage and/or access controls based on receipt of information from multiple other nodes.
  97. 102
    A distributed electronic rights management method characterized by the step of enforcing, with a protected processing environment, usage and/or access controls based on receipt of information from multiple other nodes.
  98. 103
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that said nodes are capable of at least temporarily extending electronic credit to an associated user for use in compensating rights holders.
  99. 104
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method of operating the environment characterized by the step of at least temporarily extending electronic credit to an associated user for use in compensating rights holders.
  100. 105
    A distributed electronic rights management system comprising plural nodes each having a protected processing environment, chεiracterized in that said nodes are capable of requesting and obtaining a user-specific electronic credit assurance from a clearinghouse before granting the user rights to access and/or use electronicaUy protected information.
  101. 106
    In a distributed electronic rights management system comprising plural nodes each having a protected processing environment, a method characterized by the step of requesting and obtaining a user-specific electronic credit assurance from a clearinghouse before granting the user rights to access and/or use electronicaUy protected information.
  102. 107
    A distributed electronic rights management system comprising plural nodes each having a protected processing environment, characterized in that each node is capable of performing and/or requesting an electronic debit or credit transaction as a condition to granting the user rights to access and/or use electronicaUy protected infonnation.
  103. 108
    In a distributed electronic rights management system comprising plural nodes each having a protected processing environment, a method characterized by the step of performing and/or requesting an electronic debit or credit transaction as a condition to granting the user rights to access and or use electronically protected information.
  104. 109
    A distributed electronic rights management system comprising plural nodes each having a protected processing environment, characterized in that each node can maintain an audit traU of user activities for reporting to a centralized location, the centralized location analyzing the user activities based on the audit trail.
  105. 110
    In a distributed electronic rights management system comprising plural nodes each having a protected processing environment, a method characterized by the steps of:mainta--ning, a plural locations, audit trails of user activities for reporting to a centralized location, and analyzing, at the centralized location, the user activities based on the audit traU.
  106. 111
    A distributed electronic rights m inε-gement system comprising plural nodes having protected processing environments, characterized in that said node can monitor user activities and trigger the occurrence of unrelated events based on the user activities and/or the electronic controls that associate the user activities with the unrelated events.
  107. 115
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of monitoring user activities at said nodes, and triggering the occurrence of unrelated events based on the user activities and electronic controls that associate the user activities with the unrelated events.
  108. 117
    A method of compromising a distributed electronic rights management system comprising plural nodes having protected processing environments, characterized by the foUowing steps:exposing a certification private key to aUow a person to pass a chaUenge/response protocol, defeating at least one of (a) an initialization chaUenge/response security, and/or (b) exposing external communication keys, creating a processing environment based at least in part on the above-mentioned steps, and participating in distributed rights management using the processing environment.
  109. 118
    A processing environment for compromising a distributed electronic rights management system comprising plural nodes having protected processing environments, characterized by the foUowing:means including an exposed certification private key to pass a challenge/response protocol, means for defeating at least one of (a) an initialization chaUenge/response security, and/or (b) exposing external communication keys, εmd means for participating in distributed rights management.
  110. 119
    A method of compromising a distributed electronic rights management system comprising plural nodes having protected processing environments, characterized by the step of compromising the permissions record of an electronic container and using the compromised permissions record to access and/or use electronic information.
  111. 120
    A system for compromising a distributed electronic rights management system comprising plural nodes having protected processing environments, characterized by means for using a compromised permissions record of an electronic container for accessing and/or using electronic information.
  112. 121
    A method of tampering with a protected processing environment characterized by the steps of:discovering at least one system-wide key, and using the key to obtain access to content and or administrative information without authorization.
  113. 122
    An arrangement including means for using at least one compromised system-wide key to decrypt and compromise content and/or administrative infoπnation of a protected processing environment without authorization.
  114. 123
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that said nodes can electronicεiUy fingerprint content before releasing it in unprotected form.
  115. 124
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by performing, in at least one of the nodes, the step of electronicaUy fingerprinting content before releasing it in unprotected form.
  116. 125
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that said nodes can embed, within the electronic content, an electronic fingerprint contammg specified information identifying a content rights holder and/or an indication of origin before including the content in an electronic container or aUowing access to such content.
  117. 126
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of embedding, within electronic content, an electronic fingerprint containing specif i ed information, including information identifying a content rights holder and/or an indication of origin before including the content in an electronic container or aUowing access to such content.
  118. 127
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that the system includes one or more usage clearinghouses that receive usage information from one or more of the plural nodes.
  119. 128
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of receiving, with a usage clearinghouse, usage information from one or more of said plural nodes.
  120. 129
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that the system includes one or more financial clearinghouses that receive financial infoπnation relating to the use of or access to content from one or more of nodes.
  121. 130
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of receiving, with one or more financial clearinghouses, financial information from one or more of the plural nodes.
  122. 131
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that the system includes one or more analysis clearinghouses that receive information from one or more of the plural nodes and analyzes the received information.
  123. 132
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of receiving, with one or more analysis clearinghouses, information from one or more of the plural nodes and analyzing the received information.
  124. 133
    A method of processing information pertaining to the use of or access to electronic content wherein such information is received from one or more nodes having protected processing environments.
  125. 134
    A method of providing credit for interaction with content to a protected processing environment node.
  126. 135
    A distributed electronic rights management system comprising plural nodes having protected processing environments, characterized in that the system includes one or more clearinghouses that transmits rights and/or permissioning information to one or more of the plural nodes.
  127. 136
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of transmitting rights and/or permissioning information from a clearinghouse to one or more of the plural nodes.
  128. 137
    A distributed electronic rights manεtgement system comprising plural nodes having protected processing environments, characterized in that the system includes one or more clearinghouses that periodicaUy transmit cryptographic material to one or more of said nodes, the cryptographic material renewing and/or replacing expiring cryptographic material.
  129. 138
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the step of periodicaUy transmitting cryptographic material from one or more clearinghouses to one more of said nodes, the cryptographic material renewing and/or replacing expiring cryptographic material.
  130. 139
    A secure electronic container characterized in that the container contains electronic controls for controlling the use of and/or access to electronic content that is external to the container.
  131. 140
    A method comprising:accessing electronic controls within a secure electronic container;and using the controls for at least in part controUing the use of and/or access to electronic content that is external to the container.
  132. 141
    A secure electromc container characterized in that the container contains electronic controls for controUing, at least in part, the use of and/or access to distributed electronic content.
  133. 142
    A method comprising:accessing electronic controls within a secure electronic container;and using the controls for controUing, at least in part, the use of and/or access to distributed electronic content.
  134. 143
    A secure electronic container characterized in that the container contains electronic controls that cause electronic content to expire on a time-dependent basis.
  135. 144
    A method for processing a secure electronic container including the step of causing, at least in part based on electronic controls within the container, electronic content to expire on a time-dependent basis.
  136. 145
    A method of metering use of and/or access to electronic infonnation chεiracterized by the step of maintaining a bitmap meter data structure including data partitions that subdivide the metering infonnation by time and/or subject matter.
  137. 146
    A system for metering use of and/or access to electronic information characterized by means for ma--ntaining a bitmap meter data structure including data partitions that subdivide the metering information by time εind/or subject matter.
  138. 147
    A distributed electronic rights management system comprising plural nodes having protected processing environments, chεiracterϊzed in that the system permits at least some of the nodes to securely describe permitted uses of electronic content and securely enforces said description.
  139. 148
    In a distributed electronic rights management system comprising plural nodes having protected processing environments, a method characterized by the steps of permitting at least some of the nodes to securely describe permitted uses of electronic content, and securely enforcing said description.
  140. 149
    A document management system comprising one or more electromc apphances containing one or more secure processing units and one or more secure databases operatively connected to at least one of said secure processing units, said system further including protected usage control information wherein (a) at least a portion of said control information is securely stored within one or more of said secure databases, and Oo) at least a portion of said control information governs the production of usεige information, at least a portion of which usage information is reported to one or more parties.
  141. 150
    In a document management system comprising one or more electronic apphances containing one or more secure processing units and one or more secure databases operatively connected to at least one of said secure processing units, a method for processing protected usage control information including the steps of securely storing at least a portion of said control infonnation within one or more of said secure databases, and (b) based at least in part on said control information, governing the production of usage information and the reporting of at least a portion of said usage information to one or more parties.
  142. 151
    A document management system comprising plural electronic apphances containing protected processing environments and one or more secure databases operatively connected to at least one of said protected processing environments, said system further including protected usage control information, wherein (a) at least a portion of said control information is securely stored within one or more of said secure databases, and (b) at least a portion of said control information governs the production of usage information and the reporting of at least a portion of said usage information to one or more parties.
  143. 152
    In a document management system comprising plural electronic apphances containing protected processing environments εmd one or more secure databases operatively connected to at least one of said protected processing environments, a method of handling usage control information including the steps of (a) securely storing at least a portion of said control information within one or more of said secure databases, and (b) governing, based on at least a portion of said control information, the production of usage information and the reporting of at least a portion of said usage information to one or more parties.
  144. 153
    An electronic contract system comprising electronic apphances containing one or more secure processing units and one or more secure databases operatively connected to at least one of the secure processing units, said system furthering including means for enabling plural parties to enter into an electronic arrangement, at least one of said databases containing secure control information for managing at least a portion of a plural party electronic arrangement.
  145. 154
    In an electronic contract system comprising plural electronic apphances containing one or more secure processing units and one or more secure databases operatively connected to at least one of the secure processing units, a method characterized by the steps of enabling plural parties to enter into to an electronic arrangement, and using secure control information contained by at least one of said databases for managing at least a portion of a plural party electronic aπεmgement.
  146. 155
    An electronic apphance arrangement containing at least one secure processing unit and at least one secure database operatively connected to at least one of said secure processing unit ( s ) , said arrangement including means to monitor usage of at least one aspect of apphance usage and control said usage based at least in part upon protected apphance usage control information.
  147. 156
    In an electronic apphance arrangement containing at least one secure processing unit and at least one secure database operatively connected to at least one of said secure processing unit(s), a method characterized by the steps of monitoring usage of at least one aspect of apphance usage and controUing said usage based at least in part upon protected apphance usage control information.
  148. 157
    An electronic apphance arrangement containing a protected processing environment and at least one secure database operatively connected to said protected processing environment, said aπangement including means to monitor usage of at least one aspect of εm amount of apphance usage and control said usage based at least in part upon protected apphance usage control information processed at least in part through use of said protected processing environment.
  149. 158
    In an electronic apphance arrangement containing a protected processing environment and at least one secure database operatively connected to said protected processing environment, a method characterized by the steps of monitoring usage of at least one aspect of apphance usage and controlling said usage based at least in pεirt upon protected apphance usage control information processed at least in part through use of said protected processing environment.
  150. 159
    An electronic apphance arrangement containing one or more CPUs wherein at least one of the CPUs incorporates an integrated secure processing unit, said arrangement storing protected apphance usage control information designed to be securely processed by said integrated secure processing unit.
  151. 160
    In an electronic apphance arrangement containing one or more CPUs wherein at least one of the CPUs incorporates an integrated secure processing unit, a method including the step of storing and securely processing protected modular component apphance usage control information with said integrated secure processing unit.
  152. 161
    An electronic apphance arrangement containing at least one first secure processing unit and one or more video controUers where at least one of the video controUers incorporates at least one second secure processing unit, said arrangement storing protected video function control information designed to be securely processed by said incorporated secure processing unit(s).
  153. 162
    In an electronic apphance arrangement containing at least one first secure processing unit and one or more video controUers where at least one of the video controUers incorporates at least one second secure processing unit, the method characterized by the step of storing protected video function control information designed to be securely processed by said incorporated secure processing unit(s).
  154. 163
    An electronic apphance arrangement containing one or more video controUers where at least one of the video controUers incorporates at least one secure processing unit, said arrangement storing protected video function control information designed to be securely processed by said incorporated secure processing unit(s), wherein at least a portion of said video function control information is stored within a secure database operatively connected to at least one of said at least one secure processing units.
  155. 164
    In an electronic apphance arrangement containing one or more video controUers where at least one of the video controUers incorporates at least one secure processing unit, a method including the steps of storing protected video function control infoπnation designed to be securely processed by sεdd incorporated secure processing unit(s), within a database operatively connected to at least one of said at least one secure processing units.
  156. 165
    An electronic apphance arrangement containing one or more video controUers and at least one secure processing unit, said arrεmgement storing component, modular protected video function control information designed to be securely processed by said secure processing unit(s), wherein at least a portion of said video function control infonnation is stored within a secure database operatively connected to at least one of said at least one secure processing unit(s).
  157. 166
    An electronic apphance arrangement containing one or more video controUers and at least one secure processing unit, a method including the step of storing component, modular protected video function control information designed to be securely processed by said secure processing unit(s), within a secure database operatively connected to at least one of said at least one secure processing unit(s).
  158. 167
    An electronic apphance arrangement containing at least one secure processing unit and one or more network communications means where at least one of the network communications means incorporates at least one further secure processing unit, said arrangement storing protected networking control information designed to be processed by said incorporated secure processing unit(s).
  159. 168
    In an electronic apphance arrangement containing at leεist one secure processing unit and one or more network communications means, a method characterized by the steps of incorporating, vrithin at least one of the network communications means, at least one further secure processing unit, storing networking control information at least in part within said incorporated secure processing unit(s), and securely processing said protected networking control information with said secure processing unit(s).
  160. 169
    An electronic apphance arrangement containing one or more modems where at least one of the modems incorporates at least one secure processing unit, said arrangement storing modular, component protected modem control information designed to be securely processed by said incorporated secure processing unit(s).
  161. 170
    In an electronic apphance arrangement containing one or more modems where at least one of the modems incorporates at least one secure processing unit, a method characterized by the step of storing and securely processing modular, component protected modem control information with said incorporated secure processing unit(s).
  162. 171
    An electronic apphance arrangement containing at least one secure processing unit and one or more modems where at least one of the modems includes at least one further secure processing unit, said arrangement storing protected modem control information designed to be securely processed by said included secure processing unit(s).
  163. 172
    In an electronic apphance arrangement containing at least one secure processing unit and one or more modems where at least one of the modems includes at least one further secure processing unit, a method including the step of storing and securely processing protected modem control infonnation within said included secure processing unit ( s ) .
  164. 173
    An electronic apphance arrangement containing at least one secure processing unit and one or more CD-ROM devices where at least one of the CD-ROM devices incorporates at least one further secure processing unit, said arrangement storing protected CD-ROM control information designed to be securely processed by said incorporated secure processing unit ( s ) .
  165. 174
    In an electromc apphance arrangement containing at least one secure processing unit and one or more CD-ROM devices where at least one of the CD-ROM devices incorporates at least one further secure processing unit, a method characterized by the step of storing and securely processing protected CD-ROM control information within sεiid incorporated secure processing unit(s).
  166. 175
    An electronic apphance arrangement containing one or more network communications means where at least one of the network communications means incorporates at least one secure processing unit, said arrangement storing modulεir, component, protected networking control information designed to be securely processed by said incorporated secure processing unit(s).
  167. 176
    In an electronic apphance arrangement containing one or more network communications means where at least one of the network communications means incorporates at least one secure processing unit, a method characterized by the step of storing and securely processing protected networking control information with said incorporated secure processing unit(s).
  168. 177
    A set-top controUer arrεmgement containing a protected processing environment and a database operatively connected to said protected processing environment, said arrangement further containing control information for controUing usage of said controUer based upon processing of at least a portion of said control information within said protected processing environment, wherein at least a portion of said control information is stored within said database.
  169. 178
    In a set-top controUer arrangement containing a protected processing environment and a database operatively connected to said protected processing environment, a method characterized by the step of:(a) using control information within the set-top controUer arrangement for controUing usage of said controUer based upon processing of at least a portion of said control information within said protected processing environment, and storing at least a portion of said control information vάthin said database.
  170. 179
    An electronic gεime arrangement containing a protected processing environment for controlling the use of electronic games, said arrangement including game usage control information, database means operatively connected to said protected processing environment for, at least in part, storing usage control information for regulating at least some aspect of use of at least a portion of at least one of said games, and traveling objects containing protected electronic game content.
  171. 180
    In -m electronic game arrangement containing a protected processing environment for controlling the use of electronic games, a method including the steps of:(a) including game usage control information within a database means operatively connected to said protected processing environment;εmd (b) regulating, at least in part with the stored usage control information, at least some aspect of use of at least a portion of at least one of said games.
  172. 182
    An electronic gε-me arrangement conta-Lning interoperable protected processing environments for controUing the use of interactive games, said arrangement including protected game usage control infonnation, and database means operatively connected to said protected processing environments for, at least in part, storing game usage control information.
  173. 183
    In an electronic game arrangement containing protected processing environments, a method comprising:(a) storing, within a secure database means operatively connected to said protected processing environments protected game usage control infonnation;and (b) controlling the use of interactive games based at least in part on the storing game usage control information.
  174. 184
    An electronic game arrεmgement containing interoperable protected processing environments for controlling the use of games, said arrangement including component, modular, protected game usage control information, wherein at least a portion of said protected control information was provided independently by plural parties securing their respective rights in at least one electronic value chain.
  175. 185
    In an electronic gεime arrangement containing interoperable protected processing environments for controlling the use of games, a method including the steps of:(a) providing at least a portion of component, modular, protected game usage control -----formation independently by plural parties;and (b) using the control information at least in part to securing respective rights of said plural parties in at least one electronic value chain.
  176. 186
    An electronic multimedia arrangement containing protected processing environments for controlling the use of multimedia, said arrangement including component, modular multimedia usage control infoπnation and database means operatively connected to said protected processing environments for, at least in part, storing multimedia usage control information.
  177. 187
    In an electronic multimedia arrangement containing protected processing environments for controUing the use of multimedia, a method including the steps of storing multimedia usage control information within a database means operatively connected to said protected processing environments, and using the stored control information to control multimedia.
  178. 188
    An electronic multimedia εirrangement containing a protected processing environment for controlling the use of multimedia, said arrangement including multimedia usage control information, database means operatively connected to said protected processing environment for, at least in part, storing multimedia usage control information, and protected traveling objects containing distributed multimedia electronic content.
  179. 189
    In an electronic multimedia arrangement containing a protected processing environment, a method characterized by the steps of storing multimedia usage control information within a database means operatively connected to said protected processing environment, and controlling, based at least in part on the stored information, protected traveling objects containing distributed multimedia electromc content.
  180. 190
    An electronic multimedia arrangement containing interoperable protected processing environments for controUing the use of multimediεi, said arrangement including component, modular, protected multimedia usage control information, wherein at least a portion of said protected control information was provided independently by plural parties securing their respective rights in at least one electronic value chain.
  181. 192
    In an electronic multimedia arrangement containing protected processing environments, a method comprising providing at least a portion of component, modular, protected multimedia usage control information independently by plural parties securing their respective rights in at least one electronic value chain, and using the usage control infonnation to control the use of multimedia.
  182. 194
    An integrated circuit supporting multiple encryption algorithms comprising at least one microprocessor, memory, input/output means, at least one circuit for encrypting and/or decrypting information and one or more software programs for use with at least one of the microprocessors to perform encryption and/or decryption functions.
  183. 195
    In a secure integrated circuit supporting multiple encryption algorithms comprising at least one microprocessor, memory, input/output means, and providing a protected processing environment, a method characterized by executing at least a portion of one or more software programs with the microprocessor to perform encryption and/or decryption functions within the integrated circuit.
  184. 196
    An integrated circuit comprising at least one microprocessor, memory, at least one real time clock, at least one random number generator, at least one circuit for encrypting and or decrypting information and independently dehvered and/or independently dehverable certified software.
  185. 197
    An integrated circuit comprising at least one microprocessor, memory, input/output means, a tamper resistant barrier and at least a portion of a Rights Operating System.
  186. 198
    An integrated circuit comprising at least one microprocessor, memory, input/output means, at least one real time clock, a tamper resistant barrier and means for recording interruption of power to at least one of the real time clocks.
  187. 199
    A method of distributing information characterized by the steps of compressing infonnation, encrypting the compressed infoπnation at the first location, distributing the encrypted information to one or more second locations, using a tamper resistant integrated circuit to first decrypt and then decompress the information.
  188. 200
    A system for distributing information characterized by:means for compressing information, m ans for encrypting the compressed information at the first location, means for distributing the encrypted information to one or more second locations, and means for using a tamper resistant integrated circuit to first decrypt and then decompress the information.
  189. 201
    A method of securely managing distributed events characterized by the steps of providing secure event processing environments to one or more users, enabling a first user to specify control information for event management through the use of a first secure event processing environment, and managing the processing of such an event through the use of a second secure event processing environment.
  190. 202
    A system for securely managing distributed events characterized by:a first secure event processing environment for enabling a first user to specify control information for event management, and a second secure event processing environment interoperable with the first event processing environment for managing the processing of such an event.
  191. 203
    A method for enabling electronic commerce chain of handling and control characterized by the step of a first and a second party independently specifying protected, modular component control information describing requirements related to the operation of an electronic commerce value chain.
  192. 204
    A system for enabling electronic commerce chain of handling and control characterized by means for permitting a first and a second party to independently specify protected, modular component control information describing requirements related to the operation of an electronic commerce value chain of handling and control, and means for securely enforcing the requirements described by the control information.
  193. 205
    A method for enabling electronic commerce characterized by the step of a first and a second party independently stipulating control information managing the use of digital information, wherein said first and said second party independently maintain persistent rights enforced by said control information as said digital information moves through a chain of handling and control.
  194. 206
    A system for enabling electronic commerce including:means for aUowing a first party to stipulate control information managing the use of digital information, means for aUowing a second party to stipulate control information managing the use of the digital information, and chain of handhng and control means for maintaining persistent rights enforced by said control information as said digital information moves from one location and/or process to another.
  195. 207
    A method for secure maintenance of electronic rights comprising a first step of plural parties in a value chain independently and securely stipulating control information regardin their electronic rights, wherein said control information is used to enforce conditions related to the use of electronic information distributed in software containers.
  196. 208
    A system for secure maintenance of electronic rights comprising:means permitting plural parties in a value chain to independently and securely stipulates control information regarding their electronic rights, and means for using said control infonnation to enforce conditions related to the use of electronic infonnation distributed in software containers.
  197. 209
    A method for securely controlling the use of protected electronic content including the step of supporting modular separate control information arrangements for managing at least one event related to use of said content such that a user may select between separate control infonnation arrangements for managing such at least one event.
  198. 210
    A system for securely controlling the use of protected electronic content including modular separate control information arrangements for managing at least one event related to use of said content such that a user may select between separate control information arrangements for managing such at least one event.
  199. 211
    A method employing separate, modulεir control structures for managing the use of encrypted digital information characterized by the step of enabling commercial value chain participants to support plural relationships between two or more of:( 1) content event triggering, (2) auditing, and ( 3) budgeting, control variables.
  200. 212
    A system for employing separate, modular control structures for managing the use of encrypted digital information characterized by means for enabling commercial value chain participants to support plural relationships between two or more of:( 1 ) content event triggering, (2) auditing, and ( 3 ) budgeting, control variables.
  201. 213
    A method of chain of handling and control enabling a party not directly participating in an electronic value chain to contribute secure control infoπnation to enforce at least one control requirement, said method characterized by a first step of a first value chain participant stipulating control information associated with digital infoπnation and a second step wherein said not directly participating party independently and securely contributes secure control information for inclusion in an aggregate control information set including said associated control information, said aggregate control information at least in part managing conditions related to the use of at least a portion of said digital information by a second value chain participant.
  202. 214
    A chain of handling and control system for enabling a party not directly participating in an electronic value chain to contribute secure control information to enforce at least one control requirement, said system characterized by:means for aUowing a first value chain participant to stipulate control information associated with digital infoπnation, means for aUowing the not directly participating party to independently and securely contribute secure control information for inclusion in εm aggregate control information set including said associated control infonnation, and means responsive to said aggregate control information for at least in pεirt managing conditions related to the use of at least a portion of said digital information by a second value chain participant.
  203. 215
    A method of electronic commerce control information management for delegating the adrr-inistration of certain rights held by a value chain party to a second value chain party characterized by the step of said first party stipulating secure control information describing at least a portion of their rights related to one or more chain of handling and control electronic events wherein said first party provides further control information authorizing said second party to administer some or aU of said rights as an agent for said first pεirty.
  204. 216
    A system for electronic commerce control information management for delegating the administration of certain rights held by a value chain party to a second value chain party characterized by:means for allowing said first party to stipulate secure control information describing at least a portion of their rights related to one or more chain of handling and control electronic events;and mea s for aUowing said first party to provide further control information authorizing said second party to administer some or all of said rights as an agent for said first party.
  205. 217
    A method of governing tεixation of commercial events resulting from electronic chain of handling and control characterized by a first step of distributing secure digital information to a user and specifying secure control information controlling at least one condition for use of said digitεil information and a second step of a government agency securely, independently contributing secure control information for automaticaUy governing tax payments for said commercial events.
  206. 218
    A system for governing taxation of commercial events resulting from electronic chain of handling and control characterized by:means for distributing secure digital infonnation to a user;means for specifying secure control information controlling at least one condition for use of said digital infoπnation;and means for aUowing a government agency to securely, independently contribute secure control information for automaticaUy governing tax payments for said commercial events.
  207. 219
    A method of governing privacy rights related to electronic events characterized by a first step of a first party protecting digital information containing information descriptive of preventing a second party from at least one unauthorized use and a second step of specifying certain control information related to use of at least a portion of said protected digital infonnation, wherein sεdd control information enforces at least one right of said second party related to privacy and/or permitted use(s) of personal and/or proprietary infonnation included in said protected digital information.
  208. 220
    A system for governing privacy rights related to electronic events characterized by:means for permitting a first party to protect digital information containing information descriptive of preventing a second party from at least one unauthorized use;means for specifying certain control information related to use of at least a portion of said protected digital information;and means for using the control information to enforce at least one right of said second party related to privacy and/or permitted use(s) of personal and/or proprietary information included in said protected digital information.
  209. 221
    A method of governing privacy rights related to electronic events characterized by a first step of a first pεirty protecting digital information from at least one unauthorized use and stipulating certain control infonnation for establishing conditions for use of said protected information and a second step of a user of said digital information stipulating further control information regulating the reporting of information regεirding said user's use of at least a portion of said digital infoπnation.
  210. 222
    A system for governing privacy rights related to electronic events chεiracterized by:means for aUowing a first party to protect digital information from at least one unauthorized use and for stipulating certain control information for establishing conditions for use of sεdd protected information;and means for aUowing a user of said digital infoπnation to stipulate further control information regulating the reporting of information regarding said user's use of at least a portion of sεdd digital information.
  211. 223
    A secure method for regulating electronic conduct and commerce characterized by a step of distributing interoperable protected processing environments and circulating amongst plural recipients of said protected processing environments software containers containing digital content and related content control information prepared for use by at least a portion of said protected processing environments, wherein said method includes the further step of regulating the use at least some of said digital content based, at least in part, on the secure processing of at least a portion of said control information through the use of at least one protected processing environment
  212. 224
    A secure system for regulating electronic conduct and commerce characterized by:distributed interoperable protected processing environments, means for circulating, amongst said protected processing environments, software containers containing digital content and related content control information prepared for use by at least a portion of said protected processing environments, and means within at least some of the protected processing environments for regulating the use at least some of said digital content based, at least in part, on the secure processing of at least a portion of said control information.
  213. 225
    A method of electronic commerce networking for enabling a secure electronic retail environment characterized by the step of supplying user certified control information, smart cards, secure processing units, and retailing teπninal arrangements networked together using VDE communication techniques and secure software containers.
  214. 226
    An electronic commerce networking system for enabling a secure electronic retail environment characterized by:means for networking together smart cards, secure processing units, and retailing terminal arrangements;and means for making the smart cards, secure processing units, and retailing teπninal arrangements interoperable with one another and with VDE communication techniques and secure software containers.
  215. 227
    A method of enabling electronic commerce apphances for securely adπiinistering user rights in commerce activities characterized by the step of providing to users at least a portion of a VDE node contained within a physical device, said device being configured to be compatible with mating connectors in host systems for supporting secure, interoperable transaction activity between plural parties.
  216. 228
    A system for securely achninistering user rights in commerce activities comprising a physical device including at least a portion of a portable VDE node, said device being configured to be compatible with mating connectors in host systems for supporting secure, interoperable transaction activity between plural parties.
  217. 229
    A method for enabling a programmable, electronic commerce environment characterized by the step of providing to multiple parties secure commerce nodes that securely process separate, modular component billing management methods, budgeting management methods, metering management methods, and related auditing management methods and further characterized by the step of supporting triggering of metering, auditing, billing, and budgeting methods in response to electronic commerce event activities.
  218. 230
    A programmable, electronic commerce environment characterized by secure commerce nodes each including:means for securely processing separate, modular component billing management methods, budgeting management methods, metering management methods, and related auditing management methods, and means for supporting triggering of metering, auditing, hilling, and budgeting methods in response to electronic commerce event activities.
  219. 231
    An electronic commerce system including modular, standardized control components comprising electronic commerce event control instructions stipulated by commerce participants, and plural electronic apphances containing one or more secure processing units which process at least a portion of such commerce event control instructions, said system further containing one or more databases, operatively connected to at least one of the secure processing units, for at least in part securely storing at least a portion of such control instructions for use by said at least one secure processing unit.
  220. 232
    In εm electronic commerce system including modular, standardized control components comprising electronic commerce event control instructions stipulated by commerce participants, and plural electronic apphances containing one or more secure processing units which process at least a portion of such commerce event control instructions, a method characterized by the step of providing one or more secure databases, operatively connected to at leεist one of the secure processing units, and at least in part securely storing, within the secure databases, at least a portion of such control instructions for use by said at least one secure processing unit.
  221. 233
    A content distribution system comprising plural electronic apphances containing one or more interoperable secure processing units operatively connected to one or more databases for use with at least one of said secure processing units, said one or more databases containing (a) one or more decryption keys for use in decrypting distributed, encrypted digital information, and (b) encrypted audit infonnation, said audit information reflecting at least one aspect of use of said distributed digital information
  222. 234
    A content distribution method comprising:distributing plural electronic apphances containing one or more interoperable secure processing units operatively connecting the apphances to one or more databases, storing within said one or more databases one or more decryption keys, using the decryption keys for decrypting distributed, encrypted digital information, and storing within the one or more databases encrypted audit information, sεtid audit information reflecting at least one εispect of use of said distributed digital information.
  223. 235
    An electronic currency system comprising plural, electronic apphances containing (a) protected processing environments, (b) encrypted electronic currency and related secure control information configured so as to be useable by at least one of said protected processing environments, and (c) usage reporting means for securely communicating electronic currency usage related information from a first interoperable protected processing environment to a second interoperable protected processing environment.
  224. 236
    An electronic currency method comprising:distributing plural, electronic apphances containing (a) protected processing environments, (b) encrypted electronic currency and related secure control information configured so as to be useable by at least one of said protected processing environments, and securely communicating electronic currency usage related information from a first interoperable protected processing environment to a second interoperable protected processing environment.
  225. 237
    A method for electronic financial activities characterized by the steps of:communicating digital containers containing financial infonnation from a first interoperable secure node to a second interoperable secure node, communicating modular, standard control information to said second secure node to, at least in part, set the conditions for use of at least a portion of said financial information, reporting information related to said use to said first interoperable secure node.
  226. 238
    A system for electronic financial activities characterized by:means for communicating digital containers containing financial information from a first interoperable secure node to a second interoperable secure node, means for communicating modular, standard control information to said second secure node, means at the second node for, at least in part, setting the conditions for use of at least a portion of said financial information, and means for reporting information related to said use from the second secure node to said first interoperable secure node.
  227. 239
    A method for electronic currency management including:communicating encrypted electronic currency from a first, interoperable secure user node to a second interoperable user node using at least one secure container, and providing secure control information for use with said at least one secure container, said secure control information, at least in part, maintaining conditionaUy anonymous currency usage information.
  228. 240
    A system for electronic currency management including:means for communicating encrypted electronic currency from a first, interoperable secure user node to a second interoperable user node using at least one secure container, and means for providing secure control information for use with said at least one secure container, said secure control infonnation, at least in part, maintaining conditionaUy anonymous currency usage information.
  229. 241
    A method for electronic financial activities management characterized by the steps of:securely communicating from a first secure node to a second secure node financial information standardized control information for controlling the use of financial information used in a financial value chain, securely communicating from said first secure node to a third secure node said financial information standardized control information for controlling the use of financial information used in a financial value chain, securely communicating encrypted financial infonnation from said second secure node to said third secure node, including communicating secure control information, processing said financial information at said third node at least in pεirt through the use of secure control infonnation supphed by said first and said second secure nodes, wherein said standardized control information is at least in part stored in a secure database contained within said third secure node.
  230. 242
    A system for electronic financial activities management characterized by the steps of:means coupled to a first and a second secure node for securely communicating from said first secure node to said second secure node financial infonnation standardized control information for controlling the use of financial information used in a financial value chain, means coupled between the first secure node and a third secure node for securely communicating from said first secure node to said third secure node said financial information standardized control infonnation for controUing the use of financial information used in a financial value chain, means coupled between the second and third nodes for securely comnramcating encrypted financial information from said second secure node to said third secure node, including communicating secure control information, and means at the third node for processing said financial information at said third node at least in part through the use of secure control information supphed by said first and said second secure nodes, and a secure database at the third node for at least in part storing said standardized control information.
  231. 243
    A method of information management characterized by the steps of creating at least one smart object at a first location, protecting at least a portion of said smart object including protecting at least one rule and/or control assigned to said smart object, distributing said at least one smart object to at least one second location, securely processing at least a portion of the contents of said at least one smart object at said at least one second location in accordance with at least a portion of at least one said rule and/or control assigned to said smart object.
  232. 244
    An information management system characterized by:means for creating at least one smart object at a first location, means for protecting at least a portion of said smart object including means for protecting at least one rule and/or control assigned to said smart object, means for distributing said at least one smart object to at least one second location, and means for securely processing at least a portion of the contents of said at least one smart object at said at least one second location in accordance with at least a portion of at least one said rule and/or control assigned to said smart object.
  233. 245
    An object processing system comprising at least one secure object containing at least in part protected executable content and at least one at least in part protected rule and/or control associated with operations related to the execution of such content, and at least one secure execution environment for processing the executable content in accordance with at least a portion of at least one of said at least one associated rule and/or control.
  234. 246
    An object processing method comprising:providing at least one secure object containing at least in part protected executable content and at least one at least in pεirt protected rule and/or control associated with operations related to the execution of such content, processing, within at least one secure execution environment, the executable content in accordance with at least a portion of at least one of said at least one associated rule and/or control.
  235. 247
    A rights distributed database environment including (a ) means aUowing one or more central authorities to establish control information for use of encrypted digital information, (b) interoperable database management systems at plural user sites for securely storing control information and audit information, ( c ) secure communication means for securely communicating control information and audit information between user sites, and (d) centralized database means for compiling and analyzing usage information from plural user sites.
  236. 248
    Within a rights distributed database environment, a method characterized by the foUowing steps:establishing control information for use of encrypted digital information, securely storing, within interoperable database management systems at plural user sites, control infoπnation and audit information, securely communicating control information and audit information between user sites, and compiling and analyzing usage information from plural user sites.
  237. 249
    A method of distributed database searching characterized by the steps of creating at least one secure object containing search criteria, transmitting at least one such secure object to one or more second locations to perform database searches in accordance with at least one rule and/or control, processing at least one database search based at least in part on the search criteria within a secure object in accordance with at least a portion of at least one of the said at least one associated rule and/or control, storing database search results in the same and/or one or more new secure objects, and transmitting the secure object containing search results to the first location.
  238. 251
    A system for distributed database searching characterized by:means for creating at least one secure object containing search criteria, means for transmitting at least one such secure object to one or more second locations to perform database searches in accordance with at least one rule and/or control, means for processing at least one database search based at least in part on the search criteria within a secure object in accordance with at least a portion of at least one of the said at least one associated rule and/or control, means for storing database search results in the same and/or one or more new secure objects, and means for transmitting the secure object containing search results to the first location.
  239. 253
    A rights management system comprising protected information, at least two protected processing arrangements, and a rights management language that aUows the expression of permitted operations and the consequences of performing such operations on at least a portion of the information processed at least in part by at least one of the protected processing arrangements.
  240. 254
    A rights management method comprising:providing protected information for processing by at least two protected processing arrangements, and expressing, in a rights management language, permitted operations and the consequences of performing such operations on at least a portion of the information processed at least in part by at least one of the protected processing arrangements.
  241. 255
    A method of protecting digital information characterized by the steps of encrypting at least a portion of the information, using a rights management language to describe the conditions related to use of the infonnation, distributing at least a portion of such information and at least a portion of such rights language expressed conditions to one or more recipients, using an electronic apphance arrangement including at least one protected processing arrangement to securely govern at least a portion of the use of such information.
  242. 256
    A system for protecting digital information characterized by:means for encrypting at least a portion of the information, means for using a rights management language to describe the conditions related to use of the information, means for distributing at least a portion of such information and at least a portion of such rights language expressed conditions to one or more recipients, and an electronic apphance arrangement including at least one protected processing arrangement for securely governing at least a portion of the use of such information.
  243. 257
    A distributed digital information management system comprising software components, a rights management language for expressing processing relationships between two or more of the software components, protected processing means for at least a portion of the software components and at least a portion of the rights management expressions, means for protecting content, means for creating software objects that relate protected content to rights management expressions, and means for dehvering protected content, rights management expressions, and such software objects from a providing location to a user's location.
  244. 258
    A distributed digital information management method comprising:expressing, in a rights management language, processing relationships between two or more of the software components, processing, within at least one protected environment, at least a portion of the software components and at least a portion of the rights management expressions, protecting content, creating softwεire objects that relate protected content to rights management expressions, and dehvering protected content, rights management expressions, and such software objects from a providing location to a user's location.
  245. 259
    An authentication system comprising at least two electronic apphances, at least two digital certificates reflecting identity information encrypted using different certifying private keys where such certificates are stored in a first electronic apphance, communications means for transmitting and receiving signals between electronic apphances, means for determining compromised and/or expired certifying private keys operatively connected to a second electronic apphance, means for the second electronic apphance to request transmission of one of the digital certificates from the first electronic apphance based at least in part on such determination, and means operatively connected to such second electronic apphance for decrypting such certificate and determining such certificate's vahdity and/or the vahdity of identity information.
  246. 260
    In a system comprising at least two electronic apphances, an authenticating method comprising:-issuing at least two digital certificates reflecting identification information, including the step of encrypting the two certificates using different certifying private keys, storing the certificates in a first electronic apphance, transmitting and receiving signals between electronic apphances, determining compromised and/or expired certifying private keys operatively connected to a second electronic apphance, requesting, with the second electronic apphance, transmission of one of the digital certificates from the first electronic apphance based at least in part on such determination, decrypting such certificate with the second electronic apphance, and deteπnining such certificate's vahdity and/or the vahdity of identity information.
  247. 261
    An authentication system comprising at least two electronic apphances, at least two digital certificates reflecting identify information encrypted using different certifying private keys where such certificates are stored in a first electronic apphance, communications means for transmitting and receiving signals between electronic apphances, means for a second electronic apphance to request transmission of one of the digital certificates from the first electronic apphance wherein the selection of which certificate is requested is based at least in pεirt on a random or pseudo-random number, means operatively connected to such second electronic apphance for decrypting such certificate and determining such certificate's vahdity and or the vahdity of identity information.
  248. 262
    In a system comprising at least two electronic apphances, an authenticating method comprising:issuing at least two digital certificates reflecting identify information, including the step of encrypting the two digital certificates using different certifying private keys, storing such certificates in a first electronic apphance, transmitting and receiving signals between electronic apphances, requesting, with a second electronic apphance, transmission of one of the digital certificates from the first electronic apphance, including the step of selecting a certificate based at least in part on a random or pseudo-random number, decrypting such certificate with the second electronic apphance;and determining such certificate's vahdity and/or the vahdity of identity information.
  249. 263
    A method of secure electronic maU characterized by the steps of creating at least one electronic message using an interoperable protected processing environment, encrypting at least a portion of said at least one message, securely associating one or more sets of control information with one or more messages to set at least one condition for the use of said at least one message, communicating the protected electronic messages to one or more recipients having protected processing environments, securely communicating at least one set of the same or differing control information to each recipient, enabling recipients of both control information and protected messages to use message information at least in part in accordance with the conditions specified by the control information.
  250. 264
    A system for secure electronic maU including multiple protected processing environments, the system characterized by:a first protected processing environment for creating at least one electronic message, the first environment including means for encrypting at least a portion of said at least one message, means for securely associating one or more sets of control information with one or more messεiges to set at least one condition for the use of said at least one message, and means for communicating the protected electronic messages to one or more recipients having interoperable protected processing environments, means for securely communicating at least one set of the same or differing control information to each recipient, and means for enabling recipients of both control information and protected messages to use message information at least in part in accordance with the conditions specified by the control information.
  251. 265
    A method of information management chεiracterized by the steps of protecting content from unauthorized use, securely associating enabling control information with at least a portion of such protected content wherein such enabling control information incorporates information describing how the enabling control infoπnation may be redistributed, dehvering at least a portion of the protected content to a first user, dehvering such enabling control infonnation to such first user, receiving a request to redistribute such enabling control infonnation from such first user, using the description of how enabling control information may be redistributed to create new enabling control information where such new enabling control information may be the same or different than the enabling control information received by such first user, dehvering the new enabling control information and/or protected infonnation to a second user.
  252. 266
    An information management system characterized by:means for protecting content from unauthorized use, means for securely associating enabhng control information with at least a portion of such protected content, including means for incorporating enabling control information describing how the enabling control information may be redistributed, means for dehvering at least a portion of the protected content to a first user, means for dehvering such enabling control information to such first user, means for receiving a request to redistribute such enabling control information from such first user, means for using the description of how enabling control information may be redistributed to create new enabhng control information where such new enabhng control information may be the same or different than the enabling control information received by such first user, and means for dehvering the new enabling control information and/or protected information to a second user.
  253. 267
    A method of controUing redistribution of distributed digital information including the steps of encrypting digital information, distributing said encrypted digital information from a first party to a second party, establishing control information regarding the redistribution of at least a portion of said encrypted digital information from said second party to at least one third party, regulating the redistribution of said at least a portion of said encrypted digital infonnation through the use of a protected processing environment processing said control information.
  254. 268
    A system for controlling redistribution of distributed digital information including:means for encrypting digital infonnation, means for distributing said encrypted digital information from a first party to at least one second party, means for establishing control information regarding the redistribution of at least a portion of said encrypted digital information from said second party to at least one third party, and a protected processing environment for processing said control information and for regulating the redistribution of said at least a portion of said encrypted digital information.
  255. 269
    A method of controUing a robot characterized by the steps of creating instructions for one or more robots, creating a secure container incorporating such instructions, εissociating control information with such secure container, incorporating at least one secure processing unit into such one or more robots, and performing at least a portion of such instructions in accordance with at least a portion of such control information.
  256. 271
    A robot control system characterized by:means for creating instructions for one or more robots, means for creating a secure container incorporating such instructions, means for associating control information with such secure container, means for incorporating at least one secure processing unit into such one or more robots, and means for performing at least a portion of such instructions in accordance with at least a portion of such control information.
  257. 273
    A method of detecting fraud in electronic commerce characterized by the steps of creating at least one secure container, associating control information with such one or more containers including control information requiring that audit information be coUected and transmitted to an auditing party, dehvering such one or more containers and such control information to at least one user, recording information identifying each container and each such user, receiving audit information, creating a profile of usage based at least in part on such received audit information and/or such control information, detecting cases where certain audit infonnation differs at least in pεirt from such profile of usage.
  258. 274
    A system for detecting fraud in electronic commerce chεiracterized by means for creating at least one secure container, means for associating control information with such one or more containers including control infoπnation requiring that audit information be coUected and transmitted to an auditing party, means for dehvering such one or more containers and such control infoπnation to at least one user, means for recording information identifying each container and each such user, means for receiving audit information, means for creating a profile of usage based at least in part on such received audit information and or such control information, and means for detecting cases where certain audit information differs at least in part from such profile of usεige.
  259. 275
    A method of detecting fraud in electronic commerce characterized by the steps of distributing at least in part protected digital information to customers, distributing one or more rights to use at least a portion of such digital information across an electronic network, aUowing a customer to use at least a part of said at least in pεirt protected digital information through the use of a protected processing environment and at least one of said one or more distributed rights, detecting unusual usage activity related to use of said digital information.
  260. 276
    A system for detecting fraud in electronic commerce chεiracterized by m ea n s for distributing at least in part protected digital information to customers, means for distributing one or more rights to use at least a portion of such digital information across an electronic network, a protected processing environment for aUowing a customer to use at least a part of said at least in part protected digital information through at least one of said one or more distributed rights, and means for detecting unusual usage activity related to use of said digital information.
  261. 277
    A programmable component arrangement comprising a tamper resistε-nt processing environment including a microprocessor, memory, a task manager, memory manager and external interface controUer, means for loading arbitrary components at least in part into the memory, meεms for initiating one or more tasks associated with processing such components, means for certifying the vεdidity, integrity and/or trustedness of such components, means for creating arbitrary components, means for associating arbitrary events with such created components, means for certifying the vahdity, integrity and/or trustedness of such created components, and means for securely dehvering such created components.
  262. 278
    In a programmable component arrangement comprising a tamper resistant processing environment including a microprocessor, memory, a task manager, memory manager and an external interface controUer, a processing method characterized by the foUowing steps:creating arbitrary components, associating arbitrary events with such created components, loading the arbitrary components at least in part into the memory, initiating one or more tasks associated with processing such loaded components, certifying the vahdity, integrity εind/or trustedness of such created components, and securely dehvering such created components.
  263. 279
    A distributed, protected, programmable component arrangement comprising at least two tamper resistant processing environments including a microprocessor, memory, a task manager, memory manager and external interface controUer, means for loading arbitrary components at least in part into the memory, means for initiating one or more tasks associated with processing such components, end means for certifying the vahdity, integrity εmd/or trustedness of such components, said arrangement further comprising means for creating arbitrary components, means for associating arbitrary events with such created components, means for certifying the vahdity, integrity and/or trustedness of such created components, means for securely dehvering such created components between at least two of said at least two tamper resistant processing environments.
  264. 280
    In a distributed, protected, programmable component arrangement comprising at least two tamper resistant processing environments including a microprocessor, memory, a task manager, memory manager and external interface controUer, a method comprising creating arbitrary components, certifying the vahdity, integrity and/or trustedness of such components, loading arbitrary components at least in part into the memory, initiating one or more tasks associated with processing such components, associating arbitrary events with such created components, and securely dehvering such created components between at least two of said at least two tamper resistant processing environments.
  265. 281
    An electronic apphance comprising at least one CPU, memory, at least one system bus, at least one protected processing environment, and at least one of a Rights Operating System or Rights Operating System layer associated with a host operating system.
  266. 282
    An operating system comprising at least one task manager, at least one memory manager, at least one input/output manager, at least one protected processing environment, means for detecting events, means for associating events with rights control functions, means for performing rights control functions at least in part vrithin such one or more protected processing environments.
  267. 283
    In an operating system comprising at least one task manager, at least one memory manager, at least one input/output manε-ger, at least one protected processing environment, an operating method comprising:detecting events, associating events with rights control functions, and performing rights control functions at least in part within such one or more protected processing environments.
  268. 284
    A method of business automation characterized by the steps of creating one or more secure containers including accounting and/or other administrative infonnation, associating control information with such one or more secure contεiiners including a description of (a) the one or more parties to whom the container may and/or must be dehvered and/or (b) the operations that one or more parties may and/or must perform with respect to such accounting and or other administrative information, dehvering one or more of such containers to one or more parties, pd enabhng the description and/or enforcement of at least a portion of such control mformation prior, during and/or subsequent to use of such accounting and/or other administrative information by one or more parties.
  269. 289
    A business automation system characterized by:means for creating one or more secure containers including accounting and/or other administrative information, means for associating, with such one or more secure containers, control information including a description of (a) the one or more parties to whom the container may and/or must be dehvered and/or (b) the operations that one or more parties may and/or must perform with respect to such accounting and or other administrative information, means for dehvering one or more of such containers to one or more parties, and means for enabling the description and/or enforcement of at least a portion of such control information prior, during and/or subsequent to use of such accounting and/or other administrative information by one or more pεirties.
  270. 294
    A method of distributing content characterized by the steps of creating one or more first secure containers, associating control information with such first containers including information describing the conditions under which some or aU of the content of such first containers may be extracted, dehvering at least a portion of such first containers and such control information to one or more parties, detecting a request by one or more of such parties to extract some or aU of the content of such first containers, determining if such request is permitted in whole or in part by such control information, to the extent permitted by such control information creating one or more second secure containers in accordance with such request and such control information, associating control information with such one or more second secure containers based at least in part on control information associated with such first containers.
  271. 295
    A system for distributing content characterized by:means for creating one or more first secure containers, means for associating control information with such first containers including information describing the conditions under which some or aU of the content of such first containers may be extracted, means for dehvering at least a portion of such first containers and such control information to one or more parties, means for detecting a request by one or more of such parties to extract some or aU of the content of such first containers, means for determining if such request is permitted in whole or in part by such control information, to the extent permitted by such control information creating one or more second secure containers in accordance with such request εind such control infonnation, and means for -associating control information with such one or more second secure containers based at least in part on control information associated with such first containers.
  272. 296
    A method of distributing content characterized by the steps of creating one or more first secure containers, associating control information with such first secure contεiiners including information describing the conditions under which such first secure containers (a) may in whole or in part be embedded into and or securely associated with one or more second secure containers and/or (b) may aUow one or more secure containers to be in whole or in part embedded into and/or securely associated with such first secure containers, dehvering at least a portion of such first secure containers and such control information to one or more parties, detecting a request by one or more of such parties or by additional parties to (a) in whole or in part embed into and/or securely associate with such first containers one or more second containers and/or (b) in whole or in part embed into and or securely associate with a secure container such first secure containers, determining if such request is permitted by control information, to the extent permitted by control information performing one or more embedding and/or secure association operations, to the extent required by control information and/or requested by one or more of such parties, modifying εmd/or creating new control information at least in part as a consequence of such one or more embedding and/or secure -association operations.
  273. 297
    A system for distributing content characterized by means for creating one or more first secure containers, means for associating control information with such first secure containers including information describing the conditions under which such first secure containers (a) may in whole or in part be embedded into and/or securely associated with one or more second secure containers and/or (b) may aUow one or more secure containers to be in whole or in part embedded into and/or securely associated with such first secure containers, means for dehvering at least a portion of such first secure containers and such control information to one or more parties, means for detecting a request by one or more of such parties to (a) in whole or in part embed into and/or securely associate with such first containers one or more second containers and/or (b) in whole or in part embed into and/or securely associate with a secure container such first secure containers, and means for determining if such request is permitted by control information, to the extent permitted by control information performing one or more embedding and/or secure association operations, to the extent required by control information and/or requested by one or more of such parties, modifying εmd or creating new control information at least in part as a consequence of such one or more embedding and/or secure association operations.
  274. 298
    A method of distributing information characterized by the steps of protecting information from unauthorized use, associating control information with such protected information, dehvering at least a portion of such protected information to one or more parties using plural pathways, dehvering at least a portion of such control information to one or more parties using the same or different plural pathways, enabling at least one of such parties to make at least some use of such protected information dehvered using a first pathway in accordance with control information at least a portion of which is dehvered using a second pathway.
  275. 300
    A system for distributing information characterized by:means for protecting information from unauthorized use, means for ε-ssociating control information with such protected information, means for dehvering at least a portion of such protected information to one or more parties using plural pathways, means for dehvering at least a portion of such control information to one or more parties using the same or different plural pathways, means for enabling at least one of such parties to make at least some use of such protected information dehvered using a first pathway in accordance with control information at least a portion of which is dehvered using a second pathway.
  276. 302
    A method of distributing information characterized by the steps of protecting infonnation from unauthorized use, associating control information with such protected information including information requiring the coUection of audit infonnation, enabling one or more parties to receive and or process audit information, dehvering at least a portion of such protected information and such control information to one or more parties, enabhng at least some use of such protected information in accordance with at least a portion of such control information that requires the coUection of audit information, dehvering such audit information to one or more of such enabled auditing parties different from such dehvering pεirty or parties.
  277. 304
    A system for distributing information characterized by means for protecting information from unauthorized use, means for associating control information with such protected information including information requiring the coUection of audit information, means for enabling one or more parties to receive and/or process audit information, means for dehvering at least a portion of such protected information and such control information to one or more parties, means for enabling at least some use of such protected information in accordance with at least a portion of such control information that requires the coUection of audit information, and means for dehvering such audit information to one or more of such enabled auditing parties different from such dehvering party or parties.
  278. 306
    A secure component-based operating process including:(a) retrieving at least one component;(b) retrieving a record that specifies a component assembly;(c) checking said component and/or said record for vahdity;(d) using said component to form said component assembly in accordance with said record;and (e) performing a process based at least in part on said component assembly.
  279. 318
    A secure component operating system process including:receiving a component;receiving directions specifying use of said component to form a component assembly;authenticating said received component and/or said directions;forming, using said component, said component assembly based at least in part on said received directions;and using said component assembly to perform at least one operation.
  280. 319
    A method comprising performing the foUowing steps within a secure operating system environment:providing code;providing directions specifying assembly of said code into an executable program;checking said received code and/or said assembly directors for validity;and in response to occurrence of an event, assembling said code in accordance with said received assembly directions to form an assembly for execution.
  281. 320
    A method for managing at least one resource with a secure operating environment, said method comprising:securely receiving a first control from a first entity external to said operating environment;securely receiving a second control from a second entity external to said operating environment, said second entity being different from said first entity;securely processing, using at least one resource, a data item associated with said first and second controls;and securely applying said first and second controls to anage said resource for use with said data item.
  282. 321
    A method for securely managing at least one operation on a data item performed at least in part by an electronic arrangement, said method comprising:(a) securely dehvering a first procedure to said electronic arrangement;(b) securely dehvering, to said electronic arrangement, a second procedure separable or separate from said first procedure;(c) performing at least one operation on said data item, including using said first and second procedures in combination to at least in part securely mεmage said operation;and (d) securely conditioning at least one aspect of use of said data item based on said dehvering steps (a) and (b) having occurred.
  283. 341
    A method for securely managing at least one operation performed at least in part by a secure electronic apphance, comprising:(a) selecting an item that is protected with respect to at least one operation;(b) securely independently dehvering plural separate procedures to said electronic apphance;(c) using said plural separate procedures in combination to at least in part securely manage said operation with respect to said selected item;and (d) conditioning successful completion of said operation on said dehvering step (b) having occurred.
  284. 342
    A method for processing based on deliverables comprising:securely dehvering a first piece of code defining a first part of a process;separately, securely dehvering a second piece of code defining a second part of said process;ensuring the integrity of the first and second dehvered pieces of code;and performing said process based at least in pεirt on said first and second dehvered code pieces.
  285. 350
    A method of securely controUing at least one protected operation with respect to a data item comprising:(a) supplying at least a first control from a first party;(b) supplying at least a second control from a second party different from said first party;(c) securely combining said first and second controls to form a set of controls;(d) securely associating said control set with sεdd data item;and (e) securely controUing at least one protected operation with respect to said data item based on said control set.
  286. 354
    A secure method for combining data items into a composite data item comprising:(a) securely providing a first data item having at least a first control associated therewith;(b) securely providing a second data item having at least a second control associated therewith;(c) forming a composite of said first and second data items;(d) securely combining said first and second controls into a composite control set;and (e) performing at least one operation on said composite of said first and second data items bεised at least in part on said composite control set.
  287. 360
    A secure method for controUing a protected operation comprising:(a) dehvering at least a first control and a second control;and (b) controUing at least one protected operation based at least in part on a combination of said first and second controls, including at least one of the foUowing steps: resolving at least one conflict between said first and second controls based on a predefined order;providing εtn interaction with a user to form said combination;and dynamicaUy negotiating between said first and second controls.
  288. 363
    A secure method comprising:selecting protected data;extracting said protected data from an object;identifying at least one control to manage at least one aspect of use of said extracted data;placing said extracted data into a further object;and associating said at least one control with said further object.
  289. 365
    A secure method of modifying a protected object comprising:(a) providing a protected object;and (b) embedding at least one additional element into said protected object without unprotecting said object.
  290. 369
    A method for managing at least one resource with a secure operating environment, said method comprising:securely receiving a first load module from a first entity externεd to said operating environment;securely receiving a second load module from a second entity external to said operating environment, said second entity being different from said first entity;securely processing, using at least one resource, a data item associated with said first and second load modules;and securely applying said first and second load modules to manage said resource for use with said data item.
  291. 370
    A method for negotiating electronic contracts, comprising:receiving a first control set from a remote site;providing a second control set;performing, within a protected processing environment, ε-n electronic negotiation between said first control set εmd said second control set, including providing interaction between said first and second control sets;and producing a negotiated control set resulting from said interaction between said first and second control sets.
  292. 371
    A system for supporting electronic commerce including:means for creating a first secure control set at a first location;means for creating a second secure control set at a second location;means for securely communicating said first secure control set from said first location to said second location;and means at said second location for securely integrating said first and second control sets to produce at least a third control set comprising plural elements together comprising ε-n electronic value chain extended -greement.
  293. 372
    A system for supporting electronic commerce including:means for creating a first secure control set at a first location;means for creating a second secure control set at a second location;means for securely communicating said first secure control set from said first location to said second location;and negotiation means at said second location for negotiating an electronic contract through secure execution of at least a portion of said first and second secure control sets.
  294. 374
    A system as in clεiim 370 further including means for charging for at least a part of said content use.
  295. 375
    A secure component-based operating system including:component retrieving means for retrieving at least one component;record retrieving means for retrieving a record that specifies a component assembly;checking means, operatively coupled to said component retrieving means and said record retrieving means, for checking said component and/or said record for vahdity;using means, coupled to said checking means, for using said component to form said component assembly in accordance with said record;and performing means, coupled to said using means, for performing a process based at least in part on said component assembly.
  296. 376
    A secure component-based operating system including:a database manager that retrieves, from a secure database, at least one component and at least one record that specifies a component assembly;an authenticating manager that checks said component and/or said record for vahdity;a channel manager that uses said component to form said component assembly in accordance with said record;and an execution manager that performs a process based at least in part on said component assembly.
  297. 377
    A secure component operating system including:means for receiving a component;means for receiving directions specifying use of said component to form a component assembly;means, coupled to said receiving means, for authenticating said received component and/or said directions;means, coupled to said authenticating means, for forming, using said component, said component assembly based at least in part on said received directions;εmd means, coupled to said forming means, for using sεdd component assembly to perform at least one operation.
  298. 378
    A secure component operating environment including:a storage device that stores a component and directions speci-fying use of said component to form a component assembly;an authenticating manager that authenticates said component and/or said directions;a channel manager that forms, using said component, said component assembly based at least in part on said directions;and a channel that executes said component assembly to perform at least one operation.
  299. 379
    A secure operating system environment comprising:a storage device that stores code and directions specifying εissembly of said code into an executable program;a vahdating device that checks said received code and/or said assembly directors for vahdity;and an event-driven channel that, in response to occurrence of εm event, assembles said code in accordance with said assembly directions to form an εissembly for execution.
  300. 380
    A secure operating environment system for managing at least one resource comprising:a communications arrεmgement that securely receives a first control from a first entity external to said operating environment, and securely receives a second control from a second entity external to sεdd operating environment, said second entity being different from said first entity;and a protected processing environment, coupled to sεdd communications arrangement, that: (a) securely processes, using at least one resource, a data item associated with said first and second controls, and (b) securely applies said first and second controls to manage said resource for use of said data item.
  301. 381
    A system for negotiating electronic contracts, comprising:a storage arrangement that stores a first control set received from a remote site, and stores a second control set;a protected processing environment, coupled to sεdd storage arrangement, that: (a) performs an electronic negotiation between said first control set and said second control set, (b) provides interaction between said first and second control sets, and (c) produces a negotiated control set resulting from said interaction between said first and second control sets.
  302. 384
    A method for supporting electronic commerce including:creating a first secure control set at a first location;creating a second secure control set;electronicaUy negotiating, at said location different from said first location, an electronic contract, including the step of securely executing at least a portion of said first and second control sets.
  303. 385
    An electronic apphance comprising:a processor;and at least one memory device connected to said processor;wherein said processor includes: retrieving means for retrieving at least one component, and at least one record that specifies a component assembly, from said memory device, checking means coupled to said retrieving means for checking said component and/or said record for vahdity, and using means coupled to said retrieving means for using said component to form said component assembly in accordance with said record.
  304. 386
    An electronic apphance comprising:at least one processor;at least one memory device connected to said processor;and at least one input/output connection operatively coupled to said processor, wherein said processor at least in part executes a rights operating system to provide a secure operating environment within said electronic apphance.
  305. 394
    A method for auditing the use of at least one resource with a secure operating environment, said method comprising:securely receiving a first control from a first entity externεd to sεdd operating environment;securely receiving a second control from a second entity external to said operating environment, said second entity being different from said first entity;using at least one resource;securely sending to s dd first entity in accordance with said first control, first audit information concerning use of said resource;and securely sending to said second entity in accordance with said second control, second audit infonnation concerning use of said resource, said second audit information being at least in part different from said first audit information.
  306. 395
    A method for auditing the use of at least one resource with a secure operating environment, said method comprising:securely receiving first and second control alternatives from an entity external to said operating environment;selecting one of said first and second control alternatives;using at least one resource;if said first control alternative is selected by said selecting step, securely sending to said entity in accordance with said first control alternative, first audit information concerning use of said resource;and if said second control alternative is selected by sεdd selecting step, securely sending to said second entity in accordance with said second control alternative, second audit information concerning use of said resource, said second audit information being at least in part different from said first audit information.
  307. 396
    A method and/or system for enabling a sale of protected digital information that has been previously distributed to users, the method or system being characterized by a secure element that selectively controls access to the protected digital information based on electronic controls -associated with the infonnation.
  308. 397
    A distributed, secure electronic point of sale system or method characterized by a secure processing element for selectively releasing goods and/or services in exchange for compensation.
  309. 398
    In a distributed digital network, an advertising method characterized by the steps of tracking usage of digital information that has associated with it one or more controls with respect to access to and/or usage of said information;and targeting advertising messages based at least in part on said tracking.
  310. 399
    A distributed electronic advertising system characterized in that the system uses a distributed network of interoperable protected processing environments to at least in part dehver advertising to users.
  311. 400
    A distributed, secure, virtual black box comprised of nodes located at VDE content container creators, other content providers, chent users, and recipients of secure VDE content usage information) site, the nodes of said virtual black box including a secure subsystem having at least one secure hardware element such as a semiconductor element or other hεirdware modtde for securely executing VDE control processes, said secure subsystems being distributed at nodes along a pathway of information storage, distribution, payment, usage, and/or auditing.
  312. 401
    A protected processing system or method providing multiple currencies and/or payment aπangements for the secure processing -and releasing of protected digital information.
  313. 402
    A distributed secure method or system characterized in that a user's age is used as a criteria for electronicaUy, securely releasing information and/or resources to the user.
  314. 403
    A method of renting an electronic apphance defining a secure processing environment.
  315. 404
    A virtual distribution environment providing εmy one or more of the foUowing features and/or elements and/or combinations thereof:a configurable protected, distributed event management system;and/or a trusted, distributed transaction and storage management arrangement;and/or plural pathways for providing information, for control infoπnation, and or for reporting;and or multiple payment methods;and/or multiple currencies;and/or EDI;and/or Electronic hanking;εmd/or electronic document management;and/or electronic secure communication;and/or e-maU;and/or distributed asynchronous reporting;and/or combination asynchronous and online management;and or privacy control by users;and/or testing;and/or using age as a class;and/or apphance control (renting, etc.);and/or telecommunications infrastructure;and/or games management;and/or extraction of content from an electronic container;and/or embedding of content into an electronic contεiiner;and/or multiple certificate to aUow for breach of a key;and/or virtual black box;and/or independence of control infonnation from content;and/or multiple, separate, simultaneous control sets for one digital information property;and/or updating control information for already distributed digital information;and/or organization information management;and/or coupled external and organization internal chain of handling and control;and/or a content usage consequence management system (reporting, payment, etc., multiple directions);and/or a content usage reporting system providing differing audit information and/or reduction going to multiple pεirties holding rights in content;and/or an automated remote secure object creation system;and or infrastructure background analysis to identify improper use;and/or seniority of control information system;and/or secure distribution and enforcement of rules and controls separately from the content they apply to;and/or redistribution management by controlling the rights and/or number of copies and or pieces etc. that may be redistributed;and/or an electronic commerce taxation system;and/or an electronic shopping system;and or an electronic catalog system;and/or a system handling electronic banking, electronic shopping, and electronic content usεige management;and/or an electronic commerce multimedia system;and/or a distributed, secure, electronic point of sale system;and/or advertising;and/or electronics rights management;and/or a distributed electronic commerce system;and/or a distributed transaction system or environment;and/or a distributed event management system;and/or a distributed right systems.
  316. 405
    A Virtual Distribution Environment substantiaUy as shown in Figure 1.
  317. 406
    An "Infoπnation Utihty" substantiaUy as shown in Figure IA.
  318. 407
    A chain of handling and control substantiaUy as shown in Figure 1.
  319. 408
    Persistent rules and control information substantiaUy as shown in Figure 2A.
  320. 409
    A method of providing different control information substantiaUy as shown in Figure 1.
  321. 410
    Rules and or control infonnation substantiaUy as shown in Figure 4.
  322. 411
    An object substantiaUy as shown in Figures 5A and 5B.
  323. 412
    A Secure Processing Unit substantiaUy as shown in Figure 6.
  324. 413
    An electronic apphance substantiaUy as shown in Figure 7.
  325. 414
    An electronic apphance substantiaUy as shown in Figure 8.
  326. 415
    A Secure Processing Unit substantiaUy as shown in Figure 9.
  327. 416
    A "Rights Operating System" ("ROS") architecture substantiaUy εis shown in Figure 10.
  328. 417
    Functional relationship^ ) between apphcations and the Rights Operating System substantiaUy as shown in Figures llA-llC.
  329. 418
    Components and component assembhes substantiaUy as shown in Figures 11D-11J.
  330. 419
    A Rights Operating System substantiaUy as shown in FIGURE 12.
  331. 420
    A method of objection creation substantiaUy as shown in Figure 12A.
  332. 421
    A "protected processing environment" software architecture substantiaUy as shown in Figure 13.
  333. 422
    A method of supporting a channel substantiaUy as shown in Figure 15.
  334. 423
    A channel header and channel detail record substantiaUy as shown in Figure 15 A.
  335. 424
    A method of creating a channel substantiaUy as shown in Figure 15B.
  336. 425
    A secure data base substantiaUy as shown in Figure 16.
  337. 426
    A logical object substantiaUy as shown in Figure 17.
  338. 427
    A stationary object substantiaUy as shown in FIGURE 18.
  339. 428
    A travelling object substantiaUy as shown in FIGURE 19.
  340. 429
    A content object substantiaUy as shown in FIGURE 20.
  341. 430
    An administrative object substantiaUy as shown in Figure 21.
  342. 431
    A method core substantiaUy as shown in Figure 22.
  343. 432
    A load module substantiaUy as shown in FIGURE 23.
  344. 433
    A User Data Element (UDE) and/or Method Data Element (MDE) substantiaUy as shown in FIGURE 24.
  345. 434
    Map meters substantiaUy as shown in FIGURES 25A-25C.
  346. 435
    A permissions record (PERC) subst-antiaUy as shown in FIGURE 26.
  347. 436
    A permissions record (PERC) substantiaUy as shown in FIGURES 26A and 26B.
  348. 437
    A shipping table substantiaUy as shown in FIGURE 27.
  349. 438
    A receiving table substantiaUy as shown in FIGURE 28.
  350. 439
    An administrative event log substantiaUy as shown in FIGURE 29.
  351. 440
    A method of interrelating and using an object registration table, a subject table and a user rights table substantiaUy as shown in Figure 30.
  352. 441
    A method of using a site record table and a group record table to track portions of a secure database substantiaUy as shown in FIGURE 34.
  353. 442
    A process for updating a secure database substantiaUy as shown in FIGURE 35.
  354. 443
    A process of inserting new elements into a secure database substantiaUy as shown in FIGURE 36.
  355. 444
    A process of accessing elements in a secure database substantiaUy as shown in FIGURE 37.
  356. 445
    A process of protecting a secure database element substantiaUy as shown in FIGURE 38.
  357. 446
    A process of backing up a secure database substantiaUy as shown in FIGURE 39.
  358. 447
    A process of recovering a secure database substantiaUy as shown in FIGURE 40.
  359. 448
    A process of enabling performing reciprocal methods to provide a chain of handling and control substantiaUy as shown in FIGURES 41A-41D.
  360. 449
    A "reciprocal" BUDGET method substantiaUy as shown in FIGURES 42A-42D.
  361. 450
    A reciprocol audit method substantiaUy as shown in FIGURES 44A-44C.
  362. 451
    A method for controlling releεise of content or other method substantiaUy as shown in εmy of FIGURES 45-48.
  363. 452
    An event method substantiaUy as shown in FIGURES 53A-53B.
  364. 453
    A billing method subst-antiaUy as shown in FIGURE 53C.
  365. 454
    An extract method substantiaUy as shown in FIGURE 57A.
  366. 455
    An embed method substantiaUy as shown in FIGURE 57A.
  367. 456
    An obscure method substantiaUy as shown in FIGURE 58A.
  368. 457
    A fingerprint method substεmtiaUy as shown in FIGURE 58B.
  369. 458
    A fingerprint method substantiaUy as shown in FIGURE 58C.
  370. 459
    A meter method substantiaUy as shown in FIGURE 6.
  371. 460
    A key "convolution" process substantiaUy -as shown in FIGURE 62.
  372. 461
    A process of generating different keys using a key convolution process to determine a "true" key substantiaUy as shown in FIGURE 63.
  373. 462
    A process of initializing protected processing environment keys substantiaUy as shown in FIGURES 64 -and/or 65.
  374. 463
    A process for decrypting information contained within stationary objects substantiaUy as shown in FIGURE 66.
  375. 464
    A process for decrypting infoπnation contained within traveling objects substantiaUy as shown in FIGURE 67.
  376. 465
    A process for initializing a protected processing environment substantiaUy as shown in FIGURE 68.
  377. 466
    A process of downloading fiπnw-are into a protected processing environment substantiaUy as shown in FIGURE 69.
  378. 467
    Multiple VDE electronic apphances connected together with a network or other communications means substantiaUy as shown in FIGURE 70.
  379. 468
    A portable VDE electronic apphance substantiaUy as shown in FIGURE 71.
  380. 469
    "Pop-up" displays that may be generated by the user notification and exception interface substantiaUy as shown in Figures 72A-72D.
  381. 470
    A smεirt object substantiaUy as shown in FIGURE 73.
  382. 471
    A method of processing smart objects substantiaUy as shown in FIGURE 74.
  383. 472
    Electronic negotiation substantiaUy as shown in any of FIGURES 75A-75D.
  384. 473
    An electronic -agreement substantiaUy as shown in FIGURES 75E-75F.
  385. 474
    Electronic negotiation processes substantiaUy as shown in any of FIGURES 76A-76B.
  386. 475
    A chain of handling and control substantiaUy as shown in FIGURE 77.
  387. 476
    A VDE "repository" substantiaUy as shown in FIGURE 78.
  388. 477
    A process of using a chain of handhng and control to evolve and transform VDE managed content and control information substantiaUy as shown in any or aU of FIGURES 79-83.
  389. 478
    A chain of handling and control involving several categories of VDE participants substantiaUy as shown in FIGURE 84.
  390. 479
    A chain of distribution and handling within an organization substantiaUy as shown in FIGURE 85.
  391. 480
    A chain of handling and control substantiaUy as shown in Figures 86 and/or 86A.
  392. 481
    A virtual silicon container model substεmtiaUy as shown in Figure 87.
  393. 482
    A method of business automation characterized by the steps of (a) creatings one or more secure containers including encrypted accounting and/or other administrative information content, (b) associating control infoπnation with one or more of such one or more secure containers including a description of (i) the one or more parties whom may use one or more of the one or more containers, and (ii) the operations that will be performed for one or more parties with respect to such accounting and/or other administrative information, (c) electronicaUy dehvering one or more of such one or more containers such to one or more parties, and (d) enabhng through the use of a protected processing environment the enforcement of at least a portion of such control information.
  394. 483
    A business automation system characterized by:means for providing at least one secure container including administrative information content having control information associated therewith, εind a protected processing environment for enforcing, at least in part, the control information.
  395. 484
    A business automation system comprising (a) distributed, interoperable protected processing environment instaUations, (b) secure containers for distribution of digital information, (c) control infonnation supporting the automation of chain of handling and control functions.
  396. 485
    A method of business automation characterized by the steps of providing interoperable protected processing environment nodes to plural parties, communicating first encrypted digital infonnation from a first party to a second party, communicating second encrypted digital information including at least a portion of said first communicated digital infoπnation and/or information related to the use of said first digit-al information, to a third party different from said first or second parties, wherein use of s dd second encrypted digital information is regulated, at least in part, by an interoperable protected processing environment avaUable to said third party.
  397. 486
    A business automation system characterized by:plural protected processing environment nodes, means for communicating digital information between the nodes, and wherein at least one of the nodes includes means for regulating the use of said communicated digital information.
  398. 487
    A method for chain of handling and control characterized by the steps of (a) a first party placing protected digital information into a first software container and stipulating rules and controls governing use of at least a portion of said digital information, (b) providing said software container to a second party, wherein said second party places said software container into a further software container and stipulates rules and controls for at least in part managing use of at least a portion of said digital information and/or said first software container by a third party.
  399. 488
    A chain of handling and control system characterized by:means for placing digital information into a first software container and for stipulating rules and/or controls governing use of at least a portion of said digital information, and means for placing sεdd software container into a further software container and for stipulating further rules and/or controls for at least in part managing use of at least a portion of said digital information and/or said first software container.
  400. 489
    A system for chain of handling and control including (a) a first container containing at least in part protected digital information, (b) at least in part protected control information stipulated by a first pεirty establishing conditions for use of at least a portion of said digital content, (c) a second container different from said first container, said second container containing said first container, (d) control information stipulated independently by a second party for at least in part setting conditions for managing use of the contents of said second container.
  401. 490
    A system for electronic advertising including:(a) s to provide digital information to users for their use, (b) means to provide advertising content to said users in combination with said digital information, (c) means to audit use of said digital information, (d) means to securely acquire usage information regarding use of advertising content, (e) means to securely report infonnation based upon said advertising content usage infonnation, (f) compensating at least one content provider at least in part based upon use of said advertising content.
  402. 491
    A method for electronic advertising characterized by the steps of (a) placing digital information into a container, (b) associating advertising information with at least a portion of said digital information, (c) securely providing said container to a container user, (d) monitoring user viewing of advertising information, and (d) receiving payment from an advertiser, wherein said payment is related to user viewing of said advertising information.
  403. 492
    A system for electronic advertising involving (a) means to containerize digitεd information including both content and advertising information, (b) means to monitor viewing of at least a portion of said advertising information, (c) means to charge for user viewing of at least a portion of said advertising infonnation, (d) means to securely communicate infonnation based upon said viewing in a secure container, and (e) control information related to said containerized digital information for managing the communication of said information based upon said viewing.
  404. 493
    A method for electronic advertising characterized by the steps of (a) containerizing digital information including both content and advertising infoπnation, (b) monitoring user viewing of at least a portion of said advertising information, (c) charging for user viewing of at least a portion of said advertising information, (d) securely communicating information based upon said viewing in a secure container, and (e) at least in pεirt managing, through the use of control information related to said advertising information, the communication of information based upon said viewing.
  405. 494
    A method of clearing transaction information characterized by the steps of (a) securely distributing digital information to a first user of an interoperable protected processing environment, (b) securely distributing further digital information to a user of an interoperable protected processing environment different from said at first user (c) receiving infoπnation related to usage of said digital information, (d) receiving information related to usage of said further digital information, and (e) processing infoπnation received according to steps (c) and (d) to perform at least one of (I) an administrative, or (II) an analysis, function.
  406. 495
    A system for clearing transaction information including (a) a first container containing at least in pε-rt protected digital information and associated control information, (b) a second secure container conta-Lning further at least in part protected digital information and associated control infonnation, (c) means to distribute said first -and second containers to users, (d) communication means for communicating information at least in part derived from user usage of said first contεiiner digital information, (e) communication means for communicating information at least in part derived from user usage of said second container digital information, (f) processing means at a clearinghouse site for receiving the information communicated through steps (d) and (e), wherein said processing means perform administrative and/or analysis processing of at least a portion of said communicated information.
  407. 496
    A method for clearinghouse analysis characterized by the steps of:(a) enabhng plural independent cleεiringhouses for administrating and/or analyzing usage of distributed, at least in part protected, digital information, (b) providing interoperable protected processing environments to plural, independent users, and (c) enabling a user to select a clearinghouse for use with an interoperable protected processing environment
  408. 497
    A system for clearinghouse analysis including (a) plural independent clearinghouses for administrating and/or analyzing usage of distributed, at least in part protected, digital information, (b) at least one interoperable protected processing environments at each of plural user locations, (c) selecting means for enabhng a user to select one of said plural independent clearinghouse to perform payment and/or analysis functions related to the use of at least a portion of said at least in part protected, digital information.
  409. 498
    A method of electronic advertising characterized by the steps of creating one or more electronic advertisements, creating one or more secure containers including at least a portion of such advertisements, associating control information with such advertisements including control information describing at least one of:(a) reporting at least some advertisement usage information to one or more content providers, advertisers and/or agents, (b) providing one or more credits to a user based on such user's viewing and/or other usage of such advertisements, (c ) reporting advertisement usage infonnation to one or more market analysts, (d) providing a user with ordering infoπnation for and/or means for ordering one or more products and/or services, and/or (e) providing one or more credits to a content provider based on one or more users' viewing and/or other usage of such advertisements, providing such containers and such control information to one or more users, enabhng such users to use such containers at least in part in accordance with such control information.
  410. 499
    A system for electronic advertising including (a) means to provide digital information to users for their use, (b) means to provide advertising content to said users in combination with said digital information, (c ) means to audit use of said digital information, (d) means to acquire usage information regarding use of advertising content, (e) means to securely report information based upon said advertising content usage information, and (f) compensating at least one content provider at least in part based upon use of such advertising content.
  411. 500
    A system for chain of handling and control including (a) a first container containing at least in part protected digital infonnation, (b) at least in part protected control infonnation stipulated by a first party establishing condition for use of at least a portion of said digital content, (c ) a second container different from said first container, said second container containing said first container, and (d) control infonnation stipulated independently by a second party for at least in part setting conditions for managing use of the contents of said second container.
  412. 501
    A method of operating a clearinghouse characterized by the steps of receiving usεige information related at least in part to use of secure containers from plural parties, determining payments due to one or more parties based at least in part on such usage information, performing and/or causing to be performed transactions resulting in payments to such parties based at least in part on such determinations.
  413. 502
    An electronic clearinghouse comprising:means for receiving usage information related at least in part to use of secure containers from plural parties, means for determining payments due to one or more parties bεised at least in part on such usage information, means for performing εmd/or causing to be performed transactions resulting in payments to such parties based at least in part on such determinations.
  414. 503
    A method of operating a clearinghouse characterized by the steps of receiving usage information related at least in part to use of secure containers from plural parties, determining reports of usεige for one or more parties based at least in part on such usage information, creating and/or causing to be created reports of usage based at least in part on such determination, dehvering at least one of such reports to at least one of such parties.
  415. 504
    A method of operating a clearinghouse characterized by the steps of receiving permissions and/or other control information from one or more content providers including information that enables dehvery of at least one right in at least one secure container to other parties, receiving requests from plural parties for one or more rights in one or more secure containers, dehvering permissions -and or other control information to such parties based at least in pεirt on such requests.
  416. 505
    A method of operating a clearinghouse characterized by the steps of receiving information from one or more parties establishing a party's identity information, creating one or more electronic representations of at least a portion of such identity information for use in enabling and/or withholding at leεist one right in at least one secure container, performing an operation to certify such electronic representations, dehvering such electronic representations to such party.
  417. 506
    A method of operating a clearinghouse characterized by the steps of receiving a request for credit from a party for use with secure containers, determining an amount of credit based at least in part on such request, creating control information related to such an amount, dehvering such control information to such user, receiving usage infoπnation related to use of such credit, performing and/or causing to be performed at least one transaction associated with coUecting payment from such user.
  418. 507
    A method for contributing secure control information with respect to an electronic value chain wherein control information is contributed by a party not directly participating in said value chain, comprising steps of:aggregating said contributed control information with control information associated with digital information stipulated by one or more parties in an electronic value chain, said aggregate control information at least in part managing conditions related to the use of at least a portion of said digital information.
  419. 508
    A method for entering the payment of taxes associated with commercial events wherein secure control information for automaticaUy governing tax payments for said commercial events is contributed by a party comprising steps of:aggregating said secure control infonnation with control information that has been contributed by a separate party and controUing at least one condition for use of digital information.
  420. 509
    A method for general purpose reusable electronic commerce arrangement characterized by the steps of:(a) providing component structures, modular methods that can be configured together to comprise event controUed (b) providing integrateable protected processing environments to plural independent users;(c) employing secure communications means for communicating digital control information between integrateable protected processing environments;and (d) enabhng database managers operably connected to said processing environments for storing at least a portion of said provided component modular methods.
  421. 510
    A system for general purpose, reusable electronic commerce including:(a) component modular methods configured together to comprise event control structures;(b) at least one interoperable processing environment at each of plural independent user locations;(c) secure communications means for communicating digital control information between interoperable protected processing environments;and (d) secured database managers operably connected to said protected processing environments for storing at least a portion of said component modular methods.
  422. 511
    A general purpose electronic commerce credit system including:(a) a secure interoperable protected processing environment;(b) general purpose credit control infonnation for providing credit for user usage of at least in part protected digital information;and (c) at least in part protected digital information related control information for providing necessary information for employing credit through the use, at least in part, of said general purpose credit control information.
  423. 512
    A method for enabhng a general purpose electronic commerce credit system including:(a) providing secure interoperable protected processing environments;Ob) supplying general purpose credit control information for providing credit for user usage of at least in part protected digital information;and (c) providing, at least in part, protected digital information related control information for providing necessary information for employing credit through the use, at least in part, of said general purpose credit control information.
  424. 513
    A document management system comprising one or more electromc apphances containing one or more SPUs and one or more secure databases operatively connected to at least one of the SPUs.
  425. 514
    An electronic contract system comprising one or more electronic apphances containing one or more SPUs and one or more secure databases operatively connected to at least one of the SPUs.
  426. 515
    An electronic apphance containing at least one SPU and at least one secure database operatively connected to at least one of the SPU(s).
  427. 516
    An electronic apphance containing one or more CPUs where at least one of the CPUs is integrated with at least one SPU.
  428. 517
    An electronic apphance containing one or more video controUers where at least one of the video controUers is integrated with at least one SPU.
  429. 518
    An electronic apphance containing one or more network communications means where at least one of the network communications means is integrated with at least one SPU.
  430. 519
    An electronic apphance containing one or more modems where at least one of the modems is integrated with at least one SPU.
  431. 520
    An electronic apphance containing one or more CD- ROM devices where at least one of the CD-ROM devices is integrated with at least one SPU.
  432. 521
    An electronic apphance containing one or more set¬ top controUers where at least one of the set-top controUers is integrated with at least one SPU.
  433. 522
    An electronic apphance containing one or more game systems where at least one of the game systems is integrated with at least one SPU.
  434. 523
    An integrated circuit supporting multiple encryption algorithms comprising at least one microprocessor, memory, input output means, at least one circuit for encrypting and/or decrypting infonnation and one or more software programs for use with at least one of the microprocessors to perform encryption and/or decryption functions.
  435. 524
    An integrated circuit comprising at least one microprocessor, memory, at least one real time clock, at least one random number generator, at least one circuit for encrypting and or decrypting information and independently dehvered and/or independently dehverable certified software.
  436. 525
    An integrated circuit comprising at least one microprocessor, memory, input/output means, a tamper resistant barrier and at least a portion of a Rights Operating System.
  437. 526
    An integrated circuit comprising at least one microprocessor, memory, input output means, at least one real time clock, a tamper resistant barrier and means for recording interruption of power to at least one of the real time clocks.
Independent claims437