Method of managing role-based digital rights in a computer system.
Abstract
A computer system manages role-based digital rights by creating a chain of trust that originates with a user who intends to act as a registration authority whose status can be verified to verify that the user is licensed to act as the authority register. The registration authority creates an organization account and a first member whose status is verified by consulting a status verification server. The derived authorities granted to members are based on the first member and, ultimately, on the registration authority to ensure that there is a chain of trust linking each member of an organization to the registration authority.

Term
6.8 yearsleft in the term
Expires 17 July 2033.
- Priority
- Filed
- Granted
- Today
- Expires
15 claims: 7 independent, 8 dependent
- 1A computer-implemented method of role-based digital rights management in a computer system, the method comprises:1. Un método implementado por computadora de gestión de derechos digitales basados en roles en un sistema de cómputo, el método comprende: verificar un estado legal de un primer usuario que pretende actuar como una. autoridad de registro al enviar una solicitud de verificación de estado a un servidor de organismo licenciante que almacena información de estado relacionada con el estado legal del primer usuario para comprobar que el primer usuario tiene licencia para actuar como la autoridad de registro;verify a legal status of a first user who intends to act as one. registration authority by sending a status check request to a licensing agency server that stores status information related to the legal status of the first user to verify that the first user is licensed to act as the registration authority;verificar un estado legal de una organización que tiene una estructura jerárquica de roles al enviar una solicitud de verificación de estado a un servidor de verificación de estado que almacena información relacionada con el estado legal de la organización verificada por la autoridad de registro o por cualquier otra autoridad derivada de autoridad de registro de una autoridad de registro original;verify a legal status of an organization that has a hierarchical role structure by submitting a status check request to a status check server that stores information related to the legal status of the organization verified by the registration authority or any other authority derived from registration authority from original registration authority;if the legal situations of the first user and the organization are verified, allow user input from the registration authority to create an account for the organization within a document interaction and transaction management application that enables si las situaciones jurídicas del primer usuario y de la organización son verificadas, permitir entradas de usuario de la autoridad de registro para crear una cuenta para la organización dentro de una aplicación de gestión de transacciones e interacción de documentos que permite la interacción con documentos electrónicos almacenados de interaction with stored electronic documents I Μ π ' I Μ π ' Λ J. ' .λ .· ΙΜΤ.η,ΤΟ Λ J. '.λ. · ΙΜΤ.η, ΤΟ DE LA «ορ,-εολιί IND' ISTKIAL manera segura en una bóveda virtual y realizar transacciones electrónicas para la organización;OF THE «ορ, -εολιί IND 'ISTKIAL way securely in a virtual vault and carry out electronic transactions for the organization;verificar un estado legal de un primer miembro de la organización al enviar una solicitud de verificación de estado al servidor de verificación de estado, el primer miembro habiendo sido verificado por la autoridad de registro o por cualquier otra autoridad derivada de autoridad de registro de la autoridad de registro original, en donde la autoridad de registro también verifica que el primer miembro tenga capacidad legal para actuar en el primer rol;y si se verifica el estado legal del primer miembro, permitir entradas de usuario de la autoridad de registro para definir un primer rol dentro de la organización para el primer miembro, el primer rol confiriendo una primera autoridad para actuar en representación de la organización, en donde la primera autoridad del primer miembro se basa en la autoridad de registro. verify a legal status of a first member of the organization by submitting a request for status verification to the status verification server, the first member having been verified by the registration authority or by any other authority derived from the registration authority of the authority original registration, where the registration authority also verifies that the first member has legal capacity to act in the first role;and if the legal status of the first member is verified, allow user input from the registration authority to define a first role within the organization for the first member, the first role conferring a first authority to act on behalf of the organization, in where the first authority of the first member is based on the authority of record.
- 3The method according to claim 3. El método de conformidad con la reivindicación 2, comprising:2, que comprende: receive user input from the second member to perform a restricted action in the application;recibir entradas de usuario del segundo miembro para llevar a cabo una acción restringida en la aplicación;verificar que el segundo miembro tenga la autoridad necesaria para llevar a cabo la acción restringida;y realizar la acción restringida en la aplicación sólo si el segundo miembro tiene la autoridad necesaria. verify that the second member has the necessary authority to carry out the restricted action;and perform the restricted action on the app only if the second member has the necessary authority.
- 4El método de conformidad con la reivindicación Four. The method according to claim 1, comprising assigning a plurality of first roles to a plurality of first members, the first members being governed by a reconfigurable majority rule control scheme. 1, que comprende asignar una pluralidad de primeros roles a una pluralidad de primeros miembros, los primeros miembros se rigen por un esquema de control de regla de mayoría reconfigurable.
- 5A computer-readable medium that comprises a digital rights management method, said method characterized in that when it is executed by a processor of 5. Un medio legible por computadora que comprende un método de gestión de derechos digitales, dicho método caracterizado porque cuando se ejecuta por un procesador de DE LA i» OF THE i » ÍNBOSTRIAL el dispositivo de dicho método:ÍNBOSTRIAL the device of this method: a first user a computing device, causes computation to perform the following steps of verifying a legal status of which it intends to act as a registration authority by sending a status verification request to a licensing body server that stores status information related to the legal status of the first user to verify that the first user is licensed to act as the registration authority;un primer usuario un dispositivo de cómputo, provoca que cómputo ejecute las siguientes etapas de verificar un estado legal de que pretende actuar como una autoridad de registro al enviar una solicitud de verificación de estado a un servidor de organismo licenciante que almacena información de estado relacionada con el estado legal del primer usuario para comprobar que el primer usuario tiene licencia para actuar como la autoridad de registro;verificar un estado legal de una organización que tiene una estructura jerárquica de roles al enviar una solicitud de verificación de estado a un servidor de verificación de estado que almacena información relacionada con el estado legal de la organización verificada por la autoridad de registro o por cualquier otra autoridad derivada de autoridad de registro de una autoridad de registro original;verify a legal status of an organization that has a hierarchical role structure by submitting a status check request to a status check server that stores information related to the legal status of the organization verified by the registration authority or any other authority derived from registration authority from original registration authority;if the legal situations of the first user and the organization are verified, allow user inputs from the registration authority to create an account for the organization within a document interaction and transaction management application that allows interaction with electronic documents stored securely in a virtual vault and conduct electronic transactions for the organization;si las situaciones jurídicas del primer usuario y de la organización son verificadas, permitir las entradas de usuario de la autoridad de registro para crear una cuenta para la organización dentro de una aplicación de gestión de transacciones e interacción de documentos que permite la interacción con documentos electrónicos almacenados de manera segura en una bóveda virtual y realizar transacciones electrónicas para la organización;verificar un estado legal de un primer miembro de verify a legal status of a first member of I P1 I P1 -A. A, - w*. Λ -TO. A, - w *.Λ INJTITüro MEXICANO MEXICAN INJTITüro De LA rRCIMEDAIi INDUSTRIAL la organización al enviar una solicitud de verificación de estado al servidor de verificación de estado, el primer miembro habiendo sido verificado por la autoridad de registro o por cualquier otra autoridad derivada de autoridad de registro de la autoridad de registro original, en donde la autoridad de registro también verifica que el primer miembro tenga capacidad legal para actuar en el primer rol;y si se verifica el estado legal del primer miembro, permitir las entradas de usuario de la autoridad de registro para definir un primer rol dentro de la organización para el primer miembro, el primer rol confiriendo una primera autoridad para actuar en representación de la organización, en donde la primera autoridad del primer miembro se basa en la autoridad de registro. From LA rRCIMEDAIi INDUSTRIAL the organization when sending a request for status verification to the status verification server, the first member having been verified by the registration authority or by any other authority derived from the registration authority of the original registration authority, in where the registration authority also verifies that the first member has legal capacity to act in the first role;and if the legal status of the first member is verified, allow the registration authority user inputs to define a first role within the organization for the first member, the first role conferring a first authority to act on behalf of the organization, where the first authority of the first member is based on the authority of record.
- 89. A computer system for role-based digital rights management, the system comprises:9. Un sistema de cómputo para la gestión de derechos digitales basados en roles, el sistema comprende: an application server having a processor operably coupled to memory to run a transaction management application and un servidor de aplicaciones que tiene un procesador operativamente acoplado a una memoria para ejecutar una aplicación de gestión de transacciones e INSTITUTE MtXiCA ^ '? INSTITUTO MtXiCA^’ ? I heard La íRGf * í-í> Al) Oí La íRGf*í-í>Al) INDl ^ TtlAL document interaction that allows interaction with electronic documents safely stored in a virtual vault and conducting electronic transactions for an organization;INDl^TtlAL interacción de documentos que permite la interacción con documentos electrónicos almacenados de manera segura en una bóveda virtual y realizar transacciones electrónicas para una organización;a licensing body server to verify a legal status of a first user that intends to act as a registration authority upon receiving a request for a status verification and for that stores status information related to the legal status of the first user to verify that the first user is licensed to act as the registration authority;un servidor de organismo licenciante para verificar un estado legal de un primer usuario que pretende actuar como una autoridad de registro al recibir una solicitud de verificación de estado y para eso almacena información de estado relacionada con el estado legal del primer usuario para comprobar que el primer usuario tiene licencia para actuar como la autoridad de registro;a status check server for storing information about organizations and members whose legal status has been verified by the registration authority or any other authority derived from the registration authority of an original registration authority, wherein the registration authority also verifies that the first member has legal capacity to act in the first role;un servidor de verificación de estado para almacenar información sobre organizaciones y miembros cuyo estado legal ha sido verificado por la autoridad de registro o cualquier otra autoridad derivada de autoridad de registro de una autoridad de registro original, en donde la autoridad de registro también verifica que el primer miembro tenga capacidad legal para actuar en el primer rol;en donde la aplicación que se ejecuta en el servidor de aplicaciones está programada para: where the application running on the application server is programmed to: enviar una solicitud de verificación de estado al servidor de organismo licenciante para verificar el estado de la autoridad de registro;submitting a status check request to the licensing body server to check the status of the registration authority;IMPI IMPI INSTITUTO MtXlCAN... MtXlCAN INSTITUTE ... L'c LA L’c LA INCUS TÜAI. INCUS TÜAI. enviar una solicitud de vprÍfÍracinn rU ai servidor de verificación de estado para verificar el estado de una organización;send a vprÍfÍracin request to the health check server to check the status of an organization;if the legal status of the first user and the organization are verified, allow user input from the registration authority to create an account for the organization within the application;si se verifican el estado legal del primer usuario y de la organización, permitir entradas de usuario de la autoridad de registro para crear una cuenta para la organización dentro de la solicitud;enviar una solicitud de verificación de estado al servidor de verificación de estado para verificar el estado de un primer miembro de la organización;y si se verifica el estado legal del primer miembro, permitir entradas de usuario para definir un primer rol dentro de la organización para el primer miembro, el primer rol confiriendo una primera autoridad para actuar en representación de la organización, en donde la primera autoridad del primer miembro se basa en la autoridad de registro. ’ sending a status check request to the status check server to verify the status of a first member of the organization;and if the legal status of the first member is verified, allow user inputs to define a first role within the organization for the first member, the first role conferring a first authority to act on behalf of the organization, where the first authority of the first member is based on registration authority. '
- 1213. A computer-implemented method of role-based digital rights management in a computer system, the method comprises:13. Un método implementado por computadora de gestión de derechos digitales basados en roles en un sistema de cómputo, el método comprende: verificar un estado legal de una autoridad de registro al enviar una solicitud de verificación de estado verify a legal status of a registration authority by submitting a status verification request IM r i IM ri INSTITUTO MEXICan- ) r^iíeWgL^ INSTITUTO MEXICan-) r ^ iíeWgL ^ D>. LA PFOPItiíAJ D>. THE PFOPItiíAJ INDI ST »| AL TMTTg to a licensing body status verification system to verify that the registration authority is licensed to act as the registration authority;INDI ¡ST»| AL TMTTg a un sistema de verificación de estado de organismo licenciante para comprobar que la autoridad de registro tiene licencia para actuar como la autoridad de registro;verificar un estado legal de una entidad al enviar una solicitud de verificación de estado a un sistema de verificación de estado de entidad que almacena información de estado relacionada con el estado legal de la entidad verificada por la autoridad de registro o por cualquier otra autoridad derivada de autoridad de registro de una autoridad de registro original;verify a legal status of an entity by submitting a status verification request to an entity status verification system that stores status information related to the legal status of the entity verified by the registration authority or any other authority derived from registration authority of an original registration authority;if the legal status of the entity is verified, allow user input from the registration authority to create an account for the entity within a document interaction and transaction management application that enables interaction with electronic documents stored securely in a virtual vault and carry out electronic transactions for the entity;si el estado legal de la entidad se verifica, permitir entradas de usuario de la autoridad de registro para crear una cuenta para la entidad dentro de una aplicación de gestión de transacciones e interacción de documentos que permite la interacción con documentos electrónicos almacenados de manera segura en una bóveda virtual y realizar transacciones electrónicas para la entidad;verificar un estado legal de un primer miembro asociado con la entidad al enviar una solicitud de verificación de estado al sistema de verificación de estado, el primer miembro habiendo sido verificado por la autoridad de registro o por cualquier otra autoridad derivada de autoridad de registro de la autoridad de registro original, en donde la autoridad de registro verify a legal status of a first member associated with the entity by submitting a status verification request to the status verification system, the first member having been verified by the registration authority or by any other authority derived from the registration authority of the entity original registration authority, where the registration authority 74 IMPI 74 IMPI ΙΜ'ΤίηΠι, MtXJCANl> DE LA PROMIUAD industrial also verifies that the first member___has__ legal capacity to act on behalf of the entity;and if the legal status of the first member is verified, allow user input from the authority of ΙΜ’ΤίηΠι, MtXJCANl > DE LA PROMIUAD industrial también verifica que el primer miembro___tenga__capacidad legal para actuar en representación de la entidad;y si se verifica el estado legal del primer miembro, permitir entradas de usuario de la autoridad de 5 registry to define a first role with respect to the entity for the first member, the first role conferring a first authority to act on behalf of the entity, where the first authority of the first member is based on the authority of record. 5 registro para definir un primer rol con respecto a la entidad para el primer miembro, el primer rol confiriendo una primera autoridad para actuar en representación de la entidad, en donde la primera autoridad del primer miembro se basa en la autoridad de registro. 10 10
- 1314. a computer-implemented method of conferring legal authority to avatars representing users within a computer-generated virtual world in which users interact with each other through their respective avatars, the method comprises:14. un método implementado por computadora para conferir autoridad legal a avatares que representan usuarios dentro de un mundo virtual generado por computadora en el que los usuarios interactúan entre sí mediante sus respectivos avatares, el método comprende: 15 verificar un estado legal de una autoridad de registro al enviar una solicitud de verificación de estado a un sistema de verificación de estado de organismo licenciante para comprobar que la autoridad' de registro tiene licencia para actuar como la autoridad de registro;fifteen verifying a legal status of a registration authority by submitting a status verification request to a licensing body status verification system to verify that the registration authority is licensed to act as the registration authority;20 verificar un estado y capacidad de un usuario que pretende volverse un miembro del mundo virtual al enviar una solicitud de verificación de estado a un sistema de verificación de estado que almacena información de estado relacionada con el estado legal del usuario y la capacidad twenty verify a status and ability of a user who intends to become a member of the virtual world by submitting a status check request to a status check system that stores status information related to the user's legal status and ability 25 legal to become a member of the virtual world, where 25 legal para volverse un miembro del mundo virtual, en donde INSTITUTO MfeXICAN: 'ÍH LA Pk (' f'K> Aí INTUISTRI Al INSTITUTO MfeXICAN: ’ ÍH LA Pk( ’f'K >Aí INTUISTRI Al el estado legal y la capacidad legal han sido verificadas por la autoridad de registro o porque cualquier otra autoridad derivada de autoridad de registro de una autoridad de registro original;y si se verifica el estado del usuario, permitir entradas de usuario de la autoridad de registro para crear una cuenta para el miembro dentro del mundo virtual, la cuenta vincula al miembro con un avatar único, en donde la autoridad del avatar en el mundo virtual se basa en la autoridad de registro. the legal status and legal capacity have been verified by the registration authority or because any other authority derived from the registration authority of an original registration authority;and if the user's status is verified, allow user input from the registration authority to create an account for the member within the virtual world, the account links the member with a unique avatar, where the avatar authority in the virtual world it is based on the registration authority.
Independent claims7
224 paragraphs in 11 sections, as filed
Role-based access control (RBAC) is a technique for controlling access to a computer system or network. In an organization's computer system, each user is assigned a role or function (hereinafter the role). User access rights or permissions to perform tasks in the computer system are assigned to roles. In this way, RBAC provides a framework for assigning user access rights and permissions based on roles and not based directly on the identity of the Users themselves.
In a conventional RBAC implementation, however, there is no correlation between an assigned role in the computer system and an authority bequeathed é ^ írSft ^ o
<img file="MX347104B_D0001.tif" />
real to perform an action in raps ementa g organization. A user can occupy a role X that allows him to electronically perform a task Y in the computer system, but there is nothing in a conventional RBAC implementation that guarantees that the performance of task Y by the User in role X is actually authorized and / or that has any legal effect.
While electronic signatures can provide cryptographically identification and non-repudiation mechanisms, it is impossible to determine that an electronic signature, or other electronic transaction or digital action performed by a user occupying a particular role is actually legally authorized. The legal authority of the user occupying a particular role has to date been overlooked by RBAC systems.
This problem has implications not only in terms of internal corporate control, but also in the field of electronic commerce, especially in an international electronic commerce transaction between distant organizations in which a user of a first organization may not be able to easily determine what another user from a second organization
<img file="MX347104B_D0002.tif" />
it really has the authority to bind the second organization.
An e-commerce solution for role-based authorization was disclosed in US Patent Application Publication No. 2001/0021928 (Ludwig et al.) Entitled Method For Inter-Company Role-Based Authorization that uses role certificates to enable a user from a first organization authenticates another user from a second organization. However, this technology is not intended to link a role with a real world legal authority to act on behalf of an organization.
Such a solution is disclosed in the present description and in the attached drawings.
BRIEF DESCRIPTION OF THE DRAWINGS
Other features and advantages of the present technology will be apparent from the following detailed description, taken in conjunction with the accompanying drawings, in which:
Figure 1 is a schematic representation of a computer system for role-based digital rights management according to embodiments of the present invention;
IΜ Ρ ϊ
: .Λ:. ΛΟίύΛΰ
Figure 2 is a flowchart '^ W d ^ btneS' the main steps of a role-based digital Cte ”deiwh ©» ™ management method;
Figure 3 is a flow chart outlining the main steps of an electronic commerce method;
Figure 4 is an example of a Registration Authority Verification (RA) page;
Figure 5 is an example of a subsequent RA verification page;
Figure 6 is an example of an RA checklist;
Figure 7 is an example of a role management screen that the RA uses to assign a role to a user;
Figure 8 is an example of an e-commerce transaction dashboard;
Figure 9 is a schematic representation of a computer system for conferring legal authority to avatars representing users within a computer generated virtual world; Y
Figure 10 is a flow chart depicting the steps of a method for conferring legal authority to avatars representing users within a computer generated virtual world.
It should be noted that throughout <sup>| N</sup>
IAL d 'attachments, the characteristics equal nrtán.
by like reference numbers.
SHORT DESCRIPTION
Generally speaking, the present invention provides a novel computer system, computer-implemented method, and computer-readable medium for managing role-based digital rights. The modalities of the present invention implement an innovative paradigm for the definition of roles in the computer system that depend directly or indirectly on a registration authority to which a licensing body has granted a license to verify the identity of any legal entity such as an organization or person. For the purposes of this description, the term "check" shall be understood to describe the information verification process that allows the registration authority to check the legal status of an entity or the identity of a person. Furthermore, the present description will use the term verify in a broad sense to encompass the concept of verification. The paradigm ensures that each registered user of the system has been duly verified by a registration authority. Then the β
<img file="MX347104B_D0003.tif" />
Registration authority can assign roles to users that grant rights or permissions to perform certain actions in the system. Any action by the user within the system is presumed to be legally valid as the User's authority is ultimately derived from the registration authority. This creates a chain of trust from a registration authority to a verified system user. Due to the chain of trust, other users of the system may assume that the actions of a particular user are valid and required of them.
This chain-of-trust paradigm transposes into a digital platform the real-world process of verifying the identity of each user and verifying that the User's role confers appropriate authority to take certain actions. This technology greatly facilitates actions that are internal to the organization (for example, resolutions, shareholder votes, or other internal control processes) and also actions that are external to the organization (for example, tenders, acquisitions, contracting). This technology also greatly facilitates transactions in a virtual world.
With this in mind, there are a number of aspects of the present invention that will be described.
IΜ Ρ<sup>7</sup>' Institute;
OF LA PROpJclmD ·
One aspect of the present <sup>IN</sup>lWS-ncrettí-e ^ a method implemented by computer · ^ do management — da. digital rights based on a computer system. The method involves (i) verifying the legal status of a first User trying to act as a registration authority by sending a status verification request to a licensing body that stores the status information about the legal status of the first user to verify that the first user is authorized to act as the registration authority; (ii) verify a legal status of an organization that has a hierarchical role structure by sending a status check request to a status check server that stores status information about the legal status of the organization verified by the authority registration or by any other authority derived from the registration authority of an original registration authority; (iii) receive user input from the registration authority to create an account for the organization within a document interaction and transaction management application that enables interaction with electronic documents stored securely in a virtual vault and electronic transactions that are carried out for the organization; (iv) verify a legal status of a first member of the organization by means of the
JM p I - h
Lt ... '·. 6 ^ ΛνΛ ^ ίβ?
sending a status check request ^ s ^ L status check seSvlSor, the first mi- (i> mb.r.¡a. having — been “, verified by the registration authority or by any other authority derived from the registration authority of an original registration authority, where the registration authority also verifies that the first member has legal capacity to act in the first role ; and (v) receive user input from the registration authority to define a first role within the organization for the first member, the first role confers a first authority to act on behalf of the organization, where the first authority of the first member It is determined in the registration authority.
Another aspect of the present invention is a computer-readable medium in which instructions are stored in code that are configured to perform the steps, actions, or operations of the previous method when the computer-readable medium is loaded into memory and executed. in a processor of a computing device.
Still another aspect of the present invention is a computer system for role-based digital rights management, the system comprises (i) an application server having a processor operatively coupled to a memory to run a management application of
<img file="MX347104B_D0004.tif" />
industry) transactions and document interaction that allows interaction with electronic documents' safely stored in a virtual vault and conducting electronic transactions for the organization; (ii) a licensing body server to verify a legal status of a first User that intends to act as a registration authority upon receiving a status verification request and for this purpose stores status information related to the legal status of the first user for check that the first user is licensed to act as the registration authority; and (iii) a status check server to store status information about organizations and members whose legal status has been verified by the registration authority or any other authority derived from the registration authority of an original registration authority, where the Registration authority also verifies that the first member has a legal capacity to act in the first role. The application running on the application server is programmed to send a status check request to the licensing body server to verify the status of the registration authority, send a status check request to the status check server to verify an organization status, receive user input from
IMPI 0½¾ the registration authority to create an account for the organization within the application, send a status check request ”to the status check server to check the status of a first member of the organization, and receive a user input to define a first role within the organization for the first member, the first role confers a first authority to act on behalf of the organization, wherein the first authority of the first member is determined in the registration authority.
The invention can also be used to facilitate electronic commerce between two organizations using the document interaction and transaction management application as a common platform. The application intervenes in the transaction to ensure that the members of each organization have the authority to bind their respective organizations.
Consequently, one aspect of the present invention is a computerized method of electronic commerce between a first organization and a second organization, each with a hierarchical structure of roles defined within a common electronic commerce and document interaction application hosted in an environment. of distributed computing, where the roles confer different authorities to carry out transactions on behalf of
<img file="MX347104B_D0005.tif" />
respective organizations. The method comprises receiving 'user input from a bidding member of the first organization requesting that the document interaction and transaction management application generate an electronic contract document representing an offer to enter into a contract, the application verifying that the member bidder from the first organization occupies a role that has the authority to contractually bind the first organization with respect to the contract, the role has been defined by a first member whose status has been verified by a registration authority, where the registration authority also verifies that the first member has legal capacity to act in the first role. The method then involves generating the electronic contract document and allowing the first member to sign the document electronically only if the bidding member has the authority to contractually bind the first organization with respect to the contract. The method then involves receiving user input that identifies an accepting member who is to receive the electronic document at the second organization. The method includes verifying through the application that the accepting member occupies a role that confers authority to accept the offer on behalf of the second organization, the role being defined by a
MUv. » UAL second member whose status has been verified by a
<img file="MX347104B_D0006.tif" />
registration authority. Finally, the method includes transmitting the electronic contract document from the bidding member of the first organization to the accepting member of the second organization if the accepting member has the authority to accept the offer, receiving user inputs from the accepting member of the second organization to sign electronically the document to accept the offer, and transmit an electronic acceptance of the contract to the offering member of the first organization.
Another aspect of the present invention is a computer-readable medium in which instructions are stored in code that are configured to perform the steps, actions or operations of the previous method when the computer-readable medium is loaded into memory and executed in a processor of a computing device.
Another aspect is a computer system for electronic commerce, the system includes an application server with a processor coupled to a memory to execute instructions in code of a transaction management and document interaction application to facilitate electronic commerce between a first organization. and a second organization each with a hierarchical structure of roles that confer different
IΚ4 Ρ Τ and authorities to carry out transactions in the authorities of the respective organizations. The- s rai<sup>1</sup> we 1¾ye '»first computing device to receive user input from a bidding member of the first organization requesting that the application generate an electronic contract document representing an offer to enter into a contract. The application is programmed to verify that the bidding member of the first organization occupies a role that has the authority to contractually bind the first organization with respect to the contract, the role has been defined by a first member whose status has been verified by an authority of registry, where the registry authority also verifies that the first member has a legal capacity to act in the first role. The application is further programmed to generate the electronic contract document and allow the bidding member to sign the document electronically only if the bidding member has the authority to contractually bind the first organization with respect to the contract. The first computing device further receives user inputs that identify an accepting member who is to receive the electronic document in the second organization. The application is programmed to verify that the accepting member occupies a role that confers
IMPIOS authority to accept the offer on behalf of the second organization, the role being defined by a second ”member whose status has been verified by a registration authority. The application is then programmed to transmit the electronic contract document from the bidding member of the first organization to the accepting member of the second organization if the accepting member has the authority to accept the offer. The system includes a second computing device to receive user input from the accepting member of the second organization by electronically signing the document to accept the offer. The application is then programmed to transmit an electronic acceptance of the contract to the bidding member of the first organization.
The present invention also has applicability in virtual worlds. The present invention can be used to confer legal authority on avatars interacting in a virtual world. Yet another aspect of the present invention is a computer-implemented method of conferring legal authority to avatars representing users within a computer-generated virtual world in which users interact with each other through their respective avatars. The method comprises verifying a legal status of a registration authority by sending a status verification request to a server
ΙΜΡΙ ^^ from licensing agency to verify that<sup>VL</sup>An & nfio registry is licensed to act as the antnrity of. record; verify a status and ability of a user who intends to become a member of the virtual world by sending a status check request to a status check server that stores status information related to the user's legal status and legal ability to become a member of the virtual world, where the legal status and legal capacity have been verified by the registration authority or by any other authority derived from the registration authority of an original registration authority; and receive User input from the registration authority to create an account for the member within the virtual world, the account links the member to a unique avahar, where the avahar's authority in the virtual world is determined by the registration authority.
The thimbles and particularities of these aspects of the invention will now be described, by way of example, with reference to the accompanying drawings.
DETAILED DESCRIPTION and · X * Τ '*. T * fw μ i
In general, 'efe · invention modalities refer to a computer system, computer-implemented method, and novel computer-readable medium for managing role-based digital rights. The embodiments of the present invention implement an innovative chain-of-trust paradigm that employs registration authorities (for example, lawyers) that are licensed by a licensing body (for example, a state or provincial bar) to verify identities. of people who wish to become users of the system.
One or more original (seminal) registration authorities can create additional registration authorities by verifying the identity of each of these additional registration authorities which can, in turn, create more registration authorities. As a result, a group of registration authorities will be required for any given jurisdiction in which the system is to be installed. //
One of these registration authorities must verify the identity of a person who wishes to register as a user of the system. Only if the identity of the person has been duly verified by the registration authority can a user account be created and / or the user added to a user database as an entity
T a / i D and luj'ii i '; > 7, · Λ '/ 7;., · Κ> known. Similarly, an entity (eg a corporation) must be verified ~ (in terms of its legal status) by a registration authority before an account is created for the organization in the system. Consequently, only entities that have been verified by a registration authority can access and use the system. The platform, therefore, is restricted to entities whose identities have been formally verified by registration authorities with legal certification capacity. The user can then be assigned a role in an entity or organization. The role determines a set of rights, privileges, permissions, etc. within the document interaction and transaction management application, as explained in more detail below. As a precondition for assigning a role to a Registered User, the system verifies that the user has the right (has legal capacity) to occupy that role. This decision can be made by the RA or the system by comparing the user attributes with the legal requirements for the role.
//, Although the main application of this technology is to an organization such as a corporation that has a hierarchical set of roles within a pre-existing legal framework, the technology can also be used or adapted for digital rights management! ;; u <'1 · /, 3 with respect to any entity, where an entity3<sup>_</sup>’<sup>_</sup>§É 'éhtieñde ~ TTT general terms that encompass a legal person, trust, unincorporated association, group or any such organization, as well as a government, agency, bureau, office, department or ministry of the government. In one embodiment, the entity can also include a natural person (that is, an individual) who has the legal capacity to delegate authority to another person within a certain legal framework, for example, to grant a power of attorney. For example, a User who is a natural person Ά (who is a verified Registered User) may grant a proxy to another person User B (who is also a verified Registered User). The identities of User A and User B 7 are verified by one or more registration authorities'. The system may also, in some limited cases, verify some invariant elements of User A's legal capacity to grant the power of attorney and User B's legal capacity to accept the power of attorney. Therefore the system can provide some basic information regarding legal capacity such as age that helps to ensure that the actions taken by User B in the exercise of power are legally valid and binding on User A. The system also guarantees that a third party (User C) who interacts with User A can
<img file="MX347104B_D0007.tif" />
Of the " . ,,. ,,. , -, „. industrial X2ÍL-ÍÍ trust the authority granted to User B. This example shows how an entity can be a physical person7
SYSTEM
Figure 1 schematically illustrates a computer system in accordance with one embodiment of the present invention. This computer system has two main components: (i) an Authentication and Status Verification Server (SVS) and its associated User database whose general function is to authenticate Users and (ii) a document interaction and transaction management application whose general function is to provide authenticated Users with a software interface to interact with documents and perform electronic actions and tasks with respect to an organization of which the User is a member and has a assigned role.
As shown by way of example in Figure 1, a plurality of users who are designated by the reference numerals (10), (20), (30) communicate with the computer system over a data network, for example Internet (50), using wired or wireless digital data communication technology. For the sake of illustration, said three Users (User, User2 and User3) are illustrated by way of example in Figure 1 although the number of users may vary. Again for the sake of illustration, User2 connects to the system through the Internet (50) using a desktop computer (12), User2 connects to the system through the Internet (50) using a laptop (22) and the User3 connects to the system through a mobile device (32) communicatively connected to the Internet through a wireless network and a portal. Standard communication protocols, such as TCP / IP, HTTP, etc. they can be used to connect the system via the Internet.
The mobile device 32 can be any wireless communication device, smartphone, cell phone, wireless PDA, wireless tablet, or other portable or handheld electronic device that has wireless communication capabilities. The mobile device (32) can be wirelessly connected to the system via a wireless network (represented schematically by the base station tower (40)) using any known cellular technology or communication protocols such as, for example, GSM, EDGE, LTE, COMA , etc. Of course, other wireless technologies can be used such as, for example, Wi-Fi ™, Bluetooth®, satellite link, etc.
Τ? «Ή τ * χ ϊ» '> * {ι
-* -' <sup>;</sup>· Λ λ Jt ti ti ΐΛ λζ.ΊΓΰΛΐι ¿fA μϊαιμ.μ.
As illustrated in Figure 1, users connect to network interface servers (¿Ú) ', X! 0 / ™ “φτε ~~ 'are connected respectively via firewall {firevalls} (62), (72) to an authentication and condition verification server (SVS) (80) and to a document interaction and transaction management server (DITMS for its acronym in English) (90).
As shown in the exemplary architecture shown in Figure 1, the SVS (80) and the DITMS (90) are connected to a common ID and firewall (100) (hereinafter simply referred to as an identification server).
SVS
The SVS (80) receives and processes the authentication requests of the registered users. If the user is registered and authenticated, for example by multi-factor authentication sufficient to establish that the user is who they claim to be, access to the system is granted. The SVS (80) also stores user profile information for each registered user. In other embodiments, the authentication and verification functions can be decoupled and performed by physically different servers.
<img file="MX347104B_D0008.tif" />
inuuj i bial
The SVS (80) is consulted or questioned by the
DITMS when it is necessary to verify that the user is registered with the system and that it has an adequate status. In other words, the application of the DITM depends on the SVS to ensure that the users of the application are registered users who have been duly verified by a registration authority. The SVS guarantees that users of the DITM application are registered users who can be trusted with electronic identities.
In an application, the SVS may be replaced by an entity status verification system that stores entity status information once the entities have been duly verified by an RA.
LB-SVS
In the example shown in Figure 1, the SVS (80) is further configured to communicate with a status check server of a licensing body (84). A Licensing Body Status Check Server (LB-SVS) can be a professional organization network service or other system that stores status information from registration authorities. The LB-SVS is then consulted when it is necessary to verify that a user who is acting as a registration authority is a member with
Τ 7; Τ '<sup>-</sup>τ τ Λ '' γ <sup>U1</sup>- <sup>1</sup><sup>:</sup>'CS * ·' ^ '- * - ·' -X · '' '»good reputation of the licensing body yp / ó'b ^' bs z? Áh £ ¿'Is he legally empowered to act eiT uae-iBomontiO — deJ time as a registration authority. For example, the professional licensing body may be a state or a provincial bar that regulates and licenses lawyers. The list of attorneys who are members of a state or provincial bar is supplemented with continuously updated status information so that the system can verify that a lawyer seeking to act as a registration authority is still in good standing at that time.
DITMS
The document interaction and transaction management server (DITMS) (90) may run a document interaction and transaction management (DITM) application hosted on the DITMS (90). The DITM application offers a whole range of functionalities that allows system users to access and interact with documents in the document vault (secure virtual vault (92)). For the purposes of this description, interacting with documents should be understood in a broad sense to mean acts, actions, activities, transactions or tasks performed in relation to a document such as, but not limited to, opening, accessing, viewing, creating, editing , annotate comment highlight, delete
Ϊ '' · tr t; . J
Dt LA M'.C ^ 'rLVn INDUSTRIAL cut, copy,
<img file="MX347104B_D0009.tif" />
import, export, send emails, vote arcKTV3T7, approve, etc. Therefore, the DITM application enables the user to perform a plurality of functions on the documents and data in the secure vault.
In one example, the organization can be a corporation. Your important corporate documents such as your minute book, articles of incorporation, bylaws, resolutions, shareholders' agreements, security offerings, etc. they are stored electronically in the vault. Access to these documents by the directors of the corporation, officers, employees, external attorneys, accountants, etc. It is controlled by assigning each user a role within the corporation account in the application. Thus, the role of the manager can confer many more access rights than the role of a mere employee.
In addition to document-related interactions, the DITM application enables the user to perform and manage transactions. The transactions are intended to broadly encompass any outside business activity (for example, contracts with other organizations using the same DITM software platform, filing tax returns, filing documents for title compliance, or before any
I IM Other government or regulatory agency, etc.) or any internal activity of the organization (for example, activities related to control such as resolutions, votes, approvals, appointments, shareholder agreements, additions to the minute book, etc.), either internally within the organization or externally with another organization, or even within a virtual world.
The DITM application allows these different actions to be performed by the user who occupies a role that confers the authority to perform the action. In other words, the access rights, usage rights, permissions, and privileges granted to a given user are determined by the role assigned to the user within the organization. The role for the first member or plurality of first members is defined by the registration authority. Subsequently, the first member can create a subsidiary (second) role for a second member by exercising a derivative role creation right as long as that right has been conferred on the first member by the RA. The second member can create a third role for a third member if the second role has its own derived role creation right. As will be appreciated, any number of subsidiary roles can be created in a hierarchical chain originating with the registration authority. Each member of the chain must be a user of the ri system
ITUTO .MFXICANC DF LA PROFIFno industrial
<img file="MX347104B_D0010.tif" />
i? · A i INS11T> i 10 MüXIOÍT. m ia í'soiwm; » that has been verified by an RA. The autoi? I<sup>, l</sup>dci'd<sup>L</sup> d ^ -¾ ^ member is therefore linked to registration authority.
The DITM application may be stored and run by a single server machine (computing device) as shown by way of example in Figure 1 or, alternatively, it may be stored on and run separately by a group of servers or in a cloud computing environment. The DIMTS (90) running the DITM application may be physically distinct from the secure document vault (92) or they could be consolidated as a single machine. In other embodiments, there may be multiple servers (90) and / or multiple vaults (92), for example, to separate data by jurisdiction.
Each server (computing device) can include one or more processors (or microprocessors), memory (hard disk, solid state drive, etc.), one or more data transmission paths, communication ports, and input / output devices. .
The SVS (90) and the DITMS (90) together provide a virtual platform to authenticate users and to allow users to interact with digital documents stored in a virtual vault or perform digital transactions regarding the organization of
IΜ Ρ ί • '«• ΠΤΟΓΟΜΕΧΙΟΝν / which users are members of. The DITMS (TO /<sup>T</sup>’<sup>l</sup>dons ^^ & ^. ' to SVS to verify the status of Lili user of — íá ....> DITM application when that user is going to be assigned a role. Only if the condition check is ok, the DITMS assigns a role to the user. In most embodiments, the DITMS and / or the SVS communicate directly or indirectly with the LB-SVS to verify a status of an RA when the RA performs an operation in the DITM application.
System Interaction and Operation
Before accessing the system, each user must become a registered user of the system. As noted above, a person who intends to become a registered user of the system must be verified by a registration authority, for example an attorney in good standing with their state or provincial bar. After the person has been duly verified by a registration authority in the manner prescribed by law, the registration authority may create a user account for the user to access the system. The user account, which can contain user profile information and optionally any cryptographic material assigned to the user, can be stored in the status verification server (SVS) (80) or its database of
11Λ r: [
INSTITUTE MOT.Srl, K
Uf THE associated user (82). In one embodiment, cryptographic eT ^ mateTi ^ T may include the credentials e ~ pé'd 1ΓiCddas' “~ · by the user known only to the user.
As part of the user account creation process for the recently verified user, a status verification request is sent to the LB-SVS (84) to verify that the registration authority is a member in good standing with the licensing body and that has full and complete ability to verify and confirm the identity of the new user. The continuously updated status of each registration authority is thus stored in one of a plurality of licensing agency status check servers (generally one per jurisdiction) that can be queried in real time via a network interface to verify that the registration authority registry still has legal capacity to act as a registry authority, for example, that the lawyer has not been expelled, suspended or who has not otherwise lost his license to practice.
The registration authority thus adds the user to the user database (82) of users who have been duly verified by a registration authority. Similarly, an organization such as a corporation, limited partnership, trust, etc., can be verified by a registration authority and added to the database.
I ivi sf 1 muican- institute, data (82). The database (82) can store any entity, whether it is a corporation, a natural person, etc. Each Registration Authority (RA) must have within its jurisdiction the legal capacity to verify the identity of an entity such as an organization (eg a corporation, limited partnership, trust, etc.) or a natural person. Once verified by an RA, an account or profile for the organization or person can be created in a database (82) associated with the SVS (80). A cryptographic key, certificate, or token can be associated with the user account or the organization account. In this way, the SVS maintains a database of verified entities (organizations and users) that have been duly verified by a registration authority and are therefore unique in the system. The user profile or account may contain information, data or parameters that indicate the legal capacity of the user to assume various roles. The RA will then be able to assign a role to the registered user after ensuring that the user has full legal capacity to act. The RA then grants authority to the user by assigning the role to the user. This grant of authority from the RA to the first member can only be made if the first member is verified and has legal capacity to act instituto Mf, xtcA'4> US LA wow-w in the role. This is the first link in l & ^ '^ i'ádenft- ^ ér trust.
To summarize, the computer system includes an application server (DITMS (90)) having a processor operably coupled to memory for executing a document interaction and transaction management (DITM) application. This application allows interaction with electronic documents stored safely in a virtual vault (92) and carry out electronic transactions for the organization.
The system includes a licensing body server (LB-SVS (84)) to verify a legal status of a first user who intends to act as a registration authority. The LB-SVS receives a status check request from the SVS or the DITMS. The LB-SVS stores the status information related to the legal status of the registration authorities. Therefore, the LB-SVS acts to verify that the first user who claims to be a registration authority is currently licensed in that jurisdiction to act as the registration authority.
The status check server (SVS (80)) stores status information about organizations and members whose legal status has been verified by the registration authority or any other derived authority “----- Τ Μ F - 1. .1 . <> Α
MEXICAN INSTITUTE of registration authority of an authority HA <{¡fé<sup>3</sup>^ original. - ..................
The DITM application running on the DITMS (90) is programmed to (1) send a status check request to the LB-SVS (84) to check the status of the registration authority; (2) send a status check request to the SVS (80) to check the status of an organization; (3) receive user input from the registration authority to create an account for the organization within the application hosted on the DITMS (90); (4) send a status verification request to the SVS (80) to verify the status of a first member of the organization and (5) receive user input in the DITMS (90) to define a first role within the organization to the first member. The first role confers a first authority to act on behalf of the organization. Thus, the first authority is based on the registration authority. In embodiments of the invention, the registration authority also verifies that the first member has Illegal capacity to act in the first role. This ensures that the first member has the right to fill the first role, unlike conventional RBAC systems that do not take into consideration the legal capacity of a user to fill a particular role. By verifying the legal capacity of a user to
Τ 7 ·. In order to act in a certain role, does the system impose a real legal framework on the users of the system? Thus, the syBLum —— can act as an auditing mechanism that can be used to demonstrate ex post facto that users acted in accordance with legal requirements at the time a certain act was carried out in the system.
The document interaction and transaction management (DITM) application thus provides a virtual platform to interact with digital documents of an organization that are stored securely in a virtual vault and to perform electronic acts or transactions for, or on behalf of, the organization. The acts can be internal acts related, for example, to the internal control of the organization or external acts related, for example, to contracts entered into with other organizations. Permissions for these acts are based on assigned roles within the organization. Each role is defined to have a legal authority (that is, power or authority) to perform one or more tasks, acts, actions, or transactions.
Each role derives its legal authority ultimately from a registration authority.
In other words, the status of a Registration Authority (RA) is verified by sending a status check request to an agency server.
Τ / Ε Ρ 7 <77 ^^ ''<sup>;</sup>7777777 ΐΝ<sup>Γ</sup>> ϋ.; τχΐaι licensor, for example, LB-SVS (84). The RA then verifies the legal status of an organization from the first UTT member (or of a plurality of first members) of the organization. Thus, the authorities conferred on a member are based on the authority of registration. This creates a chain of trust that links the authority of a member of the organization to the authority of record. This paradigm imposes the legal requirements of the real world to verify the identities in the system. As a consequence, the system guarantees that there is legal authority for an electronic action carried out within the system by a user who occupies a role that was granted through a chain of trust by a registration authority.
The roles in the computer system are defined such that they depend directly or indirectly on a registration authority who has been licensed by a licensing body to verify the identity of any legal entity such as an organization or person. This paradigm ensures that each registered user of the system has been duly verified by a registration authority. The registration authority can then assign roles to users that confer rights or permissions to perform certain actions in the system. Any action by the user within the system is presumed to be legally valid as the User's authority is ultimately derived from the authority of a chain of trust sourced from Tilia duLufidad — it gives registration to a verified user of the system. Due to the chain of trust, other users of the system may assume that the actions of a particular user are valid and enforceable. This chain-of-trust paradigm transposes into a digital platform the real-world process of verifying the identity of each user and verifying that the User's role confers appropriate authority to take certain actions. This technology greatly facilitates actions that are internal to the organization (for example, resolutions, shareholder votes, or other internal control processes) and also actions that are external to the organization (for example, tenders, acquisitions, contracting).
The system architecture depicted in Figure 1 is presented as an exemplary implementation. It will be appreciated that the system can be implemented with other architectures by consolidating or distributing the various server functions. It will also be appreciated that the system can be implemented in a cloud computing environment. ROLE-BASED RIGHTS MANAGEMENT METHOD
This technology enables an automated method of role-based rights management within a
174
INSTIT'U u. «TXKU'.NU Di LA PROBIDAD organization having a hierarchical structure like a corporation. The im ^ TlCd method verifies the registration authority and then verifies the identity of the user who is to be assigned a role within an organization (by verifying that the user is registered in the SVS as a person whose identity has been verified by an organization). RA) and also verify the legal capacity of that user to act in the role to be assigned. This method creates a chain of trust that guarantees that the member designated to the role within the organization has been designated in accordance with the legal requirements imposed in that jurisdiction.
For clarity, it is to be understood that this method is presented from the perspective of the DITM application when a user creates an organization, selects users to become members of that organization, and then assigns roles to these members. This would be the case when a corporation account is created in the application by a registration authority. As a prerequisite, the legal status of the corporation must be verified. The users who are to be selected as members of the organization must also be verified. Then, roles should be assigned to members, for example, as directors, officers, shareholders, employees, etc. within the corporation. The method begins when a
<img file="MX347104B_D0011.tif" />
first user (eg a lawyer) a registration authority (RA) wishes' Iuj accounts from, the organization within the DITM application. The first user as an ostensible RA enters the system and requests the creation of an organization account, for example an account for a client corporation. The system will initially verify that the first user (the attorney) is currently a still valid RA. To do this, their status is checked with the LB-SVS (84) (for example, the professional status database maintained by their state or provincial bar).
The method therefore represents in Figure an initial step (20) 0 to verify a legal status of a first user who intends to act as a registration authority. This is done by sending a status check request over the network to a licensing body server (LB-SVS) that stores status information about the legal status of the first user. The status check request can be a message or datagram in a predefined format specifying the name and / or professional license registration number of the user. The LB-SVS runs software that is programmed to recognize the predefined format and perform an automatic search and obtain status information.
This health check request checks if the
IΜ Γ Η first user is authorized to isgiw ^ -á'a Registration Authority (RA). Assuming the first user is a valid RA, the application then allows the RA to act. Therefore, the RA may request that the SVS be consulted as to whether the corporation in question is a known entity (ie, whether the corporation has already been verified by an RA). This verification may have been carried out by the same RA or previously by another RA, that is, any other authority derived from RA from an original RA. In any case, the identity of the corporation (legal status), if verified by an RA, has been entered into the SVS database. The DITM server consults the SVS to verify that the corporation is a known entity. Thus, in step 210, a legal status of an organization is verified by sending a status verification request to the SVS. Assuming the corporation is known to the SVS because it has been checked previously, an affirmative status response is communicated to the DITMS from the SVS. The RA is then able to create an account for the organization within the DITM application.
Accordingly, in step 220, the method involves receiving user input from the RA to create an account for the organization within the application.
DITM.
IM F1 INSTITUTO MEXICANO • e la fxoritOAu
The RA will then assign a role ^<sup>5-1</sup>^ r5 ^ year selected that is a first member of the —PTganinaciótu For this, the DITM consults the SVS to verify that the selected user is a known entity, that is, that the selected user has been verified by an RA and that the user has the ability to assume the role to be assigned
Accordingly, in step 230, the system verifies a legal status of the first member of the organization by sending a status verification request to the SVS. Assuming the first member has been verified by an RA, the SVS will reply with an acknowledgment that the first member is known. The RA will then be able to assign a role within the organization to the first member because the first member has been verified. The registration authority also verifies that the first member has legal capacity to act in the first role. For example, the first role may be a director of a corporation. In a given jurisdiction, there may be requirements that the director be a resident, be of a certain minimum age, etc. These requirements are verified by the RA before assigning this role to the member. Verification of legal capacity to assume a role can also be automated by the system. In one mode, the system compares the attributes
ΙΜΡΙ
IN371TU7Ü MEXICAN
Ut LA PkOHLDA »INDUSTRIAL
<img file="MX347104B_D0012.tif" />
of the user account or user profile with a set of rules, parameters, or requirements that reflect the legal requirements of the role. For example, the role may require that the user be a citizen or resident of the jurisdiction, that the user has no criminal record, that the user has a minimum age, that the user has a professional status, degree, certification, chosen status, assigned status, delegated status, etc. These attributes can be entered in the user account in the user database (82).
These personal attributes are part of the user's profile. These attributes can be entered and verified when the RA verifies the identity of the user.
The system can then automatically query the database to compare the attributes with the requirements.
Therefore, in step 240, the application receives user input from the RA to define a first role within the organization for the first member. The first role confers a first authority to act on behalf of the organization. Thus, the first authority is based on the registration authority.
Another optional step (250) comprises receiving user input from the first member to create a second role for a second member in compliance with internal control standards that are determined by the
IΜ Ρ i INSTITUTO MEXICANO Μ
OF ιλ raoriMn legal requirements imposed on the orgSñ'í<sup>T</sup>2'átiOTV— ^ 1 second role confers a second authority papa actee & r on behalf of the organization, thus creating a chain of trust that determines the second authority of the second role in the first authority of the first role which, in turn, is determined in the status check of the registration authority. Internal control standards, for example, a majority rule system for a board of directors, is imposed on the first members of the RA, requiring that any action taken by the first member complies with the legal framework imposed on the first members. The first members may agree (by majority vote) to change the internal control standards, but this vote is limited by the original legal framework imposed by the RA pursuant to the law of the jurisdiction that governs the organization. Any statutory, regulatory, or other legal requirements for an organization within a given jurisdiction can be programmed into the system as rules or parameters that govern how members act. In other words, a hierarchy of roles can be created within the organization, each deriving its authority from the previous role. In that sense, a role can be understood as a set of rights, a right being the right to create a role. Each role (and its authority) can then be traced through the hierarchy to the first member (s) of the
JA A i 'Χλ. IV k μ MEXICAN INSTITUTE ¿Á. ,,. . ,,,. ,, P! THE ΜΟΠΕΟλι.
organization which received its authority from the • 'aWwrioító ^ a ^<sup>1</sup>' record. This is called the chain of trust.<sub>;</sub> . . ...____
In an implementation, the SVS (or one or more applications, modules, or similar execution in the SVS) guides the RA through the verification process by showing (for example, via an SVS network interface) the legal requirements to perform a verification in accordance with what is prescribed by law in a given jurisdiction. In most embodiments, the SVS stores the legal verification requirements for each of a plurality of different jurisdictions for each of a plurality of different types of entities that can be created in the system. In other words, the SVS stores in memory the verification requirements that are displayed to the RA when the RA specifies the type of entity and jurisdiction. Verification requirements therefore serve as a guide or tool in performing the steps necessary for the verification of an entity. The requirements are based on the legal framework (eg laws, statutes, regulations, codes, etc., that govern the incorporation of an entity in a given jurisdiction.
An example of the legal framework is, for example, article 335 of the Civil Code of Quebec that says: The board of directors administers the affairs of the legal person and
IΜ <sup>?</sup> 1
I HEARD THE rK.Rr.OA >> 'Λ ^ exercises all the powers necessary to<sup>INP</sup>'éT £ b;
create management positions and other positions and dulogaj ... aJ____ exercise of certain powers to the holders of said positions and to said bodies. The board of directors adopts and implements the management bylaws, subject to member approval at the next general assembly. The legal person can be, for example, a corporation, trust, etc. From this framework follows the authority of the board and the ability to create management positions and delegate the exercise of certain powers. This system provides a digital platform that reproduces the general legal framework for each type of entity for each jurisdiction.
In one application, the SVS determines the jurisdiction in response to user input from the RA, determines the entity type also in response to user input from the RA, and then presents the RA with a checklist of acts that the RA must perform to comply with the verification requirements, that is, in order to correctly verify that the organization or entity has been duly constituted or created. The RA then clicks on the different checklist boxes to indicate that it has performed each of the required checks. The checklist is automatically generated by the SVS based on the type of entity and the jurisdiction that governs the
M and
INSTIΓΌΤΟ MEXICANO i
DE LA PROmÍMI 'N DU STR M entity. In addition to or instead of the checklist, the SVS may display fields for data entry, which require the RA to enter data or information obtained from the entity. For example, the SVS may require the RA to enter a corporation number and password. The SVS will then consult a corporate registry or other government database to determine if the corporation number and password are correct. In addition, the SVS may require the RA to enter the names of all directors and their social security numbers. The SVS can then verify this data by consulting a government database. These are simple examples to illustrate how the SVS can challenge or test the RA to ensure that the RA is participating in a full and complete verification.
Optionally, the SVS can store electronic copies of any supporting document (for example, photo ID card scans, passports, fingerprints, voice prints or other biometric data, digitally signed certificates of corporate records, etc.) that used the RA to verify the entity. This supporting information can be encrypted or unencrypted in the SVS. Encryption can be used to control access to these
LNSTiTbTO mmcan · PE LA INI ^ J ^ fRíAl ***** data so that only the RA or a group of RA have access to it.
Optionally, the SVS can perform conflict checks to ensure that the status of an organization does not conflict with another organization already registered in the system. The SVS may display a warning if there is a conflict, in a mode, that the RA can manually override by providing the appropriate user input to the SVS. For example, the system may mark a corporate name conflict between an entity in one jurisdiction and another entity in a different jurisdiction that would not have been identified by the corporation records of each jurisdiction acting separately and independently.
Along the lines, the SVS can optionally perform a conflict check to ensure that a user acting as a member of one organization does not exclude the same user member from acting as a member of another organization. For example, a first organization may appoint a first member on condition that the first member devotes all of his or her time and attention to the affairs of the first organization. The SVS can warn the RA if it attempts to assign a role to that same first member in a second organization.
IMPI
INSTITUTO MEXICANO Of LA Γ »ΟΠί» ΑΓ> INDUSTRIAL
The method may further comprise a step of receiving user input from the second member to carry out a restricted action in the application, a step of verifying that the second member has the necessary authority to carry out the restricted action and a step to perform the restricted action in the application only if the second member has the necessary authority. The authority required depends on the role of the user / member.
The method may further comprise assigning a plurality of first roles to a plurality of first members, the first members being governed by a reconfigurable majority rule control scheme. For example, in the case of a corporation, the plurality of first members are the first directors. Generally, the role of the manager is assigned a set of rights and permissions. Directors are governed by a majority rule control scheme. Directors can vote to change or reconfigure the control scheme. All actions flow from the initial framework that has been instituted by the RA for the corporation that replicates the real world legal framework for the corporation.
<img file="MX347104B_D0013.tif" />
ELECTRONIC COMMERCE METHOD
This technology
INSTITUTO MtXICANj DE LA 'r PIEDA:' INDUSTRIAL also allows a computerized method of electronic commerce between a first organization and a second organization. Each organization has a hierarchical structure of roles conferred by different authorities to transact on behalf of the respective organizations. The problem that occurs conventionally in electronic commerce is that one party must have ostensible authority from the other party. In other words, it is impossible to know with certainty and in a timely manner whether the other party has the appropriate authority (for example, is legally authorized) to contractually bind your organization. The ability to act is often a matter of the user's role within the organization. The present solution to this problem is for each organization to share a document interaction and transaction management (DITM) application hosted on the network that interfaces with the SVS. The DITM application and the SVS cooperate to ensure that at least the organization and members have been duly verified by a registration authority. In addition, the system ensures that the roles have been assigned to the members by the registration authority in accordance with the legal and regulatory requirements applicable for the type of organization in question.
<img file="MX347104B_D0014.tif" />
<img file="MX347104B_D0015.tif" />
This computerized method therefore allows
INSTITUTO MEXICANO DE LA Ht.-VIEDAD INDUSTRIAL that a member of the first organization know if a member of the second organization really has the authority to act on behalf of the first organization.
Referring to Figure 3, the method starts at step 300 when the DITM application receives user input from a bidding member of the first organization. The bidding member requests that the application generate an electronic contract document that represents an offer to enter into a contract.
In response, in step 310, the application verifies that the bidding member of the first organization has a role that has authority to contractually bind the first organization in relation to the contract, the role having been defined by a first member whose status has been verified by a registration authority. The member's legal capacity to fill the role is also verified by the registration authority to ensure that the member's appointment to that role is in accordance with the applicable legal requirements.
In step 320, the application generates the electronic contract document and allows the first member to sign the document electronically only if the bidding member has the authority to bind.
IM ri injtit '; i ο MtxiON · · OF THE INDUSTRIAL I7OHFIMD
<img file="MX347104B_D0016.tif" />
contractually to the first organization with respect to the contract.
In step 330, the offering member provides user inputs that identify an accepting member who is to receive the electronic document at the second organization.
The application checks that the accepting member occupies a role that confers authority to accept the offer on behalf of the second organization in step (340). The role has been defined by a second member whose status has been verified by a registration authority. In some modalities, some elements of the user's legal capacity to occupy that role have also been verified, either directly by the RA or by the system in response to input or a command from the RA.
In step 350, the application then transmits the electronic contract document from the offering member of the first organization to the accepting member of the second organization if the accepting member has the authority to accept the offer.
In step 360, the application then receives user input from the accepting member of the second organization who can electronically sign the document to accept the offer. Finally, a
1M fi
INSTITUTO MEXICANA ΛP.
DI LA MOMEDAl · electronic acceptance is transmitted to the bidding member of the first organization. '"<sup>1</sup> -Because both organizations and their respective members have been verified by the SVS, authority is assumed for the actions taken by each member on behalf of their respective organizations. This allows an e-commerce transaction to proceed without the uncertainty of whether the individuals who claim to have contracting authority actually have the necessary authority to contractually bind their respective organizations. This computer system therefore provides a network-based or cloud-based platform for e-commerce.
Figures 4 to 7 illustrate several examples of user interfaces (screens or pages) that the system can present to enable the RA to perform verification and role assignment tasks.
As illustrated by way of example in Figure 4, a registration authority verification page (400) may include welcome information and an indication (410) that the status of the RA is being automatically verified with the LB-SVS. appropriate. Optionally, a location indication (420) of the current detected location of the RA may be displayed along with a button (430) to correct it if the location information is
I ÍVÍ X '.1
INSTINCT ΜΕ / ,, ¾ incorrect. Optionally, a
LB-SVS (440) indicating that an LB-SVS is being queried together with a correction button (450). This is useful for an RA that is a member in good standing of two different licensing bodies for two different jurisdictions, for example the New York bar and the Quebec bar.
As illustrated by way of example in Figure 5, another registration authority verification page (500) may appear when the LB-SVS returns an affirmative status response. Welcome information (510) is updated. User interface elements 520, 530 are displayed to allow the RA to verify a user or organization.
As illustrated by way of example in Figure 6, the system may present a registration authority checklist (600) to guide the RA through the verification process of an entity in a given jurisdiction. Jurisdiction (610) and entity type (620) information can be presented. Optionally, checkboxes (630) can be provided for the RA to check when each condition has been verified. Optionally, a button 6 (40) can be provided to view the applicable requirements and standards for each condition. Optionally, the screen (600) can include several
<img file="MX347104B_D0017.tif" />
task buttons (650), (660), (670), can be presented for various tasks such as finish / sign, view support documents, import support documents, request help or cancel the screen.
Figure 7 is an example of a role management screen (700) that allows the RA to assign a role to a registered user. Optionally, the screen 700 may illustrate RA information including the RA name, its status, LB-SVS, and last verification time and next verification time. The role management screen (700) may optionally include a user interface element (720) to select a registered entity from the SVS database and a user interface element (730) to select a registered user from the SVS database to whom a role is to be assigned within the selected entity.
Optionally, the screen (700) includes user interface elements (740), (750), (760) to verify the legal capacity of the user to occupy the role, to assign the role and to notify the user and / or entity of role assignment.
In an application, the method involves viewing a transaction panel such as the one shown in Figure 8 as an example.
<img file="MX347104B_D0018.tif" />
INSTITUTO MÍXI .-. ArO 21 (8θθΟ $ Μ, illustrated mode electronic commerce transactions, display or otherwise present names and corresponding roles of all members who must electronically sign the document to be legally valid and also show a signature status which indicates whether each member has signed the document. For example, as shown in Figure 8, the panel (800) presents the description of the transaction (810), closing data, an internal reference number (820) to identify the transaction in question. Checkboxes (830) or other status indicators can show if each requested member has signed on the transaction. A send reminder button (or other user interface element) (840) may be provided to send a reminder to a member who has not yet approved the transaction. The unchecked box (850) may be accompanied by a description that the system is waiting for the member's signature, as shown. An automatic reminder system can also be provided to automatically communicate reminders to those members who have not signed up yet. Other buttons or user interface elements may be displayed such as a document view button (860), a help button (870), and a cancel button (880). Additionally or alternatively, the panel may notify
INSTITUTO MEXICaN '. » Λ *
DS ΙΑ HCW.PAO sequentially to each of the members that 'cfelDeh íTrirraT * electronically the document in an order JTfédéLUMlllTRnicr: - This panel allows the bidding and accepting members to efficiently manage the transaction by ensuring that all members have signed .
In an application, the method is to create and send a counter offer to the first organization and determine whether the bidding member of the first organization still has the authority to accept the counter offer. The counter offer may, for example, be for a larger amount of money for which the bidding member no longer has authority. This optional feature could check if the terms of the counter offer are still within the scope of the bidding member's ability to contract.
In an application, the method is to determine that the accepting member is not receptive, determine if the offer is time-limited, and automatically notify another member whose role gives them equivalent authority to accept the offer. This feature allows the transaction to be approved by another member if the original bidding member or accepting member is unavailable for any reason, for example vacation, out of office for business travel, sick leave, etc.
INDUSTRIAL
APPLICABILITY TO LEGAL ACTS IN MIJUJJAÍSS WORLDS --------- In another implementation, the present technology can be adapted to a virtual world or virtual environment. A virtual world is an online computer-generated game or simulation in which users interact with objects in their environment and with each other through their respective avatars. An example of a virtual world is Second Life ™. Trading between avatars in the virtual world is carried out with a virtual currency that can have real value. For example, in Second Life ™, the virtual currency known as Linden dollars can be purchased with real dollars. An avatar can earn or spend Linden dollars in the virtual world and then redeem or exchange the Linden dollars to real US dollars. Therefore it is possible to earn money in the virtual world. Business disputes that arise in the virtual world are difficult to resolve, using traditional approaches (i.e. resorting to a court of law or alternative dispute resolution mechanisms) due to a variety of legal issues such as issues of jurisdiction and law. avatar's real world identity. Other legal issues (property, liability, etc.) cannot be easily resolved in a virtual world either, mainly due to ar
IM <sup>p</sup> 'wsnrur j v.>?'.,. ·. <· □ E LA ΤΌΗΠάι; ΙχΝΜ'Α * / identity issues. In other words, the main problem that arises in a virtual command is that the avatar cannot easily be legally linked to a real-world entity. Current technology addresses this basic problem by employing a registration authority to verify that a user is legally the virtual extension of the user. Once verified by the RA, the User and their avatar are registered in the SVS or its associated user database.
An example of a generic network-based virtual world computer system is depicted in Figure 9. The virtual world software engine (application) runs on a virtual world server (900) (pool or cloud). The virtual world server (900) may have an avatar database (930) (storage of avatar information, attributes, properties, etc.) and a graphics database (940) (storage of scene data for virtual environments that make up the virtual world). The virtual world server (900) may require the formal registration of the user before the SVS (80), which implies the verification of the user by the RA and the storage of the verified information of the user in the user database (82 ) associated with the user's unique avatar. The access of the
<img file="MX347104B_D0019.tif" />
I Μ ”<i .t» j. Λ; ; institute hx! ->; - c
Ot LA PKOHSrv j C * INDUSTRIAL
User to the virtual world can be controlled in this way so that only known and registered users (ϊ δ) 7 (20), (30) whose identities have been duly verified by a registration authority can access the virtual world.
The computer system depicted in Figure 9 therefore provides a virtual e-commerce platform or legal transaction management platform that is based on a modified version of the DITM application referred to in this document in the context of a virtual world such as a legal transaction management (LTM) application. The LTM application runs on the legal transaction management server (910) and may include or be connected to a secure document vault (920) to securely store contracts, digitally signed documents, or other similar data. The LTM server (910) depends on a registration authority to verify the identity of the users, (10), (20), (30) of the virtual world. Once verified, the user account in the SVS database (82) legally binds users to their avatars. A certificate may be issued to allow users through their avatars to digitally sign contracts and participate in formal legal acts in the virtual world such as the purchase or sale of<sup>1 to</sup>osué »<¡; w ;; ¿properties, celeB ^ ci & h- ^ é ^ employment or service contracts, termination of a legal marriage with another avatar, signing a last will and testament, etc. Any action taken by the user through his avatar in the virtual world will therefore have legal effect because the avatar is legally connected to the registered user.
The SVS can be used to store registered users and corresponding avatars. The DITM application can be adapted or transformed into a virtual world legal transaction management (LTM) application that interfaces with the virtual world game engine or gaming platform to provide a complementary platform or module for any such legal transaction. such as commercial contracts between avatars, virtual transactions related to properties, virtual corporation formations, etc. In other words, the legal transaction management application allows to legally enforce interactions and transactions between avatars within the virtual world. If a dispute arises between two avatars in the virtual world, the identity of the real users in the real world can be determined. The avatar has the legal authority in the virtual world to legally bind the user. This creates a chain of trust that links
TV rr ir _ .M ¿the avatar of the real user whose identity 'has been correctly verified according to' 'Ί'δ l'Uy registration authority whose own status as registration authority was verified when creating the user account. In this way, users of the virtual world can interact with other avatars with a much greater sense of trust based on the fact that avatars are legal extensions of registered users whose identities have been duly verified by a registration authority with legal capacity. to verify the identities of individuals within a given jurisdiction.
Verification of the RA and virtual world users can be accomplished using the LB-SVS and SVS. As illustrated in Figure 10, a status check request is transmitted in step 1000 to a licensing body status check server (LB-SVS) to check that the RA is licensed to practice as an RA. in that jurisdiction. Another status check request is transmitted in step 1010 to the SVS to verify that the user is a registered user whose identity has been verified by an RA. After these verifications are made, the RA can create a user account in step 1020, thus admitting the user as a member of the virtual world.
<img file="MX347104B_D0020.tif" />
OF THE E HOHIUMj INCIJSTKIAL
In one embodiment, the legal transaction management (LTM) application controls, manages and mediates all legal transactions within the virtual world. For example, if User A wishes to enter into a contract with User B (which is effectively done in a virtual world through avatars), then the LTM application verifies that users have authority in the real world to enter into the contract. For example, the user may be legally entitled only to enter a contract if the user is of legal age. As another example, the user may only have the right to transfer ownership to another user who meets certain criteria. The legal transaction management application in this way applies policies to certain actions to ensure that they are carried out in accordance with the legal capacity of the users and in accordance with the authority conferred on the avatar by the user.
As shown by way of example in Figure 10, the LTM application enables trading in a virtual world. The LTM can process a virtual contract between avatars according to a method as follows: step (1030), the LTM application receives user input from a first user controlling a first avatar in the virtual world causing the first avatar to present an offer to contract a second avatar who
ΙΝλΤΙΤΌΤΟ Mi / íCa, '. :) Dé FFOP1EDAD represents a second user, for example Wj'tílarwer — ra communication of an electronic document ”' that T'é'pitiseirha — and contract offered from the first avatar to the second avatar. This offer is presented in the virtual world. However, the offer can indirectly have a real effect, that is, real legal ramifications to users, assuming that there is a correlation between the value of currency (money) in the virtual world and the value of currency in the real world. The LTM application then automatically verifies in step 1040 that the first user and the second user have legal authority to enter into the contract. At step 1050, the LTM application then allows the second user to accept the offer to form a legally binding contract only if the first and second users have legal authority to make the contract. For example, the legal transaction management application may consider various factors and conditions to determine whether avatars have the legal authority of their users to enter into the contract. The factors and conditions may include the object of the contract, the age of each user, the residence of each user, the value of the transaction, the restrictions imposed on the avatars of the virtual world, the restrictions imposed on the avatars of the users, etc. . The application of LTM in this way provides a system of avatars to perform
<img file="MX347104B_D0021.tif" />
INSTITUTE ΜΓ.ΧΚαΝΙι PE la rxori £ DA,> .industrial transactions
<img file="MX347104B_D0022.tif" />
that are supposed to have a direct or indirect legal effect in the real world. The SVS further acts as a guardian or guardian of the virtual world, ensuring that only registered users whose identities have been verified by a registration authority will be admitted to the virtual world. This creates a closed online community of trusted entities in which each avatar is tied to a single user such that the user cannot repudiate the acts of their avatar.
Any of the methods disclosed in this document can be implemented in hardware, software, firmware, or any combination of these. When implemented as software, method steps, acts, or operations may be programmed or encoded as computer-readable instructions and recorded electronically, magnetically, or optically on a non-transient computer-readable medium, computer-readable memory, machine-readable memory, or computer program product. In other words, computer-readable memory or computer-readable medium comprises instructions in code that when loaded into a memory and executed in a processor of a computing device, cause the computing devices to perform one or more of the following. above methods.
«Ν5ϊΠ! lio Η Y>> 4.-.-- 4 '3
FROM
INDUSTRIAL
A computer-readable medium can be any medium that contains, stores, communicates, diffuses ~ * ~~ or transports the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-readable medium can be electronic, magnetic, optical, electromagnetic, infrared, or any semiconductor system or device. For example, computer-executable code to carry out the methods disclosed in this document can be tangibly recorded on a computer-readable medium, including, but not limited to, a floppy disk, CD-ROM, DVD, RAM, ROM, EPROM. , Flash memory or any suitable memory card, etc. The method can also be implemented in hardware. A hardware implementation may employ discrete logic circuits that have logic portals for the implementation of logic functions in data signals, an application-specific integrated circuit (ASIC) that has appropriate combinational logic gateways, programmable pre-broadcast circuits ( PGA), Programmable Pre-broadcast Field Circuits (FPGAs), etc.
This invention has been described in terms of specific embodiments, implementations, and configurations that are intended to be exemplary only. People with medium knowledge
<img file="MX347104B_D0023.tif" />
j V - -o OF THE 2SO,.-L ... D iwi / sruiAL
<img file="MX347104B_D0024.tif" />
In the art you will appreciate, upon reading this disclosure, that many obvious variations, modifications and improvements can be made without departing from the inventive concept presented herein. The scope of the exclusive right sought by the applicants, therefore, is intended to be limited only by the appended claims.
Contents11
43 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43
16 members in 11 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 201261676489 | United States of America | P | |
| 201261676489 | United States of America | P | |
| 61676489 | United States of America | – | |
| 2013000645 | Canada | W | |
| 2013000645 | Canada | W | |
| 61676489 | – | – | – |
| PCTCA2013000645 | – | – | – |
| US201261676489P | – | – | – |
| WO2013CA00645 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| CA2880095A1 | Canada | A1 | |
| WO2014015413A1 | World Intellectual Property Organization (WIPO) | A1 | |
| SG11201500645QA | Singapore | A | |
| EP2877954A1 | European Patent Office (EPO) | A1 | |
| CR20150108A | Costa Rica | A | |
| US2015200950A1 | United States of America | A1 | |
| MX2015001242A | Mexico | A | |
| EP2877954A4 | European Patent Office (EPO) | A4 | |
| HK1210531A1 | Hong Kong, China | A1 | |
| CA2880095C | Canada | C | |
| MX347104BThis record | Mexico | B | |
| BR112015001849A2 | Brazil | A2 | |
| US9843587B2 | United States of America | B2 | |
| EP2877954B1 | European Patent Office (EPO) | B1 | |
| PT2877954T | Portugal | T | |
| ES2895440T3 | Spain | T3 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 347104
- Publication, DOCDB
- 347104
- Publication, EPODOC
- MX347104
- Application
- 2015001242
- Application, DOCDB
- 2015001242
- Application, EPODOC
- MX20150001242
Titles2
- Spanish
- MÉTODO DE GESTIÓN DE DERECHOS DIGITALES BASADOS EN ROLES EN UN SISTEMA DE CÓMPUTO.
- English
- ROLE-BASED DIGITAL RIGHTS MANAGEMENT METHOD IN A COMPUTING SYSTEM.
Classification
- CPC, 7
- G06F21/10
- H04L63/101
- G06F21/57
- G06F2221/2145
- G06F2221/2141
- G06Q20/40
- H04L63/126
- IPC, 2
- G06F21 10
- G06F21 00