Reivindicaciones
1. Controller (12) for privacy management in an identity network (10) for at least one principal (20), wherein an identity network (10) is a computer network including at least an identity provider (14), a discovery service provider (16), and a service provider (18) with which the principal (20) can make transactions; a principal (20) is a system entity whose identity can be authenticated; an identity resource is either data related to an identity or group of identities, or a service associated with an identity or group of identities; and the controller (12) is configured for querying (S2) a discovery service provider (16) of the identity network (10) to obtain information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity; receiving (S4), from the discovery service provider (16), information, here referred to as addressing information, usable for addressing attributes of the identity resources available in the identity network (10) and associated with the principal's (20) identity; and interacting (S6), based on the addressing information, with a service provider (18) to create, read, modify or delete an attribute governing the use of an identity resource available in the identity network (10) and associated with the principal's (20) identity, the attribute being here referred to as privacy attribute, wherein an attribute governing the use of an identity resource specifies permissions associated with the identity resource with respect to operations that may be performed by system entities on, or in relation to, the identity resource. 2. Controller (12) of claim 1, further configured for, before querying (S2), receiving (s1), from the principal (20), a request to retrieve information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity. 3. Controller (12) of claim 1 or 2, further configured for, after receiving (S4) and before interacting (S6), making (S5a) the addressing information available to the principal (20); and receiving (S5b), from the principal (20), a request to create, read, modify or delete the privacy attribute; and wherein interacting (S6) with the service provider (18) to create, read, modify or delete the privacy attribute is based on the request received from the principal (20) to create, read, modify or delete the privacy attribute. 4. Controller (12) according to any one of the preceding claims, wherein interacting (S6) is carried out using a data services template protocol. 5. Controller (12) according to any one of the preceding claims, further configured for obtaining (S7), from at least one service provider (18) of the identity network (10), information, here referred to as usage information, regarding the usage of the identity resources associated to the principal's (20) identity in the at least one service provider (18) . 6. Controller (12) of claim 5, wherein the usage information includes information about at least one of the type of an identity resource, the attribute values of an identity resource, timestamps of access to the identity resources, and identifiers of service providers (18) which access, have accessed, use, or have used the identity resource, or subscribe or have subscribed to the identity resource. 7. Controller (12) of any one of the preceding claims, being a web service provider. 8. Method carried out by a controller (12) for privacy management in an identity network (10) for at least one principal (20), wherein an identity network (10) is a computer network including at least an identity provider (14), a discovery service provider (16), and a service provider (18) with which the principal (20) can make transactions; a principal (20) is a system entity whose identity can be authenticated; an identity resource is either data related to an identity or group of identities, or a service associated with an identity or group of identities; and the method includes querying (S2) a discovery service provider (16) of the identity network (10) to obtain information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity; receiving (S4), from the discovery service provider (16), information, here referred to as addressing information, usable for addressing attributes of the identity resources available in the identity network (10) and associated with the principal's (20) identity; and interacting (S6), based on the addressing information, with a service provider (18) to create, read, modify or delete an attribute governing the use of an identity resource available in the identity network (10) and associated with the principal's (20) identity, the attribute being here referred to as privacy attribute, wherein an attribute governing the use of an identity resource specifies permissions associated with the identity resource with respect to operations that may be performed by system entities on, or in relation to, the identity resource. 9. Method of claim 8, further including, before querying (S2), receiving (s1), from the principal (20), a request to retrieve information regarding the identity resources available in the identity network (10) and associated with the principal's (20) identity. 10. Method of claim 8 or 9, further including, after receiving (S4) and before interacting (S6), making (S5a) the addressing information available to the principal (20); and receiving (S5b), from the principal (20), a request to create, read, modify or delete the privacy attribute; and wherein interacting (S6) with the service provider (18) to create, read, modify or delete the privacy attribute is based on the request received from the principal (20) to create, read, modify or delete the privacy attribute. 11. Method according to any one of claims 8 to 10, wherein interacting (S6) is carried out using a data services template protocol. 12. Method according to any one of claims 8 to 11, further including obtaining (S7), from at least one service provider (18) of the identity network (10), information, here referred to as usage information, regarding the usage of the identity resources associated to the principal's (20) identity in the at least one service provider (18) . 13. Method of claim 12, wherein the usage information includes information about at least one of the type of an identity resource, the attribute values of an identity resource, timestamps of access to the identity resources, and identifiers of service providers (18) which access, have accessed, use, or have used the identity resource, or subscribe or have subscribed to the identity resource. 14. Computer program comprising instructions configured, when execute on a computer, to cause the computer to carry out the method according to any one of claims 8 to 13. 15. Computer program product or computer-readable medium including a computer program of claim 14.