Logo
About usInnovation CMChallengesEuropa2iEntrepreneurshipR&D&I SearchAgentsEventsReports
en
METHOD FOR PRIVACY MANAGEMENT IN AN IDENTITY NETWORK, PHYSICAL ENTITIES AND COMPUTER PROGRAM THEREFORCM Patents

Índice de la ficha

Updated at
24/07/2026
Numero publicacion
EP.2417740.A1
Fecha publicacion
15/02/2012
Numero solicitud
EP20090779272

En detalle

Resumen

A control apparatus (12) is used for the privacy management in the identity network (10) with respect to a main body person (20). An identity network (10) is a computer network which contains an identity provider (14), and a discovery service provider (16) and a service provider (18) with a main body person (20) able to perform a transaction at least. A main body person (20) is a system entity by which the said main body person's (20)'s identity can be authenticated. An identity resource (14) is in those any which are the data related to the group of an identity or an identity, or are the services relevant to the group of an identity or an identity. A control apparatus (12) is inquired to a discovery service provider (16) in order to acquire the information regarding the identity resource which can be utilized, The address information about the address attribute of an identity resource (14) is received, The privacy attribute which reigns over use of an identity resource (14) is produced, Reading and in order to change or delete, based on address information, it interacts with a service provider (18). FIG. 10A FIG. 10B

Reivindicaciones

1. Controller (12) for privacy management in an identity network (10) for at least one principal (20), wherein an identity network (10) is a computer network including at least an identity provider (14), a discovery service provider (16), and a service provider (18) with which the principal (20) can make transactions; a principal (20) is a system entity whose identity can be authenticated; an identity resource is either data related to an identity or group of identities, or a service associated with an identity or group of identities; and the controller (12) is configured for querying (S2) a discovery service provider (16) of the identity network (10) to obtain information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity; receiving (S4), from the discovery service provider (16), information, here referred to as addressing information, usable for addressing attributes of the identity resources available in the identity network (10) and associated with the principal's (20) identity; and interacting (S6), based on the addressing information, with a service provider (18) to create, read, modify or delete an attribute governing the use of an identity resource available in the identity network (10) and associated with the principal's (20) identity, the attribute being here referred to as privacy attribute, wherein an attribute governing the use of an identity resource specifies permissions associated with the identity resource with respect to operations that may be performed by system entities on, or in relation to, the identity resource. 2. Controller (12) of claim 1, further configured for, before querying (S2), receiving (s1), from the principal (20), a request to retrieve information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity. 3. Controller (12) of claim 1 or 2, further configured for, after receiving (S4) and before interacting (S6), making (S5a) the addressing information available to the principal (20); and receiving (S5b), from the principal (20), a request to create, read, modify or delete the privacy attribute; and wherein interacting (S6) with the service provider (18) to create, read, modify or delete the privacy attribute is based on the request received from the principal (20) to create, read, modify or delete the privacy attribute. 4. Controller (12) according to any one of the preceding claims, wherein interacting (S6) is carried out using a data services template protocol. 5. Controller (12) according to any one of the preceding claims, further configured for obtaining (S7), from at least one service provider (18) of the identity network (10), information, here referred to as usage information, regarding the usage of the identity resources associated to the principal's (20) identity in the at least one service provider (18) . 6. Controller (12) of claim 5, wherein the usage information includes information about at least one of the type of an identity resource, the attribute values of an identity resource, timestamps of access to the identity resources, and identifiers of service providers (18) which access, have accessed, use, or have used the identity resource, or subscribe or have subscribed to the identity resource. 7. Controller (12) of any one of the preceding claims, being a web service provider. 8. Method carried out by a controller (12) for privacy management in an identity network (10) for at least one principal (20), wherein an identity network (10) is a computer network including at least an identity provider (14), a discovery service provider (16), and a service provider (18) with which the principal (20) can make transactions; a principal (20) is a system entity whose identity can be authenticated; an identity resource is either data related to an identity or group of identities, or a service associated with an identity or group of identities; and the method includes querying (S2) a discovery service provider (16) of the identity network (10) to obtain information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity; receiving (S4), from the discovery service provider (16), information, here referred to as addressing information, usable for addressing attributes of the identity resources available in the identity network (10) and associated with the principal's (20) identity; and interacting (S6), based on the addressing information, with a service provider (18) to create, read, modify or delete an attribute governing the use of an identity resource available in the identity network (10) and associated with the principal's (20) identity, the attribute being here referred to as privacy attribute, wherein an attribute governing the use of an identity resource specifies permissions associated with the identity resource with respect to operations that may be performed by system entities on, or in relation to, the identity resource. 9. Method of claim 8, further including, before querying (S2), receiving (s1), from the principal (20), a request to retrieve information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity. 10. Method of claim 8 or 9, further including, after receiving (S4) and before interacting (S6), making (S5a) the addressing information available to the principal (20); and receiving (S5b), from the principal (20), a request to create, read, modify or delete the privacy attribute; and wherein interacting (S6) with the service provider (18) to create, read, modify or delete the privacy attribute is based on the request received from the principal (20) to create, read, modify or delete the privacy attribute. 11. Method according to any one of claims 8 to 10, wherein interacting (S6) is carried out using a data services template protocol. 12. Method according to any one of claims 8 to 11, further including obtaining (S7), from at least one service provider (18) of the identity network (10), information, here referred to as usage information, regarding the usage of the identity resources associated to the principal's (20) identity in the at least one service provider (18) . 13. Method of claim 12, wherein the usage information includes information about at least one of the type of an identity resource, the attribute values of an identity resource, timestamps of access to the identity resources, and identifiers of service providers (18) which access, have accessed, use, or have used the identity resource, or subscribe or have subscribed to the identity resource. 14. Computer program comprising instructions configured, when execute on a computer, to cause the computer to carry out the method according to any one of claims 8 to 13. 15. Computer program product or computer-readable medium including a computer program of claim 14.

Etiquetas

Inventores
Angel Monjas Llorente MiguelMaria del Alamo Ramiro JoseBeatriz San Miguel GonzalezCarlos Yelmo Garcia JuanMonjas Llorente, Miguel AngelDel Alamo Ramiro, Jose MariaSan Miguel Gonzalez, BeatrizYelmo Garcia, Juan CarlosMonjas Llorente Miguel AngelDel Alamo Ramiro Jose MariaSan Miguel Gonzalez BeatrizYelmo Garcia Juan CarlosDel Álamo Ramiro José MaríaSan Miguel González BeatrízYelmo García Juan Carlos
Solicitantes
Ericsson Telefon Ab L MUniversidad Politécnica de MadridTelefonaktiebolaget Lm Ericsson (PublMonjas Llorente Miguel AngelDel Alamo Ramiro Jose MariaSan Miguel Gonzalez BeatrizYelmo Garcia Juan CarlosTelefonaktiebolaget L M Ericsson (Publ
Clasificacion ipc
G06F 21/ 31 A IH04L 29/ 06 A IH04L 12/ 56 A IH04L 9/ 32 A IG06F 15/ 16 A IG06F 15/ 173 A I
Clasificacion cpc
G06F21/20&131A709/223
Logo

Innovation CM
Challenges
Europa2i
Entrepreneurship
R&D&I Search
Agents
Events
Reports
About us
Contact
Give us your opinion
Cookies
Legal notice
Privacy

© Copyright Espacio Madrileño de Investigación e Innovación 2026