WO1997014087A1 - Systeme et procedes de gestion d'oeuvres de creation numeriques - Google Patents
Systeme et procedes de gestion d'oeuvres de creation numeriques Download PDFInfo
- Publication number
- WO1997014087A1 WO1997014087A1 PCT/US1996/016348 US9616348W WO9714087A1 WO 1997014087 A1 WO1997014087 A1 WO 1997014087A1 US 9616348 W US9616348 W US 9616348W WO 9714087 A1 WO9714087 A1 WO 9714087A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- media
- container
- data
- work
- information
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims description 212
- 238000013475 authorization Methods 0.000 claims abstract description 84
- 238000012546 transfer Methods 0.000 claims abstract description 38
- 238000004891 communication Methods 0.000 claims description 55
- 238000004806 packaging method and process Methods 0.000 claims description 22
- 230000004044 response Effects 0.000 claims description 19
- 230000006870 function Effects 0.000 claims description 16
- 238000005516 engineering process Methods 0.000 claims description 15
- 239000000203 mixture Substances 0.000 claims description 13
- 238000009877 rendering Methods 0.000 claims description 13
- 230000009471 action Effects 0.000 claims description 11
- 238000012545 processing Methods 0.000 claims description 9
- 230000003190 augmentative effect Effects 0.000 claims description 8
- 238000007639 printing Methods 0.000 claims description 8
- 238000003860 storage Methods 0.000 claims description 7
- 230000002452 interceptive effect Effects 0.000 claims description 6
- 230000002688 persistence Effects 0.000 claims description 5
- 238000012552 review Methods 0.000 claims description 5
- 238000004422 calculation algorithm Methods 0.000 claims description 4
- 238000013461 design Methods 0.000 claims description 4
- 230000006872 improvement Effects 0.000 claims description 3
- 230000003213 activating effect Effects 0.000 claims description 2
- 230000005540 biological transmission Effects 0.000 claims description 2
- RWSOTUBLDIXVET-UHFFFAOYSA-N Dihydrogen sulfide Chemical compound S RWSOTUBLDIXVET-UHFFFAOYSA-N 0.000 abstract description 4
- 230000008569 process Effects 0.000 description 42
- 238000007726 management method Methods 0.000 description 23
- 238000004519 manufacturing process Methods 0.000 description 14
- 230000000007 visual effect Effects 0.000 description 10
- 230000003068 static effect Effects 0.000 description 9
- 230000008901 benefit Effects 0.000 description 8
- 230000000875 corresponding effect Effects 0.000 description 8
- 230000003993 interaction Effects 0.000 description 8
- 238000009826 distribution Methods 0.000 description 7
- 238000011161 development Methods 0.000 description 6
- 230000001276 controlling effect Effects 0.000 description 5
- 230000000694 effects Effects 0.000 description 5
- 238000012858 packaging process Methods 0.000 description 5
- 230000008859 change Effects 0.000 description 4
- 230000000977 initiatory effect Effects 0.000 description 4
- 239000000463 material Substances 0.000 description 4
- 230000007246 mechanism Effects 0.000 description 4
- 150000001875 compounds Chemical class 0.000 description 3
- 238000012423 maintenance Methods 0.000 description 3
- 238000012986 modification Methods 0.000 description 3
- 230000004048 modification Effects 0.000 description 3
- 230000008520 organization Effects 0.000 description 3
- 238000006243 chemical reaction Methods 0.000 description 2
- 230000000295 complement effect Effects 0.000 description 2
- 239000002131 composite material Substances 0.000 description 2
- 230000010354 integration Effects 0.000 description 2
- 230000001737 promoting effect Effects 0.000 description 2
- 238000013515 script Methods 0.000 description 2
- 230000008093 supporting effect Effects 0.000 description 2
- 241000452734 Eudoraea Species 0.000 description 1
- 230000002730 additional effect Effects 0.000 description 1
- 238000013474 audit trail Methods 0.000 description 1
- 230000003416 augmentation Effects 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000001934 delay Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 238000005538 encapsulation Methods 0.000 description 1
- 238000011156 evaluation Methods 0.000 description 1
- 238000013507 mapping Methods 0.000 description 1
- 108010041420 microbial alkaline proteinase inhibitor Proteins 0.000 description 1
- 230000003287 optical effect Effects 0.000 description 1
- 230000002085 persistent effect Effects 0.000 description 1
- 238000003825 pressing Methods 0.000 description 1
- 239000007787 solid Substances 0.000 description 1
- 238000001228 spectrum Methods 0.000 description 1
- 230000000153 supplemental effect Effects 0.000 description 1
- 230000009897 systematic effect Effects 0.000 description 1
- 238000012384 transportation and delivery Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/12—Payment architectures specially adapted for electronic shopping systems
- G06Q20/123—Shopping for digital content
- G06Q20/1235—Shopping for digital content with control of digital rights management [DRM]
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/10—Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
- G06F21/108—Transfer of content, software, digital rights or licenses
- G06F21/1086—Superdistribution
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2211/00—Indexing scheme relating to details of data-processing equipment not covered by groups G06F3/00 - G06F13/00
- G06F2211/007—Encryption, En-/decode, En-/decipher, En-/decypher, Scramble, (De-)compress
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2211/00—Indexing scheme relating to details of data-processing equipment not covered by groups G06F3/00 - G06F13/00
- G06F2211/007—Encryption, En-/decode, En-/decipher, En-/decypher, Scramble, (De-)compress
- G06F2211/008—Public Key, Asymmetric Key, Asymmetric Encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/101—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measures for digital rights management
Definitions
- media developers typically do nothing; or they attach a textual copyright warning - sometimes called a "watermark" - to the media.
- This type of “protection” ensures free access to the media, but it works only for those honest users and derivative developers who view the work and decide whether they want to license it.
- users and developers of such media cannot be sure of the authorship or integrity of the media.
- Authenticity is thus sometimes increased by restricting access to the media, such as through the use of a password.
- a password-protected World Wide Web page provides some measure of authenticity, but also discourages the open and free propagation of the information in the media.
- media developers can utilize powerful encryption tools, readily available in the public domain, such as those tools based on the RSA public key algorithm (Rivest, Shamir, & Adleman, 1977).
- encryption to protect copyrights only serves to restrict access to the information within the media, like the password described above.
- the problems of copyright heritage and permissions for derivative development and use of the media remain.
- Other objects of the invention provide tools to acquire, publish, distribute, and disseminate multimedia objects to strengthen ownership and attribution of the underlying digital creative work.
- Another object of the invention provides systems and methods for packaging and unpackaging digital creative works within a data container to facilitate the management of that work.
- Another object of the invention provides systems and methods for attaching copyright notices and other attributes to digital creative works.
- Other objects of the invention provide for (a) locating source works of derivative authors of digital creative works, (b) obtaining releases and permissions to inco ⁇ orate another work or part of another work into the digital creative work, (c) determining the source and attributes of digitally creative works, (d) promotion of communication directly to the author or owner of the digital works, (e) security and authentication of transactions and the digital work, and (f) the automation of rights management, such as acquisition, administration, and authorization of digital creative works.
- Still another object of the invention provides systems and methods for packaging and unpackaging electronic media within an electronic container to facilitate the management of copyrighted electronic media.
- a "copyrighted work” means any work that is authored and protected by U.S. and international copyright laws, including, without limitation, literary works; musical works, including any accompanying words; dramatic works, including any accompanying music; pantomimes and choreographic works; pictorial, graphic, and sculptural works; motion pictures and other audiovisual works; sound recordings; and architectural works.
- "Electronic media” means any electronic form or digital representation of a copyrighted work.
- a "Digital Creative Work” means any electronic media, multimedia content element, electronic creative work, and in particular work such as authored and protected by U.S. and international copyright laws, including, without limitation, any of the followmg in digital or electronic form: literary works; musical works, including any accompanying words; dramatic works, including any accompanying music; pantomimes and choreographic works; pictorial, graphic, and sculptural works; motion pictures and other audiovisual works; sound recordings; and architectural works.
- a Digital Creative Work can include multimedia content elements that have two or more creative works, such as a digital image and associated digital audio.
- a Digital Creative Work includes any electronic form or digital representation of a copyrighted work, including multimedia objects, and including any form or digital representation (1) stored within computer memory or other electronic memory, (2) resident on CD-ROM and /or magnetic disk or tape, (3) transmitted as a digital file through email, an on-line service such as CompuServeTM, the World Wide Web (WWW), Intranet and /or the Internet; and (4) communicated as a digital file within or into a computer network, such as a LAN or WAN, and including any communication obtained through remote access.
- a computer network such as a LAN or WAN
- a Digital Creative Work can include, but is not limited to, digital embodiments of a creative expression, such as digital audio (eg: WAV, SND, AIFF, AU), digital music sequences (eg: MIDI), digital video (eg: AVI, MOV, MPEG), digital images and graphics (eg: GIF, BMP, TIFF, JPEG, FlashPix), word processing files (eg: DOC), and spreadsheet files (eg: XLS).
- digital audio eg: WAV, SND, AIFF, AU
- digital music sequences eg: MIDI
- digital video eg: AVI, MOV, MPEG
- digital images and graphics eg: GIF, BMP, TIFF, JPEG, FlashPix
- word processing files eg: DOC
- spreadsheet files eg: XLS
- CONTAINER means an electronic or digital entity that is constructed according to the invention to enable the use of, control of, access to, and /or licensing of the Digital Creative Work.
- the CONTAINER is a logical entity that is preferably based on object technology such as C, C++, Visual Basic, Microsoft's ActiveXTM Controls, Microsoft's OLETM Controls, Apple's OpenDocTM, and Sun Microsystem's JavaTM applet component technologies.
- a CONTAINER of the invention is a data container that includes a data portion with the Digital Creative Work, and an executable portion that typically adds functionality to Web Sites, desktop applications and development tools in order to manage that Digital Creative Work.
- a CONTAINER can be distributed through many channels, such as through the Internet, CD ROM, or magnetic media. Further, a CONTAINER can be formed of different parts that are located remotely to one another; though the different parts are linked to maintain attribution within the CONTAINER.
- "METADATA” refers to data associated or encapsulated with a CONTAINER and includes a plurality of data pertinent to copyright management, including, for example, ownership identification and contact information, rights administration identification and contact information, creatorship identification and contact information, an identification and address of a registration server, listings of antecedent and related objects, and licensing terms and conditions.
- a "DIGITAL CONTRACT” means a contract secured through licensing activity between a registration server and a user of a Digital Creative Work.
- the Digital Contract includes a textual expression of enhanced permissions for use of the Digital Creative Work and may or may not be accompanied by an upgrade ⁇ f the operational controls such as the ability to print, save and /or edit the Digital Creative Work.
- SYSTEM EXTENSION means an operating system extension or “plug-in” that each user obtains prior to use and /or manipulation of one or more CONTAINERS. Specifically, the SYSTEM EXTENSION operates in conjunction with the operating system of a computer to recognize CONTAINERS and to permit authorized operations on the CONTAINER'S METADATA and /or Digital Creative Works. When needed, the EXTENSION can and will be downloaded from various trusted locations and such as described herein so as to render Digital Creative Works within CONTAINERS. However, the EXTENSION is generally resident on a user's computer so as to obviate the need to continually download the EXTENSION and to improve network efficiency.
- OBJECT means an instantiation such as an icon, graphic or other visual, on a computer, which is, or which refers to, or which points to an object such as a CONTAINER.
- an OBJECT is viewable within an application such as a Web browser such that a user directly views authorized content of the Digital Creative Work.
- a user can select or "click" the OBJECT with a computer mouse to gain additional information in and to the CONTAINER and /or to obtain additional licenses to the OBJECT'S Digital Creative Works.
- the OBJECT thus instantiates the existence of the Digital Creative Work in a composition such as a CONTAINER.
- a Digital Creative Work within a CONTAINER is actually an image (i.e., the "OBJECT") on a user's computer.
- the user will view an OBJECT and not notice anything different about the Digital Creative Work until the user tries to operate on the OBJECT in ways that are prohibited. For example, when a user attempts to click on the OBJECT, or to print the OBJECT, or to copy the OBJECT to another file, or to attempt other operations that are restricted, the EXTENSION takes over and informs the user that such operations are prohibited without an additional license to the Digital Creative Work.
- An OBJECT can be formed of a group of OBJECTS.
- an OBJECT instantiates a CONTAINER which itself can exist locally, e.g., within internal memory, and /or remotely across one or more sites on the Internet.
- the invention communicates an OBJECT to a user through a file or a continuous data stream: in the first case, the OBJECT is rendered to the user after the complete data set is received; and in the second case the OBJECT is rendered as the data is received through the communication link.
- TOOL BOX or “TOOLBOX” means a software application that is used to create or augment a CONTAINER.
- the TOOL BOX is resident on a computer to facilitate the management of Digital Creative Works from the author or creator's desktop computer.
- PACKAGER means an application which creates or augments a CONTAINER.
- the PACKAGER operates in a batch mode and is used in high-volume generation of CONTAINERS for creators and owners of large amounts of digital creative works.
- the PACKAGER can package HTML documents, i.e., Web pages, so that a user of the Web page is actually within an OBJECT that is likely composed of other OBJECTs.
- a "VIEWER” refers to software and /or hardware which renders the Digital Creative Work of a CONTAINER to a user.
- a CONTAINER can be associated with a web page that is accessed by users of the Internet.
- the user's host computer calls on 3 the appropriate media "viewer" service registered with the computer's operating 4 system.
- the computer tells the 5 SYSTEM EXTENSION to do the rendering and the SYSTEM EXTENSION, in turn, 6 calls on a GIF viewer or Tenderer to display the GIF (i.e., the Digital Creative Work 7 in this example) to the user.
- a VIEWER can refer to rendering software of 8 JPEGs, AVIs, PDFs, MIDs, etc. Indirectly, the VIEWER is sometimes embodied with 9 the SYSTEM EXTENSION or as separate software specific to the invention so as to 0 render, for example, a Digital Contract.
- the EXTENSION when asked by the user 1 (e.g., with the "click” of a computer mouse), the EXTENSION renders the associated 2 Digital Creative Works with a VIEWER specifically designed to view the Digital 3 Contract.
- the VIEWER also refers to a computer subsystem, operable by a user 4 desiring to manipulate one or more CONTAINERS that contain either (a) a shell 5 extension which responds to direct manipulation, at the computer, of OBJECTS 6 referring to CONTAINERS, or (b) an object control, which is used to display 7 CONTAINERS - or portions of CONTAINERS - within other applications.
- an object control of the invention can include ActiveX Control that permits 9 display of an OBJECT, within an application such as a web browser, that links the o computer to the CONTAINER.
- REGISTRY generally refers to a registration server that registers CONTAINERS and which operates to manage Digital Creative Works.
- a user of a particular CONTAINER communicates to the REGISTRY via on-line communication to obtain auxiliary permissions to the Digital Creative Work therein.
- the CONTAINER contains information in the METADATA which specifies the "home" or licensing site assigned to the CONTAINER.
- the CONTAINER automatically prompts the EXTENSION to locate and connect with the assigned REGISTRY through Internet communication.
- the REGISTRY includes a separate registration server and an authorization server.
- the registration server is used to register CONTAINERS
- the authorization server is used to authorize auxiliary uses of CONTAINERS, such as to provide licensing to the Digital Creative Works therein.
- the REGISTRY is typically a single registration server that operates as a registration server and as an authorization server to negotiate licenses with on-line users of Digital Creative Works.
- the invention applies object technology to the Digital Creative Work to form a data CONTAINER including the data content of the Digital Creative Work and other attributes contained in METADATA.
- attributes can include operations, services and information that describe or operate on the METADATA and /or Digital Creative Work as appropriate to the user according to the minimum and /or auxiliary permissions granted within the METADATA.
- the attributes and content of a CONTAINER are distributed between (a) the local system, i.e., where a user views and /or manipulates the CONTAINER, and (b) a registration server to which it refers across the Internet.
- the registration server further can contain attributes that, for various reasons such as volatility, security, or efficiency, cannot or should not travel to the local system.
- a repository system provides file images, i.e., persistence data, of CONTAINERS as well as resources and data referred to by CONTAINERS but not held in attributes at the registration server.
- a user at a computer accesses a particular CONTAINER through a set of property pages (e.g., tabbed dialog boxes), or "templates," that are available through the CONTAINER wherever it appears.
- a set of property pages e.g., tabbed dialog boxes
- templates available through the CONTAINER wherever it appears.
- a mouse click onto the OBJECT brings up its associated property pages to show information and to provide access to features such as email and authentication to the associated digital creative work.
- creators or authors of digital creative works bind content and attributes into a CONTAINER; and register new CONTAINERS through a locally resident TOOL BOX which facilitates the flexible design of the CONTAINER'S property pages and feature selections.
- the TOOL BOX also automates the organization and maintenance of the heritage of the Digital Creative Work, such as when the CONTAINER includes works from various authors.
- one or more CONTAINERS can be, and preferably are, registered at the REGISTRY, which preferably is a secured registration server system remote from the viewing capabilities of the SYSTEM EXTENSION or VIEWER.
- the REGISTRY (a) retains information to validate the credentials and /or authenticity of a TOOL BOX, attempting to register a work, or a CONTAINER; and (b) supplies remote services and data.
- the REGISTRY can also supply attribute data obtained indirectly from a content provider's existing legacy database.
- access to OBJECTS is generally "open" such that any user can view the associated Digital Creative Work.
- the SYSTEM EXTENSION in this aspect is thus ubiquitous, as are most or all supplementary VIEWERS. That is, when a VIEWER is called by the EXTENSION, the invention preferably utilizes handshaking standard such as Microsoft's code signing standard. Such a standard uses digital signature technology that helps one application make sure that it is talking to the authentic version of another application. Accordingly, the SYSTEM EXTENSION in this aspect is sure to call the correct VIEWER and not some other viewer that does damage to the DIGITAL WORK or CONTAINER.
- handshaking standard such as Microsoft's code signing standard.
- Such a standard uses digital signature technology that helps one application make sure that it is talking to the authentic version of another application. Accordingly, the SYSTEM EXTENSION in this aspect is sure to call the correct VIEWER and not some other viewer that does damage to the DIGITAL WORK or CONTAINER.
- the invention provides a method of packaging a digital creative work, including the steps of: encapsulating the work within a data container; encapsulating metadata within the container; and integrating, with the container, means for accessing the work and the metadata.
- the step of integrating further comprises the step of integrating, with the container, means for rendering the work.
- the method can also include any of the following steps: integrating, with the container, means for printing the work; integrating, with the container, means for copying the work; integrating, with the container, means for viewing the work; integrating, with the container, means for controlling use of the work; integrating, with the container, means for limiting use of the work; integrating, with the container, means for disallowing use of the work; integrating, with the container, means for operating on the metadata; integrating, with the container, means for providing email to one or more external addresses; integrating, with the container, means for providing web access to one or more WWW addresses; integrating, with the container, means for providing interactive licensing to the work; integrating, with the container, means for providing a link to a digital contract for the work; integrating, with the container, means for updating the metadata; and integrating, with the container, means for displaying descriptive information.
- the descriptive information can include one or more of the following: authorship information, historical information, ownership information, date information, time information, and bibliographic information. It can further
- the method of the invention can also include the step of forming the data container as a plurality of associated data that are distributed across one or more of the following: a computer network, the Internet, a LAN, a WAN, an on-line service, and an Intranet.
- the work can be selected from the group of digital images and graphics, digital photos, digital audio, digital video, digital music sequences, word processing files, spreadsheet files, and mixtures thereof.
- the digital images and graphics can include JPEG, GIF, BMP, TIFF and mixtures thereof.
- the digital audio can include WAV, SND, AIFF, AU and mixtures thereof.
- the digital music sequence can include MIDI; and the digital video can include AVI, MOV, MPEG and mixtures thereof.
- the word processing programs can include, among others, Microsoft WordTM, Novell WordPerfectTM and mixtures thereof.
- the spreadsheet programs can include, among others, Microsoft ExcelTM.
- the step of encapsulating metadata can include the step of encapsulating copyright management information.
- the copyright management information can include any of ownership identification information, ownership contact information, rights administration information, rights administration contact information, creatorship information, authorship information, creator contact information, author contact information, listings of antecedent object information, listings of related object information, licensing terms, licensing conditions, publisher information, and ownership credits. These can further include email addresses, web access addresses, and mixtures thereof.
- the step of encapsulating metadata can further include the step of encapsulating registration data, the registration data identifying an associated registration server capable of administrating the data container.
- the metadata is modifiable and accessible through on-line communication with the registration server.
- the method can include the step of storing at least part of the metadata at a database of the registration server, or the step of down-loading at least part of the metadata from the registration server.
- the methods of the invention can also include the step of providing a user interface to the data container to review at least part of the metadata on a computer.
- the user interface is preferably displayable on the computer and is selectable by a user of the computer to modify information therein.
- the step of encapsulating metadata further includes the step of encapsulating, with the data container, minimum permissions data, the minimum permissions data specifying one or more operations that can be performed on the work without a license to the work.
- the step of encapsulating metadata further includes the step of encapsulating, with the data container, minimum permissions data, the minimum permissions data specifying a default contract to the work, the default contract specifying a minimum set of operations that can be performed by applications on the work.
- Such operations include drag and drop operations, printing operations, editing operations, activating operations, saving operations, and viewing operations.
- the step of integrating means for accessing the work and the metadata can include the step of integrating, with the container, one or more of the following: means for encoding the metadata, means for compressing the metadata, means for manipulating the metadata, means for encrypting the metadata, means for decoding the metadata, and means for decrypting the metadata.
- the step of integrating means for accessing the work and the metadata can include the step of integrating, with the container, one or more of the following: means for encoding the work, means for compressing the work, means for manipulating the work, means for encrypting the work, means for decoding the work, and means for decrypting the work.
- the step of encapsulating the work further includes the step of encrypting the work.
- the step of encapsulating metadata can include: the step of associating a metadata template with the container, the metadata template describing registration with a registration server; or the step of associating a metadata template with the container, the metadata template specifying properties of the container used to register the container with a registration server.
- a further step can include specifying, within the template, a display interface used to view the properties.
- the step of encapsulating metadata includes the step of associating a metadata template with the container, the metadata template identifying user-selectable optional properties of the container. Further, the step of encapsulating metadata can include the step of associating a metadata template with the container, the metadata template specifying requirements and rules associated with the work.
- Certain aspects of the invention include providing, with the metadata template, a user interface suitable for viewing information related to the metadata and the work; and /or providing different metadata templates corresponding to different types of works; and / or providing different metadata templates corresponding to different licensing models.
- One method of the invention includes, with the step of encapsulating metadata, the step of associating, with the container, operations that can be performed on the work.
- each registration server provides on-line administration of the container and has user-selectable registration templates for associating metadata with the container, at least part of the metadata being modifiable over a lifetime of the container.
- the step of encapsulating metadata can include the step of associating, with the container, requirements of specific parties having rights in or to the work.
- the requirements can include a requirement to obtain a license to the work prior to additional use of the work.
- the requirements can also include a requirement of obtaining information about entities desiring access to the work. Such information can include address and billing information of the entities.
- the entities can include one or more of an individual, a partnership, a company, a government agency, and an educational institution.
- the step of encapsulating metadata can include the step of encapsulating information indicative of one or both of an owner and creator of the media, and further include the step of communicating with one or both of the owner and creator through one or both of email and web page access.
- the steps of encapsulating can be made through object-based technology.
- the container is formed with object-based technology such as of OLETM, ActiveXTM, OpenDocTM, and hybrid OLETM / OpenDocTM.
- the invention also provides a method of accessing a digital creative work, including: installing a system extension onto a computer, the extension including (i) means for operating in conjunction with an operating system controlling the computer; (ii) means for accessing a data container having the work and metadata, including minimum permissions data, attached thereto, the minimum permissions data specifying one or more operations that can be performed on the work without a license to the work; and (iii) means for recognizing the minimum permissions data and for enabling a user of the computer to use the work in accord with the specified operations; and accessing the container and using the work in accord with the specified operations.
- the step of installing a system extension can include the step of distributing the extension to the computer with a computer operating system; and /or the step of distributing the extension to the computer from one or more content provider sites, the content provider sites creating the media; and /or distributing the extension to the computer with creativity tools; and /or utilizing image and graphic creativity tools selected from the group of Adobe PhotoshopTM, Fractal Design PainterTM, CorelDraw; and /or utilizing multimedia authoring tools selected from the group of Macromedia DirectorTM, Macromedia AuthorwareTM, Asymetrix ToolbookTM, Aimtech IconAuthorTM; and/ or utilizing web authoring tools selected from the group of Microsoft FrontPageTM, Adobe PageMillTM, Adode SiteMillTM, SoftQuad HoTMetaL ProTM, Corel Web.DesignerTM; and/ or utilizing sound editing tools selected from the group of Macromedia SoundEdit ProTM and DigiDesign Pro ToolsTM; and /or utilizing video editing tools selected from the group of Avid Media SuiteTM, Asy
- the creativity tools of the invention can include one or more of the following: Microsoft WordTM, Microsoft ExcelTM, Microsoft PowerpointTM, and Novell WordPerfectTM.
- the container is stored in a remote database, and the methods of the invention include the step of accessing at least part of the container through on-line communication with the database.
- the step of accessing part of the container through on-line communication can include one or more of the following: communication through the Internet, commumcation through a computer network, and communication through the Intranet; and /or utilizing a file data stream wherein rendering of the work is possible only after all data representative of the work is present at the computer; and /or utilizing a continuous data stream wherein rendering of the work is possible, in part, with concurrent arrival, at the computer, of data representative of the work.
- the container is stored on a CD-ROM, and the method includes the step of accessing that part of the container through communication with a CD- ROM drive.
- the container is stored on a magnetic data disk, and the invention includes the step of accessing part of the container through communication with a disk drive.
- the container is stored within internal memory of the computer, and the method includes the step of accessing part of the container within internal memory.
- the system extension includes means for recognizing registration data within the metadata, the registration data identifying an associated registration server capable of administrating the data, and the method includes the step of contacting the registration server to negotiate, on-line, a license to the work.
- An additional step can include contacting the registration server to negotiate for auxiliary permissions data, the auxiliary permissions data specifying auxiliary uses of the media that is licensed beyond the authorized use specified in the minimum permissions data.
- the extension can include: means for recognizing the auxiliary permissions data and for enabling the user to use the work in accord with i the auxiliary uses; and / or means for recognizing registration data within the
- the registration data identifying an associated registration server capable
- the auxiliary permissions specify a set of operations that can be i performed on the work after executing a digital contract to the work.
- the auxiliary 2 permissions are usually obtained through one of email or web access.
- 3 4 The invention also provides improvements to an operating system of the type 5 which facilitates control and commumcation of a digital data processor.
- a plug-in 6 extension is used to manipulate copyrighted electronic media, the extension having 7 means for opening a data container having a digital creative work and minimum 8 permissions data attached thereto.
- the minimum permissions data specifies one or 9 more operations that can be performed on the work without a license to the work. 0
- the extension recognizes the minimum permissions data and enables a user of the 1 processor to use the work in accord with the specified operations.
- the container can also have metadata attached thereto.
- the metadata 4 typically has one or more of ownership identification information, ownership 5 contact information, rights administration information, rights administration contact 6 information, creatorship information, authorship information, creator contact 7 information, author contact information, listings of antecedent object information, 8 listings of related object information, licensing terms, licensing conditions, publisher 9 information, and ownership credits, and wherein the extension comprises means for o reviewing the metadata selectively.
- the invention provides a plug-in operating system extension, including: means for operating in conjunction with an operating system controlling a digital data processor; means for recognizing a data container having digital creative works and mimmum permissions data attached thereto, minimum permissions data specifying one or more operations that can be performed on the work without a license to the work; and means for opening the container and enabling a user of the processor to use the work in accord with the specified operations.
- the container can have registration information attached thereto, the registration information specifying a registration server capable of administering the container, and can further include means for recognizing the registration information and for communicating with the registration server to acquire properties associated with the container.
- the container can have registration information attached thereto, the registration information specifying a registration server capable of administering the document, and can include means for negotiating a digital contract with the registration server, the contract specifying licensing terms and auxiliary uses to the work.
- a server for managing digital copyrighted works, including: (A) means for communicating with at least one on-line data processor connected for communication with the server, the on-line data processor having (i) means for recognizing a secure digital document having copyrighted electronic media and minimum permissions data attached thereto, the minimum permissions data specifying minimum authorized use of the media without a license to the media; and (ii) means for opening the document and enabling a user of the processor to use the media in accord with the authorized use; (B) m e ans f or registering the document according to user-selected options at the data processor; and (C) means for negotiating with the data processor to obtain auxiliary permissions to the document and for sending the auxiliary permissions data to the data processor thereby expanding the authorized use of the data processor.
- the invention thus provides several advantages. By way of example, it provides for identification of digital creative works so that potential licensees know, or can learn of, the owner, author, creator, and publisher of the underlying digital work.
- the use of the container, based in object technology, with METADATA and the Digital Creative Work attached thereto facilitates the appropriate identification of the Work.
- the METADATA provides tiie vehicle for identification information and minimum permissions to the Work, and further provides detail for subsequent licensing of the Work.
- the invention permits substantially seamless interaction between users and the Digital Creative Work.
- OBJECTs appear like any other visual instantiation on a web page. It is only after the user tries to operate on the OBJECT beyond the user's current consumption, e.g., viewing the OBJECT on the computer screen, when it becomes apparent that there is additional control associated with the OBJECT.
- the invention also provides for the secure electronic copyright management and automatic identification of ownership of creative works distributed as digital or electronic media, particularly over computer networks.
- one aspect of the invention provides a system which packages electronic media into a secure document format (the "CONTAINER"), including a data container for the media and a minimum permissions data set to specify the minimum authorizations needed to view or otherwise access the media.
- the CONTAINER can also include a container header, a container identifier, a source works extensions module which maintains a Bibliographical history of the media, and a digital signature to authenticate the media.
- the CONTAINER and the associated network-based tools described below and constructed according to the invention, enable the attachment of minimum permissions to copyrighted works and the subsequent on-line licensing of the media.
- the CONTAINER containing the media is registered on a registration server and licensed through an authorization server (together the "REGISTRY").
- Potential licensees view the CONTAINER through the authorizations within the minimum permissions data set, and communicate with the authorization server, if desired, to obtain a license to the media.
- the licensee can utilize the media in accord with an auxiliary permissions data set that is assigned to the CONTAINER during the on-line licensing transaction.
- the invention provides for the licensing of the media to creators of derivative works, i.e., those who modify an original work of authorship and who obtain authorization to do so through an augmentation in the permissions data set.
- the modified CONTAINER is then registered on a registration server and licensed through an authorization server.
- the CONTAINER in this aspect preferably includes a sourceworks extension module which records the original and derivative authorship of the media. By retaining such information, a copyright "family tree" or electronic bibliographic record is maintained for the media.
- the authorship information in the sourceworks extensions is resident as a data element within the CONTAINER.
- the sourceworks extensions can also be maintained on or through the authorization servers, depending upon the number of servers used in the registration of derivative uses of the media.
- the invention can also record any and all users who access the media.
- the CONTAINER includes a usage module which records selected information about each user who accesses the media.
- the selected information can include, for example, a unique address of the user, individual or company accessing or utilizing the media, or the actual identity of the user.
- the user information stored in the usage module is recorded and stored only after auxiliary permissions are augmented to the minimum permissions data set; and typically, the user's identity or location is recorded in the course of the licensing transactions with the authorization server.
- the usage module can also be resident with the CONTAINER, as another data element, and /or with the authorization server. In the latter case, each time a user communicates with an authorization server to license a particular media, the user's identity or location are recorded and stored therein.
- the invention provides several advantages in the automation and tracing of copyright clearances for both the initial users and derivative developers of electronic media. Unlike the methods in the prior art - i.e., the method of relying on copyright laws and treaties to protect copyrighted works, and the method of encrypting the media through electronic keys - the CONTAINER format and system architecture of the invention provide for (1) both fair use and ownership protection; and for (2) automatic management pf media rights, including the controlled access to media in derivative works. Specifically, the system of the invention attaches certain minimum permissions to a widely-distributed version of the media packaged as a CONTAINER, thus being generally usable for free personal use. The CONTAINER creator or author determines these minimum permissions in the spirit of fair use, and the permissions data set are subsequently updated to an auxiliary permissions data set through on-line licensing should the user be interested in more advanced licensing or uses of the media.
- the invention provides an encrypted electronic signature and optional data encryption, to enhance or guarantee the authenticity of the entire work, including authorship. More particularly, in other aspects, the CONTAINER encapsulates the required data in a secure fashion using encryption; and the digital signatures are based on message digests resulting from one-way hash functions.
- system of the invention utilizes client/ server system architecture based upon the TCP/IP network protocol standard.
- TCP/IP network protocol standard Those skilled in the art will appreciate that other network protocol standards can be used without departing from the scope of the invention.
- users can unpackage or unwrap CONTAINERS through a controlled environment, specifically from within a compatible application or program extension, i.e., a Plug-in, which can provide the requisite controls over document use.
- a compatible application or program extension i.e., a Plug-in
- the invention also provides a set of easy-to-use network-based tools for registering and administering copyrights of electronic creative works.
- a viewing module is provided to view and edit media-packaged graphic, image, video, audio, and textual objects.
- This viewing module referred to herein as a "VIEWER,” is generally required, along with the SYSTEM EXTENSION, to view and edit Digital Creative Works within CONTAINERS.
- a packaging module is provided to encapsulate a newly created work in a secure, digitally-formatted package - i.e., a CONTAINER.
- the packaging module referred to herein as a "PACKAGER,” is particularly useful to authors, creators and publishers who seek to secure their copyrighted works and who seek to encapsulate other information with the works, such as authorship, ownership, minimum permissions, and source works extensions. Accordingly, a user of the PACKAGER can selectively package such information with the media to formulate a CONTAINER.
- a registration server provides registration and authorization services on a platform such as Windows NT or Unix.
- the registration server is used by information creators who want users of their works to easily identify ownership and potential licensing terms, and to transact and license those works on-line.
- the Authorization server is used by information creators and users to obtain access to Digital Creative Works and to license those works for their own use.
- the registration server for each CONTAINER operates as the authorization server for all subsequent licensing transactions to that CONTAINER.
- the combination registration server and authorization server is a REGISTRY.
- the invention provides certain other advantages over the prior art in that creators and publishers of electronic media have direct control of the copyrights they hold through the use of authorization and registration servers. Further, the invention is preferably compatible with widely accepted object technology standards, e.g., OLE and OpenDoc, to ensure compliance with the widest possible range of applications and on several platforms.
- object technology standards e.g., OLE and OpenDoc
- the invention also provides for automated and controlled network-based copyright management.
- the registration server can be scaled to fit the needs of any authorization and registration service, from single-author shops to massive centralized clearinghouses.
- the VIEWER provides a mechanism for users to gain access to the data within copyrighted CONTAINERS. Specifically, the VIEWER and SYSTEM EXTENSION ensure that operations performed on media-packaged data objects are in compliance with the permissions that have been granted to the user.
- a user can transact a license to the CONTAINER through on- line communications with the REGISTRY. More particularly, the SYSTEM EXTENSION in this aspect (i) generates a licensing request signal in response to inputs by the user, and (ii) communicates that signal to the authorization server assigned to that CONTAINER.
- This request sometimes denoted herein as a "License Request,” provides an entry point for on-line licensing of media-packaged works. In this way, a successfully licensed user can obtain auxiliary permissions to the CONTAINER of interest, thereby extending the set of operations which the user may perform for a given work.
- the SYSTEM EXTENSION operates to display selected registry information about the CONTAINER.
- This display sometimes denoted herein as the "Registry Information Display,” provides information such as authorship, ownership, and the licensing terms associated with the electronic media, thereby facilitating the user's review and evaluation of the CONTAINER prior to licensing.
- the registry information is preferably stored in the CONTAINER itself, and / or at the CONTAINER' s registration server.
- a record of the media source works is also available through the SYSTEM EXTENSION, in accord with another aspect of the invention.
- the sourceworks extensions provide a bibliography of the authors of the media so that the appropriate authors are credited with their works even after the works are edited by a derivative author.
- the sourceworks extensions are typically available within a display - sometimes denoted herein as the "Source Works Display” - at the user's computer terminal.
- the SYSTEM EXTENSION provides standardized tools and procedures for obtaining a certified digital identification of a CONTAINER, and for becoming a licensed user to that CONTAINER.
- a PACKAGER encapsulates authorship, ownership, minimum use permissions, source works information and the associated creative works in a secure package.
- the PACKAGER has several aspects, including:
- a user can display the status of permissions for each source work, obtain authorship, ownership, and licensing information from the source work's registration server, and selectively obtain auxiliary permissions as required for each source work.
- the PACKAGER allows the author to check clearances for all sources of a work in progress and to engage in EXTENSION-like licensing transactions to obtain or upgrade auxiliary permissions.
- the PACKAGER allows the author to verify and modify the information that is encapsulated with the packaged media in a CONTAINER.
- Registration is the final step in setting up a CONTAINER in accord with the invention; and the PACKAGER provides a registration client and procedure for registering a new creative work.
- the PACKAGER provides standardized tools and procedures for obtaining a certified digital identification and for becoming an authorized user.
- SDK Software Development Kit
- the invention thus facilitates the management of copyrighted works and ensures that the media packaged within a CONTAINER is authentic.
- the invention further enables the packaging of useful and selective information with the creative work, such as container identification, ownership, permissions, and sourceworks extensions. These features are provided, at least in part, by the VIEWER, SYSTEM EXTENSION, PACKAGER and the REGISTRY.
- the registration server for example, information providers of any size can take advantage of rights management for their creative works, and users on a network connected to the server enjoy easy and secure on-line licensing of the works managed therein.
- the VIEWER, SYSTEM EXTENSION and PACKAGER do not impose perceivable overhead during the course of normal rendering or editing of the work.
- the execution of VIEWER, SYSTEM EXTENSION and PACKAGER functionality is quick to ensure that network functions have good performance within the available network bandwidth.
- VIEWER, PACKAGER, Registration Server Modules and Authorization Server Modules are operable on Win95, Windows NT, MacOS and Unix-based platforms.
- the VIEWER, SYSTEM EXTENSION and PACKAGER of the invention operate in conjunction with OLE and OpenDoc.
- the invention also provides a system for authorizing access to copyrighted electronic media.
- An authorization server is connected for data transfer between an internal memory and at least one external data processor, and an internal storage stores selected information about the electronic media, e.g., the licensing terms for gaining auxiliary permissions to the media, the copyright ownership of the media, and revenue estimates about the media.
- a relay section that is responsive to a request signal by the data processor communicates the selected information to the data processor.
- a data comparison section receives response signals from the data processor and compares the selected information with the response signals. In this way, the data comparison section generates an acceptance signal when the response signals correspond to at least a part of the selected information, and communicates the acceptance signal to the data processor to authorize access to the media.
- the system can also store the media within a storage memory, in another aspect.
- This memory can be within a computer connected for electronic data transfer with the data processor, whereby the computer is responsive to the acceptance signal to transfer either (1) authorizations to access the media or (2) the media to the data processor.
- the system preferably includes a process section for tagging an encrypted digital signature to the media, thus authenticating the media.
- Another section - including a source works extension module - can also be included to append a bibliographic record to the media, the bibliographic record forming a digital representation that specifies information that references each source work and access restrictions associated with the source work.
- the system can further include a section for appending auxiliary permissions to the media, the auxiliary permissions forming a digital representation that specifies an authorized use of the media, such as viewing, copying or editing the media.
- the system includes an access control section for withholding access authorization to a portion of the media, the access control section thus being responsive to the acceptance signal to remove access restrictions to the portion.
- permissions and access to copyrighted media can be provided to specified parts of a complex multimedia object, e.g., one which includes written text, graphics and sounds.
- the invention further provides a system which controls selective access to electronic media.
- the system includes one or more servers that communicate via a data transfer link between an associated system memory containing the media and at least one external data processor.
- a communication section communicates content-specific permission information about the media to the data processor, the permission information specifying data processor actions which are restricted and which require augmented access privileges to perform.
- a storage section enables the storage of selected other information about the media; while a relay section, responsive to a request signal by the data processor, communicates the other information to the data processor.
- a data comparison section receives response signals from the data processor and compares the other information with the response signals, the data comparison section generating an acceptance signal when the response signals correspond to at least a part of the other information.
- An access section restricts data transfers between the data processor and a portion of the media, the access section being responsive to the acceptance signal to remove data transfer restrictions between the data processor and the portion witiiin U e system memory.
- the communication section of this aspect can include one of (i) a stand-alone software module, (ii) a plug-in software module corresponding to an application environment that generated or modified the media, (iii) a program extension corresponding to an application environment which generated or modified the media, (iii) a software module integrated into an application environment by way of a source code library or linkable object code performing substantially similar functions.
- the invention also provides methods for authorizing data transfers of copyrighted digital media, including: affixing content-specific permission information to the media, the permission information specifying actions which are restricted and which require augmented access privileges to perform; storing selected information about the electronic media on an authorization server connected for data transfer with at least one computer; electronically communicating selected information about the media to the computer; receiving response signals from the computer and comparing the selected information with the response signals; and generating an acceptance signal when the response signals correspond to at least a part of the selected information, thereby authorizing access to the media.
- the invention also provides for optional encryption of the data within the secure container. Accordingly, the methods of the invention include, for example, the step of encrypting the media through an RSA public key algorithm.
- the method of this aspect can also include the step of communicating a digital representation of at least one of (i) a copyright ownership of the media, (ii) a set of licensing terms for the media for different user classifications, and (iii) revenue estimates about the media.
- a method for maintaining an electronic bibliographic record of digital media including: opening an object container containing the digital media, the object container including a representation of the media, a data identifier of media, and data specifying minimum permissions required to access the media; editing the digital media in an application environment; and attaching the data identifier and minimum permissions data to the edited media into a source works list.
- the source works list provides, among other information, a bibliographic record of the authorship represented in the media.
- Such a method can also include the steps of decrypting the media, and encrypting the media after attaching the data identifier and permissions data into the source works list.
- a method of the invention also includes a process for determining the authenticity of digital media, including the step of affixing an encrypted digital signature to the media.
- the CONTAINER is authenticated by encoding a signature representing the registration of the media.
- a private key is resident with the registration server which is under strict control of the system. The authenticity - in this example - is thus granted by the registration server and proven by the digital signature in the CONTAINER.
- the private key is provided to the user of a particular application, again under the tight control of the system.
- a computer network for managing original works of authorship, including: a process actuation section for affixing copyright information to a binary data element corresponding to an authored media; a process actuation section for affixing minimum permission information to the data element, the permission information specifying access restrictions to the data element; a server for storing information concerning the rights to the media, the server including a control module for controlling access to the data element according to the minimum permission information by restricting data transfers between the server and one or more computers networked with the server; a process section for tagging the data element with supplemental information; and a process section for maintaining copyright information through derivative uses of data element throughout the network.
- the invention also provides a PACKAGER, which is a system for packaging electronic media within a secure electronic container.
- the PACKAGER includes a first process section for attaching a data identifier to the media; and a second process section for attaching minimum permissions data to the encrypted media, the minimum permissions data specifying minimum acceptance terms required to electronically access the media.
- the PACKAGER includes a process actuation section for attaching a digital signature to the media, the digital signature providing an authentication to the media; and a process actuation section for affixing source works extensions to the media, the source works extensions specifying a bibliographic record of the media.
- This bibliographic record is a digital representation that specifies bibliographic information about the authors and minimum permissions of the media, thereby providing persistence through generations of derivative use of the media.
- a SYSTEM EXTENSION and VIEWER subsystem is also provided for unpackaging electronic media configured within a secure electronic container.
- a first process actuation section recognizing permissions data attached to the media, the permissions data specifying one or more authorizations needed to electronically access the media; and a second process actuation section opens the media when a user has the authorizations corresponding to the permissions data.
- the subsystem includes a communication section that engages an authorization server when the user does not have the requisite minimum authorizations of the permissions data set; or when a user desires to augment the permissions to a particular media by transacting a license to that media.
- the communication section thus includes a process section for transmitting transactional information to the server, and for receiving, from the server, auxiliary permission to utilize the media.
- the methods of the invention can include the steps of encrypting the media, and /or transferring the container to the data processor via one of point-to-point email, CD-ROM, ftp, gopher, smtp (email), and http (World Wide Web).
- the registration server first authorizes a user with a PACKAGER through log-in process to establish a secure line, such as known in the art.
- the user and PACKAGER then generate the registration information relating to the particular CONTAINER, and transmit the information and a message digest to the registration server.
- the registration server Upon receipt, the registration server returns a "registration certificate," in digital form, that is signed by the server's private key.
- the registration server's public key is widely known, so that the registration server can operate as a certification authority for the packaged-media.
- the registration certificate is then passed through secure channels, and the PACKAGER attaches the digital signature to the CONTAINER. Accordingly, authenticity is demonstrated to anyone with a VIEWER or PACKAGER that has access to the CONTAINER.
- the registration certificate is encrypted via public key to the user's public key.
- Figure 1 illustrates one system, constructed according to the invention, for managing copyrighted works formed as CONTAINERS;
- Figure IA illustrates a schematic view of one CONTAINER constructed according to the invention
- FIG 2 shows a schematic illustration of a VIEWER and SYSTEM EXTENSION subsystem, constructed according to the invention, and which is suitable for viewing selected information within a CONTAINER such as illustrated in Figure 1 A;
- 1 Figure 3 shows a schematic illustration of a PACKAGER system, constructed
- Figure 4 illustrates a schematic diagram of a system which is constructed
- Figure 5 shows one illustrated use of the invention in the management of io copyrighted GIF files
- Figures 5a and 5b show illustrative dialog boxes displayed to a user of the
- Figure 6 shows a computer network constructed according to the invention
- Figures 7-7h show illustrative computer displays for use with a system
- Figure 10 illustrates various components of the invention, including a
- Figure 11 illustrates a system, constructed according to the invention, for
- Figure 14 shows a representative property page template constructed according
- Figure 15 illustrates a template overlaid onto an OBJECT that instantiates a
- Figure 16 schematically shows a registration server system
- FIG. 1 illustrates a system 10, constructed according to the invention, 8 whereby CONTAINER 12a, 12b are created and packaged, and then registered on 9 associated registration servers 14a, 14b, respectively. Users 16a, 16b and 16c are 0 connected for data transfers with one or more of the authorization servers 18a, 18b, 1 such as through a computer network or the Internet.
- the illustrated CONTAINERS 12a, and 12b are created as copyrighted media by author 19 and user 16a, a derivative author of the work 12a. For example, media 13 is representative of original work of authorship.
- CONTAINERS 12a, 12b are packaged as a data container, according to the systems and methods described herein, and as denoted by the copyrighted ⁇ symbol marked over the media.
- These packaged CONTAINERS 12a, 12b are registered on servers 14a, 14b, respectively, and are made available for license through authorization servers 18a, 18b.
- a single server can operate as both the registration server and authorization server.
- the CONTAINERS 12a, 12b are available for limited free use according to the minimum permissions data set assigned to each CONTAINER.
- the minimum permissions allow users with access to the CONTAINER to view the CONTAINER, but not to save or otherwise transfer the CONTAINER without first obtaining auxiliary permission from the CONTAINER'S authorization server.
- users 16a, 16b each have access to CONTAINER 12a and may therefore freely read or view the contents of the media within CONTAINER 12a at their associated personal computers 17a, 17b, respectively.
- the users 16a, 16b attempt to act on the CONTAINER 12a in a manner which is not in accordance with the permissions they hold, they are automatically prompted to obtain a license to the CONTAINER 12a.
- the licensing transaction occurs through the authorization server 18a, which connects and communicates with the users 16a, 16b through personal computers 17a, 17b.
- the users 16a, 16b may, if desired, initiate a licensing transaction with the server 18a if they know, for example, that their permissions are insufficient to access the CONTAINER 12a in the desired way.
- CONTAINER 12a Once licensed to the CONTAINER 12a, the licensed user has augmented auxiliary permissions to utilize the CONTAINER in some other way, such as saving and /or modifying the CONTAINER.
- user 16c is connected via computer 17c to the authorization server 18b, and may therefore view and, if desired, license CONTAINER 12b through server 18b.
- the format of CONTAINERS 12a, 12b are described in more detail in connection with Figure IA.
- CONTAINER 20 of Figure IA provides a secure container for electronic media, including heterogeneous multimedia data types such as musical scores coupled with graphical images. More particularly, the CONTAINER 20 provides a package that encapsulates binary data objects, shown as the data container 23, and can contain some or all of the illustrated data components 21, 22, 24, 25 and 26.
- the Container Header 21 contains basic information about the CONTAINER 20, including, without limitation, information such as a unique file format identifier, a format revision code, a document creator application type, a file type (typically the MIME type code) of the enclosed data, a comment field length, and a comment field, typically up to about 256 characters.
- the information within Container Header 21 is generally not encrypted.
- the Container Identifier 22 uniquely identifies the CONTAINER 20 by the registration server upon which the CONTAINER has been registered, and the CONTAINER'S registration or index number on that server.
- This registration code typically contains the server name and registration index.
- a registration server cross- reference table, working in conjunction with the Internet's Domain Name Service (DNS), is used to find the actual network address (typically a TCP/IP address) of the registration server.
- DNS Internet's Domain Name Service
- a unique server code may indicate local registration, usually indicating a work in progress.
- an author logged onto a computer such as the author 20 of Figure 1, and actively generating a copyright work in progress, e.g., a novel in Microsoft WordTM, will update and store the work on the local computer.
- a work in progress is a locally accessible file which has not been authenticated through the registration process.
- the Data Container 23 contains the information representing the electronic media or Digital Creative Work, typically in an original file format. If desired by the author, this data can be secured through encryption, such as through secret or public key methods known in the art.
- the data within the Container 23 is usually passed in the clear, i.e., unencrypted. However, increased control can be obtained through encryption of the associated media.
- the fields within the Data Container 23 can include the enclosed data file, and can include the data container extension code, and the data container size, among other information.
- the Source Works Extensions 24 provides a bibliographic record, or 'persistence,' of copyright uses through generations of derivative work.
- the data fields within the Sources Works Extensions 24 can include any of the Source Works Extension Code, the Container ID, and the Permissions mask. If demanded by the licensor of the work, or desired by the licensee, the Container ID and the applicable permissions mask (the set of relevant use permissions) for the source work are included in the derivative work.
- the Source Works Extensions 24 are encrypted; and any number of Source Works Extensions 24 may be included in a CONTAINER 20.
- information about successive derivative authors of the CONTAINER 20 are stored sequentially as a Source Works Extension 24.
- one Source Work Extension 24 can include the release information for any performer whose image or audio likeness appears in the current CONTAINER.
- the Source Works Extensions preferably operates to protect the source works author, even at the risk of burdening the derivative author and /or developer.
- Authors can require that their work is included as a source works extension in a derivative work, or they can leave this choice to the editor or derivative developer.
- Authors can also request that their source works are not displayed. For example, they may require the derivative developer to go through the authorization process again to obtain permissions and to include information regarding the work.
- the Minimum Permissions 25 includes a permissions data set that are distributed with all authentic copies of the CONTAINER 20. These permissions affect the minimum use of the data within the Data Container 23 in cases where an on-line licensing transaction has not yet taken place.
- the Minimum Permissions 25 thus uphold the spirit of the fair use doctrine of copyrighted works; and the careful setting of the minimum permissions data set by the author(s) or creator(s) of the media ensures easy access and limited free use ⁇ _>f Uie media up lo the minimum authorized permissions set forth in the Minimum Permissions 20. This free use through minimum permissions is made possible by viewing the CONTAINER 20 through a SYSTEM EXTENSION, constructed according to the invention and described in more detail below, which is widely distributed to potential users of the CONTAINER 20.
- Minimum permissions 25 are superseded by auxiliary permissions which are assigned to the CONTAINER 20 during an on-line licensing transaction.
- Auxiliary permissions are preferably contained in secure License Certificate documents provided by the Registration Server and encrypted to the licensee's key.
- an encrypted Digital Signature 26 is also part of the CONTAINER 20, to facilitate authentication. While the Signature 26 can be encrypted to ensure the authenticity and integrity of the CONTAINER 20, encryption of the bulk data 23 is also possible to guarantee a higher level of security. Those skilled in the art will appreciate that other orderings of the information within the CONTAINER 20 are possible, including one where the Data Container 23 is last.
- CONTAINER 20 is viewable through the SYSTEM EXTENSION and, if needed, a
- VIEWER The VIEWER is available in several formats to accommodate the differing o types of media contained within the CONTAINER.
- documents formatted 2 within the Data Container 23 of Figure IA can be opened and manipulated on 3 compatible applications such as: 4 5 • Stand-alone VIEWER applications, with SYSTEM EXTENSION functionality 6 provided therein, which allow viewing of the media and of the networked 7 licensing and registration information.
- the CONTAINER 20 of Figure IA can also include information about the 9 successive users of the CONTAINER.
- the Source Works Extensions 24 o can have an appended data field or usage module which stores selected information about the users of the CONTAINER.
- usage information can include, for example, the identity and /or location of the user.
- the usage information can be stored at the associated authorization server during or in connection with a licensing transaction to the CONTAINER.
- the CONTAINER format of Figure IA augments the multimedia data content with supplementary information which identifies, without limitation, some or all of the following information: the source, registry, and format of the data; the copyright legacy of the data; minimum permissions to use of the data prior to on-line licensing; a digital signature to prove authenticity of the data; and a use record of the users who accessed ti e media.
- FIG 2 illustrates a VIEWER and SYSTEM EXTENSION combination system 30 constructed according to the invention and which is suitable for viewing the CONTAINER 20 illustrated in Figure IA.
- the system 30 includes a series of process actuators 32a...32f, each of which decodes and /or interprets the several elements of the CONTAINER 20.
- the system 30 is connected for data transfer along data transfer line 34 to communicate and operate on the CONTAINER 36, stored for example on a server.
- the several process actuators 32 thereafter operate, in combination, to enable viewing of the media within the CONTAINER 36 and in accord with the minimum permissions data set.
- This media is illustrated in Figure 2 as the data objects 38, which are, for example, displayed in a computer screen, through data transfer line 34a, so that a user can view the contents of the media data objects.
- the system 30 can be constructed as a printed circuit board, application specific integrated circuit, a VLSI circuit, or as a software module resident within a computer and operable in connection with an internal microprocessor to perform the various process actuator functions described below in connection with process actuators 32a...32f.
- the system 30 is connected for communication with a computer display so that once the CONTAINER 36 is unpackaged, the data objects 38 within the CONTAINER 36 are viewable to the user.
- the process actuator 32a inte ⁇ rets selected information about the container header, e.g., the header 21 shown in Figure 1 A.
- This information can, for example, include the type of file within the CONTAINER 36, or a comment field specifying certain details about the media as described by the media's author.
- Process actuator 32b likewise, inte ⁇ rets selected information about the container identifier, e.g., the identifier 22 of Figure IA.
- Such identifier information includes, at least, a unique identifier of the registration server upon which the CONTAINER 36 is registered, so that appropriate on-line licensing transactions can occur with the appropriate location.
- Process actuator 32c inte ⁇ rets - and sometimes decrypts - the data formulating the media 38, so that the user can view the media 38 to evaluate whether to engage in a licensing transaction.
- the process actuator 32c provides minimum access to the media 38 in accord with the minimum permissions data set which is associated with the CONTAINER 36 and which is loaded and inte ⁇ reted by the actuator 32d.
- Process actuator 32e inte ⁇ rets selected information about the source works extensions associated with the CONTAINER 36, while process actuator 32f interprets information about the digital signature associated with the CONTAINER 36, thereby providing a means to authenticate the media 38.
- Not all process actuators 32 are required in every system 30, depending upon the form of the CONTAINER 36.
- the system 30 must be able to inte ⁇ ret the data within the CONTAINER, including, if necessary, decrypt algorithms needed to unlock any encrypted data within the CONTAINER 36; and the system 30 must identify the CONTAINER'S minimum permissions as well as the connectivity information of the CONTAINER'S associated authorization or registration server.
- the system 30 will not, however, typically permit further actions - such as copying and /or downloading of the media 38 to disk - without first obtaining auxiliary licensing permissions from the associated authorization server, 1 as described in more detail below.
- the system 30 thus provides a minimum access
- the PACKAGER 40 includes a series of process actuators o 42a...42f, each of which operates to formulate one or more of the elements of the i CONTAINER 20, Figure IA.
- the PACKAGER 40 is connected for data transfer 2 along data transfer line 44 to communicate and operate on electronic media 46.
- the 3 several process actuators 42 thereafter operate in combination to package or 4 encapsulate the media 46 into a secure CONTAINER 48.
- a user of the 5 PACKAGER 40 is generally an author of copyrighted works, and one process 6 actuator is used to specify the minimum authorized use of the media within the 7 minimum permissions data set.
- the resulting packaged media illustrated in Figure 8 3 as the CONTAINER 48, is thereafter registered on a registration server, through 9 data transfer line 44a, so that the CONTAINER 48 is available for on-line licensing o transactions by any connected user having a SYSTEM EXTENSION and connected to 1 the authorization server.
- the PACKAGER 40 can be constructed as a printed circuit 4 board, an application specific integrated circuit, a VLSI circuit, or as software 5 module resident within a computer and operable in connection with an internal 6 microprocessor to perform the various process actuator functions described above in 7 connection with process actuators 42a...42f. .
- the PACKAGER 40 is 8 connected for communication with a registration server so that once the 9 CONTAINER 48 is packaged, the data objects 46 within the CONTAINER 48 are o available for license by any connected user.
- Sufficient information is packaged within the document format to enable a potential licensee using the SYSTEM EXTENSION to engage in on-line licensing transactions to obtain, for example, copyright ownership, licensing, and revenue information about the data. If the terms are acceptable, the potential licensee uses the SYSTEM EXTENSION to obtain additional permissions for derivative development or other use not covered in the minimum permissions data set. This operation is described below in connection with Figures 4-6.
- Figure 4 illustrates a copyright management system 50 constructed according to the invention. Specifically, Figure 4 illustrates how copyright permissions will be integrated into the multimedia production environment using the described CONTAINER format.
- the media is first formulated as individual content elements 52 that are created and authored by media-specific tools, such as text editors, graphics tools, audio design tools, and digital video production tools.
- media-specific tools such as text editors, graphics tools, audio design tools, and digital video production tools.
- the elements 52 would simply enter a multimedia asset library, ready for use in production. No copyright information whatsoever would typically be affixed to the data objects prior to archiving.
- system 50 content element-specific permissions are affixed to each data object 52 before passing on to the next level of production or on to archiving.
- the system 50 inco ⁇ orates a PACKAGER 54 within a stand-alone application to affix permissions and other related authorship information to the data 52, such as described in connection with Figure 3.
- the PACKAGER 54 can be directly integrated into the media- specific tools of the developers; and, as such, the PACKAGER 54 becomes a "plug-in" tool for commercially available graphics, video, and sound development applications based on the PACKAGER software kernel.
- the heterogeneous content elements 56 are registered on a registration server 58, and, for example, released to the production library.
- a multimedia authoring or scripting environment can be used to create an interactive multimedia program which is a composite of these archived elements 56.
- the control characteristics and asset utilization of the program embodied in the control "script" may also have an affixed permissions header. Thus all of the component assets will be protected in a similar fashion.
- a VIEWER and PACKAGER 62 can be utilized as a plug-in to the associated application software which generated the media of CONTAINER 60 in the first place, so that editing and saving of the CONTAINER can occur. Such modifications and saving correspond to a "derivative use,” as described herein.
- the system 50 thus provides an effective strategy for managing both in-house and externally obtained copyrighted assets.
- a two-tiered rights clearing scheme is provided for multimedia program integration, in which both the encapsulated minimum permissions and the auxiliary permissions of all inco ⁇ orated works are reverified prior to compilation.
- the specific content of this combination of permissions, including the permissions introduced by the creator of the composite work, will dictate what sort of authorization is required at execution time.
- Upon remote execution of the compiled multimedia program a spectrum of authorization schemes are possible, from free execution, to the networked authorization of individual copyrighted assets.
- the licensing functionality of the PACKAGER /VIEWER kernel is applicable during execution as well as during production.
- Figure 5 shows a system 70, constructed according to the invention, which only manages copyrighted GIF (graphics files) media.
- the GIF CONTAINERS are created and / or modified through VIEWER and / or PACKAGER systems, such as described herein, and are managed through a registration server.
- Figure 5 shows, in particular, initial document processing, use- based licensing, header and extension maintenance, source work copyright clearance, local and remote server registration, and encrypted file formatting.
- the system 70 is based on TCP/IP.
- the major functional sections of system 70 include opening files of appropriate types, creating and modifying headers and extensions, providing permissions clearance for included sources works and attached performance releases, and CONTAINER formatting, encryption, and saving. Each of these sections is described below:
- CONTAINERS are loaded into the system 70 once packaged by a PACKAGER.
- an original work 72 created in an application environment is opened in that environment and formatted by a PACKAGER into a CONTAINER 74.
- an existing CONTAINER 76 can be opened by a SYSTEM EXTENSION (and VIEWER if needed), modified if desired, and stored as a CONTAINER 74.
- media is opened and available to the user through a combination of the application which created the media (i.e., the VIEWER) and a SYSTEM EXTENSION.
- the applications which created the media i.e., the VIEWER
- a SYSTEM EXTENSION In the case of raw GIF files, the images are displayed and a header editing dialog box appears to the creator, such as shown in Figure 5a, indicating that the system 70 is ready to start the formatting process.
- a dialog box appears listing basic information for the main file, such as shown in Figure 5b; and similar information is listed in a scrolling window for each of the Source Works.
- CONTAINER'S mimmum permissions (obtainable and resident, for example, within any CONTAINER) and any auxiliary permissions (obtained from an authorization server during a licensing transaction) will dictate how the opened file may be used.
- the publicly distributed CONTAINER files will typically have sufficient minimum permissions to allow local viewing, at least, and sometimes unlimited local derivative use.
- Publicly-distributed files which allow local viewing can be opened by the SYSTEM EXTENSION (and VIEWER, if needed); and files which require licensing to be opened, or working files which have not yet been publicly registered, must be opened with the user's key.
- auxiliary permissions files Publicly distributed files are registered on a registration server, and if encrypted, the key resident on the server is passed to the user via a secure channel. Some of these files will require licensing at viewing time, meaning that auxiliary permissions must be obtained. The auxiliary permissions files, or certificates, will be encrypted based upon the registered user's key, as are works-in-progress (not registered, and possibly with incomplete sources works clearance).
- the Container Header e.g., the header 21 of Figure IA
- the Container Header is primarily derived from attributes of the enclosed media within the CONTAINER. These attributes are displayed in the Doclnfo Editor and Viewer windows shown in Figure 5a.
- the Container ID e.g., the ID 22 of Figure IA
- Non-local document IDs can only be assigned if there is a valid registration certificate associated with the file.
- Local Container IDs are encrypted, but can only be changed by the document owner.
- Container ID maintenance is typically handled through a computerized dialog box.
- the Container ID information is displayed in a scrolling view for the set of source works associated with the current file.
- a dialog box allows the CONTAINER IDs of additional works to be specified. Permissions information can be obtained by double-clicking an entry on this list.
- a transaction with the registration server 78 of the source works 72, 76 may be initiated by selecting the appropriate CONTAINER ID. Note that the user may choose to ignore clearances for locally-generated source works.
- system 70 will not allow on-line registration to take place unless the permissions of the included source works (plus any auxiliary permissions) agree with the intended minimum permissions and maximum licensable permissions, the latter to be set at registration time.
- the registration server 78 will not allow registration unless it is proven that the source works are clear. Clearances are required for those source works extensions with insufficient minimum permissions for the intended distribution of the derivative work. These clearances are in the form of auxiliary permissions, obtained on-line with licensing transactions identical to those discussed earlier. Given the intended minimum and licensed maximum permissions, the Source Works Manager Window displays those source works whose permissions need upgrading. The user will then select each one individually to launch a licensing transaction. Clearances that are encrypted are based on the user's key, and therefore cannot be transferred.
- Private works, or works-in-progress, may not require registration, but any works which are to be publicly distributed — and, for example, encrypted using a secret key — must be registered. Users must therefore demonstrate that all source works in system 70 have been cleared prior to the registration attempt. Upon successful registration, the user of system 70 will receive an encrypted registration certificate which facilitates the saving of the CONTAINER in a publicly-viewable form. Since registration and authentication is based on a unique message digest for the file, if any changes are made to the file a new message digest must be calculated and the CONTAINER'S entry in the registration server database must be updated.
- Encrypted data is preferably formatted with a secret key that is generated at the encryption event, and transported using public key encryption.
- Applications compatible with system 70 are preferably based on TCP/IP, and therefore operate in the same manner as most popular Internet-compatible users.
- a PACKAGER of system 70 saves files in the CONTAINER format, such as described above, and preferably encrypts the data therein.
- Exemplary encryption schemes according to the invention include, without limitation:
- Encryption is initiated by the user, who also generates the secret key which is passed to the server, by secure means, and which becomes part of the registration record for that work. Upon the grant of auxiliary permissions, the server passes the key to the licensed user as part of the certificate. This is intended for publicly registered and distributed files, and a CONTAINER is not encrypted in this way without being registered first. • Encryption based on the author's key. All local works-in-progress may be encrypted in this way, ensuring that local use is possible but unregistered public use is not. • Encryption based on another user's key. This permits collaboration while protecting the collaborative work.
- a CONTAINER 74 may be freely distributed.
- Derivative users 80 can gain clearance to the CONTAINER 78 through the SYSTEM EXTENSION (and VIEWER, if needed) and in accord with the minimum permission of the CONTAINER and the auxiliary permissions from servers of all source works.
- the work 82 represents either work in progress, or publicly available work; and can be encrypted, such as described herein.
- Figure 6 illustrates a computer network 90, constructed according to the invention, for managing copyrighted electronic media.
- an original author 92 generates and packages electronic media 93, e.g., such as described in connection with Figure 3, and registers the CONTAINER 93 on registration server 94.
- the author 92 generates the work 93 on a computer that is connected to the network via data transfer line 96.
- the server 94 becomes an authorization server for any subsequent access and /or licensing of the CONTAINER 93.
- user 96 has a VIEWER and is connected to the network 90 through communication line 97.
- the user 96 can thereby access the CONTAINER 93 through the authorization server 94 up to the minimum permissions data set forth in the CONTAINER format.
- the minimum permissions permit viewing of the CONTAINER; but do not permit saving and / or transmission of the CONTAINER.
- the authorization server 94 can license the CONTAINER through an on-line licensing transaction with the authorization server 94 to obtain additional authorizations - denoted herein as auxiliary permissions - to use the media within the CONTAINER for some other use, e.g., saving or modifying the CONTAINER.
- a Derivative User /Author 100 of the CONTAINER can access and modify the contents of the CONTAINER by first obtaining auxiliary permissions to do so through the authorization server 94. More particularly, the author 100 first views the CONTAINER via the SYSTEM EXTENSION (not shown) and VIEWER and through the minimum permissions data set of the CONTAINER; then transacts a license with the Authorization server 94 to obtain the auxiliary permissions.
- the author 100 is thus connected via data transfer line 102 to the server 94; and has a SYSTEM EXTENSION, VIEWER and PACKAGER resident at his computer (note, for illustrative pu ⁇ oses, the Users and Authors 96, 100 and 120 of Figure 6 are shown with limited detail; and generally include a computer with SYSTEM EXTENSIONS, VIEWERS and/ or PACKAGERs resident at the computer).
- the CONTAINER is registered on registration server 104, through data transfer line 103, so that subsequent licensing can occur by users such as user 110.
- user 110 must obtain licensing authorization from each server 104 and 94. This process is done automatically at the user's computer terminal.
- the user 120 first accesses the modified CONTAINER through the network 90 and by connection with the server 104 through data transfer line 105.
- auxiliary permissions are obtained by connecting to each of the servers 94 and 104 through data transfer lines 107 and 105, respectively.
- Derivative author 112 connected to the server 104 via data transfer line 114, operates a VIEWER and PACKAGER (and, if desired, a SYSTEM EXTENSION) in an SDK environment.
- the SDK indicates a "Software Development Kit” and enables developers of advanced multimedia applications, games, or multimedia authoring tools (including content creation applications) to inco ⁇ orate System Extension, Viewer and Packager functionality into their applications in advanced ways.
- the SDK is appropriate, for example, when conventional OLE 2.0 compliance does not deliver the functionality or performance that the ISV demands.
- the author 112 edits and creates multimedia works and packages them through the PACKAGER resident in the SDK to provide for registration and subsequent licensing of tiiat work.
- sourceworks extensions are used.
- This extension can be resident within the CONTAINER, such as shown in Figure IA, so that the appropriate CONTAINER authorship and /or ownership is recorded and stored in the appropriate data element within the CONTAINER.
- the sourceworks extension is stored on any and all of the servers 94 and 104. In this way, the owner or authors of the CONTAINER can ensure persistence through generations of derivative use.
- use information can also be stored within the sourceworks extension, so that, for example, an owner of the server 94 or 104 can independently track the use of his or her copyrighted works simply by downloading the information at the server 94 or 104.
- each of the servers 94, 104 are owned and operated independently from the other.
- one typical owner of the server 94 is a multimedia house which generates copyrighted works for sale and distribution. Such an owner thus seeks to restrict access to the media to authorized users, thereby protecting the copyright.
- Each of the servers 94, 104 also provides selected use-base information about the CONTAINERS registered and licensed through the servers. Specifically, the selected use-base information provides a way to assess charges to the owners of the servers for services rendered in connection with the servers 94, 104.
- the use-base information is available by physically accessing the server 94, 104; but is more conveniently obtained by phoning the server and downloading the information directly. This information is not available for general users; but is typically available only to the administrator who set up the servers 94, 104 in the first place. This administrator can, for example, receives fees from the respective owners of the servers 94, 104 as part of this arrangement.
- Such an administrator would make revenue for several transactions and sales shown in Figure 6, including: (A) registrations of CONTAINERS on both registration servers 94, 104; (B) one licensing transaction for auxiliary permissions for user 96; (C) two licensing transactions for auxiliary permissions for user 110; (D) two PACKAGER modules resident at the computers of Author 92 and Derivative Author 100; (E) two registration modules to configure the servers 92, 104; and (F) one SDK module resident at author 112 (typically, the SDK includes a SYSTEM EXTENSION, VIEWER and PACKAGER).
- the network 90 can include a multitude of registration and authorization servers; and any connected computer which has the SYSTEM EXTENSION (and VIEWER, if needed) can access media on the network up to the minimum permissions authorized by the minimum permissions data set within the CONTAINER housing the respective media.
- the VIEWER allows viewing and editing of graphic, image, video, audio, and textual objects that are packaged into a CONTAINER in accord with the invention. Where objects are individually packaged, viewing and editing will be done within the window of the source application or designated viewer. Where objects are content elements within a compound document, in-place viewing and editing will be common, with an external window session being optional. Data objects - i.e., media - that are packaged according to the invention can be dragged and dropped, for example, between OLE 2.0-compliant applications such that all attribute information contained in the CONTAINER remains intact during such an operation.
- the SYSTEM EXTENSION is required for viewing and editing any CONTAINER.
- the PACKAGER and TOOLBOX are complementary to the SYSTEM EXTENSION and one is required to package media within a CONTAINER, e.g., the CONTAINER 20 of Figure IA.
- the PACKAGER or TOOLBOX is required to create derivative works from a CONTAINER; but only the SYSTEM EXTENSION is required by developers when the minimum permissions of the source works do not require clearance. This might be common for so-called "public domain" free use of works.
- the SYSTEM EXTENSION examines certain attribute information encapsulated with the data object in compliance with the CONTAINER format. Operations on the data object from within the VIEWER or editor are restricted based on the minimum permissions encapsulated with the data object and any Auxiliary Permissions subsequently obtained for the data object.
- the "Container Info" window of Figure 7 provides a local summary of the document, including all available minimum and auxiliary permissions.
- the SYSTEM EXTENSION also facilitates on-line licensing of CONTAINER- packaged works. Based on registration information encapsulated with the data, i.e., the Container ID, the SYSTEM EXTENSION contacts the CONTAINER'S Registration Server and initiates an authorization transaction. After the user is authenticated (typically utilizing the user's RSA digital signature, whereby the user's key is stamped by a certification authority), the user uses a template-like interface to request auxiliary permissions, such as shown in Figure 7a. If the permissions request does not match the user's requirements, the request may be edited, such as shown in Figure 7b. Based on the available Transaction Rules in the database for the user's classification, licensing terms are presented to the user, such as shown in Figure 7c. If the terms are accepted, a digital certificate is issued containing the auxiliary permissions for that specific derivative use and encrypted to that specific user.
- the License Request window is the entry point for licensing transactions.
- the Registration Server is identified and the set of requested permissions is displayed. If the User recently attempted an unauthorized operation, the permissions displayed are those required by that operation.
- the user has the option to edit the request, such as shown in Figure 7b, to proceed with the transaction, or to cancel out.
- a License Agreement exemplified in Figure 7c, is returned to a display terminal of the requesting user.
- This interface such as shown in Figure 7c, allows the user to verify the terms of the agreement and to agree to those terms.
- the SYSTEM EXTENSION can be used to obtain extensive information about the authorship, ownership, and licensing terms of a creative work prior to any licensing transaction.
- This information may be a combination of data permanently encapsulated with the object, including for example authorship and basic document information, and information stored on the registration server, including for example copyright ownership, licensing terms, royalty schedules, and other augmented document Information.
- Figure 7d illustrates the typical information which is available from the Registration Server and which can be displayed in a Registry Info window.
- the SYSTEM EXTENSION can also be used to obtain source works information for the media object.
- the Sources Works Display for example and as shown in Figure 7e, presents the electronic record of any work from which the current work is derived, and the available information about each of those works.
- a user who wishes to engage in an on-line transaction with a REGISTRY typically presents an RSA-based, network-standard digital signature signed by a recognized Certification Authority.
- SYSTEM EXTENSIONS and PACKAGERS can contain RSA-based standardized procedures for creating and managing public /private key pairs, for engaging in certification transactions, and for becoming registered users.
- the Certification authorities require human intervention when authenticating an individual's personal information. When valid information is received, the individual's key is stamped with a unique code from the Certification Authority which recognizes its authenticity. This certification is apparent before anything is encrypted to that key, and is apparent when the key is used to verify a digital signature (which can only have been signed by the individual using the matching key).
- CONTAINER-packaged works and which demand clearance for derivative use.
- the PACKAGER maintains a list of all 2 CONTAINER-packaged source works, their minimum permissions, and any 3 auxiliary permissions which have been granted to the current work in progress.
- the 4 Source Works Manager window such as shown in Figure 7f, allows the developer to 5 easily see the status of permissions for each work, to obtain detailed authorship, 6 ownership, and licensing information from the source work's registration server, and 7 to selectively obtain auxiliary permissions as required for each source work.
- the user can command the display of all CONTAINER- o packaged source works from the Source Works Manager window of Figure 7f .
- the user may review the minimum permissions and, if 2 available, any auxiliary permissions which have been issued. If the user chooses to 3 obtain auxiliary permissions or to upgrade the current set displayed, a licensing 4 transaction is initiated with the source-work's registration server. 5 6 Alternately, the PACKAGER can prompt the user to upgrade the permissions. 7 This happen during the registration process in the following way: after preparing the 8 CONTAINER data for the derivative work, including the requisite minimum 9 permissions, the user executes a Check Clearance, wherein all accumulated 0 permissions are checked against the minimum permissions which the developer intends to encapsulate with the derivative work. All sourceworks with permissions that are insufficient will be listed in the Clearance Status window.
- the Check Clearances function is also applied to the set of Transaction Rules which the developer intends to load on the Registration Server.
- the basic principle is that a derivative work may not grant more rights to the use of a source work than what was available before the derivative work was created.
- CONTAINER information which is encapsulated with the data object by the PACKAGER is prepared from context automatically.
- Other information can or should be manually entered or selected by the user through the a dialog window such as the Doclnfo Editor Window of Figure 7g, such as:
- the revision number identifies a version of the document format which the PACKAGER complies with.
- Minimum Permissions As described above, the minimum permissions template provides a way for the user to generate the minimum permissions that are encapsulated in the CONTAINER.
- One acceptable set of permissions such as shown in connection with the Minimum Permissions Editor window of Figure 7h, includes: Opening /Viewing restricted
- Source Works Extensions The identification of source works extensions is managed by the Source Works Manager, described, in part, in connection with Figure 7f.
- the author of the works can also track unregistered or non-CONTAINER-packaged source works using the Source Works Manager, which allows authorship and ownership information to be textually entered into the Registration Server's database when the derivative work is registered. When information or authorization is requested, only contact information will be provided.
- the Digital Signature provides authenticity and integrity of all information contained in the CONTAINER.
- One secure way to do this is to attach a RSA digital signature to the CONTAINER, which is provided by the registration server upon license. The author is a registered user in this case, and the CONTAINER is registered on a Registration Server. Appropriate evidence of certification and the CONTAINER'S hash results are contained in the signature.
- the PACKAGER can also enable encryption of the media within a CONTAINER. If an author chooses to encrypt the media, a random key for the media is generated; and during a secure registration transaction with the registration server - such as after a log-on and once the author proves she is authorized to use the server - the secret key is passed by either (i) a secure communication channel, or (ii) a certificate that is public-key encrypted to the user's key, so that only that user may use that issuance of the secret key.
- This encryption method provides for strong security since secret keys are randomly generated and are unique to a CONTAINER; and the distribution of the key to the CONTAINER is handled by the server.
- the Software Development Kit (the SDK) enables developers of advanced multimedia applications, games, or multimedia authoring tools (including content creation applications) to inco ⁇ orate SYSTEM EXTENSION, VIEWER and PACKAGER functionality into their applications in advanced ways.
- the SDK is appropriate, for example, when conventional OLE 2.0 compliance does not deliver the functionality or performance that the ISV demands.
- the SYSTEM EXTENSIONS, VIEWERs and PACKAGERs of the invention operate with most OLE 2.0-compliant content creation tools and with most tools that create compound works.
- the SDK permits the developers to follow their own coding standards but still take advantage of the invention.
- the Registration Server of the invention contains the set of services used by information creators who want users of their works to be able to easily identify ownership, obtain licensing terms, and license those works on-line.
- the Authorization Server module is the set of services those information users (who may also be information creators) will use to obtain access to information and license those works.
- the Server maintains a database of registry information pertaining to creative works which rights-holders are making available for commerce.
- the process of initiating a database entry for a work is called Registration.
- the act of processing a user's request for augmented permissions is called Authorization or licensing.
- the PACKAGER does the following:
- the PACKAGER guides the user through the series of authorization transactions required to get the necessary permissions. • When sourceworks clearances are complete, the PACKAGER performs a one-way hash function contained, for example, in an RSA Digital Signature and which become part of the works' database record for later authentication.
- the PACKAGER test ifies to the Server that the user is authentic and that all sourceworks (if any) used in the work being registered have been properly cleared.
- the Server assigns a unique registration ID to Uie CONTAINER (based, for example, on the server's ID and the number of documents registered on the server) and builds the database record based on the information held by the PACKAGER.
- the PACKAGER preferably assembles a RSA Digital Signature for the package. Contained within the signature are the registration ID and the results of the one-way hash on the document data. The signature is encrypted to the User's key, thus demonstrating authenticity.
- the SYSTEM EXTENSION does the following: • Determines that available permissions (minimum and auxiliary) are not sufficient to perform the user's desired action. • Verifies that the user is a registered, which is required only if a transaction with the Server is necessary. • Testifies that the user is registered and presents the authorization request (a request for specific auxiliary permissions) to the Authorization Server. The user's classification is also transferred and stamped with certification from the associated Certification Authority.
- the Server Based on the requested auxiliary permissions and the classification of the user, the Server presents its terms for licensing. These terms are viewable within a display window and can include, without limitation, any of:
- the systems and methods of the invention encompass novel methods and tools which will enable creators of networked multimedia programs to identify their media and to claim their rights. This is enabled, in part, by bundling the copyright information with the data element, and by formatting the CONTAINER in a manner which maintains this identification and attribution so that it persists with the copyrighted work through generations of derivative use.
- the invention therefore demonstrates the application of copyright permissions to a hierarchy of network- distributed data objects to effectively protect owners' rights.
- This invention also facilitates the licensing of multimedia content by different classes of users.
- a desktop tool can be integrated with selected viewing or production tools to feature an interactive licensing template. The invention thus demonstrates the integrated support of hierarchical permissions headers in the production environment, and demonstrates networked interactive licensing within the production environment based on hierarchical permissions.
- Figure 8 illustrates one acceptable process flow for managing copyrighted works in accord with the invention and corresponding to the methods and systems described herein.
- FIG. 9 illustrates a system 200 constructed according to the invention.
- the system 200 includes a server 202 which operates as a registration and authorization server for any of the CONTAINERS 204a, 204b, 204c, and 204d stored in a library 206.
- the library 206 can be a publisher's library of any or all of the original works owned by or authored for the publisher.
- Author 208 illustrates one such author connected to the library 206 through a personal computer 210 and communication line 212.
- the computer 210 is a data processor that includes a PACKAGER 214 constructed according to the invention and as described hereinabove.
- the PACKAGER 214 is a software module stored within the computer's internal memory 210a to control the data processor's actions in accord with the invention. Through the PACKAGER 214 , the author 208 can create and package any of the CONTAINERS 204.
- the computer 210 also includes a communication section 210b, to facilitate on-line communications, and a computer display 210c.
- the CONTAINERS 204 are secure containers of electronic media, as described herein, and are stored in the library 206 as digital files, such as within a CD-ROM, or within a computer memory.
- the CONTAINERS are stored such that a user such as User 216 can access the CONTAINERS through an on-line connection 218 between the user's personal computer 220 and the library 206.
- CONTAINER 204e represents a CD-ROM of a media-packaged work that is distributed to the User 216 by mail.
- the CD-ROM 204e for example, exemplifies one other published work that is created by the author 208 and packaged by the PACKAGER 214.
- the server 202 also functions as the registration and authorization server for CONTAINER 204e.
- ti e user's computer 220 is a data processor tiiat includes a SYSTEM EXTENSION 222 constructed according to the invention and as described hereinabove.
- the SYSTEM EXTENSION 222 is a software module stored within the computer's internal memory 220a to control the data processor's actions in accord with the invention.
- a CD-ROM 224 drive is preferably connected to the user's computer 220 via data line 220d to facilitate access to CD-ROM files such as CONTAINER 204e.
- User 216 can access any of the CONTAINERS 204a-e up to the minimum permissions authorized by each of the CONTAINERS.
- the minimum permissions data set within each CONTAINER typically authorizes the User 216 to view the CONTAINERS 204a-e; but not to download, modify, save or otherwise electronically transfer the CONTAINERS.
- the data transfers required to access the CONTAINERS 204a-d up to the minimum permissions data set occur through communication line 218; while the only data transfers required to access the CONTAINER 204e up to its minimum permissions data set are between the computer 220 and the CD-ROM drive 224.
- the data processor 220 thus includes a communication section 220b that is connected for data transfers, over communication line 226, with a compatible communication section 202a of the server 202.
- the VIEWER 222 determines from the selected CONTAINER 204 that authorization server 202 is assigned to handle all licenses to that CONTAINER, and the SYSTEM EXTENSION controls the computer 220 to connect to the server 202 at the right address so that an on-line licensing transaction can occur.
- the SYSTEM EXTENSION can display selected terms to the CONTAINER, as stored within the CONTAINER or as stored within the server 202. In either case, the SYSTEM EXTENSION causes the computer 220 to generate a licensing request signal and issue that signal to the server 202. Preferably, the user 216 also designates - through the SYSTEM EXTENSION - the desired use of the media within the CONTAINER. The user 216 can thereafter accept the licensing terms to the CONTAINER 204, and, if accepted, the user 216 receives notification from the server 202 that auxiliary permissions are granted for the desired use.
- CONTAINER 204 is a derivative work
- the SYSTEM EXTENSION 222 determines that auxiliary permissions are also required, for example, from server 228, the server designated by the original author of the media within CONTAINER 204.
- the server 202 stores transactional information about the CONTAINERS 204. For example, each license transacted through the server 202 is stored in a file 229a, such as within a computer memory 230. In this way, the owner or administrator of the CONTAINERS can assess the licensing fees generated by the CONTAINERS. Likewise, the server 202 also stores information or files 229b that set forth the number of CONTAINERS registered thereon, so that, again, the owner or CONTAINER-administrator can assess server usage.
- the files 229a, 229b are preferably available through the communication section 202a.
- the server 202 includes an internal memory 202b, connected to the communication section 202a, that stores selected information about the CONTAINERS registered thereon. For example, licensing terms to the CONTAINER 204 can be stored within the memory 202b.
- a relay section 202c operates to relay such terms to the processor 220 in response to a license request signal prompted by the user 216.
- a data comparison section 220d operates to compare the user's reply to the licensing terms, and to generate and transmit the requested auxiliary permissions when the response signals correspond to the requisite terms specified in the license information stored in memory 202b (or alternatively in the CONTAINER).
- the user 216 receives the auxiliary permissions, that user is provided with additional authorizations to use the media within the CONTAINER 204; and the SYSTEM EXTENSION 222 enables the user 216 to access the CONTAINER 204 up to the maximums allowed in the bumped-up permissions data set.
- FIG. 10 illustrates a system 298, constructed according to the invention, and provides a brief description of several components of the invention; and further illustrates certain relationships between such components.
- the system 298 provides for the making and manipulation of CONTAINERS 300 and 301.
- a CONTAINER such as CONTAINER 300 can occupy a single block of memory such within memory 302 (e.g., memory 302 can be solid state RAM within a computer 304, or ROM memory within a web server 304).
- Each CONTAINER has one or more Digital Creative Works and Metadata.
- the CONTAINER 300 for example, has DIGITAL CREATIVE WORK 306 and associated METADATA 308.
- the WORK 306 is the electronic expression created, for example, by an author or publisher, and is shown as a letter "Z" for clarity of illustration.
- the METADATA 308 provides selected information about the WORK 306; and such information can include, for example, the author's name, the minimum permissions or minimum authorized uses of the WORK 306, and licensing details.
- a CONTAINER can also occupy a plurality of locations on the Internet 307. This is illustrated by CONTAINER 301, which has several parts 301a, 301b and 301c linked through the Internet 307. As illustrated, for example, the CONTAINER 301 includes DIGITAL CREATIVE WORK 310a and 310b, each at a different location 312a, 312b, respectively; and METADATA 314b and 314c, each at a different location 312b and 312c, respectively. For illustrative pu ⁇ oses, location 312c is here shown as a REGISTRY 316 that serves as the registration server for CONTAINER 301.
- the computer 318 illustrates one of a number of users of the Internet 307.
- computer 318 typically houses web browser software 320, such as Internet ExplorerTM, within internal memory 322.
- the computer 318 also has communication software and hardware 326 which facilitates communication with the Internet 307.
- CONTAINERS 300, 301 CONTAINERS 300, 301.
- a user at computer 318 can surf the WWW (i.e., the Internet 307) and locate the CONTAINER 301 at web server 304.
- the CONTAINER 301 can be, for example, displayed on a web page at the user's screen 332 as OBJECT "Z" that instantiates the CONTAINER 301.
- the CONTAINER 301 can include, within the METADATA 308, a location on the WWW 307 to find and obtain such a SYSTEM EXTENSION 330.
- One location can be an administrative web site 334 that is also connected to the WWW 307 with a unique web address.
- the site 334 downloads the EXTENSION 330 to the computer 318 so that 1 the computer 318 can render the OBJECT "Z". Since the OBJECT "Z" is generally a
- a "VIEWER” 336 such as a JPEG viewer or the Microsoft WordTM
- the METADATA 308 specifies that registration server 338
- Figure 10 also illustrates a second computer 340 that represents an author or
- the invention provides a way to
- computer 340 includes a
- the Work 0 344 is made by a third party application, e.g., Adobe PhotoshopTM.
- the computer 340 typically includes this software within internal memory.
- this software is referred to as VIEWER 346 because the application is typically the same application that is later required to view or utilize the Work 344.
- the Work 344 will have attribution for any location on the web 307.
- the user at computer 340 can send the CONTAINER 348 onto the Internet 307 for storage, if desired, at a web site or at a REGISTRY such as REGISTRY 338.
- a user at computer 318 locate and access the CONTAINER 348, such a user sees the OBJECT "Y" as the instantiation of the CONTAINER 348. If the user attempts an operation tiiat is prohibited, tiien U e CONTAINER 348, Uirough its Metadata, locates and phones its home, which in this example is the REGISTRY 338, to begin a licensing transaction.
- Figure 11 illustrates a system 400 constructed according to the invention.
- Figure 400 further illustrates general and preferred operations and functionality of the system 400 in the management of Digital Creative Works.
- user stations 402 and 404 are computers for users of digital media connected to the Internet 406 and to each other via a network or Intranet 408.
- User stations 402 and 404 are connected to the Internet, and to the Intranet 408, via local data lines 402b and 404b, respectively.
- User stations 410 and 412 are used by creators or authors of Digital Creative Works 410a, 412a, respectively; and are connected to the Internet 406 by data lines 410b and 412b, respectively.
- Digital Creative Work 410a is shown illustratively as an "A” on the screen 410c of user station 410; while Digital Creative Work 412a is illustratively shown as an "A+B" on screen 412c of user station 412.
- the Work 412a is denoted as "A+B" to indicate that the Work 412a is a combination of creative works of both authors at stations 410 and 412.
- each of the stations 402, 404, 410 and 412 have hardware (not shown) which enables communication with the Internet 408 and /or Intranet 406.
- such hardware often includes a modem and supporting software to facilitate communication through the Internet 408, to other users, such as through email, and to selected web sites, FTP sites, URLS, newsgroups, databases, and the like.
- User station 410 also has a TOOLBOX 414; and user station 412 has a PACKAGER 416.
- the TOOLBOX 414 and /or PACKAGER 416 are used to create a CONTAINERS, here illustrated as CONTAINERS 418 and 420.
- CONTAINER 418 derives from the work 410a of station 410; while CONTAINER 420 derives from the work 410a and the work 412a of station 412.
- CONTAINERS 418 and 420 are shown connected to the data lines 410b, 412b to illustrate that the CONTAINERS are transmitted through, or dispersed on, the Internet 408.
- Each of the user stations 402, 404, 410 and 412 has a SYSTEM EXTENSION 422 installed into an associated internal memory 402d, 404d, 410d and 412d, respectively.
- These EXTENSIONS 422 operate with the operating system of the associated station so as to recognize, interact with, and access CONTAINERS.
- User stations 402 and 404 additionally have VIEWERs 424 installed into internal memory 402d and 404d, respectively.
- the VIEWERs 424 are used to view and interact with the Works within CONTAINERS.
- an OBJECT 410a is a graphic that is best viewed with a JPEG VIEWER
- the EXTENSION 422 calls that VIEWER to render the OBJECT 410a as needed to the user 402.
- user 402 sees the OBJECT "A” as the instantiation of the CONTAINER 410.
- user 404 sees the OBJECT "A+B" as U e instantiation of the CONTAINER 420.
- the Registry 426 operates to register selected CONTAINERS, and to negotiate as agent for any author of a CONTAINER.
- the Registry 426 has internal memory 426d which can be used to store CONTAINERS, METADATA to CONTAINERS, or parts of CONTAINERS and /or METADATA. It is important to note that a CONTAINER need not reside at a single memory location. Those skilled in the art will appreciate that a CONTAINER based on object technology can be, and is intended to be, dispersed across the Internet 408 so that different portions of Uie CONTAINER reside at the most logical location for that portion.
- Figure 11 also shows an administrative site 428 (and associated Registry 428a), which can operate to augment the system 400, as described below; and a generic web site 430 that provides database information such as commonly provided on the WWW.
- the administration site 428 and web site 430 include associated hardware (not shown) to facilitate the needed communication with the Internet 408 and other users 402, 404, 410 and 412 of data therein.
- the system 400 has many features, some of which are illustrated in Figure 10.
- work 410a is instantiated on the screen 410a as OBJECT "A.”
- "A” can represent a digital representation of a drawing or sketch by the author.
- "A” can be made electronically, such as through a graphic artist program (using the keyboard 410f and mouse 410g) such as Adobe IllustratorTM; or "A” can be hand-drawn and scanned within the computer 410 by an optical scanner, such as known to those skilled in the art.
- the author of CONTAINER 418 makes the Digital Work "A" for enjoyment only; and does not choose to register the CONTAINER 418 with the REGISTRY 426.
- the author at station 410 does desire recognition as the author of the work "A,” so he encapsulates METADATA 418b within the CONTAINER 418 that specifies his name.
- User 410 thereafter sends the CONTAINER 418 onto the Internet 406, where it is stored as a web page at the database or web-site 430.
- the user at user station 402 is interrogating the Internet 408 through visual interaction with her display 402c of the WWW (note for clarity of illustration that no accompanying mouse and keyboard are illustrated with user stations 402 and 404; and even though they are not required, it is intended that such instruments are present).
- User 402 accordingly has web browser software 432 (e.g., NetscapeTM and Microsoft Internet ExplorerTM) installed in internal memory 402d on the computer 402.
- web browser software 432 e.g., NetscapeTM and Microsoft Internet ExplorerTM
- the CONTAINER 418 typically seen as OBJECT A referring to the CONTAINER 418
- the SYSTEM EXTENSION 422 and VIEWER 424 permit viewing of the OBJECT "A.”
- the author's name can also be displayed, if desired, through the METADATA and as specified by the author at station 410.
- the CONTAINER 418 is integrated with object controls utilizing ActiveXTM, or similar object control, the CONTAINER 418 need not comprise data that is resident at the same location. Rather, a CONTAINER can include data that is spread across the network 406 or Internet 408. Because the CONTAINER 418 is formed with object-based controls, when user station 402 encounters the web page at site 430 that refers to the CONTAINER 418, the computer 402 first interrogates its registry to see if that control is available internally. 1 If not, the computer automatically finds and installs the control over the Internet 408
- the user at station 412 represents an author and a user of CONTAINERS.
- user station 412 has a SYSTEM EXTENSION 422 within internal memory
- the invention keeps track of the derivative uses and edits of digital
- the user at station 412 chooses to register the work 412a with
- the user at station 412 first initiates a registration 2 o request to communicate and request registration of CONTAINER 420.
- the registration 2 o request to communicate and request registration of CONTAINER 420.
- the user at station 412 can select a corresponding property
- 6 412 can each function as such a remote server; and the author at station 412
- the REGISTRY can have multiple templates available for different
- That Registry would require certain protocols and information (e.g., 9 addresses) to identify that Registry and to communicate thereto.
- This example is not a common occurrence whereby the original creator, user 410, chose to make an unregistered OBJECT "A".
- Such a creator 410 thus preferably makes the unregistered OBJECT A with "open" permissions so that the associated Work 410a can be inco ⁇ orated into other works, e.g., the Work 412a.
- the identification of the original author i.e., "source work”
- source work will be reflected in the source works page of the new template, if available.
- the onus is on the user to contact the creator by whatever means that creator lists in the property pages of the unregistered OBJECT A, possibly a phone, fax, email, or other contact.
- an unregistered OBJECT can carry substantially all U e information of a registered object.
- the users at stations 410 and 412 can thus package CONTAINERS from within creativity tools, within an Application Programming Interface (API) for a particular plug-in, or directly from the shell: in the case of tiie user at station 410, the TOOLBOX 414 indicates tiiat the work 410a was created from within a creativity tool such as Adobe IllustratorTM; while station 412 has a PACKAGER 416 installed as a direct shell application to produce CONTAINERS.
- These tools together with the registration process at the Registry 426, assure the user that the attached METADATA information is not easily removed, altered or forged.
- Such users are then able to catalog, share, and generally manipulate such sets in an organized way; and with a large degree of automated help from the system 400.
- the attached METADATA information is accessible from any representation of the works 410a and 412a, especially from a rendition of the content as well as any iconic ones.
- User station 404 is very similar to Uie user station 402, except that the user at station 404 has accessed a registered work 412a, as opposed to the unregistered work 410a in CONTAINER 418. Accordingly, the METADATA 420b of CONTAINER 420 specifies the minimum permissions of the work 412a. Typically, for example, that minimum permissions allows the user 404 to view the work 412a on the screen 404c; yet further actions such as print, copy, drag and drop are prohibited and are not possible without a license to the work 412a.
- a license to this activity must be negotiated through the Registry 426, where the CONTAINER 420 was registered. If the METADATA 420b permits the license of the work 412a in terms of the number of prints, then the user at station 404 can contact the Registry 426 and proceed with appropriate licensing terms.
- CONTAINERS live on as data items within the Internet 408. It is likely that the individual or company which created the work associated with a particular work no longer exists relative to Uie Internet 408 and Registry 426. For example, one creator of Digital Creative Works is a publisher of magazines; and if that magazine goes out of business, then subsequent licenses to their works are problematic. There are several ways to deal with this problem. First, the publisher in such a situation can notify Uie Registry that it is going out of business and tiiat future transactions as to their CONTAINERS are prohibited. Alternatively, the publisher can inform change the METADATA within the CONTAINER so as to unregister the CONTAINER, thereby providing a free license to the works within the CONTAINER. Note that the publisher could specify, in the METADATA, information about the publisher and suggestions for alternative contact points; and that METADATA is available to users with VIEWERS.
- the Registry 426 can contact the administrative site 428 to decide the fate of the CONTAINER. At that point, ti e administrative site can specify that no additional information is known; and, for example, that access to the CONTAINER is prohibited.
- the administration site 428 also operates in default situations where the Registry does not answer. In that case, the administration site 428 can review the status of the CONTAINER and inform the requesting user to call the Registry later, for example if a temporary problem exists or if the Registry is too busy. Alternatively, the administrative site can function as an alternative Registry, if set up by the creator of the CONTAINER.
- the invention thus supports commerce between the owners and creators of digital content, i.e., the Digital Creative Work. Specifically, the invention provides a method for the owner to license the work, while also providing a method for the multimedia developers and publishers to make productive use of the work's content. The invention thus provides a uniform, timely, and persistent means of identifying digital content in the networked environment.
- an Internet-based application is built around the OBJECT as supported by the TOOLBOX and the Registration Server.
- the SYSTEM EXTENSION enables OBJECTS to be viewed on target operating systems and from within a variety of applications.
- the invention inco ⁇ orates object technology such as Internet-extended OLE, the standard object technology developed by MicrosoftTM that allows a variety of media types to be shared by applications throughout the Internet.
- object technology such as Internet-extended OLE, the standard object technology developed by MicrosoftTM that allows a variety of media types to be shared by applications throughout the Internet.
- the invention also provides substantially uniform representation of content within other applications. That is, creativity tools such as graphics, sound, video, word processing, and multimedia authoring tools are presented with a substantially uniform interface to host applications, relieving those applications from the responsibility of rendering all media types. Further, the creators and owners of content (i.e., Digital Creative Works) can, with the invention, store and make available the METADATA which can be critical to licensing and other derivative uses.
- the invention creates documents, or CONTAINERS, through a process called packaging.
- the PACKAGER merges content (i.e., Digital Creative Work), Metadata, and active interface controls and presents this to the user through a set of property pages designed for the specific business problem being addressed.
- the result of this packaging is instantiated as an OBJECT.
- Figure 13 illustrates one packaging process according to the invention. In Figure 13, Digital Creative Work and Metadata associated with that content are combined with the desired template to create the OBJECT.
- a CONTAINER is much easier t ⁇ track and t ⁇ manage than conventional content because the Metadata is accessible directly from the CONTAINER.
- the owner or creator will choose to attach a small amount of identifying data to the Digital Creative Work, with the larger and /or most volatile data being supplied to the CONTAINER from a remote registration server via the Internet.
- owners and creators can ensure that potential users always obtain up-to-date ownership, contact, and licensing information about specific content elements. Owners can thus be sure that the positive identification, direct communications, and possibility of automated licensing will maximize the likelihood that their content will get used in legitimate or legal derivative works.
- CONTAINERS also reduce the workload of multimedia developers, publishers, and other derivative users of content by making the identification of content and its ownership substantially instantaneous and by reducing or eliminating delays, errors and misdirection when communicating with the appropriate rights management authorities.
- one way to convert Digital Creative Works to CONTAINERS and OBJECTs begins with the use of a Template Editor.
- the Template Editor presents an interface for designing sets of properties and property pages that organize the presentation of the CONTAINER'S Metadata and buttons that initiate various functions of the OBJECT.
- the Template Editor enables content owners to create layouts for property pages, placing various controls on the pages. These controls can, without limitation, include:
- Fields for static data that will ultimately be bound to the object • Fields for dynamic data that will ultimately be stored on a remote server • Labels for clarifying or identifying sections of the property page • Buttons for initiating an email or web access action • Buttons for retrieving dynamic data from a remote server • Other elements including illustrations, logos, or icons
- FIG 14. Another template and an associated OBJECT, instantiating a CONTAINER, is shown, representatively, in Figure 15.
- a user of the invention can employ one of several tools to make the CONTAINER: the Toolbox, the Express Packager, and the Software Developers Kit (SDK).
- Each tool merges the various input elements to create a CONTAINER or Object.
- the user of the tool specifies the source content element (e.g., photo, sound, video, text, etc.) and the Template to be used in the packaging process.
- the user then supplies the data required by the Template.
- the PACKAGER taking its basic instructions from the Template, creates the CONTAINER, binding static data to the content and automatically storing dynamic data on the designated Registration Server.
- the TOOLBOX is a graphical desktop tool designed for individual users packaging relatively small amounts of content. From a standard graphical user interface, the user specifies the content source file and designates the appropriate Template. The Toolbox then prompts the user for the necessary input to complete the required entries specified by the Template. Upon completion of the required entries, the Toolbox will update the associated server with dynamic data, if any, and create a CONTAINER.
- the Express Packager is a batch-oriented PACKAGER tool which converts high volume content elements to CONTAINERS. When using the Express Packager, the operator specifies a set of content files, the template, and a source of the required input data.
- the Express Packager then automatically accepts the input and converts the files to the right format.
- the SDK Packager is designed for applications where functionality according to the invention is to be built into existing content production tools. As an example, certain Internet publishers provide various "just-in-time" content delivery systems. In such a case, the SDK Packager is used whereby the publisher's existing production tools automatically invoke the packaging process to follow the same model of receiving content, template, and data as input to produce the CONTAINER.
- an owner can create a registered object by communicating with the Registration Server.
- the owner can use one of the packaging tools to create an unregistered object.
- static information is bound to the content but there is no record placed on a Registration Server.
- the Registration Server provides the communications link to Objects. Usually, it is the creator of the Template who establishes the relationships between the dynamic data required by the Object and the Registration Server.
- the Registration Server listens for various types of requests entered by viewers of the content (i.e., the Digital Creative Work). Those requests can be for specific elements of data that will be displayed on property pages, or for other data that will support functions such as email or web site addressing. The requests may also include transactions that require interfacing to legacy business systems or financial transaction systems.
- the Registration Server is built to respond to such requests and to interface with existing information and transaction systems. In such a role, it can:
- the Administration Server is a database that contains document and business information and transaction rules pertaining to owner's distributed content.
- the Administration Server is used to supply this information to the Registration Server when requested by the a user interacting with an OBJECT.
- SYSTEM EXTENSION acts as an extension to the user's operating system, ensuring that required functionality is available from within various applications and not just through an Internet browser.
- the SYSTEM EXTENSION is preferably compact, self-installing, and freely distributed via the Internet or as part of a customer's packaged solution.
- the CONTAINER can be created by the Toolbox or Express Packager.
- the content owner either by way of the Toolbox or the Express Packager, associates Digital Creative Work with Metadata, such as artistic or business attribution information (credits) and permission parameters. It is intended that the invention operate with all standard digital formats for the underlying source work, including GIF, JPEG, WAV, AVI, and others.
- the content owners edit the Metadata values or properties using a set of Property Pages as an interface.
- the set of required and optional properties for a particular OBJECT are defined by a Template, created using the Template Editor.
- the Template also describes the visual layout used in the property page presentation of the Metadata.
- a variety of Templates may be created and applied to different types of content and for different business or licensing models.
- a content owner can also choose to create either registered or unregistered CONTAINERS.
- unregistered OBJECTs all content and Metadata properties are stored in the CONTAINER itself.
- the Metadata properties are typically stored in two locations: within U e CONTAINER and remotely on a Registration Server. Properties stored within the CONTAINER are referred to herein as static; properties that are retrieved from a Registration Server are referred to herein as dynamic, since their values may change during the life of the CONTAINER .
- a Template supplied by the designated Registration Server is used. That Template specifies the dynamic properties to be supplied by the user that will be transferred to and stored in the Registration Server. If an unregistered object is to be created, the content owner can select one of several default Templates or he can create a custom T emplate that allows static attribution information and communications with the creator /owner by email and web page access only. Registered CONTAINERS are better suited to content that is destined for commercial use. Advantages of registration include authentication, ability to serve to the user variable data such as terms for licensing, ability to change information after distributing the object, and automated transactions.
- Unregistered CONTAINERS may be desirable for material with a very short life cycle (e.g., weather maps), very low value (e.g., vacation photos), or for non-commercial distribution where the user simply wants to attach identifying information and facilitate email or web page access.
- a very short life cycle e.g., weather maps
- very low value e.g., vacation photos
- non-commercial distribution where the user simply wants to attach identifying information and facilitate email or web page access.
- CONTAINERS can be rendered on systems where SYSTEM EXTENSION functionality is installed.
- Restrictions - CONTAINERS encourage compliance with the Copyright Laws by intercepting attempts to perform certain types of operations on Uie Digital Creative Work (e.g., drag-and-drop, copy, save or print).
- Content - The CONTAINERS can contain all standard and commonly used formats for image, sound, video, and text display.
- Property Pages - Property pages adhere to standard representations consistent witii the operating system and other applications. Static data is displayed on pages. Also, for Registered Objects, dynamic data can be retrieved on demand from a Registration Server.
- CONTAINERS provide the capability to initiate communications to a creator/ owner through the following mechanisms: - Email - Email addresses can be stored in the CONTAINER'S properties, and email messages can be initiated when viewing the Object's property pages. Email messages can be edited and transmitted a number of ways including SMTP (direct Internet mail protocol), MAPI (Mail API) or by launching a user's configured email client application (e.g., Eudora or Microsoft Exchange).
- SMTP direct Internet mail protocol
- MAPI Mail API
- launching a user's configured email client application e.g., Eudora or Microsoft Exchange.
- - Web page access - URLs can be stored in the CONTAINER'S properties, and a web browser such as Netscape NavigatorTM or Microsoft Internet ExplorerTM can be launched to access the specified page.
- - Registration Server transactions - Registered CONTAINERS can initiate a variety of transactions with a Registration Server. Transactions include the retrieval of Dynamic Properties, the completion of a Permission Contract, and payment for licensing fees. These transactions can be authenticated using cryptographic techniques.
- SYSTEM EXTENSION functionality provides the necessary functions to allow a user to render an OBJECT and to access property pages and functions. It is generally provided (e.g., "delivered") as an extension to the operating system
- the SYSTEM EXTENSION is intended to be widely and freely distributed online and through traditional distribution media such as CD-ROMs and diskettes.
- Such extensions should have the following properties: • Compact - The Extensions will often be loaded electronically by a user through a web-page or FTP server. • Self-installing - The Extension can be installed with little or no interaction. • Self-updating - Updates required for subsequent releases will be automatically detected and installed. • Backward Compatible - New Versions of the Extension will always be able to view and use older OBJECTS.
- the Registration Server is the storage and administrative facility for registered CONTAINERS.
- a registration server is the primary component required for organizations running a REGISTRY.
- a REGISTRY is, for example, analogous to a Web site, except that instead of sending HTML pages and responding to requests with the HTTP protocol, the REGISTRY is interacting across a network with OBJECTS.
- a REGISTRY can include a batch or real-time link to an organization's legacy permission or rights management system.
- the major functions of the Registration Server can, without limitation, include: • Object Registration - The Registration Server is the where the dynamic properties for a registered CONTAINERS are stored. These properties can be updated by the Registration Server administrator when necessary. Objects retrieving these properties will immediately reflect the updated values.
- Template Creation The Template Editor provides the operator of a registration server with the ability to create and customize Templates, including the layout of property pages and the definition of the static and dynamic properties to be associated with Objects. Templates can be organized and grouped for distribution to creators / owners for use with the Toolbox or the Express Packager.
- Creator /Owner Registration Several options are available for initiating a relationship with a creator/ owner depending upon the business model adopted by the operator of a registration server. These options range from assigning a simple user account name and password to a sophisticated high-security procedure using officially certified digital signatures.
- External System Linkages The Registration Server can interface to existing rights management systems through one of several mechanisms: - The Express Packager allows one-way batch creation of Objects.
- the Packaging API allows real-time creation of Objects.
- the API is two- way, enabling Uie update of data in the extemal system based on changes made to the Registration Server.
- the Registration Server Database Mapper allows a direct interface from the Server to an existing external database.
- the Mapper allows a flexible mapping of the Object Properties to legacy systems.
- the Report Writer Pre-formatted and customized reports are available, including the following classes of reports: - Registered Object Reports - Creator / Owner Account Reports - Inquiry and Permission Transaction Reports - Server Activity Reports - Systems Operation Reports
- One exemplary Registration Server schematic is shown in Figure 16.
- the Registration Server also provides for certain problem situations that may arise with Objects. • Servicing Objects for which the Registration Server record has been removed or transferred. If ownership has been transferred, then a transaction request may simply be redirected to the appropriate server. A special "backstop" server can be provided so that an Object contact the backstop server if all other attempts to locate the appropriate Registration Server fail. This server includes a master directory of Registration Servers. If the relationship between the creator and the Registration Server has terminated, then an appropriate notification will be returned. • Servicing Objects which submit requests that for one reason or another violate an authenticity check. If the server receives any unusual transaction requests, including requests indicating an authentication failure, then an audit trail will be maintained.
- the Administration Server is an add-on component for operators of the Registration Server.
- the Administration Server serves small publishers, service bureaus, and independent professionals who do not have existing methods for administering royalties, handling on-line financial transactions, and reporting on the financial and administrative activity of the system.
- the Administration Server brings some of the necessary publishing functionality to the small user.
- the packaging process associates Metadata with Digital Creative Works and instantiates the CONTAINER as an Object.
- the METADATA is displayed by means of its property pages; the properties required on these pages and their layout is specified by the object's property page template. Templates can be used for both registered and unregistered Objects, but are of special importance when an OBJECT is registered.
- the Template Editor enables the operator of a Registration Server to create and customize templates, including the layout of property pages and the definition of the static and dynamic properties to be associated witii Objects. Templates may be organized and grouped for distribution to creators and owners for use with the Toolbox or the Express Packager.
- the Template Editor preferably has a GUI with a palette-oriented desktop motif consistent with current visual software design tools (e.g.: Visual Basic).
- a Template contains a hierarchy of data items, including, without limitation, the following: • A collection of property pages. • For each property page, a collection of controls that will appear on that page. • For each property page, a collection of property seta A property set is a collection of property descriptors that define tiie attributes of each property. • The definition of the template's home Registration Server. • The definition of the template's connection object.
- the Template Editor gives the user the tools to define property sets and their associated property descriptors. Each descriptor is uniquely identified upon creation. Each property page interface is built from a set of controls. The user selects each control from a palette and draws on a form in a fashion similar to Visual Basic. For each control selected, the user can define a new property descriptor to be associated with the control or may select from a set of "hard-coded" routines that the selected control can execute. Each control is assigned a unique identifier upon creation.
- the user can save everything as a Template that can be inserted into another Template Editor project. Alternatively they may save the work as a bound template that can be used directiy by a packaging tool to create Objects.
- the Template Editor Prior to saving the user's work as a bound Template, the Template Editor automatically generates an input data form that may be optionally edited.
- the template editor When saving as a bound template, the template editor generates a fixed-format input data file that will be parsed by the PACKAGER.
- the Express Packager is used by content owners who convert large amounts of content into CONTAINERS by automatically merging Metadata and Digital Creative Work.
- the Express Packager creates registered and unregistered Objects and generally has two modes of operation: • Conversion Mode enables large numbers of existing digital files to be converted into CONTAINERS. When operating in conversion mode, the Express Packager actively gets the content and the input data file that describes the Metadata and creates the CONTAINER . Data is either retrieved from a database or from a text file or other intermediate container storing the pertinent information. • Creation Mode enables the Express Packager to operate under the control of another program through the real-time Packaging API (LPAPI). In this way, the Express Packager operates in a passive mode, taking its instructions from other applications. This mode is appropriate for packaging content that is created in real-time such as the output from Java applications, CGI scripts, proprietary publishing applications, etc.
- LPAPI real-time Packaging API
- the LPAPI can be made available through an OLE Automation interface to enable a flexible and industry-standard protocol used to create and register Objects.
- the LPAPI allows custom interactive or batch interfaces to be built using a large array of development and scripting tools such as Visual Basic, C++, Microsoft Office applications, and other similar applications.
- the LPAPI can also be made available "off the shelf” for use in applications such as web servers (CGI, IS API), browsers (Java, ActiveX, plug-ins) and third party programs such as creativity tools and multimedia development systems.
- applications such as web servers (CGI, IS API), browsers (Java, ActiveX, plug-ins) and third party programs such as creativity tools and multimedia development systems.
- the Toolbox can be used by content owners to interactively create CONTAINERS.
- the Toolbox focus es on ease-of-use through an intuitive interface with on-line help, wizards, and other supporting mechanisms.
- the Toolbox can create registered and unregistered CONTAINERS.
- the Toolbox combines Templates provided by the Registry for registered objects, or by other means for unregistered objects. Some Registries can choose to use standard Templates.
- the Template Editor is useful, for example, for creators who are using Registries that allow Objects to be registered with custom templates that are derived from those supplied by the Registry. This provides the Registry with the capacity to allow creators to add additional properties that complement those required by the Registry.
- the Toolbox can use cryptographic techniques to ensure the integrity of the CONTAINER and to provide two-way authentication of the parties involved in object registration.
Landscapes
- Engineering & Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- Business, Economics & Management (AREA)
- Signal Processing (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Software Systems (AREA)
- Computing Systems (AREA)
- Accounting & Taxation (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Multimedia (AREA)
- Finance (AREA)
- Technology Law (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Storage Device Security (AREA)
Abstract
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
AU76624/96A AU7662496A (en) | 1995-10-13 | 1996-10-11 | System and methods for managing digital creative works |
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US08/543,161 US5765152A (en) | 1995-10-13 | 1995-10-13 | System and method for managing copyrighted electronic media |
US08/543,161 | 1995-10-13 | ||
US2548596P | 1996-08-29 | 1996-08-29 | |
US60/025,485 | 1996-08-29 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO1997014087A1 true WO1997014087A1 (fr) | 1997-04-17 |
Family
ID=26699799
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/US1996/016348 WO1997014087A1 (fr) | 1995-10-13 | 1996-10-11 | Systeme et procedes de gestion d'oeuvres de creation numeriques |
Country Status (2)
Country | Link |
---|---|
AU (1) | AU7662496A (fr) |
WO (1) | WO1997014087A1 (fr) |
Cited By (49)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO1998058306A1 (fr) * | 1997-06-17 | 1998-12-23 | Shopnow.Com Inc. | Procede et system permettant d'introduire sans risque des informations electroniques dans une application d'achat en direct |
WO1999008171A1 (fr) * | 1997-08-05 | 1999-02-18 | Wittkoetter Erland | Dispositif et procede permettant la sortie protegee de documents memorises transmis par voie electronique |
WO1999005600A3 (fr) * | 1997-07-28 | 1999-05-14 | Apple Computer | Procede et dispositif d'application de licences d'utilisation des logiciels |
WO1999055055A1 (fr) * | 1998-04-17 | 1999-10-28 | Iomega Corporation | Systeme de cle de donnees electroniques protegees sur un support particulier de maniere a empecher une reproduction illicite |
EP0859503A3 (fr) * | 1997-02-12 | 1999-12-22 | Nec Corporation | Système de filigrane électronique |
EP1081575A1 (fr) * | 1999-09-01 | 2001-03-07 | Matsushita Electric Industrial Co., Ltd. | Méthode et appareil pour traiter des droits d'auteurs de données |
EP1081574A1 (fr) * | 1999-09-01 | 2001-03-07 | Matsushita Electric Industrial Co., Ltd. | Méthode et appareil pour traiter des droits d'auteurs de données |
WO2001016671A1 (fr) * | 1999-09-01 | 2001-03-08 | Matsushita Electric Industrial Co., Ltd. | Systeme de protection des donnees numeriques par le droit d'auteur |
WO2001030041A3 (fr) * | 1999-10-20 | 2001-09-20 | George J Tomko | Systeme et procede de manipulation sure de donnees sur un reseau |
EP0969668A3 (fr) * | 1998-06-29 | 2002-03-13 | Canon Kabushiki Kaisha | Protection du droit d'auteur pour des données d'image en mouvement |
GB2366969A (en) * | 2000-09-14 | 2002-03-20 | Phocis Ltd | Copyright protection for digital content distributed over a network |
GB2368245A (en) * | 2000-10-17 | 2002-04-24 | Mode Internat Ltd | Distribution system for digital works with associated metadata |
EP0936531A3 (fr) * | 1998-02-12 | 2002-05-08 | Hitachi, Ltd. | Procédé de recherche d'informations et système associé |
US6434535B1 (en) | 1998-11-13 | 2002-08-13 | Iomega Corporation | System for prepayment of electronic content using removable media and for prevention of unauthorized copying of same |
EP1248988A2 (fr) * | 1999-04-12 | 2002-10-16 | Reciprocal, Inc. | Systeme et procede de gestion des droits en matiere de donnees |
WO2002095551A1 (fr) * | 2001-05-22 | 2002-11-28 | Matsushita Electric Industrial Co., Ltd. | Systeme de gestion de contenu comportant un serveur de gestion de regles d'utilisation |
WO2003013141A1 (fr) * | 2001-07-31 | 2003-02-13 | Matsushita Electric Industrial Co., Ltd. | Systeme, appareil et procede de distribution de contenus, et programme et support d'enregistrement de programme correspondants |
DE10146926A1 (de) * | 2001-09-24 | 2003-04-24 | Rainer Annuscheit | Verfahren zur Vermittlung und Bereitstellung beweglicher oder veränderbarer Informationsinhalte |
GB2385439A (en) * | 2002-02-15 | 2003-08-20 | Hewlett Packard Co | Digital rights management printing system |
WO2002101521A3 (fr) * | 2001-06-12 | 2003-10-23 | Ibm | Procede d'incorporation invisible de l'identification de la licence d'un logiciel sous licence dans un document textuel |
WO2001016821A3 (fr) * | 1999-09-01 | 2003-10-30 | Matsushita Electric Ind Co Ltd | Systeme de distribution, carte memoire a semi-conducteur, appareil de reception, support d'enregistrement lisible par ordinateur et procede de reception |
EP0935209A3 (fr) * | 1998-02-06 | 2003-12-10 | Hitachi, Ltd. | Méthode pour la vente de contenus de donées et système de cyber-centre commercial pour la méthode et medium de stockage pour le logiciel de vente de contenus de donées |
EP1308821A3 (fr) * | 2001-10-30 | 2004-03-17 | Hitachi, Ltd. | Système et procédé d'authentification |
EP1008250A4 (fr) * | 1997-08-29 | 2004-05-19 | Aladdin Knowledge Systems Ltd | Distribution de logiciels electroniques a plusieurs paliers |
US6826546B1 (en) * | 2000-08-17 | 2004-11-30 | Ideaflood, Inc. | Method and system for licensing a copy of a copyright protected work |
EP1334421A4 (fr) * | 2000-10-25 | 2004-12-29 | Thomson Financial Inc | Systeme de commerce electronique |
EP1233324A3 (fr) * | 2001-02-16 | 2005-02-16 | Matsushita Electric Industrial Co., Ltd. | Système de distribution de données |
EP1343318A3 (fr) * | 1998-03-16 | 2005-04-13 | Intertrust Technologies Corp. | Procedes et appareil de commande et de protection continues du contenu de supports |
EP1290593A4 (fr) * | 2000-04-20 | 2005-12-28 | Photolibrary Com Pty Ltd | Systeme et procede de micro-concession de licence |
EP1475775A3 (fr) * | 2003-04-21 | 2006-05-31 | Yamaha Corporation | Dispositif utilisant un contenu musical capable de gérer la copie de contenu musical |
US7117367B2 (en) | 2001-06-12 | 2006-10-03 | International Business Machines Corporation | Method of authenticating a plurality of files linked to a text document |
EP1257931A4 (fr) * | 2000-01-26 | 2006-11-22 | Digimarc Corp | Liaison d'objets audio et d'autres objets media |
US7233948B1 (en) | 1998-03-16 | 2007-06-19 | Intertrust Technologies Corp. | Methods and apparatus for persistent control and protection of content |
US7240209B2 (en) | 2001-06-12 | 2007-07-03 | International Business Machines Corporation | Methods of invisibly embedding and hiding data into soft-copy text documents |
US7246246B2 (en) | 1998-04-17 | 2007-07-17 | Iomega Corporation | System for keying protected electronic data to particular media to prevent unauthorized copying using a compound key |
WO2007091189A3 (fr) * | 2006-02-06 | 2007-11-01 | Koninkl Philips Electronics Nv | Droits derives sur du contenu numerique controles |
EP1208499A4 (fr) * | 1999-05-19 | 2007-11-07 | Digimarc Corp | Procedes et systemes utilisant le filigrane numerique dans des supports musicaux et autres |
CN100365614C (zh) * | 2000-12-07 | 2008-01-30 | 索尼英国有限公司 | 加水印和传送资料 |
JP2008530653A (ja) * | 2005-02-08 | 2008-08-07 | コンテントガード ホールディングズ インコーポレイテッド | 将来的に作成されるディジタル・コンテンツに対する使用権を確立するための方法及び装置 |
WO2009133498A1 (fr) * | 2008-04-29 | 2009-11-05 | Koninklijke Philips Electronics N.V. | Gestion de contenus numériques |
US7809138B2 (en) | 1999-03-16 | 2010-10-05 | Intertrust Technologies Corporation | Methods and apparatus for persistent control and protection of content |
AU2003203745B2 (en) * | 2003-03-24 | 2010-11-18 | Microsoft Technology Licensing, Llc | System and method for user modification of metadata in a shell browser |
WO2011127564A1 (fr) * | 2010-04-14 | 2011-10-20 | Legitmix, Inc. | Système et procédé permettant de crypter une œuvre dérivée en utilisant une clé de chiffre créée à partir de ses sources |
US8245306B2 (en) | 2002-02-15 | 2012-08-14 | Galo Gimenez | Digital rights management printing system |
US8359251B2 (en) | 2000-10-25 | 2013-01-22 | Thomson Financial Llc | Distributed commerce system |
US8925102B2 (en) | 2010-10-14 | 2014-12-30 | Legitmix, Inc. | System and method of generating encryption/decryption keys and encrypting/decrypting a derivative work |
US20180365396A1 (en) * | 2017-06-15 | 2018-12-20 | Joel Rucker | Copyright verification system |
DE102018123835A1 (de) * | 2018-06-07 | 2019-12-12 | Evga Corporation | Dezentralisiertes System zur Erstellung von Softwareinformationen und Verfahren hierfür |
US10521853B2 (en) | 2000-10-25 | 2019-12-31 | Refinitiv Us Organization Llc | Electronic sales system |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5023907A (en) * | 1988-09-30 | 1991-06-11 | Apollo Computer, Inc. | Network license server |
WO1994027228A1 (fr) * | 1993-05-10 | 1994-11-24 | Apple Computer, Inc. | Systeme de determination automatique de l'etat de contenus ajoutes a un document |
-
1996
- 1996-10-11 WO PCT/US1996/016348 patent/WO1997014087A1/fr active Application Filing
- 1996-10-11 AU AU76624/96A patent/AU7662496A/en not_active Abandoned
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5023907A (en) * | 1988-09-30 | 1991-06-11 | Apollo Computer, Inc. | Network license server |
WO1994027228A1 (fr) * | 1993-05-10 | 1994-11-24 | Apple Computer, Inc. | Systeme de determination automatique de l'etat de contenus ajoutes a un document |
Non-Patent Citations (2)
Title |
---|
"MULTIMEDIA MIXED OBJECT ENVELOPES SUPORTING A GRADUATED FEE SCHEME VIA ENCRYPTION", IBM TECHNICAL DISCLOSURE BULLETIN, vol. 37, no. 3, 1 March 1994 (1994-03-01), pages 413 - 417, XP000441522 * |
CHOUDHURY A K ET AL: "Copyright protection for electronic publishing over computer networks", IEEE NETWORK, MAY-JUNE 1995, USA, vol. 9, no. 3, ISSN 0890-8044, pages 12 - 20, XP000505280 * |
Cited By (88)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6073124A (en) * | 1997-01-29 | 2000-06-06 | Shopnow.Com Inc. | Method and system for securely incorporating electronic information into an online purchasing application |
EP1515534A3 (fr) * | 1997-02-12 | 2005-04-06 | Nec Corporation | Système de filigrane électronique |
SG86997A1 (en) * | 1997-02-12 | 2002-03-19 | Nec Corp | Electronic watermark system |
EP1628462A3 (fr) * | 1997-02-12 | 2006-03-08 | Nec Corporation | Système de filigrane électronique |
EP0859503A3 (fr) * | 1997-02-12 | 1999-12-22 | Nec Corporation | Système de filigrane électronique |
US6421450B2 (en) | 1997-02-12 | 2002-07-16 | Nec Corporation | Electronic watermark system |
WO1998058306A1 (fr) * | 1997-06-17 | 1998-12-23 | Shopnow.Com Inc. | Procede et system permettant d'introduire sans risque des informations electroniques dans une application d'achat en direct |
US6188995B1 (en) | 1997-07-28 | 2001-02-13 | Apple Computer, Inc. | Method and apparatus for enforcing software licenses |
WO1999005600A3 (fr) * | 1997-07-28 | 1999-05-14 | Apple Computer | Procede et dispositif d'application de licences d'utilisation des logiciels |
US8027925B1 (en) | 1997-07-28 | 2011-09-27 | Apple Inc. | System method and apparatus for authorizing access |
WO1999008171A1 (fr) * | 1997-08-05 | 1999-02-18 | Wittkoetter Erland | Dispositif et procede permettant la sortie protegee de documents memorises transmis par voie electronique |
US6674859B1 (en) | 1997-08-05 | 2004-01-06 | Brainshield Technologies, Inc. | Device and method for the protected output of electronically transmitted and stored documents |
EP1008250A4 (fr) * | 1997-08-29 | 2004-05-19 | Aladdin Knowledge Systems Ltd | Distribution de logiciels electroniques a plusieurs paliers |
US7856405B2 (en) | 1998-02-06 | 2010-12-21 | Hitachi, Ltd. | Contents sales method and cyber mall system using such method and storage medium storing therein its contents sales program |
EP0935209A3 (fr) * | 1998-02-06 | 2003-12-10 | Hitachi, Ltd. | Méthode pour la vente de contenus de donées et système de cyber-centre commercial pour la méthode et medium de stockage pour le logiciel de vente de contenus de donées |
EP1762973A2 (fr) | 1998-02-06 | 2007-03-14 | Hitachi, Ltd. | Procédé de vente de contenus et système de cyber-centre commercial utilisant ledit procédé et support de stockage sur lequel est stocké le programme de vente de contenus |
US7457780B2 (en) | 1998-02-06 | 2008-11-25 | Hitachi, Ltd. | Contents sales method and cyber mall system using such method and storage medium storing therein its contents sales program |
EP1762973A3 (fr) * | 1998-02-06 | 2008-03-12 | Hitachi, Ltd. | Procédé de vente de contenus et système de cyber-centre commercial utilisant ledit procédé et support de stockage sur lequel est stocké le programme de vente de contenus |
EP0936531A3 (fr) * | 1998-02-12 | 2002-05-08 | Hitachi, Ltd. | Procédé de recherche d'informations et système associé |
US8526610B2 (en) | 1998-03-16 | 2013-09-03 | Intertrust Technologies Corporation | Methods and apparatus for persistent control and protection of content |
US9532005B2 (en) | 1998-03-16 | 2016-12-27 | Intertrust Technologies Corporation | Methods and apparatus for persistent control and protection of content |
EP1343318A3 (fr) * | 1998-03-16 | 2005-04-13 | Intertrust Technologies Corp. | Procedes et appareil de commande et de protection continues du contenu de supports |
US7233948B1 (en) | 1998-03-16 | 2007-06-19 | Intertrust Technologies Corp. | Methods and apparatus for persistent control and protection of content |
US7822201B2 (en) | 1998-03-16 | 2010-10-26 | Intertrust Technologies Corporation | Methods and apparatus for persistent control and protection of content |
US8130952B2 (en) | 1998-03-16 | 2012-03-06 | Intertrust Technologies Corporation | Methods and apparatus for persistent control and protection of content |
US7246246B2 (en) | 1998-04-17 | 2007-07-17 | Iomega Corporation | System for keying protected electronic data to particular media to prevent unauthorized copying using a compound key |
WO1999055055A1 (fr) * | 1998-04-17 | 1999-10-28 | Iomega Corporation | Systeme de cle de donnees electroniques protegees sur un support particulier de maniere a empecher une reproduction illicite |
US6535919B1 (en) | 1998-06-29 | 2003-03-18 | Canon Kabushiki Kaisha | Verification of image data |
EP0969668A3 (fr) * | 1998-06-29 | 2002-03-13 | Canon Kabushiki Kaisha | Protection du droit d'auteur pour des données d'image en mouvement |
US7127516B2 (en) | 1998-06-29 | 2006-10-24 | Canon Kabushiki Kaisha | Verification of image data |
US6434535B1 (en) | 1998-11-13 | 2002-08-13 | Iomega Corporation | System for prepayment of electronic content using removable media and for prevention of unauthorized copying of same |
US7809138B2 (en) | 1999-03-16 | 2010-10-05 | Intertrust Technologies Corporation | Methods and apparatus for persistent control and protection of content |
EP1248988A2 (fr) * | 1999-04-12 | 2002-10-16 | Reciprocal, Inc. | Systeme et procede de gestion des droits en matiere de donnees |
EP1208499A4 (fr) * | 1999-05-19 | 2007-11-07 | Digimarc Corp | Procedes et systemes utilisant le filigrane numerique dans des supports musicaux et autres |
US7096268B1 (en) | 1999-09-01 | 2006-08-22 | Matsushita Electric Industrial Co., Ltd. | Copyrighted data processing method and apparatus |
WO2001016671A1 (fr) * | 1999-09-01 | 2001-03-08 | Matsushita Electric Industrial Co., Ltd. | Systeme de protection des donnees numeriques par le droit d'auteur |
EP1081575A1 (fr) * | 1999-09-01 | 2001-03-07 | Matsushita Electric Industrial Co., Ltd. | Méthode et appareil pour traiter des droits d'auteurs de données |
EP1586975A1 (fr) * | 1999-09-01 | 2005-10-19 | Matsushita Electric Industrial Co., Ltd. | Méthode et appareil pour traiter des droits d'auteurs de données |
EP1081574A1 (fr) * | 1999-09-01 | 2001-03-07 | Matsushita Electric Industrial Co., Ltd. | Méthode et appareil pour traiter des droits d'auteurs de données |
WO2001016672A1 (fr) * | 1999-09-01 | 2001-03-08 | Matsushita Electric Industrial Co., Ltd. | Procede et appareil de traitement de donnees protegees par le droit d'auteur |
USRE42019E1 (en) | 1999-09-01 | 2010-12-28 | Panasonic Corporation | Distribution system, semiconductor memory card, receiving apparatus, computer-readable recording medium and receiving method |
AU784672B2 (en) * | 1999-09-01 | 2006-05-25 | Matsushita Electric Industrial Co., Ltd. | Distribution system, semiconductor memory card, receiving apparatus, computer-readable recording medium and receiving method |
USRE41096E1 (en) | 1999-09-01 | 2010-02-02 | Panasonic Corporation | Distribution system, semiconductor memory card, receiving apparatus, computer-readable recording medium and receiving method |
US7096504B1 (en) | 1999-09-01 | 2006-08-22 | Matsushita Electric Industrial Co., Ltd. | Distribution system, semiconductor memory card, receiving apparatus, computer-readable recording medium and receiving method |
WO2001016821A3 (fr) * | 1999-09-01 | 2003-10-30 | Matsushita Electric Ind Co Ltd | Systeme de distribution, carte memoire a semi-conducteur, appareil de reception, support d'enregistrement lisible par ordinateur et procede de reception |
EP1089241A3 (fr) * | 1999-09-01 | 2004-01-28 | Matsushita Electric Industrial Co., Ltd. | Système de protection du droit d'auteur de données numériques |
WO2001030041A3 (fr) * | 1999-10-20 | 2001-09-20 | George J Tomko | Systeme et procede de manipulation sure de donnees sur un reseau |
EP1257931A4 (fr) * | 2000-01-26 | 2006-11-22 | Digimarc Corp | Liaison d'objets audio et d'autres objets media |
EP2469855A1 (fr) * | 2000-01-26 | 2012-06-27 | Digimarc Corporation | Liaison D'objets Audio et D'autres Objets Media |
EP1290593A4 (fr) * | 2000-04-20 | 2005-12-28 | Photolibrary Com Pty Ltd | Systeme et procede de micro-concession de licence |
US6826546B1 (en) * | 2000-08-17 | 2004-11-30 | Ideaflood, Inc. | Method and system for licensing a copy of a copyright protected work |
GB2366969A (en) * | 2000-09-14 | 2002-03-20 | Phocis Ltd | Copyright protection for digital content distributed over a network |
US7210039B2 (en) | 2000-09-14 | 2007-04-24 | Phocis Limited | Digital rights management |
GB2368245A (en) * | 2000-10-17 | 2002-04-24 | Mode Internat Ltd | Distribution system for digital works with associated metadata |
US8359251B2 (en) | 2000-10-25 | 2013-01-22 | Thomson Financial Llc | Distributed commerce system |
US8700506B2 (en) | 2000-10-25 | 2014-04-15 | Thomson Financial Llc | Distributed commerce system |
EP1334421A4 (fr) * | 2000-10-25 | 2004-12-29 | Thomson Financial Inc | Systeme de commerce electronique |
EP2056248A1 (fr) * | 2000-10-25 | 2009-05-06 | Thomson Financial Inc. | Systeme de Commerce Electronique |
US10521853B2 (en) | 2000-10-25 | 2019-12-31 | Refinitiv Us Organization Llc | Electronic sales system |
CN100365614C (zh) * | 2000-12-07 | 2008-01-30 | 索尼英国有限公司 | 加水印和传送资料 |
US7443982B2 (en) | 2000-12-07 | 2008-10-28 | Sony United Kingdom Limited | Watermarking and transferring material |
US7962964B2 (en) | 2000-12-07 | 2011-06-14 | Sony United Kingdom Limited | Watermarking and transferring material |
EP1233324A3 (fr) * | 2001-02-16 | 2005-02-16 | Matsushita Electric Industrial Co., Ltd. | Système de distribution de données |
US7110543B2 (en) | 2001-05-22 | 2006-09-19 | Matsushita Electric Industrial Co., Ltd | Content management system, content management terminal, usage rule management server, content management method, and content management program |
WO2002095551A1 (fr) * | 2001-05-22 | 2002-11-28 | Matsushita Electric Industrial Co., Ltd. | Systeme de gestion de contenu comportant un serveur de gestion de regles d'utilisation |
US7475429B2 (en) | 2001-06-12 | 2009-01-06 | International Business Machines Corporation | Method of invisibly embedding into a text document the license identification of the generating licensed software |
US7240209B2 (en) | 2001-06-12 | 2007-07-03 | International Business Machines Corporation | Methods of invisibly embedding and hiding data into soft-copy text documents |
WO2002101521A3 (fr) * | 2001-06-12 | 2003-10-23 | Ibm | Procede d'incorporation invisible de l'identification de la licence d'un logiciel sous licence dans un document textuel |
US7117367B2 (en) | 2001-06-12 | 2006-10-03 | International Business Machines Corporation | Method of authenticating a plurality of files linked to a text document |
US7913313B2 (en) | 2001-06-12 | 2011-03-22 | International Business Machines Corporation | Method and system for invisibly embedding into a text document the license identification of the generating licensed software |
WO2003013141A1 (fr) * | 2001-07-31 | 2003-02-13 | Matsushita Electric Industrial Co., Ltd. | Systeme, appareil et procede de distribution de contenus, et programme et support d'enregistrement de programme correspondants |
DE10146926A1 (de) * | 2001-09-24 | 2003-04-24 | Rainer Annuscheit | Verfahren zur Vermittlung und Bereitstellung beweglicher oder veränderbarer Informationsinhalte |
EP1308821A3 (fr) * | 2001-10-30 | 2004-03-17 | Hitachi, Ltd. | Système et procédé d'authentification |
GB2385439B (en) * | 2002-02-15 | 2006-05-03 | Hewlett Packard Co | Digital rights management printing system |
GB2385439A (en) * | 2002-02-15 | 2003-08-20 | Hewlett Packard Co | Digital rights management printing system |
US8245306B2 (en) | 2002-02-15 | 2012-08-14 | Galo Gimenez | Digital rights management printing system |
AU2003203745B8 (en) * | 2003-03-24 | 2010-12-23 | Microsoft Technology Licensing, Llc | System and method for user modification of metadata in a shell browser |
AU2003203745B2 (en) * | 2003-03-24 | 2010-11-18 | Microsoft Technology Licensing, Llc | System and method for user modification of metadata in a shell browser |
EP1475775A3 (fr) * | 2003-04-21 | 2006-05-31 | Yamaha Corporation | Dispositif utilisant un contenu musical capable de gérer la copie de contenu musical |
US9836615B2 (en) | 2003-04-21 | 2017-12-05 | Yamaha Corporation | Music-content using apparatus capable of managing copying of music content, and program therefor |
JP2008530653A (ja) * | 2005-02-08 | 2008-08-07 | コンテントガード ホールディングズ インコーポレイテッド | 将来的に作成されるディジタル・コンテンツに対する使用権を確立するための方法及び装置 |
WO2007091189A3 (fr) * | 2006-02-06 | 2007-11-01 | Koninkl Philips Electronics Nv | Droits derives sur du contenu numerique controles |
WO2009133498A1 (fr) * | 2008-04-29 | 2009-11-05 | Koninklijke Philips Electronics N.V. | Gestion de contenus numériques |
US8782803B2 (en) | 2010-04-14 | 2014-07-15 | Legitmix, Inc. | System and method of encrypting a derivative work using a cipher created from its source |
WO2011127564A1 (fr) * | 2010-04-14 | 2011-10-20 | Legitmix, Inc. | Système et procédé permettant de crypter une œuvre dérivée en utilisant une clé de chiffre créée à partir de ses sources |
US8925102B2 (en) | 2010-10-14 | 2014-12-30 | Legitmix, Inc. | System and method of generating encryption/decryption keys and encrypting/decrypting a derivative work |
US20180365396A1 (en) * | 2017-06-15 | 2018-12-20 | Joel Rucker | Copyright verification system |
DE102018123835A1 (de) * | 2018-06-07 | 2019-12-12 | Evga Corporation | Dezentralisiertes System zur Erstellung von Softwareinformationen und Verfahren hierfür |
Also Published As
Publication number | Publication date |
---|---|
AU7662496A (en) | 1997-04-30 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US7047241B1 (en) | System and methods for managing digital creative works | |
WO1997014087A1 (fr) | Systeme et procedes de gestion d'oeuvres de creation numeriques | |
US7647642B2 (en) | System and method for managing copyrighted electronic media | |
US5765152A (en) | System and method for managing copyrighted electronic media | |
JP4512153B2 (ja) | コンテンツを確実に頒布するためのシステム | |
CN100437508C (zh) | 管理数字内容使用权利的方法和装置 | |
US7512798B2 (en) | Organization-based content rights management and systems, structures, and methods therefor | |
US8458273B2 (en) | Content rights management for document contents and systems, structures, and methods therefor | |
JP4511828B2 (ja) | ディジタル作品の権利を譲渡するシステム | |
KR100949657B1 (ko) | 유연한 권리 템플릿을 이용하여 권리 관리 시스템에서디지털 컨텐츠에 대한 서명된 권리 라벨(srl)을 얻기 | |
US7392547B2 (en) | Organization-based content rights management and systems, structures, and methods therefor | |
US7062650B2 (en) | System and method for verifying integrity of system with multiple components | |
US20020077986A1 (en) | Controlling and managing digital assets | |
US20050132207A1 (en) | System and method for authoring learning material using digital ownership rights | |
US7549062B2 (en) | Organization-based content rights management and systems, structures, and methods therefor | |
Jamkhedkar et al. | DRM as a layered system | |
EP1410629A1 (fr) | SYSTèME ET MéTHODE DE RECEPTION ET DE STOCKAGE D'UN FLUX DE TRANSPORT | |
Kidawara et al. | Encapsulating multimedia contents and a copyright protection mechanism into distributed objects | |
Hiroshi HOSHINO | 204 E-business: Key Issues, Applications and Technologies B. Stanford-Smith and PT Kidd (Eds.) IOS Press, 2000 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AK | Designated states |
Kind code of ref document: A1 Designated state(s): AL AM AT AU AZ BA BB BG BR BY CA CH CN CU CZ DE DK EE ES FI GB GE HU IL IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MD MG MK MN MW MX NO NZ PL PT RO RU SD SE SG SI SK TJ TM TR TT UA UG UZ VN AM AZ BY KG KZ MD RU TJ TM |
|
AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): KE LS MW SD SZ UG AT BE CH DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI |
|
DFPE | Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101) | ||
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
REG | Reference to national code |
Ref country code: DE Ref legal event code: 8642 |
|
NENP | Non-entry into the national phase |
Ref country code: JP Ref document number: 97515244 Format of ref document f/p: F |
|
122 | Ep: pct application non-entry in european phase | ||
NENP | Non-entry into the national phase |
Ref country code: CA |