发明名称 METHOD FOR MANAGING AND CHECKING DATA FROM DIFFERENT IDENTITY DOMAINS ORGANIZED INTO A STRUCTURED SET
摘要 The invention relates to a method and system for managing and checking different identity data relating to a person. According to the invention, a derived-identity management server generates for the person at least part of the identity data with which said person can be authenticated in relation to a service provider for the derived-identity domain, on the basis of information derived from identity data from parent domains. The identity data generation processing ensures that no link can be established from two authentications in two separate domains in the absence of link information. If necessary, said link information is transmitted by a parent domain to a derived-identity server so that the latter establishes the link between the identity data of the derived-identity domain and the identity data of the parent domain, e.g. for the cascade revocation of a person from various domains.
申请公布号 US2014181932(A1) 申请公布日期 2014.06.26
申请号 US201214237556 申请日期 2012.08.02
申请人 Patey Alain;Chabanne Herve;Bringer Julien 发明人 Patey Alain;Chabanne Herve;Bringer Julien
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. Method of management and control of different identity data of an individual, these data corresponding to several identity domains organised into a structured set, in which at least one controlling system can be used for a given identity domain to implement an authentication of the individual from the identity data associated with this domain for the individual, characterised in that identity data can be generated for a derived identity domain for which identity data are necessary for one or more parent domains, an authentication processing of the individual is implemented for each parent identity domain starting from identity data of the individual for the parent domain, on a management server of the derived identity domain, during which: information dependent on the parent domain identity data and at least one item of information to prove validity of these data are transmitted to the derived identity domain management server,the derived identity management server authenticates the individual for the parent domain and uses the proof information to control that the information transmitted is valid, and in that, depending on the authentication and control results: the derived identity management server generates at least some of the identity data with which the individual can authenticate himself with a service provider for the derived identity domain, as a function of the information transmitted, for the individual,said derived identity management server stores derived information containing all or some of the information exchanged during the authentication processing so that the link between identity data of the derived identity domain and identity data of the parent domain can be made later if required, depending on link information transmitted by a parent domain, the generation processing done by the different identity servers being such that no link can be created from two authentications in two distinct domains if this link information is not available.
地址 Issy-Les-Moulineaux FR