IP Library Granted Patent US 9,626,667
Granted Patent B2
US 9,626,667 · App. 11/583,527 · Granted Apr 18, 2017

Digital rights management engine systems and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,626,667
App. No.
11/583,527
Granted
Apr 18, 2017
Kind
B2
Abstract

Systems and methods are described for performing digital rights management. In one embodiment, a digital rights management engine is provided that evaluates license associated with protected content to determine if a requested access or other use of the content is authorized. In some embodiments, the licenses contain control programs that are executable by the digital rights management engine.

Claims (27)

1. A method of managing enterprise documents, the method comprising:

authoring, by a first software application executing on a first computing device, an electronic document;

encrypting, by a digital rights management plug-in executing on the first computing device, the electronic document;

associating, by the digital rights management plug-in executing on the first computing device, a license with the encrypted electronic document, the license comprising an encrypted first key configured to decrypt the encrypted electronic document and a control program, the control program comprising instructions for determining:

a logical connection between a node associated with a first group of users and a second node based on possession of one or more link objects, and

a callback;

sending, by the first computing device, the encrypted electronic document and the license to a second computing device;

receiving the encrypted electronic document and the license by the second computing device from the first computing device;

determining authorization to access the encrypted electronic document, comprising:

determining the logical connection between the node associated with the first group of users and the second node based on possession of the one or more link objects by executing the control program using a virtual machine of the second computing device, the second computing device comprising the second node, wherein at least one of the one or more link objects comprises an encrypted second key, the second key configured to decrypt the encrypted first key;

determining the callback by executing the control program using the virtual machine;

determining a host application of the second computing device supports the callback using the host application;

calling a control routine according to the callback using the host application;

recording access to the encrypted electronic document in a database by executing the control routine using the virtual machine;

providing an authorization indication to the host application based on execution of the control routine using the virtual machine; and

accessing the encrypted electronic document based on the authorization comprising:

decrypting, by the second computing device, the encrypted second key using a key associated with the second computing device,

decrypting, by the second computing device, the encrypted first key using the decrypted second key,

decrypting, by the second computing device, the electronic document using the decrypted first key, and

accessing the decrypted electronic document.

2. The method of claim 1 , wherein encrypting the electronic document and associating the license with the electronic document further comprises:

receiving, by the first computing device, a first template selection from a set of one or more templates, the one or more templates expressing policy conditions that can be imposed on access to electronic documents, the digital rights management plug-in automatically converting the policy conditions expressed by the selected first template into the control program.

3. The method of claim 1 , further comprising: creating, by the digital rights management plug-in, a controller object configured to securely bind the control program with the encrypted first key.

4. The method of claim 3 , the controller object including a hash of a content key object and a control object, wherein the content key object comprises the encrypted first key, wherein the method further comprises associating the control program with the control object.

5. The method of claim 4 , the controller object being signed with a hashed message authentication code using an unencrypted version of the encrypted first key.

6. The method of claim 4 , the controller object being signed with a public key signature of an author of the electronic document.

7. The method of claim 6 , the public key signature being signed with a hashed message authentication code using an unencrypted version of the encrypted first key.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
SECURITY INTEREST Recorded Mar 18, 2020
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD
Reel/Frame 052189/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2007
From: BOCCON-GIBOD, GILLES; BOEUF, JULIEN G.; MANENTE, MICHAEL G.; BRADLEY, WILLIAM B.
To: INTERTRUST TECHNOLOGIES CORP.
Reel/Frame 018718/0123 →