IP Library Granted Patent US 7,694,342
Granted Patent B2
US 7,694,342 · App. 11/741,556 · Granted Apr 6, 2010

Systems and methods for managing and protecting electronic content and applications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,694,342
App. No.
11/741,556
Granted
Apr 6, 2010
Kind
B2
Abstract

Systems and methods are disclosed for managing and protecting electronic content and applications. Applications, content, and/or users can be given credentials by one or more credentialing authorities upon satisfaction of a set of requirements. Rights management software/hardware is used to attach and detect these credentials, and to enforce rules that indicate how content and applications may be used if certain credentials are present or absent. In one embodiment an application may condition access to a piece of electronic content upon the content's possession of a credential from a first entity, while the content may condition access upon the application's possession of a credential from a second entity and/or the user's possession of a credential from a third entity. Use of credentials in this manner enables a wide variety of relatively complex and flexible control arrangements to be put in place and enforced with relatively simple rights management technology.

Claims (30)

1. A method for managing the use of electronic content at a user's computing device, the method including:

executing an application program on the user's computing device, the application program being capable of rendering electronic content, the application program having at least a first digital certificate associated therewith, the first digital certificate being generated by or on behalf of a first entity comprising an association of one or more content providers, the first digital certificate being associated with the application program if the application program meets certain predefined criteria set by the association, the predetermined criteria including that the application program will handle the electronic content with at least a predefined level of security;

requesting the application program to render a piece of electronic content, the piece of electronic content having at least a second digital certificate associated therewith, the second digital certificate being generated by or on behalf of a second entity different from the first entity, and the piece of electronic content further having associated therewith at least one electronic rule, the at least one electronic rule including data specifying one or more conditions associated with rendering the piece of electronic content, the one or more conditions including a condition that the piece of electronic content may be rendered by an application program having the first digital certificate associated therewith;

verifying, at the user's computing device, the association of the second digital certificate with the piece of electronic content;

using a rights management program running on the user's computing device to examine the data included in the at least one electronic rule and to determine that the piece of electronic content may be rendered by an application program having the first digital certificate associated therewith;

verifying the association of the first digital certificate with the application program using the rights management program; and

rendering the piece of electronic content using the application program, wherein the piece of electronic content comprises an authorizing document, and the second entity associates the second digital certificate with the authorizing document if the authorizing document originated from a certified entity.

2. The method as in claim 1 , wherein the second entity comprises an entity concerned with controlling the nature of the electronic content rendered by the application program, and the second digital certificate is associated with the piece of electronic content if the piece of electronic content meets certain predefined standards.

3. The method as in claim 2 , wherein the second entity comprises an entity that determines whether content is appropriate for particular individuals, and the second digital certificate indicates that the piece of electronic content is deemed to be appropriate for particular individuals.

4. The method as in claim 1 , wherein the predefined level of security includes a requirement that the application verify that an application user has a predefined certificate before rendering the authorizing document.

5. The method as in claim 4 , wherein the predefined certificate indicates that the application user is an individual who can perform an action authorized by the authorizing document based on the authorizing document.

6. The method as in claim 4 , wherein an individual is identified by a digital certificate issued by a third entity different from the first and second entities, wherein the individual is an individual who can perform an action authorized by the authorizing document based on the authorizing document.

7. The method as in claim 1 , wherein the certified entity is identified by a third digital certificate issued by a third entity different from the first and second entities.

8. The method as in claim 7 , wherein the second entity determines that an authorizing document originated from the certified entity by checking for the presence of the third digital certificate issued by the third entity.

9. The method as in claim 8 , wherein the application program is further associated with a fourth digital certificate, the fourth digital certificate attesting to a determination having been made by a fourth entity that the application program possesses a predefined functionality.

10. The method as in claim 9 , wherein the predefined functionality includes functionality that ensures that the application program verifies the association of the second digital certificate with the piece of electronic content before rendering the piece of electronic content.

11. The method as in claim 10 , further including;

verifying the association between the application and the fourth digital certificate.

12. The method as in claim 1 , wherein the step of verifying the association of the second digital certificate with the piece of electronic content is performed during or after the step of verifying the association of the first digital certificate with the application program.

13. The method as in claim 1 , wherein the step of verifying the association of the first digital certificate with the application program includes computing a hash of at least part of the application program and comparing the hash to a value contained in the digital certificate.

14. The method as in claim 1 , further including:

decrypting a secure container containing the piece of electronic content and the at least one electronic rule; and

retrieving the at least one electronic rule from the secure container.

15. The computer readable medium storing instructions that, when executed by a computer, cause the computer to perform a method for managing the use of electronic content at a user's computing device, the method comprising:

executing an application program on the user's computing device, the application program being capable of rendering electronic content, the application program having at least a first digital certificate associated therewith, the first digital certificate being generated by or on behalf of a first entity comprising an association of one or more content providers, the first digital certificate being associated with the application program if the application program meets certain predefined criteria set by the association, the predetermined criteria including that the application program will handle the electronic content with at least a predefined level of security;

requesting the application program to render a piece of electronic content, the piece of electronic content having at least a second digital certificate associated therewith, the second digital certificate being generated by or on behalf of a second entity different from the first entity, and the piece of electronic content further having associated therewith at least one electronic rule, the at least one electronic rule including data specifying one or more conditions associated with rendering the piece of electronic content, the one or more conditions including a condition that the piece of electronic content may be rendered by an application program having the first digital certificate associated therewith;

verifying, at the user's computing device, the association of the second digital certificate with the piece of electronic content;

using a rights management program running on the user's computing device to examine the data included in the at least one electronic rule and to determine that the piece of electronic content may be rendered by an application program having the first digital certificate associated therewith;

verifying the association of the first digital certificate with the application program using the rights management program; and

rendering the piece of electronic content using the application program, wherein the piece of electronic content comprises an authorizing document, and the second entity associates the second digital certificate with the authorizing document if the authorizing document originated from a certified entity.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION,
To: PLS IV, LLC
Reel/Frame 066428/0412 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
SECURITY INTEREST Recorded Mar 18, 2020
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD
Reel/Frame 052189/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2020
From: MAHER, DAVID P.; RUDD, JAMES P.; SWENSON, ERIC J.; LANDSMAN, RICHARD A.
To: INTERTRUST TECHNOLOGIES CORP.
Reel/Frame 051859/0701 →