System and method for authenticating peer components
Abstract
A system and method for controlling the usage of data objects in component object systems. According to the invention, each data object includes a peer list that defines one or more peer data objects that are required by the data object. Upon receipt of a data object, the system verifies the integrity of the data object. Further, the system identifies the integrity of the peer data objects. If the system cannot find the peer data objects, or the system cannot authenticate the peer data objects, the system may optionally retrieve a peer data object that can be authenticated from a data object depository. In addition to validating the integrity of the data object, the system verifies that the data object is authorized to communicate with each of the peer data objects. Further, the system verifies that the peer data objects are authorized to communicate with the data object.

Term
Term ended
Expired 15 January 2019, 7.7 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
30 claims: 6 independent, 24 dependent
- 1tí® Ια Property industry # tí® Ια Propiedad industria# 1. A method of controlling data usage on a computer that has one or more like ^ data objects, 5 the method comprises:z 1. Un método para controlar el uso de datos en una computadora que tiene uno o más objetos de ^datos semejantes, 5 el método comprende:· z proporcionar un objeto de datos, el objeto de datos incluye una descripción de uno o más de los objetos de datos semejantes que son requeridos para el uso del objeto de datos;providing a data object, the data object includes a description of one or more like data objects that are required for use of the data object;10 determining whether like data objects are authorized to communicate with the data object;10 determinar si los objetos de datos semejantes están autorizados para comunicarse con el objeto de datos;determinar si el objeto de* datos está autorizado para comunicarse con los objetos de datos semejantes;y conectar el objeto de datos a los objetos de datos determine if the * data object is authorized to communicate with peer data objects;and connect data object to data objects 15 semejantes basados en la autorización otorgada, de modo que el objeto de datos pueda comunicarse con los objetos de datos semejantes y los objetos de datos semejantes puedan comunicarse con el objeto de datos. fifteen peers based on the authorization granted, so that the data object can communicate with the like data objects and the like data objects can communicate with the data object. 20 20
- 1617. A system for controlling the use of a data object, the system comprises:17. Un sistema para controlar el uso de un objeto de datos, el sistema comprende: one or more like data objects, like data objects collectively define a software application;uno o más objetos de ..datos semejantes, los objetos de datos semejantes definen colectivamente una aplicación de software;..ci lX » ..cí lX» 48 Qj 48 Qj Institute a parser capable of reading from a Mexican object (if the Data Property a description of one or more data objects that industry is required for use of the data object;Instituto un analizador sintáctico capaz de leer desde un objeto Mexicano (fe la Propiedad de datos una descripción de uno o más objetos de datos que industriad son requeridos para uso del objeto de datos;a validation data object module, capable of un módulo de objetos de datos de validación, capaz de 5 determining whether the data object is authorized to communicate with one or more like data objects;5 determinar si el objeto de datos está autorizado para comunicarse con uno o más objetos de datos semejantes;a peer validation module, capable of determining whether peer data objects are authorized to communicate with the data object;and 10 a wiring module capable of controlling the connection of the like data objects to the data object. un módulo semejante de validación, capaz de determinar si los objetos de datos semejantes están autorizados para comunicarse con el objeto de datos;y 10 un módulo de cableado capaz de controlar la conexión de los objetos de datos semejantes al objeto de datos. le you
- 1718. Does the system disagree? with claim 17, further comprising a validation module capable of 18. El sistema desacuerde? con la reivindicación 17, que comprende adicionalmente un módulo de validación capaz de 15 verificar la integridad del objeto de datos. fifteen verify the integrity of the data object. -i- i · . ... -i- i ·. ...
- 1920. Un objeto de datos que está configurado que está cableado dinámicamente a uno o más objetos de datos, el objeto de datos comprende:twenty. A data object that is configured to be dynamically wired to one or more data objects, the data object comprises: lyi · &. lyi ·&. 49 ID 1 jg. ·· Institute a description of one or more data objects that are Mexican (is the Property required to connect to the data object before the data object can be accessed by the data objects similar »· and 49 ID 1 jg.·· Instituto un descripción de uno o más objetos de datos que soñ‘ Mexicano (fe la Propiedad requeridos para que se conecten con el objeto de datos antes trtáustiWI de que el objeto de datos pueda ser accesado por los objetos de datos semejantes»· y 5 at least one digital signature that identifies a supplier of the data object. 5 al menos una firma digital que identifica a un suministrador del objeto de datos.
- 2122. The data object according to the claim 22. El objeto de datos de acuerdo con la reivindicación 15 20» en donde la firma digital, fue firmada por un banco» y en donde el objeto de datos contiene dinero virtual. fifteen 20 »where the digital signature was signed by a bank» and where the data object contains virtual money.
- 222. 3. A system for controlling the use of data in a computer that has one or more similar data objects. 23. Un sistema para .controlar el uso de datos en una computadora que tiene uno o más, objetos de datos semejantes» 20 el sistema comprende medios para JLeer un objeto de datos» el objeto de datos > J incluye una descripción de uno o más objetos de datos semejantes que son requeridos para el uso del objeto de datos twenty the system comprises means for JRead a data object »the data object> J includes a description of one or more similar data objects that are required for the use of the data object Instituto ™ · · Mexican and configured in a state that is not used by the objects of similar data;Instituto ™· · Mexicano y configurados en un estado que no es usado por los objet^ijgPropiedad fntíastrtaí de datos semejantes;means of determining whether like data objects are authorized to communicate with the object medios para determinar si los objetos de datos semejantes están autorizados para comunicarse con el objeto 5 of data;5 de datos;means for * determining whether the data object is authorized to communicate with like data objects;medios para* determinar si el objeto de datos está autorizado para comunicarse con los objetos de datos semejantes;means for converting the data object into a state 10 that is used by the like data object;and means for connecting the data object to the like data objects, so that the data object can communicate with the like data object and the like data objects can communicate with the object of medios para convertir el objeto de datos en un estado 10 que es usado por el objeto de datos semejantes;y medios para conectar el objeto de datos a los objetos de datos semejantes, de modo que el objeto de datos pueda comunicarse con el objeto de datos semejantes y los objetos de datos semejantes puedan comunicarse con el objeto de 15 datos. fifteen data. ..tí ..you
Independent claims6
311 paragraphs in 8 sections, as filed
SYSTEM AND METHOD TO AUTHENTICATE COMPON
LIKE
<img file="MX214637B_D0001.tif" />
<img file="MX214637B_D0002.tif" />
Exican institute
TOpiectod tndustrtaí
BACKGROUND OF THE INVENTION
Field of Invention.
This invention belongs to the field of data management. More particularly, the invention pertains to a system and method for authenticating like data objects in component object systems.
Description of Related Technology
Historically, "software applications (programs) were designed as repositories that were used to support factories" before the arrival of just-in-time manufacturing (JIT). Before manufacturing at JIT, "warehouses were stocked with each part" regardless of when the part would be needed or whether the part would be needed at all. Similarly "software applications have traditionally been formed using a plurality of modules" which are stored in the software application "regardless of whether all modules may be needed. A technological problem in
<img file="MX214637B_D0003.tif" />
jgft ··· Institute develop a solution based on an es'quW ©) dffiarM> object
Cfe Property software code is typically compiled and linked to executable program. Once the code is in an executable state, integrating additional components into the program is difficult.
However, new object models now provide for dynamic integration of data objects into a worker application. For example, glimpses of
The Internet, which uses an interpretive environment, allows for the dynamic integration of various data objects, such as a Java apple, in the quick review to the Internet.
Although data objects, according to current object models, contain some limited one-way security features, there is currently no way for the data object to authenticate the identity of the peek and for the peek to authenticate the identity of the peek. data object. At best, data objects are designed with a simple security scheme, in which quick review can decide whether or not to trust the data object. If the data object is validated, this data object is granted access to certain features of the system. Otherwise, if the
<img file="MX214637B_D0004.tif" />
<img file="MX214637B_D0005.tif" />
data object is not validated, it is given an access
<img file="MX214637B_D0006.tif" />
<feta Industrial Property to the characteristics of the system.
Likewise, using current technology, data objects cannot verify the identity of the peek or other data objects that have been installed in this peek.
Due to this limitation, safe and secure data objects cannot be developed, since they cannot guarantee that the target environment will recognize and understand its internal security.
Therefore, there is a need for a system that can authenticate the identity of a data object to its peers, each time this data object is used.
Furthermore, the system must be able to authenticate the identity of peers to the data object. After the data object and the like data objects are identified, the data object must be able to dynamically connect to the like data objects.
Similarly, if the data object needs a striped peer data object, and if this selected peer data object cannot be found in the system or the peer data object cannot be authenticated, the
<img file="MX214637B_D0007.tif" />
The system must be able to retrieve a peer that can be authenticated.
¡¿¡¡¿-, ·· Object Institute “'· Aleateano (felá Property Industriad
COMPENDIUM OF THE INVENTION
The animation system of the present invention has several features, none of which is solely responsible for its convenient attributes. Without limiting the scope of this invention "which is expressed by the claims that follow" its most prominent features will now be summarized.
One embodiment of the invention includes a method of controlling data usage on a computer "having one or more like data objects," this method involves supplying a data object "this data object includes a description of one or more of the like data" which determines whether the like data objects are allowed to communicate with the data object "which determines whether the data object is authorized to communicate with similar data objects' and that
0 connects the data object to peer data objects based on the authorization granted that such a data object can communicate with
<img file="MX214637B_D0008.tif" />
like data and these similar data objects communicate with the data object.
Another embodiment of the invention includes a system for controlling the use of a data object "the system comprises one or more like data objects" these like data objects collectively define a software application "a parser capable of reading from an object data a description of one or more similar data objects »that are required for the use of the data object» a data object validation module »capable of determining whether the data object is authorized to communicate with one or more peer data objects »a peer validation module capable of determining whether peer data objects are authorized to communicate with the data object» and a wiring module »capable of controlling the connection of the data objects similar to the data object.
BRIEF DESCRIPTION OF THE DRAWINGS
Figure 1 is a high-level block diagram "illustrating a plurality of data object providers" a data object and animation system of the
<img file="MX214637B_D0009.tif" />
present invention »connecting the dat object
<img file="MX214637B_D0010.tif" />
<img file="MX214637B_D0011.tif" />
<1θΙα Property plus similar data objects. tntíustifflri
Figure 2 is a block diagram, illustrating a number of modules' that comprise the animation system shown in Figure 1.
Figure 3 is a block diagram illustrating the components of the data object »shown in the
Figure 1 »these components include: a digital object identifier» a list of peers »a list of identifications, a manufacturing information, one or more sub-components» and an export list.
Figure 4 is a block diagram illustrating the elements of one of the subcomponents shown in Figure 3.
Figure 5 is a block diagram illustrating the items in the export list »shown in Figure 3.
Figure δ is a block diagram illustrating a field of wiring data "that is contained in selected subcomponents" shown in the Figure.
<img file="MX214637B_D0012.tif" />
<img file="MX214637B_D0013.tif" />
Figure 7 is a block diagram »
Afc ·? Institute fl ^ - 'iiWtecteGino <fe the Property
<img file="MX214637B_D0014.tif" />
Exemplary data that may be contained in tndosfrtol subcomponents shown in Figure 3.
Figure 8 is a block diagram illustrating exemplary code that may be contained in the subcomponents shown in Figure 3,
Figure 9 is a flowchart »illustrating a process for creating the data object, shown in Figure 3.
Figure 10 is a flow chart illustrating a process for connecting the data objects with the like data objects' shown in Figure 1.
DETAILED DESCRIPTION OF THE MODALITIES OF THE INVENTION
The following detailed description is directed to certain specific embodiments of the invention. However "the invention may be incorporated in a multitude of different ways" as defined and covered by the claims.
System Review
Figure 1 is a high-level block diagram, illustrating an animation system 100 of the
<img file="MX214637B_D0015.tif" />
present invention.
This system
100 de <1θΙα Possible property authentication and connection of a llfttddsAifflri data object to one or more similar data objects or components
118 in a safe and secure environment. Following authentication and assuming that data object 112 is authorized to communicate with peer data objects 118, animation system 100 coordinates the connection of data object 112 with peer data objects 118.
As shown in Figure 1, the animation system 100 may communicate with one or more data object providers 107, which contain the data object 112. An exemplary data object provider can be one of the following: a database data 104, a server computer 106, a removable media storage 110 or a hardware device 111 (computer equipment). The removable media store 110 may be a floppy disk, compact disk, hard disk, tape drive, ROM, or other persistent storage medium. The hardware device 111 can be a logic chip, a ROM memory, a RAM memory, a smart card, or a central processing unit.
<img file="MX214637B_D0016.tif" />
flfev Institute
In one embodiment of the invention, the ^ Sj'etWexfeano (felá Property data 112 can be kept in a Java ArÜukntiiori (JAR) file. This JAR file is a platform-independent file format, which aggregates many files into one. Using The JAR file format, multiple Java apples, and their required components can be bundled together into a single file, making it easy to transfer them between computers. Additional information regarding JAR files is located in the Jar Guide http: //iava.sun.eom/products/idk/1.1./docs/guide/iar/iarGuide.html, published by Sun Microsystems, Inc. of Mountainview ,
California, and which is incorporated herein by reference. In another embodiment of the invention, data object 112 is a hardware device.
It will be noted that each of the like data objects 118 is a data object, as defined herein, with the like term merely distinguishing its role. The schematic of data object 112 and similar data objects 118 is noted below with reference to
Figure 3.
Similar data objects 118 can define together, or in isolation, one or more applications of
<img file="MX214637B_D0017.tif" />
<img file="MX214637B_D0018.tif" />
¿Ffi. · · Software Institute. Software applications may include <f the Property example, a word processor, a database, a personal finance utility, a graphing tool, a look at the Internet, a computer game, a communications program, a computer. authorization program, an e-exchange, a multimedia producer or a contract manager. A process for using like data objects is outlined below with reference to the
Figure 10.
In one embodiment of the invention, animation system 100 is an executable computer program, which resides on client computer 102. This system
100 Animation includes several modules, which are typically compiled separately and linked into a single executable program. The modules of the animation system 100 are described below with reference to Figure 6.
The animation system 100 (Figure 1) can be written in any program language, such as C, C ++,
BASIC, Pascal, Java and FORTRAN. C, C ++, BASIC, Pascal,
Java and FORTRAN are industry standard programming languages, for which many commercial compilers and interpreters can be used to create executable code.
<img file="MX214637B_D0019.tif" />
LJ | ώ £. ·· Institute
Also, the system 10 0 animation can be ^ uSaMextoono (fetus Property related to various operating systems, such as, ln0ttStllofl example, UNIS, Solaris, Disk Operating System (DOS), OS / 2,
Windows 3.X, Windows 98, Windows CE, Palm Pilot OS and Windows
NT.
The customer computer 102 can be any conventional general purpose computer using one or more microprocessors, such as, for example, a processor.
Pentium, a Pentium II processor, a Pentium processor
Pro, one xx86 processor, one 8051 processor, one processor
IPS, a Power PC processor, or an Alpha processor.
Additionally, the client computer 102 can be a specialized computer, such as a handheld computer, a telephone, a course guide, a satellite, a smart card, an embedded computing device, or a network of computing devices.
Figure 2 is a block diagram, illustrating the components of the animation system 100 (Figure 1).
This animation system 100 includes an analyzer
0 syntactic 150 for reading data object 112. Animation system 100 also includes validation module 152. This validation module 152 includes two
<img file="MX214637B_D0020.tif" />
<img file="MX214637B_D0021.tif" />
subcomponents, that is, a valid object module 158 and a like object module 160 via valid data object module 158 is configured to verify the integrity of the data object 112 (Figure 1) before the data object is connected to like data objects 118 {Figure 1). The validation peer module 160 is used to validate the integrity of each peer data object 118.
Animation system 100 also includes a wiring module 154, which communicates with validation module 152. The wiring module 154 reads data object 112 to determine which similar data objects and / or hardware configuration are required by the data object for proper operation. The process for connecting the data component with the like data components is outlined below with reference to Figure
10.
In addition, the animation system 100 includes an event manager 156. This event manager is responsible for sending events to data object 112, before this data object 112 connects to peer data objects 118 (Figure 1) and later.
<img file="MX214637B_D0022.tif" />
LÜJL2 | ñ £. ·· Institute
Figure 3 is a diagram illustrating the ^ 't) aMs @ ÍKQno (theta Property constituents of the data object 112. This diUdíéStrtQfl 112 object includes a digital object identifier 200, which uniquely identifies the data object. Digital objects can be generated according to any standard or proprietary identification scheme.
Additional information regarding the exemplary digital object identification framework is described in About the
D0l <http://www.doi.org/overview.html> published by the International Digital Object Identifier Foundation and incorporated herein by reference.
Data object 112 also includes a list
202 peers (Figure 3). This peer list 202 defines all peer data objects, as shown in Figure 1, that are required by data object 212 for proper operation. In one embodiment of the invention, peer list 202 is a linked list of peer list structures (not shown), each of the peer list structures representing one of the peer data objects
118. Each of the structures in the peer list contains the name of a peer data object, a
<img file="MX214637B_D0023.tif" />
LdInstitute version number that is associated with the ^ Le object<sup>;</sup>'dfeSHÍCCinQ (theta Peer property and a location identifier, (nflblstflari location identifier designates a location where the peer data object can be retrieved ”if the data object is not stored on the client's computer 102. In a mode According to the invention "the location identifier is a Universal Resource Locator (URL) designating a web site. Alternatively" the location identifier may identify the database 104.
Optionally "peer list 202 may include a description of a decrypted data object (not shown) that is responsible for decrypting the contents of the subcomponents of data object 112.
This data object 112 also includes a list
204 identification (Figure 3). The identification list 204 contains one or more "digital identifiers" that can be used to authenticate the identity of one or more signers of the identifications in the identification list 204.
Each digital identification of the data object
112 it is based on both the content of the data object 112 and the signer's private key. Each of the
<img file="MX214637B_D0024.tif" />
digital IDs can be created through
<img file="MX214637B_D0025.tif" />
tí © ÍQ Property of a key function and an identification trufcétfltflíl private function, which encrypt the data object using the private key. Each of the digital identifiers also includes a public key that can be used to verify the authenticity of the data object 112.
In one embodiment of the invention, each of the digital identifications has an associated digital certificate. Digital certificates are issued by a certifying authority that documents the identities of those to whom digital certificates are issued with a given key.
When public and private keys are available for data object 112, the public key is sent to the certification agency with some proof of identification. The certificate authority verifies the identification and then sends the applicant a certificate that attests the match between the provider name of the data object 112 and the public key along with a hierarchy of certificates, or chain of certificates, verifying the public key of the authority that certifies.
The provider of data object 112 may present this
<img file="MX214637B_D0026.tif" />
', certificate chain when desired' with demonstrating the legitimacy of the public key of the
CTyGvSiVYuH
Additional information regarding digital IDs and digital certificates is described "for example" by RSA Data Security http: //www/rsa.com.
The address information 205 includes the data object. This address information 205 may include the name of the provider of the data object 112 "the name of the data object" and / or any other information that the provider of the data object 112 wants to include about this data object 112.
Similarly, data object 112 includes one or more subcomponents 206. These subcomponents include the content of data object 112. A description of each of the types of subcomponents 206 is noted below with reference to Figure 3.
Lastly, the data object 112 includes an export list 210. This export list 210 defines the procedures that are exported to the like data objects 118 and an animation system 100. Peer data objects 118 use the exported routines to access subcomponents 206, which are associated with '
data object 112, A description of export 210 is noted below with reference to
<img file="MX214637B_D0027.tif" />
g¡¿. ·· Instituto iiB't cMoxtoano <fe te Property la Fifróhistrfnrfl
5.
Figure 4 is a block diagram, illustrating the elements in each of the subcomponents 206 (Figure
3). Each subcomponent 206 includes a name field 302, a type 3 04 field, a data field 306, and an identification field 308. The name field 302 contains a sequence of arbitrary characters that identify the subcomponent 206. The type field 304 of the subcomponent
206 includes a description of the type of subcomponent 206.
In one embodiment of the invention, each of the 2 06 subcomponents defined falls into one of six types: wire-like, wire-animator, auto-wire, data, state, and code. The type of each of the subcomponents 206 determines what type of information is included in the data field 306. For the convenience of description, each type of the subcomponents 206 is referenced below by the identifier, which is defined in the data field. type 304. For example, a subcomponent that has a type 304 field that identifies self-wiring is referred to as a self-wiring subcomponent. As another
<img file="MX214637B_D0028.tif" />
LÜJLl Institute example, a subcomponent that has a field of tipüa04M®5 (Seano (felá Property designates data referred to as a data subcomponent, (ndUStltoA
In one embodiment of the invention, the wiring-like sub-components, the wiring-animator sub-components, and the self-wiring components are.
each serial JavaBeans. Additional information regarding JavaBeans can be found in the JavaBeans API
Specificaction, Veraions 1.01, published by Sun
Microsystems, which is incorporated herein by reference.
Each of the like wired subcomponents, i.e. selected subcomponents 206 in data object 112, describes the connection between the state subcomponents in data object 112 and the state subcomponents in one of the like data objects 118 (Figure 1 ).
Each wiring-animator subcomponent includes a description of how to connect the state components in data object 112 to animation system 100 (Figure 1). Still referring to Figure 3, a self-wiring component includes a description of how to connect two state subcomponents within data object 112. The data subcomponents, subcomponents of
<img file="MX214637B_D0029.tif" />
<td>invention.</td><td>the</td>
<td>status and</td><td>the</td>
<td>out using</td><td>the</td>
<td>modality,</td><td>every</td>
State institute and code subcomponents are used to dCTrsíii $ toxfcan <J <fe te Property function of data object 112 once this data object 112 is connected to peer data objects (Figure 1).
In one embodiment of the invention, data subcomponents, state subcomponents code subcomponents, are implemented using Java programming language. In this mode, each state subcomponent is a serial JavaBean. Also, each subcomponent of code is a Java class. However, it will be noted that in alternative embodiments of the invention, the code component may also comprise other types of code, such as, for example, Visual Basic Script,
JavaScript, or a dynamic linked library (DLL).
Finally, the identification field 308 (Figure
3) defines one or more digital IDs for subcomponent 206. Each of the digital IDs in ID field 308 is a unique identifier for each subcomponent, similar to the unique identifiers provided in list of IDs 204 (Figure 3).
<img file="MX214637B_D0030.tif" />
<fe te Property procedures of export list 210. This list ^<sub>n</sub>¿^ F<sub>(</sub>| g | export 210 defines the list of procedures that are exported by data object 112. Jja export list
210 includes a get-cell ID procedure 400, which supplies the ID list 204 (Figure 3) to the animation system 100 (Figure 1). This animation system 100 (Figure 1) uses the ID list 204 to determine the identity of the signers of digital object 112.
Also, the export list 210 includes a get-data-object-id procedure 402. Upon request, "this data object obtain-identity procedure 402 supplies the applicant with" such as animation system 100 or similar data objects.
118 »the identifier 200 of digital objects (Figure 3).
Referring to Figures 1 and 3, the animation system 100 may use the object identifier 200 to determine whether the data object 112 should be allowed to connect with like data objects 118.
Likewise »as shown in Figure 5» the export list 210 includes a procedure 404 of
21'
<img file="MX214637B_D0031.tif" />
get-list-of-entries. This procedure ^ 4 lagituto
Mexican sisífeteProBfedcKí get-list-of-entries, supply the industry?
animation 100 (Figure 1) a list of the names that are identified in the name field 302 (Figure 4) in each of the subcomponents 206 (Figure 3).
¡S »1 a. 1 * ij — j 't ci 21C5 díc χ * »gL c. zl C5XX x xx, c. 1 u / ^ rcx uxx procedure of obtaining-certificate of identification
Using this get-certificate of identification procedure 406 "any of the like data objects 118 by means of the animation system 100" can obtain the digital certificate that is associated with one or more of the digital identifications that are in the object.
Likewise, the export list 210 includes a procedure 408 of getting input name. This procedure 408 of obtaining input name provides an applicant with the handling of one of the selected subcomponents 206 (Figure 3). It will be noted that before the requester can obtain handling of one of the subcomponents 206, the selected subcomponent must be wired to the requester by the animation system 100.
<img file="MX214637B_D0032.tif" />
gtr .'- Instituto i rrcluy Mexicano
Export list 210 also <fc Property procedure 412 to get peers list. fatitestrioA procedure 412 for obtaining peers list supplies list 202 of peers (Figure 3) to animation system 100 (Figure 1}. This animation system 100 uses list 2 02 of peers to determine whether each of the objects 118 of Similar data that may be required by data object 112 is contained within the customer's computer 102.
Furthermore, the export list 210 also defines a procedure 414 of obtaining authentication. This procedure 414 of obtaining authentication supplies the name of an authentication system (not shown) that can be used to supply the conditions under which data object 112 will allow itself to be connected to peer data objects 118 (Figure 1 ). In one embodiment of the invention, the authentication system is one of the subcomponents in the data object 112. In another embodiment of the invention, the authentication system is a component in the animation system 100. In yet another embodiment of the invention, the authentication system is contained in one of the like data objects 118.
<img file="MX214637B_D0033.tif" />
'
Institute
The authentication system examines a plurá 'L'ic8fe<sup>xican</sup>
0Θ te Property of "arbitrarily defined" conditions on data object 112 "before the authentication system allows data object 112 to be connected to a set data object" such as one of similar data objects 118. In a "Embodiment of the Invention" the authentication system examines the list of identifications 204 and each field of identifications in subcomponents 206 to verify the identity of the established data object. Once the identity of an applicant is determined 'such as one of the similar data objects
118. the authentication system determines whether the requester should be allowed to connect to data object 112.
Lastly, the export list 210 includes a procedure 418 to activate the object. This procedure 418 of activating the object is used by the system
100 animation (Figure 1) to activate the data object
112 after the animation system connects data object 112 to like data objects 118.
0 Figure 6 is a diagram illustrating the elements in a wiring data field. This wiring data field describes the content of the data field 'Λ-α - *
<img file="MX214637B_D0034.tif" />
· Institute
06 (Figure 4) for the subcomponents of alarnbr'S.'dcy ^^ & Qn® <fe te Similar property, the subcomponents of the wiring of the animad <fe<sup>£</sup>kf<sup>s</sup>fa ^ the self-wiring subcomponents. Each of the data fields 306 (Figure 4) that is associated with the wiring subcomponents describes how to interconnect two of the status subcomponents. The data field defines a listener 500, a source 502 »an add method 504» a remove method 506 »and a source indicator 508.
The listener 500 contains a listener identifier, which identifies one of the subcomponents 206 as responsible for listening for events. As a counterpart to the listener 502, the source 502 contains a source identifier that identifies one of the subcomponents 206 as responsible for sending events.
The add method 504 identifies a method in the source component »to start the listener component that receives events. The removal method 504 identifies a method in the source component that can be invoked to stop the listener subcomponent from listening for events. The source identifier identifies the address of the events »identified by the listener
500 and source 502. Additional information regarding the
<img file="MX214637B_D0035.tif" />
g¡¿. ·· Instituto JgrpuíMesficano connection subcomponents in a Java mode »<fe te Property found in JavaBeans API Specification, Version 1.01 tR & tstriafl
Sun Microsystems »pages 54-58.
Figure 7 is a block diagram illustrating an "exemplary content" data item 510 that may be contained in data field 306 of a data subcomponent. It will be noted that the data may include »by way of example» a book »a poem» an article »bank account information» a contract »a multimedia presentation» or any other type of data that the data provider wishes to protect in a safe environment.
Figure 8 is a block diagram illustrating an exemplary code item 512 that may be contained in data field 306 (Figure 4) of a code subcomponent. Each code subcomponent typically includes user-defined aggregate data types. For example »a code subcomponent can contain both data members that represent the types
0 data as the function members that perform operations on data types. In the example »as se
<img file="MX214637B_D0036.tif" />
<img file="MX214637B_D0037.tif" />
In Figure 8, the code subcomponent shows a Java class.
Instituto contiWaKicano tí® Industrial Property
Each of the status subcomponents defines the present information of one of the class subcomponents. For example, referring to Figure 8, an instance of the Java class, shown in Figure 8, may include information regarding the variable account status.
System Operation
Figure 9 is a flow chart illustrating a process of creating data object 112, shown in Figure 1. It is noted that data object 112 can be created using any known object model, such as the Java Beans, Active X, LiveConnect and OpenDoc, or the System Object Model (SOM), or any object model that may be developed later. In one embodiment of the invention, the data object 112 is created on the computer.
106 from the server by means of an object wrapper
0 data {not shown). In this mode, each of the states shown in Figure 9 corresponds to a public method of the data object packer. A provider of
<img file="MX214637B_D0038.tif" />
Institute data objects, you want to create a data object. ,, jnifoc ^. ® <5 © te Property each of the object's public packer methods ^ Hfe *<sup>S</sup>^^ data in succession, to create the data object. It will be noted that, in one embodiment of the invention, the data object 112 is created by the animation system 100.
Starting from state 604, the content provider wants to distribute some type of information to others. For example, the information may include a book, a poem, an article, a bank account information, a contract, a multimedia presentation, video, music, a universal resource identifier to dynamic content, such as streaming media. or any other type of data that the data content provider wishes to protect in a secure environment.
In state 604, a digital object identifier 200, which uniquely identifies data object 112, is added to this data object 112. In one embodiment of the invention, the identifier of the data object is provided by animation system 100. In another embodiment of the invention, the identifier of the data object is acquired from a third party.
<img file="MX214637B_D0039.tif" />
Industry?
Continuing to state 608, the address information (Figure 3) is entered into data object 112 (Figure 1). The address information 205 may include the name of the provider of the data object 112, the name of the data object, and / or any other information that the provider of the data object 112 wishes to include about the data object 112.
Next, in state 612, the subcomponents
06 (Figure 3) are added to data object 112. The sub-components include: the animator wiring sub-components, the auto-wiring sub-components, the pair-wiring sub-components, the data sub-components, and the code sub-components. The purpose of each of the above subcomponents is described below with reference to Figure 4.
Moving to state 614, the peer list structures that collectively comprise the list
04 pairs (Figure 3), are added to data object 112 (Figure 1). Each pair list structure is named after a selected peer data object (Figure 1), a version number of the selected peer data object, and a location identifier of r * im g
jti
<img file="MX214637B_D0040.tif" />
Institute where the selected similar data object can be
Cfe te Property located, if this selected similar data object can be found on client computer 102 (Figure 1}.
Continuing to state 618, each of the subcomponents 206 (Figure 3) is digitally signed by one or more signers. Each of the digital signatures can be created through the use of an arbitrary function and a private signature function that encrypts the arbitrary function of the data object, which uses a private key.
Next, in a state 622, the data object 112 is digitally signed by one or more signers. Data object 112 can be signed by the same process that is used to sign each subcomponent, as described above with reference to state 622. In one embodiment of the invention, a Security Demand of
Certified by RSA Data Security, of San Mateo, CA, for the signing process.
Finally, in a state 626, object 112 of
0 Data is stored on a data storage device, such as a disk. In one embodiment of the invention, the data object 112 is placed in series using the
<img file="MX214637B_D0041.tif" />
Java and stored as a JAR file. In another fashion of the invention, the data object 112 is stored as an ASCII text file.
Figure 10 is a flow chart illustrating a process of integrating data object 112 {Figure 1) with like data objects 118 (Figure 1}. Starting from state 700, client computer 102 (Figure 1) receives the data object 112 from a data object provider. This data object provider can be, for example, the database 104, the server computer 110 or the removable storage medium 110, as shown in FIG. 1.
In one embodiment of the invention, the animation system 100 (Figure 1) is automatically notified of the presence of the data object 112 by the operating system (not shown) on the customer's computer 102, after the data object 112 it is received by the client's computer 102. In this mode, the operating system is configured to examine the information 205
0 address (Figure 3) in data object 12, for j<sub>etherm</sub>£<sub>nar</sub> data object handler. Also, in this mode, the address information 205 of animation system 100 as its manipulator.
<img file="MX214637B_D0042.tif" />
Wft
<img file="MX214637B_D0043.tif" />
Institute
Mgjpcano 'property fnckistricri
It will be noted that once the data object 112 is received by the client computer 102 (FIG. 1), the data object 112 is in a state not usable by the like data objects 118. Before data object 112 can be connected to like data objects 118, the identity of each like data object 118 will be established. Also, the animation system
100 you need to determine whether similar data objects
118 They are authorized to communicate with the data object 112.
Next, in a state 704 (Figure 10), the animation system 100 (Figure 1) authenticates the data object to ensure that the data object 112 has not been improperly altered, or otherwise violated. . Animation system 100 examines each of the signatures in signature list 204 (Figure 3), using a public key that can be obtained from the data object provider 112. In addition, the animation system 100 can be used to obtain the signature certifier procedure 406 (Figure 5) to analyze one or more
<img file="MX214637B_D0044.tif" />
digital certificate, data.
¿¡Ti, · · Institute associated with the object ^ TLÍ 2 Mé & CCino <feta Industrial property
Moving to state 708 (Figure 10), the system
100 Animation (Figure 1) uses procedure 412 to obtain the peer list (Figure 5), which obtains this peer list 202 (Figure 3). Continuing to state
712 (FIG. 10), animation system 100 determines whether all required peer data objects 118 that are identified by peer list 202 are present on client computer 102. If all of the like data objects 118 are not present, the animation system 100 proceeds to a state 714. In state 714, the animation system 100 retrieves any of the like data objects 118 not present. As discussed above, each of the peer list structures in this list 202 includes a location identifier, which identifies where each of the missing peer data objects 118 can be found. For example, the location identifier may refer to database 104 (Figure 1), the server computer
106 (Figure 1), removable storage media 110
<img file="MX214637B_D0045.tif" />
(Figure 1) or from some other depository of the oh data.
étb ^^ year © Industrial Property
If the animation system 100 (Figure 1) cannot retrieve any of the missing similar data objects 118 »the animation system 100 stops and does not allow any action regarding the use of the data objects 112 (Figure 1) . However »if the system
100 can retrieve the missing data objects, this animation system 100 proceeds to the state
716.
From any decision state 712 or from state 714 "the animation system 100 (FIG. 1) proceeds to state 716. In state 716" the animation system 100 animates each like data object 118 (FIG. 1). To animate like data objects 118 »the animation system 100 performs each of the states 700-730 (Figure
10) in connection with each like data object 118.
By executing the animation process on each of the like data objects 118 118, the animation system 100 ensures that the like data objects 118 are not inappropriately altered or otherwise violated.
<img file="MX214637B_D0046.tif" />
LOJJ
Institute state 720 (Figure (Figure 1) wire object state 720. System 100 of
Next, in animation system 100 data 112 to itself. In animation connects selected subcomponents 206 of data object 112 to animation system 100. In one mode. of the invention, animation system 100 includes a connection data object (not shown), similar in format to data object 112, for communication with this data object 112.
In state 720, the animation system 100 reads the data in the wiring data field 306 of each subcomponent 206, as shown in Figure 6, that is, the listener field 500, the source field 502, the field
504 of the add method, field 506 of the remove method, and field 508 of the source indicator, to determine the appropriate connections for the data object
112. Additional information regarding the connection of subcomponents can be found in the JavaBeans API
Specification, Version 1.01, published by Sun Microsystems, pages 54-58.
As part of the animator wiring process, the animation system 100 (Figure 1) invokes the
<img file="MX214637B_D0047.tif" />
Institute procedure 414 to obtain authentication (Figuraos) ^ (βκίοαηο <fe ta Property associates with data object 112 »to retrieve felíustrtol authentication system (not shown) for data object 112. As discussed before» the system authentication can reside in one or more sites, including »the object
112 data "the animation system 100" or one of the similar data objects. The authentication system verifies the animation system 100 if a given connection must be made.
Continuing to state 722 »the animation system 100 (Figure 1) interconnects the subcomponents 206 in the data object 112» Similar to the animator wiring process »in the auto-wiring process» the animation system 100 examines the field of data wiring in each of the auto-wiring subcomponents to determine how the data object 112 will be constructed. In identifying the like wiring subcomponent "the animation system 100 examines the contents of the pair wiring component" to determine the appropriate connections.
Similar to the animation wiring process "in the self-wiring process" the animation system 100 (Figure 1) queries the authentication system for ~ - "¡Ή
<img file="MX214637B_D0048.tif" />
'Institute determine whether a connection should be made. For example »jy | g ^ j<sub>DC</sub>|<sub>do not</sub> (fetus Property data object 112 may contain a wired au | rfj {üstitQÍI subcomponent indicating that a first subcomponent should be connected to a second subcomponent. However, the authentication system can only allow the connection as long as the object provider data is kept in a virtual account »which is maintained by the authentication system.
Moving to state 726 »the animation system 100 (Figure 1) will execute the pair wiring. ' Animation system 100 searches subcomponents 206 to find wiring subcomponents in pairs. In the "pair wiring" process the animation system 100 uses the information in the wiring data field to connect the subcomponents 206 that are identified by the wiring subcomponents.
In the process of wiring pairs »the system
100 Animation (FIG. 1) determines whether data object 112 is authorized to communicate with data objects 118 in pairs. Advantageously, each of the objects
118 in pairs and the data object 112 »can define» by means of the authentication system »various restrictions
ΙψΙ, «# ·
Η
<img file="MX214637B_D0049.tif" />
til ¿αχ / Institute regarding its use. As discussed before »each objective (felá Property
<td>data includes</td><td>; procedure 414</td><td>of</td><td>get</td><td>fntittstita *</td>
<td>authentication</td><td>(Figure 5) that identifies</td><td>the</td><td>system</td><td>of</td>
<td>authentication</td><td>for the data object.</td><td>East</td><td>system</td><td>of</td>
<td>5 authentication</td><td>defines the conditions of</td><td>use</td><td>respect</td><td>to the</td>
data object.
For example "assuming data object 112 (Figure 1)" according to address information 205 (Figure 3) in data object 112, proposes to be a cartoon animation for children. However "in fact" the data object 112 has been breached with and improperly modified so that it appears to be personal information of others. In this example »since the data object 112 has changed» the animation system 100 cannot verify the signatures in the list 204 of these signatures (Figure
3) of data object 112. Also "in this example" like data objects 118 define a personal finance program (not shown). If the data object 112 attempts to access the personal finance program »the animation system 100 (Figure 1) would check with the like data objects 118 to determine if the data object 112 should be authorized to access the lyi · &.
<img file="MX214637B_D0050.tif" />
ÜJ · Institute similar data objects 118. In this case, the sTBtemWeglteano <fe the Authentication Property of similar data objects fadiísiiiai will deny the request.
Thus, if the animation system 100 (Figure 1) determines that the data object 112 (Figure 1) is not authorized to access the data objects 'similar'
118, the animation system 100 determines whether to stop or continue with a further action related to the object '
112 of data. Still referring to state 72 6, if the animation system 100 determines that authorization is allowed, the animation system 100 then determines whether like data objects 118 are authorized for access to data object 112 by having each of like data objects 118 access their associated authentication system.
For example, suppose data object 112 was created by ACME Corporation (ACME). In this example, the data object 112 includes in one of the subcomponents 206 a document that describes the corporate policies of
0 ACME. Also, in this example, the like data objects 118 define a word processing system, and one of the like data objects 118 is responsible for
<img file="MX214637B_D0051.tif" />
edit documents and other data objects <sup>!</sup>!&EU
118 is responsible for viewing the documents. One of W '<sup>01</sup>'Subcomponents 206 (Figure 3) in data object 112 can indicate that only system administrators are authorized to edit data object 112. If this data object 112 is distributed to an employee, ACME can adjust the data object 112 so that it is not authorized to connect to the like data object that is responsible for editing. In this example, the data object 112 will only be set to be authorized to communicate with viewing the data object.
Finally, in the 73 0 state, the animation system 10 0 (Figure 1) initiates the data object 112 by invoking the activated object procedure 418 (Figure 5) that is associated with the data object 112.
Animation system 100 (Figure 1) of the present invention enables dynamic connection of data components in a secure environment. Animation system 100 ensures that before data object 112 is
0 connect to one of the peer data objects 118, that peer data object has not been improperly altered. In addition, the animation system 100 of the present
<img file="MX214637B_D0052.tif" />
The invention includes a two-vi security scheme in which the data object, depending on the identity of fegustita »like data objects, authorizes these like data objects to communicate with the data object. Conversely, each of the peer data objects checks the contents of the data object. Each peer data object can depend on the identity of the data object, determining whether it allows the data objects to communicate with themselves.
The data objects of the present invention can be advantageously used to define various types of electronic business management solutions. For example, using the present invention, one of the like data objects can act as a contract handler for a managed data object. Before executing an act using the handled data object, the contract handler may require payment of a fee by the user. Optionally, the contract handler can supply a contract data object
0 that defines the terms of use of the handled data object. The data object of the contract may contain virtual currency, which is due each time another object of
QJ
<img file="MX214637B_D0053.tif" />
.¿Fc-. ·· Instituto ™ · '· Mexican data request an action from the data object ^^ l ^ fópjectaQl tntíustrtai
In addition, the contract object may place variable restrictions on the use of the handled data object, such as defining access to the handled data object for a particular time or for a particular number of uses. Variable constraints can be dependent on one or more payment plans, which can be selected by other data objects.
Similarly, for example, the data object of the present invention can be advantageously used to define a data object of a shopper. These buyer data objects can be distributed on the Internet with some virtual currency and configured to find the cheapest seller of a particular product. In this example, the buyer data object can be digitally signed by a bank, which confirms that this data object has a valid virtual currency.
Also, for example, one or more data objects may be provided to sell a particular item. In one embodiment of the invention, when the buyer data object encounters the seller data objects, the buyer data object may attempt to notify the seller.
<img file="MX214637B_D0054.tif" />
^ -. ·· Provider institute for this buyer data object. In ; M »ano tí © the Invention Modality Property, the data object of the can be configured to negotiate with the data object of the vendor. Advantageously, through the use of the signatures and certificates, the buyer data object can verify the identity of the seller data object and confirm that the seller is indeed in the business of selling the products in question. Additionally, the seller's agent can determine that the buyer's data object actually has a valid virtual currency to purchase the seller's products.
The above examples are a few applications of the present invention. The animation system of the present invention enable new and unlimited possibilities regarding new solutions in electronic commerce.
While the previous detailed description has shown, described and pointed out novel characteristics of the invention applied to various modalities, it will be understood that omissions, substitutions and changes in the shape and details of the illustrated device or process can be made by those skilled in the art, without departing from
<img file="MX214637B_D0055.tif" />
spirit of invention. The scope of the invention is indicated by the appended claims rather than by the preceding description. All changes that are within the meaning and range of equivalence of the claims "will be within their scope.
Contents8
65 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65
25 members in 15 offices
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 7173798 | United States of America | P |
Members25
| Document | Office | Kind | |
|---|---|---|---|
| CA2315212A1 | Canada | A1 | |
| WO9936854A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2322899A | Australia | A | |
| EP1047992A1 | European Patent Office (EPO) | A1 | |
| CN1287639A | China | A | |
| KR20010024853A | Republic of Korea | A | |
| JP2002509313A | Japan | A | |
| EP1047992B1 | European Patent Office (EPO) | B1 | |
| AT216095T | Austria | T | |
| ATE216095T1 | Austria | T1 | |
| DE69901231D1 | Germany | D1 | |
| RU2000115287A | Russian Federation | A | |
| DK1047992T3 | Denmark | T3 | |
| PT1047992E | Portugal | E | |
| DE69901231T2 | Germany | T2 | |
| ES2175936T3 | Spain | T3 | |
| US6510516B1 | United States of America | B1 | |
| MX214637BThis record | Mexico | B | |
| AU765747B2 | Australia | B2 | |
| CN1153140C | China | C | |
| US6802006B1 | United States of America | B1 | |
| US2005027988A1 | United States of America | A1 | |
| KR100539987B1 | Republic of Korea | B1 | |
| CA2315212C | Canada | C | |
| US7650504B2 | United States of America | B2 |
Numbers
- Application
- 9906914
Titles2
- Spanish
- SISTEMA Y METODO PARA AUTENTICAR COMPONENTES SEMEJANTES
- English
- SYSTEM AND METHOD FOR AUTHENTICATING SIMILAR COMPONENTS
Classification
- CPC, 4
- G06F21/565
- G06F11/00
- G06F21/64
- G06F2221/2115
- IPC, 5
- G06F21 00
- G06F1 00
- G06F21 12
- G06F21 33
- G06F21 44