Interoperable systems and methods for peer-to-peer service orchestration
Abstract
Systems and methods are described for performing policy-managed, peer-to-peer service orchestration in a manner that supports the formation of self-organizing service networks that enable rich media experiences. In one embodiment, services are distributed across peer-to-peer communicating nodes, and each node provides message routing and orchestration using a message pump and workflow collator. Distributed policy management of service interfaces helps to provide trust and security, supporting commercial exchange of value. Peer-to-peer messaging and workflow collation allow services to be dynamically created from a heterogeneous set of primitive services. The shared resources are services of many different types, using different service interface bindings beyond those typically supported in a web service deployments built on UDDI, SOAP, and WSDL. In a preferred embodiment, a media services framework is provided that enables nodes to find one another, interact, exchange value, and cooperate across tiers of networks from WANs to PANs.
Claims
exact text as granted — not AI-modified1 . A system for authorizing a given action to be performed on a piece of electronic content, the system comprising:
means for executing a control program, the control program being operable to determine whether the given action can be performed on the piece of electronic content, wherein the control program is operable to evaluate a set of one or more conditions that must be satisfied in order for performance of the given action to be authorized, and wherein at least a first condition in the set of one or more conditions comprises a requirement that a first node representing a first entity be reachable from a second node representing a second entity; and means for evaluating one or more link objects to determine if the first node is reachable from the second node, each link object expressing a relationship between two entities.
2 . The system of claim 1 , in which at least a second condition in the set of one or more conditions comprises a requirement that a third node representing a third entity be reachable from the second node.
3 . The system of claim 1 , further comprising:
means for deriving a first cryptographic key from the one or more link objects, the first cryptographic key being capable of decrypting a second cryptographic key, the second cryptographic key being capable of decrypting the piece of electronic content.
4 . The system of claim 1 , in which the control program is contained in a control object.
5 . The system of claim 4 , in which the control object is cryptographically bound to a content key object, the content key object comprising an encrypted cryptographic key, the cryptographic key being configured for use in decrypting the piece of electronic content.
6 . A system comprising:
means for encrypting a piece of electronic content; means for associating a license with the piece of electronic content, the license comprising a control program, the control program requiring, as a condition of authorizing decryption of the piece of electronic content, possession of a set of one or more link objects logically connecting a first node object with a second node object, the license further comprising an encrypted version of a first key for use in decrypting the piece of electronic content; means for sending the piece of electronic content to a remote computer system; means for determining that the remote computer system has possession of a set of one or more link objects logically connecting the first node object with the second node object, wherein at least one of the one or more link objects comprises an encrypted version of a second key for use in decrypting the first key; means for decrypting the second key using a key associated with the remote computer system; means for decrypting the first key using the second key; and means for decrypting the piece of electronic content using the first key.
7 . The system of claim 6 , in which the license further comprises a controller object securely binding the control program with the first key.
8 . The system of claim 7 , in which the controller object include a hash of a content key object and a control object, wherein the content key object comprises an encrypted version of the first key, and the control object comprises the control program.
9 . A computer-readable medium comprising program code, the program code being operable, when executed by a computer system, to cause the computer system to perform actions comprising:
receiving a request from a user of the computer system to access a piece of electronic content; retrieving a license associated with the piece of electronic content, the license comprising a control object, a controller object, a protector object, and a content key object; retrieving a control program from the control object; and executing the control program to determine if the request may be granted, wherein executing the control program includes evaluating one or more link objects to determine if one or more conditions expressed by the control program are satisfied, wherein each link object represents a relationship between two entities, and wherein evaluating the one or more link objects includes determining whether a first node object associated with a first entity is reachable from a second node object associated with a second entity.
10 . The computer-readable medium of claim 9 , in which the controller object is configured to securely bind the control object with the content key object.
11 . The computer-readable medium of claim 9 , in which the protector object is configured to securely bind the content key object with the piece of electronic content.
12 . The computer-readable medium of claim 11 , in which the content key object includes an encrypted cryptographic key, the encrypted cryptographic key, when decrypted, being configured for use in decrypting the piece of electronic content.
13 . The computer-readable medium of claim 12 , further comprising program code that, when executed by the computer system, is operable to cause the computer system to derive a decryption key from the one or more link objects, the decryption key being configured for use in decrypting the encrypted cryptographic key.
14 . The computer-readable medium of claim 12 , wherein at least one of the one or more link objects comprises an encrypted version of a first key, the first key being configured for use in decrypting the encrypted cryptographic key, wherein the computer-readable medium further comprises program code that, when executed by the computer system, is operable to cause the computer system to perform actions comprising:
decrypting the first key using a second key associated with the computer system; decrypting the encrypted cryptographic key using the first key; and decrypting the piece of electronic content using the cryptographic key.
15 . The computer-readable medium of claim 9 , in which the first entity comprises a user, and in which the second entity comprises a device capable of rendering electronic content.
16 . A computer-readable medium comprising program code, the program code being operable, when executed by a computer system, to cause the computer system to perform actions comprising:
executing a control program, the control program being operable to determine whether a given action can be performed on a piece of electronic content, wherein the control program is configured to evaluate a set of one or more conditions that must be satisfied in order for performance of the given action to be authorized, and wherein at least a first condition in the set of one or more conditions comprises a requirement that a first node representing a first entity be reachable from a second node representing a second entity; and evaluating one or more link objects to determine if the first node is reachable from the second node, each link object expressing a relationship between two entities.
17 . The computer-readable medium of claim 16 , in which at least a second condition in the set of one or more conditions comprises a requirement that a third node representing a third entity be reachable from the second node.
18 . The computer-readable medium of claim 16 , further comprising:
means for deriving a first cryptographic key from the one or more link objects, the first cryptographic key being capable of decrypting a second cryptographic key, the second cryptographic key being capable of decrypting the piece of electronic content.
19 . The computer-readable medium of claim 16 , in which the control program is contained in a control object.
20 . The computer-readable medium of claim 19 , in which the control object is cryptographically bound to a content key object, the content key object comprising an encrypted cryptographic key, the cryptographic key being configured for use in decrypting the piece of electronic content.
21 . A computer-readable medium comprising program code, the program code being operable, when executed by a computer system, to cause the computer system to perform actions comprising:
encrypting a piece of electronic content; associating a license with the piece of electronic content, the license comprising a control program, the control program requiring, as a condition of authorizing decryption of the piece of electronic content, possession of a set of one or more link objects logically connecting a first node object with a second node object, the license further comprising an encrypted version of a first key for use in decrypting the piece of electronic content; sending the piece of electronic content to a remote computer system; determining that the remote computer system has possession of a set of one or more link objects logically connecting the first node object with the second node object, wherein at least one of the one or more link objects comprises an encrypted version of a second key for use in decrypting the first key; decrypting the second key using a key associated with the remote computer system; decrypting the first key using the second key; and decrypting the piece of electronic content using the first key.
22 . The computer-readable medium of claim 21 , in which the license further comprises a controller object securely binding the control program with the first key.
23 . The computer-readable medium of claim 22 , in which the controller object include a hash of a content key object and a control object, wherein the content key object comprises an encrypted version of the first key, and the control object comprises the control program.Join the waitlist — get patent alerts
Track US2009094453A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.