These inventions relate to secure and trusted delivery of digital information. More specifically, these inventions pertain to techniques, methods and systems for providing reliable, trusted, verifiable delivery, handling, creation and/or execution of digital items such as documents, executable code (e.g., Java applets), and/or any other information capable of being represented in digital form. The present invention also relates to commercial and other electronic activities involving a trusted third party electronic go-between (such as a computer controlled process) to audit, validate, and/or direct electronic transactions, executions and/or delivery and/or to archive information representing and/or at least in part comprising securely communicated digital information.
There is a great need for convenient, cost effective techniques to securely handle and deliver documents and other items. Existing methods such as express and personal couriers, registered mail, facsimile and electronic mail fulfill some of these needs but these techniques each have their problems and are deficient in important ways.
Trusted Personal Couriers
Perhaps the ultimate in secure document handling is the personal trusted courier. Many of us have seen spy films showing a trusted courier delivering documents containing state secrets. In such scenarios, the document sender places the document or other item into a lockable attaché case. The sender seals and locks the case with a key or combination that only he and the recipient have. The courier handcuffs the case to his or her wrist, boards an airplane and flies to the required destination—all the while carefully guarding the attaché case and its contents. Upon arriving at the destination, the courier personally delivers the case to the intended recipient. The recipient unlocks the case and retrieves its contents, all the while having a high degree of assurance that the contents have been kept secret.
The confidentiality, security and reliability provided by a personal trusted document courier has never really been matched by any other form of document delivery. Even though we sometimes might want or need the services of a personal trusted document courier, it is likely that practical reasons (such as cost and availability) require us to use less trusted forms of delivery for even our most important and confidential documents or other items. Moreover, even the trusted courier technique does not provide a reliable means of later providing how and when the information was used by the recipient and/or subsequently handled by others to whom the recipient may pass the information and what information was actually sent. This approach also cannot provide the degree of interactivity between the sender and the recipient possible in a world of near instantaneous communications, including seamlessly supporting processes related to rights management, and document creation and dissemination.
As discussed below, existing alternatives to the trusted courier are more practical and less expensive, and some offer advantages such as instantaneous communications and interactivity—but all suffer from various disadvantages.
Express Courier Services
Federal Express and other express courier services provide rapid (for example, overnight) delivery services at a relatively high degree of trustedness.
In the typical case, the sender places the items to be delivered into a special, tear resistant sealed envelope, and fills out an “air bill” that lists the sender's name, address and telephone number, and the intended recipient's name, address and telephone number. The “air bill” also lists options such as, for example, the type of delivery service required (i.e., delivery next business morning, next business afternoon, or second business day), whether the sender requires Federal Express to obtain the recipient's signature, the payment method, and a unique “tracking number” used to uniquely identify the package.
Once the package is complete and ready to send, the sender may provide it to Federal Express through a number of different methods:
Federal Express maintains a fleet of aircraft that shuttle most packages to a central sorting and routing facility for subsequent dispatch to various destinations across the United States and the world. A fleet of delivery trucks deliver the packages from local airports to each recipient. At the sender's option, a delivery person may obtain a recipient's signature at the time she delivers the package—providing documentation that may later be used to prove the package was in fact received by the intended recipient or someone at his or her home or office.
Federal Express uses automated computer tracking and package handling equipment to route individual packages to their destinations. Delivery information is put into the tracking computer to allow customers and service people to automatically retrieve information about when and to whom particular packages were actually delivered, or where the package happens to be at the moment.
Federal Express and other similar document delivery services have been highly successful because they cost-effectively ensure reliable delivery of original documents and other items. Nevertheless, they do have some significant disadvantages and limitations. For example:
These problems are exacerbated when several individuals and/or organizations in different geographical locations are all parties to a transaction—a complex, multiparty contract, for example—and all must sign or otherwise process and/or execute one or more related documents.
Registered Mail
A relatively more secure delivery technique is registered mail. Registered mail correspondents can have a high degree of confidence that their packages will arrive at their required destinations—but may not like the time delays and additional expense associated with this special form of mail handling.
To use registered mail, the sender places her document or other items into a sealed envelope or package and takes her package to the nearest Post Office. For security, the Post Office may prohibit the use of resealable tape and mailing labels, and instead require the package to be sealed with paper tape and the address to be written directly on the package. These safeguards help to ensure that any attempts to tamper with the package or its contents will be detected.
The Post Office securely transports the registered mail package to the recipient, requiring each postal employee who accepts custody of the package along its journey to sign and time stamp a custody record. The postal carrier at the recipient's end personally delivers the package to the recipient—who also has to sign for it and may be asked to produce proof of identification. The custody record establishes a chain of custody, listing every person who has had custody of the package on its journey from sender to recipient.
As discussed above, registered mail is relatively secure and confidential but delivery takes a long time and is very labor and infrastructure intensive.
Facsimile
Facsimile is an electronic-based technology that provides virtually instantaneous document delivery. A facsimile machine typically includes a document scanner, a document printer, and electronic circuits that convert document images to and from a form in which they can be sent over a telephone line. Facsimile requires each of the sender and the intended recipient to have a facsimile machine. The sender typically places the document to be sent into a document feeder attached to a facsimile machine. The sender then typically keys in the telephone number of the intended recipient's facsimile machine and presses a “start” button. The sender's facsimile machine automatically dials and establishes contact with the recipient's facsimile machine.
Once a good connection is established, the sender's facsimile machine begins to optically scan the document one page at a time and convert it into digital information bits. The sender's facsimile machine converts the digital bits into a form that can be transmitted over a telephone line, and sends the bits to the intended recipient's facsimile machine. The sender's facsimile machine may also send as part of the document, a “header” on the top of each page stating the sender's identity, the page number of the transmission, and the transmission time. However, these headers can be changed at will by the sender and therefore cannot be trusted.
Since the recipient's facsimile machine receives the transmitted information at the same time the sender's facsimile machine is sending it, delivery is virtually instantaneous. However, sending a document to an unattended facsimile machine in an insecure location may result in the document falling into the wrong hands. Another common scenario is that the facsimile machine operator, through human error, dials the wrong telephone number and ends up delivering a confidential document to the wrong person (for example, the local grocery store down the street, or in some unfortunate cases, the opposing side of a negotiation, legal proceeding or other pitched battle). Thousands of faxes are lost every day in a “black hole”—never arriving at their desired destinations but possibly arriving at completely different destinations instead.
More and more, people are using electronic mail to send documents, messages, and/or other digital items. The “Internet explosion” has connected millions of new users to the Internet. Whereas Internet electronic mail was previously restricted primarily to the academic world, most corporations and computer-savvy individuals can now correspond regularly over the Internet.
Currently, Internet electronic mail provides great advantages in terms of timeliness (nearly instantaneous delivery) and flexibility (any type of digital information can be sent), but suffers from an inherent lack of security and trustedness. Internet messages must typically pass through a number of different computers to get from sender to recipient, regardless of whether these computers are located within a single company on an “Intranet” for example, or on Internet attached computers belonging to a multitude of organizations. Unfortunately, any one of those computers can potentially intercept the message and/or keep a copy of it. Moreover, even though some of these systems have limited “return receipt” capabilities, the message carrying the receipt suffers from the same security and reliability problems as the original message.
Cryptography (a special mathematical-based technique for keeping messages secret and authenticating messages) is now beginning to be used to prevent eavesdroppers from reading intercepted messages, but the widespread use of such cryptography techniques alone will not solve electronic mail's inherent lack of trustedness. These electronic mail messages, documents and other items (e.g., executable computer programs or program fragments) that might have been sent with them as “attachments,” remain vulnerable to tampering and other unauthorized operations and uses once decrypted and while delivery may be reported, actual use can not be demonstrated. Some people have tried to develop “privacy enhanced” electronic mail, but prior systems have only provided limited improvements in reliability, efficiency and/or security.
The Present Inventions Solve these and Other Problems
As discussed above, a wide variety of techniques are currently being used to provide secure, trusted confidential delivery of documents and other items. Unfortunately, none of these previously existing mechanisms provide truly trusted, virtually instantaneous delivery on a cost-effective, convenient basis and none provide rights management and auditing through persistent, secure, digital information protection.
In contrast, the present inventions provide the trustedness, confidentiality and security of a personal trusted courier on a virtually instantaneous and highly cost-effective basis. They provide techniques, systems and methods that can bring to any form of electronic communications (including, but not limited to Internet and internal company electronic mail) an extremely high degree of trustedness, confidence and security approaching or exceeding that provided by a trusted personal courier. They also provide a wide variety of benefits that flow from rights management and secure chain of handling and control.
The present inventions preferred embodiment make use of a digital Virtual Distribution Environment (VDE) as a major portion of its operating foundation, providing unique, powerful capabilities instrumental to the development of secure, distributed transaction-based electronic commerce and digital content handling, distribution, processing, and usage management. This Virtual Distribution Environment technology can flexibly enable a wide variety of new business models and business practices while also supporting existing business models and practices.
The Virtual Distribution Environment provides comprehensive overall systems, and wide arrays of methods, techniques, structures and arrangements, that enable secure, efficient electronic commerce and rights management on the Internet and other information superhighways and on internal corporate networks such as “Intranets”. The present inventions use (and in some cases, build upon and enhances) this fundamental Virtual Distribution Environment technology to provide still additional flexibility, capabilities, features and advantages. The present invention, in its preferred embodiment, is intended to be used in combination a broad array of the features described in Ginter, et al, including any combination of the following:
A. VDE chain of handling and control,
B. security trusted internodal communication,
C. secure database,
D. authentication,
E. cryptographic,
F. fingerprinting,
G. other VDE security and communication techniques,
H. rights operating system,
I. object design and secure container techniques,
J. container control structures,
K. ARPML rights and process control language,
L. electronic negotiation,
M. secure hardware, and
N. smart agent (smart object) techniques.
For example, parties using the Virtual Distribution Environment can participate in commerce and other transactions in accordance with a persistent set of rules they electronically define. Such techniques, systems and arrangements bring about an unparalleled degree of security, reliability, efficiency and flexibility to electronic commerce, electronic rights management and other important business models. The present inventions make use of these persistent electronic rules to provide secure, automated, cost-effective electronic control for electronic document and other digital item handling and/or delivery, and for the electronic formation and negotiation of legal contracts and other documents.
By way of non-exhaustive summary, these present inventions provide a highly secure and trusted item delivery and agreement execution services providing the following features and functions:
The present inventions also provide for the use of a trusted third party electronic go-between or intermediary in various forms, including the “virtual presence” of such go-between through the rules and controls it contributes for distributed governance of transactions described in the present invention, and further through the use of a distributed, go-between system operating in on-line and/or off-line modes at various user and/or go-between sites. Such a trusted third-party go-between can provide enhanced and automated functionality, features and other advantages such as, for example:
These and other features and advantages provided by the present invention will become better and more completely understood by studying the following detailed description of presently preferred exemplary embodiments in conjunction with the drawings, of which:
The entire disclosure of the above-referenced Ginter et al. patent specification is incorporated by reference in connection with
Item 4054 might be a document such as a handwritten or typed letter, or it could be a legal document such as a contract. It could have both text and pictures, just text or just pictures. It could be a sound recording, a multimedia presentation, or a visual work such as a film or television program. Item 4054 could be any item or information capable of being represented in digital form. The item 4054 can be initially presented to the appliance 600 in electronic form (for example, on a diskette), or the appliance can convert it from some other form into electronic form.
Electronic delivery person 4060 receives item 4054 in digital form and places it into a secure electronic container 302—thus forming a digital “object” 300. A digital object 300 may in this case be, for example, as shown in
In this example, sender 4052 sends item 4054 by supplying the document to an electronic appliance 600A. In this example, electronic appliance 600A is an intelligent electronic walk-up kiosk that may be located in a public place or on private property, such as the offices or work areas of a firm. Appliance 600A in this example has a document slot 4102 into which sender 4052 can feed item 4054. Electronic appliance 600A can automatically, optically scan the item 4054 and convert it into digital information for sending over an electronic connection or network 4058 (such as, for example, electronic highway 108 shown in
Referring to
Also as shown in
Also as shown in
Electronic appliance 600A may also ask the user to identify intended recipient 4056 (
Sender 4052 may also specify the electronic address of recipient 4056, or it might let system 4050 automatically, securely and confidentially locate the recipient using a secure directory service as described in the copending Shear et al. application.
Once sender 4052 has selected the service options she desires, appliance 600 may next display a message on computer screen 4104 asking sender 4052 to insert item 4054 into document slot 10′ for electronic scanning. When the sender 4052 inserts the document 4054 or other item (
The item 4054 to be sent need not be a document, but could be any type of item capable of being transformed into digital form such as, for example:
After appliance 600 has scanned or otherwise received the entirety of document 4054 or other item, appliance 600 may calculate and display a total price on computer screen 4104 and ask sender 4052 to pay for the service (
Example Electronic Delivery and Return Receipt
There are advantages to using multiple authentication techniques in combination. For example, a well made certificate is essentially unforgeable (which is to say, it would be easier to fabricate a electronic fingerprint carrying device, for example, than a well made certificate 4064 barring unforeseen advances in mathematics), but the trouble with certificates is the weakness of correlation between physical access (e.g., holding the card, or sitting at the appliance) and permission to use. Passwords are a weak form of authentication—that is, establishing this correlation. Biometric techniques, particularly iris and retinal scans, are stronger forms of authentication. It is possible for biometric information to be encoded in a field of a certificate 4064, and for the software controlling the card to confirm that the biometric input is consistent with the field in the certificate prior to authorizing use of the certificate or the card in general. This authentication may be limited in time (e.g., using an inactivity time out, each time the card is inserted, etc.) In addition, a transaction might require this authentication to occur simultaneous with use (rather than for an entire session, even if the card only requires one authentication per session).
After payment has been arranged (
Electronic delivery person 4060 may also note various information about the delivery (illustrated here by having him write the information down on a clipboard 4066, but implemented in practice by electronically storing an “audit” trail). System 4050 may—based on the particular receipt options sender 4052 requested—provide the sender with an electronic and/or paper receipt of the type shown in
The sender's electronic appliance 600A and the recipient's electronic appliance 600B can report their respective “audit trails” periodically or upon completion of delivery or some other event. They can report the audit information to a support facility such as information utility usage analyst 200C (see
Other Types of Electronic Appliances can be Used
As mentioned above, the kiosk appliances 600 shown in
Secure electronic delivery can also be from one personal computer 4116 to another.
Secure delivery can also be from one personal computer 4116 to another.
Electronic Execution of a Legal Document
System 4050 supports “simultaneous” as well as non-simultaneous contract or other document execution among contracting parties 4070. Simultaneous completion allows multiple parties located in physically different locations to directly and simultaneously participate in the execution of legal documents and/or other transactions that require authorizations.
Currently, businesses often prefer simultaneous execution of documents at what is called a “closing.” Such closings for important documents frequently require the presence of all participants at the same location to simultaneously sign all necessary legal documents. Business executives are often reluctant to sign a set of documents and then send them to the next party to sign, since special legal lanauage may be required to release the first (or early) signing party if the documents are not quickly signed by other participants and since certain liabilities may exist during this interim period.
One relatively weak form of authentication is physical possession of the card 4109. Nonetheless, if some form of weak authentication is used and biometric information is gathered in real time by sensor 4124, it may be correlated with some trusted record stored elsewhere, and/or delivered along with the item 4054. If biometric information is codelivered with the item 4054, and it is ever actually used, it must be correlated with a trusted record (this trusted record could, for example, be generated by the person providing biometric data in the presence of a trusted party if the validity of a transaction is called into question, at the sacrifice of significant automation and “commercial confidence” benefits). The ability to establish trust as the transaction occurs, rather than having some degree of nonrepudiation later (imagine if the transaction were fraudulent, and a user relied on the person showing up to give a retinal scan) is one significant benefit of example system 4050.
If the parties are simultaneously at their respective electronic appliances 600, they may verify each other's identity using video cameras and screens built into the kiosk. Such simultaneous execution has the advantage of allowing multiple parties at different physical locations to negotiate a deal in real time and then simultaneously, reliably execute and receive final, signed agreement copies that are valid and legally binding.
Trusted delivery mechanism 4060 may send messages such as offers 4054A and acceptances 4054B between the two electronic appliances 600A, 600B. These messages may be packaged within secure electronic containers 302. Some of these may be human readable, others may be automated as in
Once the parties 4070A, 4070B agree on the terms of the contract, they may securely indicate their agreement and system 4050 can generate an electronic and/or paper contract document 4068 that evidences and memorializes the agreement. As will be discussed below, contract document 4068 may have special attributes such as seals 4200, hand-written signatures 4300 and/or visual or hidden “electronic fingerprint” information 4400. Such seals 4200, signatures 4300 and electronic fingerprints 4400 can be used to establish the authenticity of the document (for example, preventing a signatory from repudiating it and to allowing it to be admitted as evidence in a court of law).
System 4050 can electronically pass contract 4068 along a “chain” from one party 4070 to the next (“Round Robin”), collecting signatures as it travels along. System 4050 can also allow each party 4070A-4070F to communicate with any other party. One copy of contract 4068 could be passed along from party to party and iteratively signed at the respective signers' locations. The last signer could then broadcast final, signed copies of contract 4068 to all parties. The electronic containers 302 can specify who the next recipient of contract is—forming a trusted chain of handling and control for contract 4068.
In one example, all of the parties 4070 may be required to hit an “I Agree” button (e.g., by placing a finger onto a biometric sender 4124 shown in
Trusted Electronic Go-Between
The drawings show the trusted go-between 4700 as a person for purposes of illustration only. In the preferred example, trusted go-between 4700 may be a computer that performs its functions electronically in a highly automatic and efficient way. In one example, the computer's capabilities may be augmented by human participation.
The Trusted Electronic Go-Between can Help with Contracts
In one example, trusted electronic go-between 4700 can also act as a mediator to resolve disputes between the contracting parties 4070A, 4070B, and can help negotiate the contract. At the conclusion of the contracting process, trusted electronic go-between 4700 may affix its own seal 4200A to the executed contract document 4068. This seal 4200A may provide a guarantee or assurance that all of the steps required by trusted electronic go-between 4700 were fulfilled before the contract 4068 was executed and that the contracting parties 4070A, 4070B are who they say they are and had authorization to execute the contract.
It is extremely useful to have trusted go-between 4700 monitoring this activity to order the application of signatures (if required), and to allow a roll back if the system fails before applying all of the signatures. The role of go-between 4700 may, in some circumstances, be played by one of the participant's SPU's 500 (PPEs), since SPU (PPE) behavior is not under the user's control, but rather can be under the control of rules and controls provided by one or more other parties other than the user (although in many instances the user can contribute his or her own controls to operate in combination with controls contributed by other parties). In another example, the go-between role 4700 may comprise a “virtual go-between” comprised of a one, a combination of plural, or all, nodes of participants in a collective or other group. Governance can be shared through the interaction of rules and controls of the various node PPEs producing a go-between control role. Upon the completion of a go-between managed transaction, transaction audit information for archive, billing, security, and/or administrative purposes may be securely transmitted, directly, or through one or more other participating in the virtual go-between.
The Secure Electronic Go-Between can be Used within and Between Organizations
In this example, organization A user nodes 600(A)(1), . . . , 600(A)(N) each have an instance of a virtual distribution environment protected processing environment, and can communicate with one another over Intranet 5100(A) via secure electronic containers 302. Similarly, organization A user nodes 600(B)(1), . . . , 600(B)(N) each have an instance of a virtual distribution environment protected processing environment, and can communicate with one another over Intranet 5100(B) via secure electronic containers 302. In addition, organization A and organization B can communicate with one another over Internet 5104 via secure electronic containers 302.
Organization A's private trusted go-between 4700(A) may be used for facilitating organization A's internal communications and processes. Private trusted go-between 4700(A) might be used, for example, to carefully track documents and other items sent from one user to another within organization A. The public go-between 4700(C), meanwhile, can be used to coordinate between organization A and organization B without, for example, revealing confidential information of either organization to the other organization. Below are more detailed examples of how the
More about the Secure Electronic Container
In this example, secure container 302 may contain a digital image 4068I of a document or other item 4054 to be delivered from one party to another. This image may include one or more seals 4200, one or more hand-written signatures 4300, and one or more electronic fingerprints 4400. The item 4054 may be multiple pages long or it may be a single page. The item 4054 may contain text, pictures or graphical information, computer instructions, audio data, computer data, or any combination of these, for example. Image 4068I may be represented in a so-called “universal” format to allow it to be created and displayed and/or printed by any standard software application capable of processing items in the appropriate “universal” format. If desired, image 4068I may include cover sheets, virtual “stick on” notes, and/or the like. Secure container 302 may contain any number of different 4054.
Container 302 may also contain another, data version 4068D of the item 4054. This data version 4068D might, for example, comprise one or more “word processing” files corresponding to a text document, for example.
The container 302 may also contain one or more tools 4074 for using image 4068I and/or data 4068D. Tools 4074 might be used to allow the intended recipient 4056 to manipulate or view the image 4068I and/or the data 4068D. Tools 4074 might be computer programs in one example (as mentioned above, item 4054 can also be a computer program such as a program being sold to the recipient).
Secure container 302 may also contain an electronic, digital control structure 4078. This control structure 4078 (which could also be delivered independently in another container 302 different from the one carrying the image 4068I and/or the data 4068D) may contain important information controlling use of container 30′. For example, controls 4078 may specify who can open container 30′ and under what conditions the container can be opened. Controls 4078 might also specify who, if anyone, object 300 can be passed on to. As another example, controls 4078 might specify restrictions on how the image 4068I and/or data 4068D can be used (e.g., to allow the recipient to view but not change the image and/or data as one example). The detailed nature of control structure 4078 is described in connection, for example, with
Secure container 302 may also include one or more routing slips 4072 and one or more audit trails 4077. Routing slip 4072 and audit trail 4076 are data structures defined by and/or associated with electronic controls 4078, and may be integrated as part of these electronic controls (see
Document Signatures
System 4050 in this example can accommodate any or all of these conventions by imprinting various graphics and/or symbols on printed item 4054. In the
Hand-written signature 4300 may be a graphical image of the signer's own hand-written signature. System 4050 can obtain this hand-written signature image 43.00 in a number of ways. For example, system 4050 may require the signer to sign his or her signature at the time item 4054 is created. In this example, once the document is finalized, sender 4052 or contracting party 4070 can sign his or her signature using a magnetic or pressure-sensitive signature capture device, for example. Such conventional signature capture devices electronically capture the image of a person's signature and store it in a memory. System 4050 can then—once it securely obtains the authorization of the signer with a very high degree of trustedness and sureness (e.g., by requesting a password, biometric test, etc.)—place hand-written signature 4300 onto an appropriate part of item 4054.
Alternatively, the signer may carry his or her hand-written signature on a portable storage medium such as, for example, a magnetic, smart or memory card. The portable storage unit may employ rules and controls for budgeting the number of times and/or class and/or other circumstances of a transaction that a signature can be employed, or before the device needs to re-connect to a remote authority as disclosed in the above-referenced Shear et al. patent. The signer can present this storage medium to system 4050 as a source for the signature image 4300 shown in
In still another example, system 4050 may securely maintain hand-written signature files for a number of different users in a secure archive or “secure directory services” as disclosed in the above-referenced Shear et al. patent disclosure. At a user's request, system 4050 may call up the signature file pertaining to that user and impress the corresponding signature onto item 4054. If an image representation of a signature is stored on portable media or in a directory service, the image may be stored in an electronic container 302. Such a container 302 permits the owner of the signature to specify control information that governs how the signature image may be used. In addition, or alternatively, the signature image may be stored in or securely associated with a field of a digital certificate (that may, for example, also incorporate other identifying information).
System 4050 also is capable of imprinting special seals 4200 onto item 4054.
In this example, outer portion 4204 is used for encoding digital information.
System 4050 can recover the encoded information by scanning and analyzing an image of item 4054 in either digital or printed form. In one embodiment, system 4050 can create electronic controls 4078 based at least in part on this information it obtains from seal 4200.
The hash function may operate on a document in its image form, or its text equivalent (producing two different hash values). In addition, the text version of a document may be pre-processed before operation of the hash function to simplify verification of a document if it must be rekeyed into a verification system (e.g., in the case where all electronic copies of a document have been lost). Since cryptographically strong hash functions are extremely sensitive to the slightest change in data (yielding different values if, for example, a tab character is keyed as a series of spaces) this pre-processing may normalize the document by, for example, discarding all font and formatting information and//or reducing each occurrence of “whitespace” (e.g., spaces, tabs, carriage returns, etc.) into a single space. If the same pre-processing is applied to a retyped version of the document before the hash function is applied, it will have a much higher likelihood of yielding the same hash value if the documents are substantively the same.
System 4050 may later recover this information by digitally and/or optically scanning the image of item 4054 and analyzing the pattern of seal 4200 to recover digital signature 4216. System 4050 may then apply the public key corresponding to the private key used to encrypt the information—thereby recovering the hash, time and digital certificate, while at the same time authenticating the information as having been encrypted with the relevant private key(s). In this example, System 4050 also has the original document image 4054 available to it, and may therefore duplicate the one-way hash process 4212 and compare the hash value it gets with the hash value encoded within seal 4200. Mismatches indicate that the seal 4200 may have been copied from another document and does not apply to the document currently being analyzed.
Other types of digital identifying information that system 4050 might affix to the document include, for example:
Electronic appliance 600 may be any type of electronic device such as a personal computer, intelligent kiosk, set top box, or dedicated stand-alone communications appliance—just to name a few examples. Processor 4126 is connected to
A document handler/destroyer 4115 may be provided to feed multi-page documents into document reader/scanner 4114 and—in one embodiment—to destroy documents to ensure that only one “original” exists at a time. Such controlled document destruction might, for example, be useful in allowing sender 4052 to deliver an original stock certificate to a transfer agent. The sender 4052 could insert the original certificate into appliance 600—which may scan the original to convert it to digital information (e.g., through use of OCR technology), confirm delivery, and then destroy the original paper version. Secure controls 4078 could be used to ensure that only a single original ever exists on paper.
Processor 4126 is also connected to secure and/or insecure digital or other storage 4130 (such as, for example, magnetic disks, random access memory, optical disks, etc.), and to a communications device 666 permitting the processor to communicate electronically with other processors or devices via an electronic network 4058 (672). In one example, appliance 600 may be provided with additional and/or different components such as shown in
Example Process to Send an Item
Once the appliance 600 has been properly initialized, the first step in a send process 4500 may be to authenticate the identity of sender 4052 (
In this particular example, the authentication step 4502 may involve an application program executing on appliance 600 requesting authentication support from protected processing environment 650—for example, sending to the protected processing environment an authentication “event” requesting the protected processing environment to authenticate the sender and providing authentication information to the protected processing environment (
In this particular example, the protected processing environment 650 may examine the authentication information provided to it (e.g., the output of biometric sensors, password information, information read from an identity card, etc.) and determine (based on methods provided in one or more electronic control sets) whether it has sufficient basis to conclude with a requisite, specified degree of assurance that the sender is who she says she is (
The nature and characteristics of this sender authentication test performed by PPE 650 may vary depending on the particular electronic control set being used—as dictated by particular applications. As discussed above, in situations that have legal significance in which non-repudiation is very important, PPE 650 may impose a relatively stringent authentication test. Other, more routine situations may use control sets that impose less stringent authenticity checks.
The PPE 650 may abort the process if it decides there is insufficient information to form a trusted belief of authenticity and/or if it determines that the sender is not who she says she is (
The sender's appliance 600 may next need to identify or “register” the intended recipient(s) 4056 (
Why might the sender's PPE 650 need to contact the recipient before sending the item? The answer is that it may be necessary or desirable for the sender 4052 and the recipient 4056 to negotiate and/or agree as to the appropriate electronic controls that should apply. In an item transmission scenario, for example, such an “agreement” might work out who is going to pay for the delivery service, which recipient appliance (home or office) the document is to be delivered to, what kind of return receipt is acceptable to both parties, etc.
The PPE 650's “register recipient” event processing may, for example, allow the proposed recipient to deliver a set of controls to the sender's system that defines the parameters of receipt. Some general purpose systems may use the default settings in the kiosk or other transmission station. The address itself may provide an indication to the transmitting station as to whether it may or must request a set of control information from the recipient prior to transmission.
More complicated scenarios may require further coordination. For example, an option to destroy the original item at the send end and recreate it at the recipient's end (e.g., in the case of the stock certificate mentioned earlier) is both a send option and a receipt option. Similarly, options pertaining to procedures for electronic contract execution typically will require pre-agreement from both the sender and the recipient (i.e., from all parties to the contract). In these cases, there should be some menu options that are driven by the address of the proposed recipient—and there may be an electronic (or humanly-driven) negotiation to resolve conflicts.
The PPE 650's “register recipient” processing may also require input or other interaction from the user.
This dynamic user interface approach allows control structures to be more “self describing” in the sense that application programs do not need to know ahead of time (i.e. when they are written) all of the fields, values, etc. for the structures. This gives structure designers more freedom in how their controls are designed. Given a rich enough grammar in the DTD 1108, designers needn't concern themselves with whether application programs will have the ability to manage the interaction with a user regarding their structures. This capability can also be used to create controls that support the electronic negotiation process shown for example in
The PPE 650 then may determine whether it needs to request and obtain a control set from the recipient to proceed (
On the other hand, if PPE 650 must get a recipient's control set (
Once PPE 650 determines how to contact the recipient, it may construct an administrative object 870 (see
The PPE 650 within the recipient's electronic appliance 600 or other responding VDE node may process administrative object 870 upon receiving it (
The sender's PPE 650 may register the received controls (
If the problem is not critical (“N” exit to
Referring to
Document Options
Delivery Options
Contract Execution Options
Teleconferencing Options
Trusted Go-Between Options
In the dynamic user interface model, for example, the user options associated with a contract offer (which are used to create electronic controls associated with the electronic transaction) might relate to a suggested addition, modification, deletion, etc. to an existing item 4054. If the VDE-aware applications used by the participants included word processing capabilities (given that the negotiation has a text based portion), for example, the VDE protected content in the offer could be represented as a “redline” or “revision marking.” The controls could further include aspects that manage modification of content in a controlled way (e.g., see
The options (and associated controls) associated with a contractual offer may also permit the offerer and/or the recipient to add comments to the offer before it is sent and/or accepted. These comments and/or some or all of the negotiation history may be recorded and managed using the audit capabilities of VDE and/or one or more repositories for VDE objects.
In this example, the PPE 650 checks the user input for validity (
PPE 650 may next specify any audit and routing controls based on the user input it has received and/or the recipient controls it has registered (
Control set 4078 can be used to enforce a secure chain of handling and control on document container 302 and/or its contents. This secure chain of handling and control may be used, for example, to specify delivery, routing, auditing or other parameters as discussed above.
In performing step 4512, appliance 600 may also create routing slip 4072 (see
Exception list 4529 may indicate “named exceptions” (e.g., communications failure, line busy, refused receipt, refused payment request, etc.) paired with a list of responses (e.g., try again, cancel entire transaction, send report, invoke event in PPE) and data parameterizing the responses (e.g., number of retries, list of recipients of cancellation notices, report recipients, control information identifier and additional parameters for control use and/or invocation; respectively).
Recipient receipt information field 4527 for each recipient may indicate, for example, the nature of the receipt required, and the recipients of that receipt. A receipt “template” may be included in the container, may be referenced in an archive, or may be named out of a set of default templates stored in each appliance.
The routing slip 4072 (see
In another example, an entire class of users may be permitted to access the documents (through the presence of a certificate indicating their membership in a class, for example), and the routing slip 4072 may be used to record who has handled a particular version of the document. Through use of chain of handling and control techniques, the presence of certain users on the routing slip may permit further control information to be specified by a user. For example, after an analyst's research report has been reviewed by three other analysts, a manager may be permitted to modify the control information associated with the report to permit transmission to “public” users.
Electronic controls 4077 may also include one or more control methods specifying the type of audit information that is to be maintained in connection with the electronic transaction. This audit information may be used for constructing a receipt 4066, to provide evidence preventing repudiation, and for a variety of other functions. Such audit information may be maintained exclusively within the sender's appliance 600, it might be maintained exclusively within the recipient's appliance secure database, it might be maintained exclusively within the trusted go-between 4700's appliance 600 secure database, or it might be maintained in a combination of any or all of these. Additionally, the audit information may or may not be delivered with item 4054 depending on the particular objectives. A usage clearinghouse 200c as described above in connection with
As mentioned above, audit information 4077 associated with use of a document may be transmitted to many different parties. Audit information 4077 may also be treated as part of the signaling methodology described for reciprocal methods (see
Referring once again to
The appliance 600 is then ready to accept item 4054 (such as a document) to be sent if the item hasn't already been inputted (
Appliance 600 may store the item in any of multiple representations. For example, it could store it in Adobe Acrobat (PDF) or other text based page description. Storing the document in CCIT Group III Facsimile format is an example of a “universal” image format for black and white images. Group V is an example of a color format. TIFF is another example that incorporates many image types, as well as different compression formats and descriptive metadata.
PPE 650 may perform various tests on the inputted item and/or other results of the user interaction provided by block 4512E in accordance with one or more user controls. For example, if the sender has specified that he is sending a 6 page letter but only inputs five pages, PPE 650 may notice this discrepancy and notify the sender (
PPE 650 may embed any seals 4200, signatures 4300 or hidden signatures 4400 into the item if needed (
Depending upon the particular electronic controls being used, placement of the sender's signature or seal on the document may be based on the PPE 650's authentication of the sender as shown in FIG. 111—and may require an additional indication of assent from the sender—for example, pressing a “Yes” button, providing additional biometric or other identification information (e.g., “place your finger on the sensor if you want to sign this letter” or “Provide your mother's maiden name to sign this letter”). Such authentication is important for non-repudiation and to prevent fraud. The sender might actually sign his signature on a pressure-sensitive or magnetic-sensing signature capture and/or verification pad, provide a bit-map image of his signature by presenting a “smart card” storing it (plus using appropriate authentication techniques to assure that the bitmap image is being presented by the true signature owner), or provide enough information through user interaction as described above that the PPE 650 can access an electronic signature file containing the signature (e.g., stored locally within appliance 600 or accessible over network 672 from an archive).
In the multi-party execution example shown in
Appliance 600 may next place the item and associated electronic controls into one or more secure containers 302 (
Referring to
Appliance 600 may, through further interaction with PPE 650, immediately and/or later provide a receipt such as shown in
For purposes of security and trustedness, PPE 650 may actually “issue” the receipt—although it may use various other portions of appliance 600 (e.g., receipt printer 4112A, display 4104, card/media reader 4108, 4132, etc.) to output the receipt to the sender 4052. PPE 650 may also or alternatively maintain a copy of the receipt information (and/or the audit information 4077 on which it is based) within its secure database 610 (see
Example Receive Process
Intended recipient 4056 may be given an option of accepting or declining delivery of the object (
PPE 650 may next securely authenticate the received item to ensure that it is not a counterfeit (
PPE 600 may analyze any seal or other secure information that is part of the item 4054. For example, although the item image may be captured and cropped by untrusted processes, the analysis of the image data is preferably done inside the PPE 650. Once the seal option of the image is identified, an analysis process will be run to recover the digital information stored in the seal (or steganographically encoded in the document). The next step is to determine what the expected values should be. To do this, the PPE 650 may make requests of an application program running locally to determine a user's expectations, may use a digital representation of a receipt or other audit data, and/or may contact a trusted go-between or other trusted third party to obtain the appropriate expected values. To facilitate this process, there may be some unencrypted information in the seal that can be used to establish a correlation with other information (e.g., a receipt, a transaction number, etc.). If such information is not available, a local store or a trusted third party might compare the entirety of the recovered digital information with stored records to determine such a correlation. In other cases, the expected values may be determined from context (e.g. a default set of expected values; or by examining the seal information itself, in either encrypted or decrypted form, for “tags” or other schema or semantic information).
Once the expectation values of the information is determined, any encrypted portion must be decrypted using the public key corresponding to the private key used above to make the seal. This key can be obtained using the mechanisms discussed in Ginter et al.
Once decrypted, the expected values may be compared with the actual values to determine correlation. Information about the correlation may be reported to a user and/or a third party, as appropriate. In addition, some or all of the seal information may be included in such report.
Once PPE 650 is satisfied that the received item is authentic, it may embed receipt related information into the item if the electronic controls 4078 associated with the item require it (
Referring again to
Referring again to
If recipient 4056 wants to redistribute the item to another person (
Example Trusted Electronic Go-Between Detailed Architecture and Operation
In addition to the secure archive, witnessing and transaction management functions discussed above, trusted electronic go-between 4700 may perform additional services, such as, for example:
The trusted electronic go-between 4700 may comprise or include a “transaction authority” as disclosed in the above-referenced Shear et al. patent disclosure, and may have the same structure and architecture as shown in
The trusted electronic go-between 4700 may be one computer or many. It may be centralized or distributed. It may be public or private. It may be self-sufficient, or it may operate in conjunction with other go-betweens or other support services. It may be entirely automatic, or it may include functions and tasks that must be performed using human skills and expertise. It could be owned by a corporation or other organization, or it could be a cooperative. It could charge for its services, or it might offer its services free of charge.
As illustrated in
In another trusted go-between topology, each of the participants could have one or more trusted intermediaries that interact with each other on behalf of the participants.
In this specific example, additional electronic appliance 600B may be owned and/or operated by an entity having the legal authority to be an electronic notary public. The notary public protected processing environment 650B may execute a control set 914B relating to notary functions. Control set 914B in this example, has a reciprocal relationship between an overall control set 914A executed by a protected processing environment 650A of electronic appliance 600A. As shown in
The illustrated reciprocal control sets 914A, 914B may reciprocally interact as described above in connection with
Similarly, the reciprocal control set 914A operated by electronic appliance protected processing environment 650A may include methods 1000 responding to reciprocal events, such as, for example:
The control sets 914B, 914A thus define and control the processing which go-between 4700 performs on documents and other items in order to notarize them. Human users may interact with this process if desired through optional user interfaces 4714, 4716. Such human intervention may be required under certain circumstances (for example, if a live human witness might be required to testify as to certain notarization facts, if the automatic processes determine that a fraud is being attempted, etc.). The dynamic interface technology described above can provide a mechanism for delivering a user interface through the system without direct intervention by the provider of the overall service with respect to user interface, and by the notary with respect to the customer relationship.
Example Trusted Go-Between Process Upon Item Receipt
Trusted electronic go-between 4700 may also archive transmission related data as determined by the electronic control set 4078 associated with the item 4054 being sent, the transaction type and/or sender and/or recipient information (
Trusted electronic go-between 4700 may next further process the received item 4054 in accordance with requirements provided by electronic control set 4078 (
As part of this processing, trusted electronic go-between 4700 may, if necessary, redistribute the electronic container 302 to the intended recipient 4056 (
Example Trusted Go-Between Process to Archive and Redistribute an Item
Unless it already has the required permission to redistribute the object 300 (e.g., based on controls within the object's container 302), trusted go-between 4700 may need to request permission to redistribute (
If trusted go-between 4700 is unable to obtain the necessary additional permissions (“no” exit to decision block 4782,
Trusted go-between 4700 may perform appropriate payment processing (
Example Process for Trusted Go-Between to Provide an Item from its Secure Archives
In most instances, retrieving archived data requires a user to authenticate themselves, and present information identifying the container. Some containers may require more than one party to retrieve data (e.g., both the recipient and the sender), in most cases a user who is not party to the transaction cannot retrieve data (an exception could be a government authority, such as a court or tax auditor). In one interesting case, all electronic copies have been lost or were never stored (presumably, the archive only contains transaction information and a hash value).
In this example, the trusted go-between 4700 may authenticate the received request, and in the process may also satisfy itself that the requestor has authorization to make the request (
Assuming the request and requester are both authentic, trusted go-between 4700 may access the requested item(s) from its secure archive 4702(
In this example, trusted go-between 4700 may optionally notify the owner(s) or other interested parties of item 4054 that it has provided a copy to the authorized requestor (
Example Contract Execution Process
Alice may indicate to protected processing environment 500 within her electronic appliance 600 that she wishes to sign the contract—thereby creating a legal “offer” (
In this response to this action, Alice's protected processing environment 500 may affix Alice's signature 4300 and/or appropriate personal seals 4200 to the contract (see
Upon receipt by Bob's electronic appliance (
Assume that Bob reads the contract, and agrees to sign it
Alice's protected processing environment 500 may send notification of Alice's confirmation to Bob (
In this example, Alice's protected processing environment may also send a copy of the signed, sealed contract to a trusted go-between 4700 for notarization and/or archival purposes (see
In one specific example, the delivered contract can be a non-disclosure agreement co-delivered with an item(s) 4054 subject to the non-disclosure provisions of the agreement. Associated electronic controls automatically enforce the non-disclosure provisions of the agreement with respect to the co-delivered item(s) 4054.
Example Contract Execution Mediated by a Trusted Go-Between
Upon receiving the object (
Upon receipt of the object, Bob's protected processing environment 500 may open the container 302 (
The trusted go-between 4700 may notify Alice of Bob's intention to sign the contract (
The following are some non-exhaustive examples of how system 4050 provided by the present inventions can be used in a variety of different, illustrative contexts.
Automobile Purchase
Document Notary
To prevent either party from later repudiating the contract 4068, trusted go-between 4700 may require certain secure indication(s) allowing the trusted go-between to verify that Bob and Ted are who they say they are. These indications required by trusted go-between 4700 should have sufficient reliability that they will later stand up in a court of law. One possibility is for trusted go-between 4700 to capture biometric information such as photographic images, fingerprints, handprints, retina patterns or the like. Another possibility is to rely on the digital signatures (and thus the security of the private keys) of Bob and Ted—possibly in conjunction with digital certificates and biometric sensing techniques as described above. In system 4050, Bob's private key and Ted's private key might never be exposed outside of their respective secure electronic appliances 600, 600′—preventing each of them from voluntarily exposing their private keys as a basis for repudiating the contract.
Trusted go-between 4700 may be completely electronic and automatic. It may receive container 302(1), and open the container to access the contract 4068 it contains. Trusted go-between 4700 may create a notarial seal 4200 on the document encoded with information encrypted using the trusted go-between's private key. This encrypted information might indicate the time and date the trusted go-between received the document; a digital certificate number that securely identifies the trusted go-between; and the “hash” value of the signed contract 4068 (see
Trusted go-between 4700 may then store the notarized document 4068′ within its secure electronic archive 4702. The trusted go-between 4700 may also, if desired, supply copies of the notarized document back to Bob (4070a) and Ted (4070b) within additional electronic containers so they each have record copies of the notarized contract 4068′.
Suppose a dispute arises between Bob and Ted. Bob wants to enforce the contract 4068 against Ted. Ted claims he never signed the contract. Trusted go-between 4700 supplies a copy of the notarized contract 4068′ to a court of law 5016 or other dispute resolver. By electronically analyzing the executed contract 4068′, the court 5016 can read the notarization assurance of trusted go-between 4700 that Ted did in fact execute contract 4068. So long as the trusted go-between 4700 required sufficient verification of Ted's identity before electronically notarizing the document 4068′, the court 5016 should accept the notarization as conclusive evidence that Ted executed it.
Because of the extremely high degree of trustedness possible using system 4050, the
Teleconferencing
This teleconferencing capability can be useful, for example, to allow sender 4052 and recipient 4056 to verify they each are who they say they are, and to assist in negotiating contract 4068 or otherwise discussing the content of an item 4054. In order to further assure the authenticity of the communication, a secure communications link may be established using key exchange techniques (e.g., Diffie-Hellman) and encryption of the signal between the stations.
Secure containers 302 may be used to encapsulate the video and audio being exchanged between electronic kiosk appliances 600, 600′ to maintain confidentiality and ensure a high degree of trustedness. Thus, in this example, each secure container 302(2) might contain some portion of or multiple video images and/or some portion of or multiple audio segments. Electronic appliances 600, 600′ can exchange such secure container 302(2) back and forth in rapid succession to provide real time audio and video transmission In order to improve performance, the containers themselves may remain at the users' sites, and only the encrypted contents transmitted between the participants. This may allow one or two containers to protect the entire communications between the parties.
In still another variation, the teleconferencing shown in
Doctor Management/Coordination of Health Records
The doctor 5000 may then send container 302(1) to a trusted go-between 4700. Trusted go-between 4700 could be a computer within a doctor's office, or it could be a commercially operated trusted go-between specializing in health care transactions or usable in general types of transactions. Trusted go-between 4700 might be instructed by electronic controls 4078 to time and date stamp electronic container 302(1) upon receipt, and to store the electronic container within its secure archive 4702. It might also be instructed to maintain patient records 5004 completely confidential (indeed, controls 4078 may prevent the trusted go-between 4700 from itself having any access to these patient records), but to forward a copy of the patient records 5004 to the patient's insurance company 5008 so the insurance company can pay for the medical services rendered by the doctor 5000. For example, the trusted go-between 4700 in one example has no access to the content of the container 302(1), but does have a record of a seal of the contents. If trusted go-between 4700 has the seal, it can interact with other parties to confirm the contents of the seal—without needing to know or disclosing (as the case may be) the contents. Controls 4078 might also instruct trusted go-between 4700 to forward the drug prescription 5006 to the patient's selected drug store 5010 upon the request of patient 5002.
The patient 5002 could make such a forwarding request, for example, by operating an intelligent kiosk 600′ at the drug store 5010. The patient's electronic request 5012 could be sent to trusted go-between 4700, which in response might retrieve the drug prescription 5006 from its secure archive and forward it electronically within a secure container 302(3) to the drug store 5010 chosen by patient 5002.
One of the patient records 5004 might be a consent form that was executed by patient 5002. To help prevent the patient 5002 from later repudiating his consent, doctor 5000 might register this consent form with trusted go-between 4700—which could then “witness” it by notarizing it and affixing its seal, date stamp and/or digital signature. Trusted go-between 4700 could provide this consent form 5014 to a court of law 5016 and/or medical malpractice company in the event that patient 5002 sued the doctor for medical malpractice.
Complex Business Transaction
Trusted go-between 4700 registers the contract 4068, and then creates an electronic list of rules based on contract 4068. A partial example rule list is shown in
Trusted go-between 4700 may need to communicate with each of a number of parties in order to determine whether the conditions have been satisfied. For example:
In this example, trusted go-between 4700 may receive electronic notifications in secure containers 302 as each step in the overall process is completed. As illustrated in FIG. A3A, trusted go-between 4700 can electronically check each completed condition off of its electronically-maintained condition list as it receives such event notifications. Trusted go-between 4700 maintains this electronic list 4704 in a secure, validated and authenticated manner using system 4050—requiring, for example, receipt of electronic containers having event notifications that are signed cryptographically with one or more digital signatures from the appropriate parties. In this way, trusted go-between 4700 can maintain a highly reliable and validated, authenticated audit of the transaction steps as the overall transaction proceeds.
In addition, trusted go-between 4700 may, if desired, be empowered to issue additional requirements and/or instructions to facilitate the progress of the transaction. For example, trusted go-between 4700 might be a private trusted go-between operated by lender 5042—and thus, might be empowered to select which lawyer 5046 to use and to send that lawyer, automatically, appropriate instructions and forms for completing the transaction. As another example, the trusted go-between 4700 may be part of the business operated by lawyer 5046 or other settlement agent, and may thus be empowered to select and instruct escrow bank 5040.
When trusted go-between 4700 determines, based on the electronic rules/control set 4704 and the notifications it has received that all conditions for settlement have been satisfied, the trusted go-between may allow the “atomic transaction” to settle by issuing appropriate notifications and/or instructions—once again using secure electronic containers 302 and the receipt, verification, authentication, and other mechanisms discussed above to ensure reliability, confidentiality and a high degree of trustedness. For example:
All of these various coordination steps can be performed nearly simultaneously, efficiently, rapidly and with an extremely high degree of trustedness based on the user of electronic containers 302 and the secure communications, authentication, notarization and archiving techniques provided in accordance with the present inventions.
Court Filings and Docket Management
For example, defendant's attorney 5052 can specify one container 302 for opening by his co-counsel, client or client's in-house counsel, and program another container 302 for opening only by opposing (plaintiff's) counsel 5050. Because of the unique trustedness features provided by system 4050, the defendant's attorney 5052 can have a high degree of trust and confidence that only the authorized parties will be able to open the respective containers and access the information they contain.
Appliances 600, 600′ may issue highly trusted and reliable return receipts as described above. These highly trusted electronic return receipts may substitute for certificates of service if court 5016 permits.
The lawyers 5050, 5052 can also electronically file any of these exchanged documents with the court 5056 by sending the documents to the clerk 5054 via secure electronic containers 302. In this example, the clerk 5054 may actually be a computerized trusted go-between 4700 (represented here by a person but implemented in practice in whole or in part by one or more secure electronic appliances 600). The clerk 5054 may present a digital certificate evidencing that it is authorized to open a secure container 302 it has received. The clerk may then date stamp each received document (this may involve placing a seal 4200 on the document but more typically might involve simply placing a digital time signature on the document). The clerk 5054 may file the document electronically within a secure electronic archive 4702 that can provide a database for linking related documents together.
The judge 5056 might have a secure electronic appliance 600 in the courtroom or in chambers that could be used to view and/or print documents from the secure electronic archive 4702. The judge 5056 could instantly call up any filing to determine when it was received by the clerk 5054 and to review its contents. Different authorizations and/or encryption strengths could be used with respect to publicly available documents and documents under seal (for example, so that sealed documents could only be opened by the judge 5056 or her staff).
The judge 5056 could write her orders and opinions using electronic appliance 600. She could then send these documents within a secure electronic container 302(3) for filing by the clerk 5054 in secure electronic archive 4702, and for automatic service on the lawyers 5050, 5052.
In this example, the clerk/trusted go-between 4700 could also be used to ensure compliance with the local rules of court. For example, the clerk/trusted go-between 4700 could maintain, in electronic form, electronic controls 4078 indicating the time and formal requirements with respect to different kinds of filings. The clerk/trusted go-between 4700 could automatically check all incoming filings from the lawyers 5050, 5052 to ensure compliance with the local rules, and to issue notices and other appropriate forms in accordance with the local rules. Use of a dynamic interface technology may be used to generate and deliver a set of controls to the sender's system that defines the parameters of receipt—and default controls may be used to specify appropriate parameters, formats, etc.
Note that in this example, documents can be controlled independently of where they are routed. For example, defendant's litigating counsel 5052 could specify electronic controls that would allow court 5016 to access a document that need not be filed with the court but which might be of interest to the court at a later date (e.g., letter between opposing counsel later used as an exhibit to a motion). The fact of document transmission (along with some information about the document such as document title and identifier) could be transmitted without actually transmitting the document itself—allowing the court to retrieve the document itself independently at a later time if desired.
Patent Office Automation
Upon receiving the patent application 5062, a trusted go-between 4700 within the Patent Office 5064 could open the container 302(1) and access the patent application 5062. Trusted go-between 4700 could electronically examine the patent application 5062 to ensure it meets all formal requirements, and could also date/time stamp the received patent application in order to document its filing date.
Trusted go-between 4700 could automatically issue the inventor 5060 a filing receipt based upon secure receipt of the patent application 5062 using the return receipt techniques described above. Trusted go-between 4700 could then deposit the patent application 5062 into a secure electronic archive 4702 to await examination. Trusted go-between 4700 could include appropriate routing information based on a routing slip as described above to route the patent application 5062 to the appropriate group and/or patent examiner 5064 within the Patent Office 5064.
A patent examiner 5064 could examine the patent application 5062 by requesting a copy of it from electronic archive 4702. All communications could take place within secure electronic containers 302(2) to ensure confidentiality and reliability—completely avoiding the problem of lost files. The patent examiner 5064 could conduct prior art searches using the same electronic appliance 600′ used to review the patent application 5062. The examiner 5064 could print out a copy of the patent application 5062 as desired.
The patent examiner 5064 could also use electronic appliance 600′ to draft office actions and notices. The examiner 5064 could communicate these notices and actions via trusted go-between 4700 to the inventor 5060. Trusted go-between 4700 could maintain copies of the examiner's actions and notices within secure electronic archive 4702—ensuring their confidentiality and also making sure they do not become lost. System 4050 could provide a return receipt when the inventor 5060 opened the electronic container 302 containing the examiner's actions or notices—thus proving in a highly reliable and trusted fashion that the inventor had in fact received what the examiner sent. Similarly, inventor 5060 could file responses (and could even teleconference with the examiner 5064) via electronic appliance 600. The high degree of trustedness and confidentiality provided by system 4050 along with the return receipt and other options discussed above provide a highly reliable, confidential communications means that can be used to demonstrate when items were actually filed.
Once the examiner—after conducting a lengthy prior art search and carefully analyzing the patent application 5062 to ensure that the invention is patentable—is fully and completely satisfied that the inventor 5060 is entitled to a patent, the examiner 5064 could instruct the trusted go-between 4700 to grant the application as a patent. Trusted go-between 4700 could retrieve a copy of the application 5062 from the secure electronic archive 4702, use automatic means to transform it into an issued patent, and insert a seal 4200 (for example, bearing the digital certificate of the Patent Office 5064) onto the document. The trusted go-between 4700 could then issue the granted patent 5066 to the inventor 5060 by sending it in a secure electronic container 302(3)—thus ensuring that it does not get lost and is in fact received by the inventor.
Members of the public could obtain a copy of the issued patent 5066 by requesting one from trusted go-between 4700. Trusted go-between 4700 could maintain a copy of the issued patent 5066 within secure electronic archive 4702, along with electronic controls 4078 that specify the document is a matter of public record and can be disclosed to members of the public. Other documents in secure electronic archive 4702 (e.g., patent applications 5062 that have not yet been published) can be maintained confidential by use of electronic controls 4078 specifying that only certain people (e.g., patent examiner 5064) can access them.
The
The disclosure service could also simply send the inventor a signed hash value, and then discard the document; since the hash value could be used with a copy preserved by the inventor. The service could archive the signed hash value themselves as well (although that is not required).
Tax Filing System
Appliance 600 may help the taxpayer 405′ complete her tax return 5070. For example, the appliance 600 could ask a series of questions based on a preprogrammed electronic script. The appliance 600 could calculate the taxes owed, and—once taxpayer 405) approved the tax return 5070—allow the taxpayer to electronically sign the return as described above. Appliance 600 could accept tax payments via credit or smart cards, debit authorizations from bank accounts, etc. Appliance 600 could also issue a paper or electronic receipt to the taxpayer 4052 assuring the taxpayer that the tax return 5070 has been filed. A court might accept this receipt as evidence of timely filing.
Tax authority 5072 may include an internal trusted go-between 4700 that registers and securely date stamps all tax return filings 5070 and places them into a secure electronic archive 4702. The trusted go-between 4700 can also analyze each tax return 5070 to ensure that it complies with electronic rules embodying the tax laws (some of this process could be performed by humans and some by computers if desired). Trusted go-between 4700 can provide, to a payment mechanism 5074, an electronic container 302(2) requesting the payment mechanism to issue a refund to (or collect a deficiency from) the tax payer 4052. In one example, payment can be in the form of electronic currency carried within one or more secure containers 302(3). If the return is structured appropriately for automated processing, tax calculations and application of relevant tax rules can also be automated by the trusted go-between.
Inter and Intra Organization Communications
Organization A's Intranet 5104 might also be used to exchange and/or distribute highly confidential design specifications. System 4050 can provide a highly secure audit trail indicating who has had access to a container containing the confidential design specifications; when the person(s) accessed it; and what they did with the specification (print a copy, view it on screen for so many minutes, make a copy of it, etc.) System 4050 (with or without the assistance of a trusted go-between 4700(A) can also maintain, in digital form, a detailed record of who has “signed off” on the design specifications—thus ensuring personal accountability and providing a high degree of efficiency.
Private transaction authorities 4700(A), 4700(B) can also provide a “firewall” function to protect confidential information from escaping to outside of the respective organizations A, B. Suppose for example that organization A is an integrated circuit design house and organization B is an integrated circuit foundry. Organization A designs and specifies the circuit layout of a chip, producing a “tape out” that it sends to organization B. Organization B manufactures an integrated circuit based on the “tape out”, and delivers chips to organization A.
System 4050 can be used to facilitate the above business transaction while protecting confidentiality within each of organizations A and B. For example:
Integration with Communications Switching
Telecommunications are becoming ubiquitous in post-industrial societies. As a convenience to customers, the trusted go-between could offer many of its services as part of, or in conjunction with providers of telecom services. In one non-limiting example shown in
After selection of delivery options and trusted go-between services, and after making arrangements for payment, the sender's computer 5102 faxes the document pages 4058d, 4058e, 4058h to the trusted go-between 4700. In one example, the trusted go-between 4700 applies seals 4200 to each page 4058d, 4058e, 4058f of the faxed document and an additional seal for the overall document. The trusted go-between 4700 then faxes the sealed document to the recipient fax machine 5104. The trusted go-between 4700 also archives and notarizes the sealed document in case the sender or other authorized party requires proof that the document was sent on a particular time and date to a device with a particular telephone number. In the event that the sender's and/or recipient's appliance is VDE aware (e.g., fax machine 4014c equipped with a protected processing environment 650), this service will be provided with additional levels of security and trustedness.
In another example, the sender may prefer to have the document delivered in a secure container over a network such as the Internet, in which case, the sender may indicate the recipient's network address. The sender may connect a personal computer 5102 with a modem to another special number and send a digital item to the trusted go-between 4700 using Internet protocols. In this one example, the sender may not have yet installed VDE, and so the trusted go-between takes the document or item and puts it in a secure container along with controls selected by the sender and delivers the secure container to the recipient, who in this example, does have VDE installed.
These examples illustrate the more general point that the trusted go-between 4700 may provide a range of value-added services even to parties who do not yet have the VDE installed on their appliances, and can enhance the security and trustedness of item delivery nevertheless.
While the invention has been described in connection with what is presently considered to be the most practical and preferred embodiment, it is to be understood that the invention is not to be limited to the disclosed embodiment, but on the contrary, is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
This is a division of application Ser. No. 09/632,944, filed Aug. 4, 2000, pending, which is a continuation of application Ser. No. 09/221,479, filed Dec. 28, 1998, now U.S. Pat. No. 6,185,683, which is a continuation of application Ser. No. 08/699,711, filed Aug. 12 1996, now abandoned, which is a continuation-in-part of application Ser. No. 08/388,107, filed Feb. 13, 1995, now abandoned, all of which are incorporated herein by reference. This application is a continuation-in-part of commonly assigned copending Ser. No. 08/388,107 of Ginter et al. filed 13 Feb. 1995, entitled “Systems and Methods for Secure Transaction Management and Electronic Rights Protection” (hereafter “Ginter et al.”). This application is related to concurrently filed commonly assigned copending application Ser. No. 08/699,712 of Ginter et al. entitled “Trusted Infrastructure Support Systems, Methods and Techniques, Commerce Process Control and Automation, Distributed Computing, and Rights Management” (hereafter referred to as “Shear et al” to avoid confusion with the “Ginter et al” reference in the paragraph above). The entire disclosure (including the drawings) of this related Shear et al. patent application is incorporated by reference into this specification as if expressly set forth in this specification.
Number | Name | Date | Kind |
---|---|---|---|
3573747 | Adams et al. | Apr 1971 | A |
3609697 | Blevins | Sep 1971 | A |
3790700 | Callais et al. | Feb 1974 | A |
3796830 | Smith | Mar 1974 | A |
3798359 | Feistel | Mar 1974 | A |
3798360 | Feistel | Mar 1974 | A |
3798605 | Feistel | Mar 1974 | A |
3806874 | Ehrat | Apr 1974 | A |
3806882 | Clarke | Apr 1974 | A |
3829833 | Freeny, Jr. | Aug 1974 | A |
3845391 | Crosby | Oct 1974 | A |
3906448 | Henriques | Sep 1975 | A |
3911397 | Freeny, Jr. | Oct 1975 | A |
3924065 | Freeny, Jr. | Dec 1975 | A |
3931504 | Jacoby | Jan 1976 | A |
3946200 | Juodikis | Mar 1976 | A |
3946220 | Brobeck et al. | Mar 1976 | A |
3956615 | Anderson et al. | May 1976 | A |
3958081 | Ehrsam et al. | May 1976 | A |
3970992 | Boothroyd et al. | Jul 1976 | A |
3996449 | Attanasio et al. | Dec 1976 | A |
4020326 | Coulthurst | Apr 1977 | A |
4048619 | Forman, Jr. et al. | Sep 1977 | A |
4071911 | Mazur | Jan 1978 | A |
4104721 | Markstein et al. | Aug 1978 | A |
4112421 | Freeny, Jr. | Sep 1978 | A |
4120030 | Johnstone | Oct 1978 | A |
4141005 | Ronner et al. | Feb 1979 | A |
4162483 | Entenman | Jul 1979 | A |
4163280 | Mori et al. | Jul 1979 | A |
4168396 | Best | Sep 1979 | A |
4183085 | Roberts et al. | Jan 1980 | A |
4196310 | Forman et al. | Apr 1980 | A |
4200913 | Kuhar et al. | Apr 1980 | A |
4209787 | Freeny, Jr. | Jun 1980 | A |
4217588 | Freeny, Jr. | Aug 1980 | A |
4220991 | Hamano et al. | Sep 1980 | A |
4232193 | Gerard | Nov 1980 | A |
4232317 | Freeny, Jr. | Nov 1980 | A |
4236217 | Kennedy | Nov 1980 | A |
4246638 | Thomas | Jan 1981 | A |
4253157 | Kirschner et al. | Feb 1981 | A |
4259720 | Campbell | Mar 1981 | A |
4262329 | Bright et al. | Apr 1981 | A |
4265371 | Desai et al. | May 1981 | A |
4270182 | Asija | May 1981 | A |
4278837 | Best | Jul 1981 | A |
4305131 | Best | Dec 1981 | A |
4306289 | Lumley | Dec 1981 | A |
4309569 | Merkle | Jan 1982 | A |
4319079 | Best | Mar 1982 | A |
4321672 | Braun et al. | Mar 1982 | A |
4323921 | Guillou | Apr 1982 | A |
4328544 | Baldwin et al. | May 1982 | A |
4337483 | Guillou | Jun 1982 | A |
4361877 | Dyer et al. | Nov 1982 | A |
4375579 | Davida et al. | Mar 1983 | A |
4405829 | Rivest et al. | Sep 1983 | A |
4433207 | Best | Feb 1984 | A |
4434464 | Suzuki et al. | Feb 1984 | A |
4442484 | Childs, Jr. et al. | Apr 1984 | A |
4442486 | Mayer | Apr 1984 | A |
4446519 | Thomas | May 1984 | A |
4454594 | Heffron et al. | Jun 1984 | A |
4458315 | Uchenick | Jul 1984 | A |
4462076 | Smith, III | Jul 1984 | A |
4462078 | Ross | Jul 1984 | A |
4465901 | Best | Aug 1984 | A |
4471163 | Donald et al. | Sep 1984 | A |
4471216 | Herve | Sep 1984 | A |
4484217 | Block et al. | Nov 1984 | A |
4494156 | Kadison et al. | Jan 1985 | A |
4513174 | Herman | Apr 1985 | A |
4523271 | Levien | Jun 1985 | A |
4525599 | Curran et al. | Jun 1985 | A |
4528588 | Lofberg | Jul 1985 | A |
4528643 | Freeny, Jr. | Jul 1985 | A |
4529870 | Chaum | Jul 1985 | A |
4553252 | Egendorf | Nov 1985 | A |
4558176 | Arnold et al. | Dec 1985 | A |
4558413 | Schmidt et al. | Dec 1985 | A |
4562305 | Gaffney, Jr. | Dec 1985 | A |
4562306 | Chou et al. | Dec 1985 | A |
4562495 | Bond et al. | Dec 1985 | A |
4573119 | Westheimer et al. | Feb 1986 | A |
4577289 | Comerford et al. | Mar 1986 | A |
4578530 | Zeidler | Mar 1986 | A |
4584639 | Hardy | Apr 1986 | A |
4584641 | Guglielmino | Apr 1986 | A |
4588991 | Atalla | May 1986 | A |
4589064 | Chiba et al. | May 1986 | A |
4590552 | Guttag et al. | May 1986 | A |
4593183 | Fukatsu | Jun 1986 | A |
4593353 | Pickholtz | Jun 1986 | A |
4593376 | Volk | Jun 1986 | A |
4595950 | Lofberg | Jun 1986 | A |
4597058 | Izumi et al. | Jun 1986 | A |
4598288 | Yarbrough et al. | Jul 1986 | A |
4599489 | Cargile | Jul 1986 | A |
4609777 | Cargile | Sep 1986 | A |
4609985 | Dozier | Sep 1986 | A |
4621321 | Boebert et al. | Nov 1986 | A |
4621334 | Garcia | Nov 1986 | A |
4634807 | Chorley et al. | Jan 1987 | A |
4644493 | Chandra et al. | Feb 1987 | A |
4646234 | Tolman et al. | Feb 1987 | A |
4649515 | Thompson et al. | Mar 1987 | A |
4652990 | Pailen et al. | Mar 1987 | A |
4658093 | Hellman | Apr 1987 | A |
4670857 | Rackman | Jun 1987 | A |
4672572 | Alsberg | Jun 1987 | A |
4672605 | Hustig et al. | Jun 1987 | A |
4677434 | Fascenda | Jun 1987 | A |
4677552 | Sibley, Jr. | Jun 1987 | A |
4680731 | Izumi et al. | Jul 1987 | A |
4683553 | Mollier | Jul 1987 | A |
4683968 | Appelbaum et al. | Aug 1987 | A |
4685055 | Thomas | Aug 1987 | A |
4685056 | Barnsdale, Jr. et al. | Aug 1987 | A |
4688169 | Joshi | Aug 1987 | A |
4691350 | Kleijne et al. | Sep 1987 | A |
4696034 | Wiedemer | Sep 1987 | A |
4700296 | Palmer, Jr. et al. | Oct 1987 | A |
4701846 | Ikeda et al. | Oct 1987 | A |
4712238 | Gilhousen et al. | Dec 1987 | A |
4713753 | Boebert et al. | Dec 1987 | A |
4740890 | William | Apr 1988 | A |
4747139 | Taaffe | May 1988 | A |
4748561 | Brown | May 1988 | A |
4757533 | Allen et al. | Jul 1988 | A |
4757534 | Matyas et al. | Jul 1988 | A |
4757914 | Roth et al. | Jul 1988 | A |
4759060 | Hayashi et al. | Jul 1988 | A |
4768087 | Taub et al. | Aug 1988 | A |
4780821 | Crossley | Oct 1988 | A |
4791565 | Dunham et al. | Dec 1988 | A |
4796181 | Wiedemer | Jan 1989 | A |
4796220 | Wolfe | Jan 1989 | A |
4799156 | Shavit et al. | Jan 1989 | A |
4807288 | Ugon et al. | Feb 1989 | A |
4816655 | Musyck et al. | Mar 1989 | A |
4817140 | Chandra et al. | Mar 1989 | A |
4823264 | Deming | Apr 1989 | A |
4827508 | Shear | May 1989 | A |
4858121 | Barber et al. | Aug 1989 | A |
4864494 | Kobus, Jr. | Sep 1989 | A |
4864616 | Pond et al. | Sep 1989 | A |
4866769 | Karp | Sep 1989 | A |
4868736 | Walker | Sep 1989 | A |
4868877 | Fischer | Sep 1989 | A |
4881197 | Fischer | Nov 1989 | A |
4888798 | Earnest | Dec 1989 | A |
4893248 | Pitts et al. | Jan 1990 | A |
4893332 | Brown | Jan 1990 | A |
4903296 | Chandra et al. | Feb 1990 | A |
4907269 | Guillon et al. | Mar 1990 | A |
4919545 | Yu | Apr 1990 | A |
4924378 | Hershey et al. | May 1990 | A |
4926480 | Chaum | May 1990 | A |
4930073 | Cina, Jr. | May 1990 | A |
4937863 | Robert et al. | Jun 1990 | A |
4941175 | Enescu et al. | Jul 1990 | A |
4949187 | Cohen | Aug 1990 | A |
4953209 | Ryder, Sr. et al. | Aug 1990 | A |
4962533 | Krueger et al. | Oct 1990 | A |
4967403 | Ogawa | Oct 1990 | A |
4975647 | Downer et al. | Dec 1990 | A |
4975878 | Boddu et al. | Dec 1990 | A |
4977594 | Shear | Dec 1990 | A |
4995082 | Schnorr | Feb 1991 | A |
4999806 | Chernow et al. | Mar 1991 | A |
5001752 | Fischer | Mar 1991 | A |
5005122 | Griffin et al. | Apr 1991 | A |
5005200 | Fischer | Apr 1991 | A |
5010571 | Katznelson | Apr 1991 | A |
5014234 | Edwards, Jr. | May 1991 | A |
5022080 | Durst et al. | Jun 1991 | A |
5023907 | Johnson et al. | Jun 1991 | A |
5027397 | Double et al. | Jun 1991 | A |
5032979 | Hecht et al. | Jul 1991 | A |
5047928 | Wiedemer | Sep 1991 | A |
5048085 | Abraham et al. | Sep 1991 | A |
5050212 | Dyson | Sep 1991 | A |
5050213 | Shear | Sep 1991 | A |
5051932 | Inoue et al. | Sep 1991 | A |
5058162 | Santon et al. | Oct 1991 | A |
5065429 | Lang | Nov 1991 | A |
5070400 | Lieberman | Dec 1991 | A |
5079648 | Maufe | Jan 1992 | A |
5091966 | Bloomberg et al. | Feb 1992 | A |
5103392 | Mori | Apr 1992 | A |
5103459 | Gilhousen et al. | Apr 1992 | A |
5103476 | Waite et al. | Apr 1992 | A |
5109413 | Comerford et al. | Apr 1992 | A |
5111390 | Ketcham | May 1992 | A |
5113518 | Durst, Jr. et al. | May 1992 | A |
5119493 | Janis et al. | Jun 1992 | A |
5126936 | Champion et al. | Jun 1992 | A |
5128525 | Stearns et al. | Jul 1992 | A |
5129084 | Kelly, Jr. et al. | Jul 1992 | A |
5136643 | Fischer | Aug 1992 | A |
5136646 | Haber et al. | Aug 1992 | A |
5136647 | Haber et al. | Aug 1992 | A |
5136716 | Harvey et al. | Aug 1992 | A |
5138712 | Corbin | Aug 1992 | A |
5146575 | Nolan, Jr. | Sep 1992 | A |
5148481 | Abraham et al. | Sep 1992 | A |
5150407 | Chan | Sep 1992 | A |
5155680 | Wiedemer | Oct 1992 | A |
5163091 | Graziano et al. | Nov 1992 | A |
5164988 | Matyas et al. | Nov 1992 | A |
5168147 | Bloomberg | Dec 1992 | A |
5185717 | Mori | Feb 1993 | A |
5187787 | Skeen et al. | Feb 1993 | A |
5191573 | Hair | Mar 1993 | A |
5191693 | Umetsu | Mar 1993 | A |
5199066 | Logan | Mar 1993 | A |
5199074 | Thor | Mar 1993 | A |
5201046 | Goldberg et al. | Apr 1993 | A |
5201047 | Maki et al. | Apr 1993 | A |
5204897 | Wyman | Apr 1993 | A |
5206951 | Khoyi et al. | Apr 1993 | A |
5208748 | Flores et al. | May 1993 | A |
5214700 | Pinkas et al. | May 1993 | A |
5214702 | Fischer | May 1993 | A |
5216603 | Flores et al. | Jun 1993 | A |
5218605 | Low et al. | Jun 1993 | A |
5221833 | Hecht | Jun 1993 | A |
5222134 | Waite et al. | Jun 1993 | A |
5224160 | Paulini et al. | Jun 1993 | A |
5224163 | Gasser et al. | Jun 1993 | A |
5235642 | Wobber et al. | Aug 1993 | A |
5237614 | Weiss | Aug 1993 | A |
5241671 | Reed et al. | Aug 1993 | A |
5245165 | Zhang | Sep 1993 | A |
5247575 | Sprague et al. | Sep 1993 | A |
5251294 | Abelow | Oct 1993 | A |
5257369 | Skeen et al. | Oct 1993 | A |
5260999 | Wyman | Nov 1993 | A |
5263157 | Janis | Nov 1993 | A |
5263158 | Janis | Nov 1993 | A |
5263165 | Janis | Nov 1993 | A |
5265164 | Matyas et al. | Nov 1993 | A |
5276735 | Boebert et al. | Jan 1994 | A |
5276901 | Howell et al. | Jan 1994 | A |
5280479 | Mary | Jan 1994 | A |
5283830 | Hinsley et al. | Feb 1994 | A |
5285494 | Sprecher et al. | Feb 1994 | A |
5287407 | Holmes | Feb 1994 | A |
5291598 | Grundy | Mar 1994 | A |
5301231 | Abraham et al. | Apr 1994 | A |
5301326 | Linnett et al. | Apr 1994 | A |
5311591 | Fischer | May 1994 | A |
5315448 | Ryan | May 1994 | A |
5319705 | Halter et al. | Jun 1994 | A |
5319735 | Preuss et al. | Jun 1994 | A |
5319785 | Thaller | Jun 1994 | A |
5325524 | Black et al. | Jun 1994 | A |
5335169 | Chong | Aug 1994 | A |
5335346 | Fabbio | Aug 1994 | A |
5337357 | Chou et al. | Aug 1994 | A |
5337360 | Fischer | Aug 1994 | A |
5341429 | Stringer et al. | Aug 1994 | A |
5343526 | Lassers | Aug 1994 | A |
5343527 | Moore | Aug 1994 | A |
5347579 | Blandford | Sep 1994 | A |
5349642 | Kingdon | Sep 1994 | A |
5351293 | Michener et al. | Sep 1994 | A |
5354097 | Tel | Oct 1994 | A |
5355474 | Thuraisngham et al. | Oct 1994 | A |
5359721 | Kempf et al. | Oct 1994 | A |
5361359 | Tajalli et al. | Nov 1994 | A |
5365587 | Campbell et al. | Nov 1994 | A |
5367621 | Cohen et al. | Nov 1994 | A |
5369702 | Shanton | Nov 1994 | A |
5369707 | Follendore, III | Nov 1994 | A |
5371792 | Asai et al. | Dec 1994 | A |
5373440 | Cohen et al. | Dec 1994 | A |
5373561 | Haber et al. | Dec 1994 | A |
5375240 | Grundy | Dec 1994 | A |
5383113 | Kight et al. | Jan 1995 | A |
5388211 | Hornbuckle | Feb 1995 | A |
5390247 | Fischer | Feb 1995 | A |
5390297 | Barber et al. | Feb 1995 | A |
5390330 | Talati | Feb 1995 | A |
5392220 | Van den Hamer et al. | Feb 1995 | A |
5392390 | Crozier | Feb 1995 | A |
5394469 | Nagel et al. | Feb 1995 | A |
5408501 | Cornaby | Apr 1995 | A |
5410598 | Shear | Apr 1995 | A |
5412717 | Fischer | May 1995 | A |
5418713 | Allen | May 1995 | A |
5420927 | Michali | May 1995 | A |
5421006 | Jablon et al. | May 1995 | A |
5422645 | Nettleton et al. | Jun 1995 | A |
5422953 | Fischer | Jun 1995 | A |
5428606 | Moskowitz | Jun 1995 | A |
5428685 | Kadooka et al. | Jun 1995 | A |
5432851 | Scheidt et al. | Jul 1995 | A |
5432928 | Sherman | Jul 1995 | A |
5432950 | Sibigtroth | Jul 1995 | A |
5438508 | Wyman | Aug 1995 | A |
5440634 | Jones et al. | Aug 1995 | A |
5442645 | Ugon et al. | Aug 1995 | A |
5444779 | Daniele | Aug 1995 | A |
5449895 | Hecht et al. | Sep 1995 | A |
5449896 | Hecht et al. | Sep 1995 | A |
5450490 | Jensen et al. | Sep 1995 | A |
5450493 | Maher | Sep 1995 | A |
5453601 | Rosen | Sep 1995 | A |
5453605 | Hecht et al. | Sep 1995 | A |
5455407 | Rosen | Oct 1995 | A |
5455861 | Faucher et al. | Oct 1995 | A |
5455953 | Russell | Oct 1995 | A |
5457746 | Dolphin | Oct 1995 | A |
5457747 | Drexler et al. | Oct 1995 | A |
5458494 | Krohn et al. | Oct 1995 | A |
5463565 | Cookson et al. | Oct 1995 | A |
5473687 | Lipscomb et al. | Dec 1995 | A |
5473692 | Davis | Dec 1995 | A |
5479509 | Ugon | Dec 1995 | A |
5485622 | Yamaki | Jan 1996 | A |
5490216 | Ricahrdson, III | Feb 1996 | A |
5491800 | Goldsmith et al. | Feb 1996 | A |
5497479 | Hornbuckle | Mar 1996 | A |
5497491 | Mitchell et al. | Mar 1996 | A |
5499298 | Narasimhalu et al. | Mar 1996 | A |
5504757 | Cook et al. | Apr 1996 | A |
5504818 | Okano | Apr 1996 | A |
5504837 | Griffeth et al. | Apr 1996 | A |
5505461 | Bell et al. | Apr 1996 | A |
5508913 | Yamamoto et al. | Apr 1996 | A |
5509070 | Schull | Apr 1996 | A |
5513261 | Maher | Apr 1996 | A |
5517518 | Morson et al. | May 1996 | A |
5521815 | Rose, Jr. et al. | May 1996 | A |
5524933 | Kunt et al. | Jun 1996 | A |
5530235 | Stefik et al. | Jun 1996 | A |
5530752 | Rubin | Jun 1996 | A |
5533123 | Force et al. | Jul 1996 | A |
5534855 | Shockley et al. | Jul 1996 | A |
5534975 | Stefik et al. | Jul 1996 | A |
5535322 | Hecht | Jul 1996 | A |
5537526 | Anderson et al. | Jul 1996 | A |
5539735 | Moskowitz | Jul 1996 | A |
5539828 | Davis | Jul 1996 | A |
5550971 | Brunner et al. | Aug 1996 | A |
5553282 | Parrish et al. | Sep 1996 | A |
5557518 | Rosen | Sep 1996 | A |
5557798 | Skeen et al. | Sep 1996 | A |
5563946 | Cooper et al. | Oct 1996 | A |
5568552 | Davis | Oct 1996 | A |
5572673 | Shurts | Nov 1996 | A |
5574962 | Fardeau et al. | Nov 1996 | A |
5577209 | Boyle et al. | Nov 1996 | A |
5581686 | Koppolu et al. | Dec 1996 | A |
5581800 | Fardeau et al. | Dec 1996 | A |
5592549 | Nagel et al. | Jan 1997 | A |
5603031 | White et al. | Feb 1997 | A |
5606609 | Houser et al. | Feb 1997 | A |
5613004 | Cooperman et al. | Mar 1997 | A |
5621797 | Rosen | Apr 1997 | A |
5625693 | Rohatgi et al. | Apr 1997 | A |
5629770 | Brassil et al. | May 1997 | A |
5629980 | Stefik et al. | May 1997 | A |
5633932 | Davis et al. | May 1997 | A |
5634012 | Stefik et al. | May 1997 | A |
5636276 | Brugger | Jun 1997 | A |
5636292 | Rhoads | Jun 1997 | A |
5638443 | Stefik et al. | Jun 1997 | A |
5638504 | Scott et al. | Jun 1997 | A |
5640546 | Gopinath et al. | Jun 1997 | A |
5644686 | Hekmatpour | Jul 1997 | A |
5646997 | Barton | Jul 1997 | A |
5649099 | Theimer et al. | Jul 1997 | A |
5655077 | Jones et al. | Aug 1997 | A |
5671279 | Elgamal | Sep 1997 | A |
5678170 | Grube et al. | Oct 1997 | A |
5682027 | Bertina et al. | Oct 1997 | A |
5687236 | Moskowitz et al. | Nov 1997 | A |
5689565 | Spies et al. | Nov 1997 | A |
5689566 | Nguyen | Nov 1997 | A |
5689587 | Bender et al. | Nov 1997 | A |
5692047 | McManis | Nov 1997 | A |
5692180 | Lee | Nov 1997 | A |
5692980 | Trotman | Dec 1997 | A |
5699427 | Chow et al. | Dec 1997 | A |
5710834 | Rhoads | Jan 1998 | A |
5715314 | Payne et al. | Feb 1998 | A |
5715403 | Stefik | Feb 1998 | A |
5717923 | Dedrick | Feb 1998 | A |
5721788 | Powell et al. | Feb 1998 | A |
5724424 | Gifford | Mar 1998 | A |
5724425 | Chang et al. | Mar 1998 | A |
5732398 | Tagawa | Mar 1998 | A |
5734719 | Tsevdos et al. | Mar 1998 | A |
5740549 | Reilly et al. | Apr 1998 | A |
5745569 | Moskowitz et al. | Apr 1998 | A |
5745604 | Rhoads | Apr 1998 | A |
5745678 | Herzberg et al. | Apr 1998 | A |
5748763 | Rhoads | May 1998 | A |
5748783 | Rhoads | May 1998 | A |
5748960 | Fischer | May 1998 | A |
5754849 | Dyer et al. | May 1998 | A |
5757914 | McManis | May 1998 | A |
5758152 | LeTourneau | May 1998 | A |
5759101 | Von Kohorn | Jun 1998 | A |
5765152 | Erickson | Jun 1998 | A |
5768426 | Rhoads | Jun 1998 | A |
5774872 | Golden et al. | Jun 1998 | A |
5778385 | Pratt | Jul 1998 | A |
5787334 | Fardeau et al. | Jul 1998 | A |
5802590 | Draves | Sep 1998 | A |
5819263 | Bromley et al. | Oct 1998 | A |
5832119 | Rhoads | Nov 1998 | A |
5842173 | Strum et al. | Nov 1998 | A |
5845281 | Benson et al. | Dec 1998 | A |
5878421 | Ferrel et al. | Mar 1999 | A |
5892899 | Aucsmith et al. | Apr 1999 | A |
5892900 | Ginter et al. | Apr 1999 | A |
5896454 | Cookson et al. | Apr 1999 | A |
5910987 | Ginter et al. | Jun 1999 | A |
5915019 | Ginter et al. | Jun 1999 | A |
5917912 | Ginter et al. | Jun 1999 | A |
5920861 | Hall et al. | Jul 1999 | A |
5940504 | Griswold | Aug 1999 | A |
5940505 | Kanamaru | Aug 1999 | A |
5943422 | Van Wie et al. | Aug 1999 | A |
5949876 | Ginter et al. | Sep 1999 | A |
5956408 | Arnold | Sep 1999 | A |
5966440 | Hair | Oct 1999 | A |
5978484 | Apperson et al. | Nov 1999 | A |
5982891 | Ginter et al. | Nov 1999 | A |
5991876 | Johnson et al. | Nov 1999 | A |
5996756 | Schmodde et al. | Dec 1999 | A |
5999949 | Crandall | Dec 1999 | A |
6009170 | Sako et al. | Dec 1999 | A |
6016393 | White et al. | Jan 2000 | A |
6026193 | Rhoads | Feb 2000 | A |
6044205 | Reed et al. | Mar 2000 | A |
6085238 | Yuasa et al. | Jul 2000 | A |
6102965 | Dye et al. | Aug 2000 | A |
6112181 | Shear et al. | Aug 2000 | A |
6135646 | Kahn et al. | Oct 2000 | A |
6138119 | Hall et al. | Oct 2000 | A |
6157721 | Shear et al. | Dec 2000 | A |
6185683 | Ginter et al. | Feb 2001 | B1 |
6237786 | Ginter et al. | May 2001 | B1 |
6240185 | Van Wie et al. | May 2001 | B1 |
6253193 | Ginter et al. | Jun 2001 | B1 |
6292569 | Shear et al. | Sep 2001 | B1 |
6363488 | Ginter et al. | Mar 2002 | B1 |
6389402 | Ginter et al. | May 2002 | B1 |
6393484 | Massarani | May 2002 | B1 |
6427140 | Ginter et al. | Jul 2002 | B1 |
6449367 | Van Wie et al. | Sep 2002 | B2 |
6477559 | Veluvali et al. | Nov 2002 | B1 |
6519615 | Wollrath et al. | Feb 2003 | B1 |
6590998 | Rhoads | Jul 2003 | B2 |
6618484 | Van Wie et al. | Sep 2003 | B1 |
6640304 | Ginter et al. | Oct 2003 | B2 |
6647130 | Rhoads | Nov 2003 | B2 |
6658568 | Ginter et al. | Dec 2003 | B1 |
6668325 | Collberg et al. | Dec 2003 | B1 |
6785815 | Serret-Avila et al. | Aug 2004 | B1 |
6807534 | Erickson | Oct 2004 | B1 |
6832316 | Sibert | Dec 2004 | B1 |
6938021 | Shear et al. | Aug 2005 | B2 |
6944555 | Blackett et al. | Sep 2005 | B2 |
6948070 | Ginter et al. | Sep 2005 | B1 |
6950867 | Strohwig et al. | Sep 2005 | B1 |
6959384 | Serret-Avila | Oct 2005 | B1 |
6961854 | Serret-Avila et al. | Nov 2005 | B2 |
6973499 | Peden et al. | Dec 2005 | B1 |
7050586 | Shamoon | May 2006 | B1 |
7051212 | Ginter et al. | May 2006 | B2 |
7058805 | Sibert | Jun 2006 | B2 |
7062500 | Hall et al. | Jun 2006 | B1 |
7069451 | Ginter et al. | Jun 2006 | B1 |
7076652 | Ginter et al. | Jul 2006 | B2 |
7085839 | Baugher et al. | Aug 2006 | B1 |
7092914 | Shear et al. | Aug 2006 | B1 |
7095854 | Ginter et al. | Aug 2006 | B1 |
7100199 | Ginter et al. | Aug 2006 | B2 |
20010042043 | Shear et al. | Nov 2001 | A1 |
20020023214 | Shear et al. | Feb 2002 | A1 |
20020048369 | Ginter et al. | Apr 2002 | A1 |
20020087859 | Weeks et al. | Jul 2002 | A1 |
20020112171 | Ginter et al. | Aug 2002 | A1 |
20020152173 | Rudd | Oct 2002 | A1 |
20030023856 | Horne et al. | Jan 2003 | A1 |
20030041239 | Shear et al. | Feb 2003 | A1 |
20030046244 | Shear et al. | Mar 2003 | A1 |
20030069748 | Shear et al. | Apr 2003 | A1 |
20030069749 | Shear et al. | Apr 2003 | A1 |
20030084003 | Pinkas et al. | May 2003 | A1 |
20030105721 | Ginter et al. | Jun 2003 | A1 |
20030163431 | Ginter et al. | Aug 2003 | A1 |
20040054630 | Ginter et al. | Mar 2004 | A1 |
20040059951 | Pinkas et al. | Mar 2004 | A1 |
20040073813 | Pinkas et al. | Apr 2004 | A1 |
20040103305 | Ginter et al. | May 2004 | A1 |
20040107356 | Shamoon et al. | Jun 2004 | A1 |
20040123129 | Ginter et al. | Jun 2004 | A1 |
20040133793 | Ginter et al. | Jul 2004 | A1 |
20050027871 | Bradley et al. | Feb 2005 | A1 |
20050050332 | Serret-Avila et al. | Mar 2005 | A1 |
20050060560 | Sibert | Mar 2005 | A1 |
20050060584 | Ginter et al. | Mar 2005 | A1 |
20050108555 | Sibert | May 2005 | A1 |
Number | Date | Country |
---|---|---|
A-3681597 | Feb 1998 | AU |
A-3681697 | Feb 1998 | AU |
A-3684097 | Feb 1998 | AU |
29 43 436 | Oct 1979 | DE |
3 803 982 | Jan 1990 | DE |
0 084 441 | Jul 1983 | EP |
0 128 672 | Dec 1984 | EP |
0 135 422 | Mar 1985 | EP |
0 180 460 | May 1986 | EP |
0 367 700 | May 1990 | EP |
0 370 146 | May 1990 | EP |
0 398 645 | Nov 1990 | EP |
0 399 822 | Nov 1990 | EP |
0 421 409 | Apr 1991 | EP |
0 456 386 | Nov 1991 | EP |
0 469 864 | Feb 1992 | EP |
0 469 864 | Feb 1992 | EP |
0 565 314 | Oct 1993 | EP |
0 567 800 | Nov 1993 | EP |
0 570 123 | Nov 1993 | EP |
0 593 305 | Apr 1994 | EP |
0 651 554 | May 1995 | EP |
0 653 695 | May 1995 | EP |
0 668 695 | Aug 1995 | EP |
0 668 695 | Aug 1995 | EP |
0 695 985 | Feb 1996 | EP |
0 696 798 | Feb 1996 | EP |
0 727 727 | Feb 1996 | EP |
0 715 243 | Jun 1996 | EP |
0 715 244 | Jun 1996 | EP |
0 715 245 | Jun 1996 | EP |
0 715 247 | Jun 1996 | EP |
0 725 376 | Aug 1996 | EP |
0 749 081 | Dec 1996 | EP |
0 778 513 | Jun 1997 | EP |
0 795 873 | Sep 1997 | EP |
0 913 757 | May 1999 | EP |
2136175 | Sep 1984 | GB |
2264796 | Sep 1993 | GB |
2294348 | Apr 1996 | GB |
2295947 | Jun 1996 | GB |
57-000726 | Jan 1982 | JP |
61 121145 | Jun 1986 | JP |
62-225059 | Oct 1987 | JP |
62-241061 | Oct 1987 | JP |
63 129564 | Jun 1988 | JP |
63 289646 | Nov 1988 | JP |
01-068835 | Mar 1989 | JP |
01 68853 | Mar 1989 | JP |
64-068835 | Mar 1989 | JP |
01 248891 | Oct 1989 | JP |
01 296363 | Nov 1989 | JP |
02-242352 | Sep 1990 | JP |
02-247763 | Oct 1990 | JP |
02-294855 | Dec 1990 | JP |
04-100148 | Feb 1992 | JP |
04 117548 | Apr 1992 | JP |
04 504794 | Aug 1992 | JP |
04-369068 | Dec 1992 | JP |
05-020359 | Jan 1993 | JP |
06-103058 | May 1993 | JP |
05 173892 | Jul 1993 | JP |
05-181734 | Jul 1993 | JP |
05-257783 | Oct 1993 | JP |
05 258463 | Oct 1993 | JP |
05-268415 | Oct 1993 | JP |
06 501120 | Jan 1994 | JP |
06-035807 | Feb 1994 | JP |
06 152585 | May 1994 | JP |
06 161719 | Jun 1994 | JP |
06-175794 | Jun 1994 | JP |
06-215010 | Aug 1994 | JP |
06-225059 | Aug 1994 | JP |
06 250924 | Sep 1994 | JP |
07-056794 | Mar 1995 | JP |
07-084852 | Mar 1995 | JP |
07-141138 | Jun 1995 | JP |
07-200317 | Aug 1995 | JP |
07-200492 | Aug 1995 | JP |
07-244639 | Sep 1995 | JP |
07-302244 | Nov 1995 | JP |
07 319681 | Dec 1995 | JP |
08-111679 | Apr 1996 | JP |
08-137795 | May 1996 | JP |
08-152990 | Jun 1996 | JP |
08-185292 | Jul 1996 | JP |
08-185298 | Jul 1996 | JP |
08-272746 | Oct 1996 | JP |
10-513289 | Dec 1998 | JP |
WO8502310 | May 1985 | WO |
WO8503584 | Aug 1985 | WO |
WO9002382 | Mar 1990 | WO |
WO9206438 | Apr 1992 | WO |
WO9222870 | Dec 1992 | WO |
WO9301550 | Jan 1993 | WO |
WO9401821 | Jan 1994 | WO |
WO9403859 | Feb 1994 | WO |
WO9406103 | Mar 1994 | WO |
WO9416395 | Jul 1994 | WO |
WO9418620 | Aug 1994 | WO |
WO9422266 | Sep 1994 | WO |
WO9427406 | Nov 1994 | WO |
WO9514289 | May 1995 | WO |
WO9600963 | Jan 1996 | WO |
WO9603835 | Feb 1996 | WO |
WO9605698 | Feb 1996 | WO |
WO9606503 | Feb 1996 | WO |
WO9613013 | May 1996 | WO |
WO9617467 | Jun 1996 | WO |
WO9621192 | Jul 1996 | WO |
WO9624092 | Aug 1996 | WO |
WO9624155 | Aug 1996 | WO |
WO9625006 | Aug 1996 | WO |
WO9627155 | Sep 1996 | WO |
WO9703423 | Jan 1997 | WO |
WO9707656 | Mar 1997 | WO |
WO9722074 | Jun 1997 | WO |
WO9727155 | Jul 1997 | WO |
WO9732251 | Sep 1997 | WO |
WO9743761 | Nov 1997 | WO |
WO9748203 | Dec 1997 | WO |
WO9809209 | Mar 1998 | WO |
WO9810381 | Mar 1998 | WO |
WO9837481 | Aug 1998 | WO |
WO9845768 | Oct 1998 | WO |
WO9901815 | Jan 1999 | WO |
WO9924928 | May 1999 | WO |
WO9948296 | Sep 1999 | WO |
WO 0075925 | Dec 2000 | WO |
WO 0106374 | Jan 2001 | WO |
WO 0109702 | Feb 2001 | WO |
WO 0110076 | Feb 2001 | WO |
Number | Date | Country | |
---|---|---|---|
20050246541 A1 | Nov 2005 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 09632944 | Aug 2000 | US |
Child | 11102514 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 09221479 | Dec 1998 | US |
Child | 09632944 | US | |
Parent | 08699711 | Aug 1996 | US |
Child | 09221479 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 08388107 | Feb 1995 | US |
Child | 08699711 | US |