EP1515216B1

Systems and methods for secure transaction management and electronic rights protection

Abstract

This record has no abstract on file.

EP1515216B1, drawing sheet 1
Sheet 1 of 20

Term

Term ended

Expired 13 February 2016, 10.6 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

15 claims: 13 independent, 2 dependent

  1. 1
    A secure component-based operating process which is to be carried out in a protected processing environment (503) that is resistant to tampering by users of the equipment on which the protected processing environment is operated, said process comprising:a. retrieving at least one component;b. retrieving a record that specifies a component assembly (690);c. checking said component and/or said record for validity;d. assembling said component assembly (690) in accordance with said record using said component, wherein said component assembly provides functions needed for a user to perform a task on an object (300), and the assembly of said component assembly is based at least in part on context parameters relating to the object or user;and e. performing a process based at least in part on said component assembly (690), which process includes executing the component in the protected processing environment.
  2. 4
    A process as in any of the preceding claims wherein said component comprises executable code.
  3. 5
    A process as in any of the preceding claims wherein said component comprises a load module.
  4. 6
    A process as in any of the preceding claims wherein said component is assembled to form, at least in part, a second component assembly.
  5. 7
    A process as in any of the preceding claims, wherein:said record comprises: (i) directions for assembling said component assembly;and (ii) information that at least in part specifies a control;and said process further comprises controlling said step (d) and/or said step (e) based at least in part on said control.
  6. 8
    A process as in any of the preceding claims wherein said component has a security wrapper, and said controlling step comprises selectively opening said security wrapper based at least in part on said control.
  7. 9
    A process as in any of the preceding claims wherein:said record includes at least one decryption key;and said controlling step includes controlling use of said decryption key.
  8. 10
    A process as in any of the preceding claims, wherein said component is encrypted, a validation/correlation tag is stored under the encrypted layer of the component, and the validation/correlation tag is compared to one or more tags provided by a requesting process or expected by the protected processing environment to ensure a match.
  9. 11
    A process as in any of the preceding claims including performing at least two of said steps (a) and (e) at least in part within tamper resistant hardware.
  10. 12
    A method as in any of the preceding claims wherein said performing step (e) includes metering usage.
  11. 13
    A method as in any of the preceding claims wherein said performing step (e) includes auditing usage.
  12. 14
    A method as in any of the preceding claims wherein said performing step (e) includes budgeting usage.
  13. 15
    An electronic appliance (600) comprising a protected processing environment (503) that is resistant to tampering by users of the electronic appliance, the secure processing unit (500) being arranged to perform secure data management processes, the electronic appliance comprising:a. means for retrieving at least one component;b. means for retrieving a record that specifies a component assembly (690);c. means for checking said component and/or said record for validity;d. means for assembling said component assembly (690) in accordance with said record, wherein said component assembly provides functions needed for a user (112) to perform a task on an object (300), and the assembly of said component assembly is based at least in part on context parameters relating to the object or user;and e. means for performing a process based at least in part on said component assembly (690), which process includes executing the component in the protected processing environment.