EP1531379B1

Systems and methods for secure transaction management and electronic rights protection

Abstract

This record has no abstract on file.

EP1531379B1, drawing sheet 1
Sheet 1 of 41

Term

Term ended

Expired 13 February 2016, 10.6 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

15 claims: 2 independent, 13 dependent

  1. 1
    A method for processing based on independent deliverables to be carried out in a protected processing environment (503) that is resistant to tampering by users of equipment on which the protected processing environment is operated, said process comprising:receiving a first piece of executable code defining a first part of a process, said process involving a governed object (300), said first piece of executable code being separate from said governed object;separately receiving a second piece of executable code defining a second part of said process, said second piece of executable code being separate from said governed object;ensuring the integrity of said first and second delivered pieces of executable code, by generating a first hash of at least a portion of said first piece of executable code and comparing said first hash with a first expected value, and by generating a second hash of at least a portion of said second piece of executable code and comparing said second hash with a second expected value;assembling the first piece of executable code and the second piece of executable code to form a component assembly (690), the component assembly being assembled at least in part according to instructions contained in a permissions record (808) that identifies the first piece of executable code and/or the second piece of executable code;ensuring that a calling process has authorization to call said first and second delivered pieces of executable code by verifying the calling process's knowledge of a value of a first tag associated with said first piece of executable code and a value of a second tag associated with said second piece of executable code;and performing said process involving said governed object based at least in part on said first and second delivered executable code pieces, wherein said process includes controlling use of the governed object (300) in accordance with information contained in the permissions record (808) regarding rights associated with the governed object, and recording information regarding at least one performance of at least a portion of said process.
  2. 15
    An electronic appliance (600) comprising a protected processing environment (503) that is resistant to tampering by users of the electronic appliance, the protected processing environment (503) being arranged to perform secure data management processes, the electronic appliance comprising:means for receiving a first piece of executable code defining a first part of a process, said process involving a governed object (300), said first piece of executable code being separate from said governed object;means for separately receiving a second piece of executable code defining a second part of said process, said second piece of executable code being separate from said governed object;means for ensuring the integrity of said first and second delivered pieces of executable code, by generating a first hash of at least a portion of said first piece of executable code and comparing said first hash with a first expected value, and by generating a second hash of at least a portion of said second piece of executable code and comparing said second hash with a second expected value;means for assembling the first piece of executable code and the second piece of executable code to form a component assembly (690), the component assembly being assembled at least in part according to instructions contained in a permissions record (808) that identifies the first piece of executable code and/or the second piece of executable code;means for ensuring that a calling process has authorization to call said first and second delivered pieces of executable code by verifying the calling process's knowledge of a value of a first tag associated with said first piece of executable code and a value of a second tag associated with said second piece of executable code;and means for performing said process involving said governed object based at least in part on said first and second delivered executable code pieces, wherein said process includes controlling use of the governed object (300) in accordance with information contained in the permissions record (808) regarding rights associated with the governed object, and recording information regarding at least one performance of at least a portion of said process.