Nova Patents
CA2834785C

Method for handling privacy data

Abstract

The present invention aims to improve data protection against illegal access by a strong differentiation of the security level specific on a type of data so that when the protection on a part of the data is violated, the remaining data are still inaccessible. A method for controlling access, via an open communication network, to user private data, comprising steps of: dividing the user private data into a plurality of categories, each category defining a privacy level of the data,encrypting the user private data of each category with a category key pertaining to the category of the data,attributing to a stakeholder an entity configured for accessing to at least one category of user private data, and authorizing the access to the at least one category of user private data for the entity of the stakeholder, by providing the stakeholder with the category keys required for decrypting the user private data of the corresponding category.

CA2834785C, drawing sheet 1
Sheet 1 of 2

Term

5.6 yearsleft in the term

Expires 9 May 2032.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

16 claims: 2 independent, 14 dependent

  1. 1
    A method for controlling access, via an open communication network (C), to user private data (dC1, dC2,...dCn) being provided by a plurality of source entities (SE1, SE2, ...SEn), the method comprising steps of:dividing the user private data (dC1. dC2,...dCn) into a plurality of categories (C1, C2,...Cn), each category (C1, C2,...Cn) defining a privacy level of the user private data (dC1, dC2,...dCn);encrypting by each source entity (SE1. SE2, ...SEn) the user private data (dC1, dC2,...dCn) of each category (C1, C2, ...On) with a category key (KC1, KC2, ...KCn) pertaining to the category (C1, C2, ...Cn) of the user private data (dC1, dC2, ...dCn), each category key (KC1, KC2, ...KCn) being independent of other category keys;storing temporarily or permanently the encrypted user private data ((dC1)KC1, (dC2)KC2,.... (dCn)KCn) in at least one database (DB1, DB2,...DBn) controlled by at least one database controlling entity (DBCE);attributing to a stakeholder (S1, S2, ...Sn) at least one entity (CE1, CE2, ...Cn) configured for accessing to at least one category (C1, C2, ...Cn) of user private data (dC1, dC2, ...dCn);and authorizing the access to the at least one category (C1, C2, ...Cn) of user private data (dC1, dC2, ...dCn) for the at least one entity (CE1, CE2, ...Cn) of the stakeholder (S1, S2, ...Sn), by providing the at least one entity (CE1, CE2, ...Cn) with the category keys (KC1, KC2, ...KCn) required for decrypting the user private data (dC1, dC2, ...dCn) of the corresponding category (C1, C2, ...Cn).
  2. 4
    The method according to any one of claims 1 to 3 wherein the open communication network (C) is entirely or partly a smart grid network.
  3. 5
    The method according to any one of claims 1 to 3 wherein the open communication network (C) is entirely or partly a home area network.
  4. 6
    The method according to any one of claims 1 to 5 wherein the category keys (KC1, KC2,... KCn) are either of symmetrical type or asymmetrical type or of a combination of symmetrical and asymmetrical keys.
  5. 7
    The method according to any one of claims 1 to 6 wherein the category keys (KC1, KC2,... KCn) are used in combination with other keys.
  6. 9
    The method according to any one of claims 1 to 8 wherein the at least one database controlling entity (DBCE) consists of a managing center managing the plurality of source entities (SE1, SE2,...SEn) each sending, periodically or at scheduled time, data to the at least one database controlling entity (DBCE) which feeds the database (DB1, DB2,...DBn).
  7. 11
    The method according to any one of claims 4 to 10 wherein the user private data are metering data divided into the plurality of categories (C1, C2, ...Cn), the metering data of each category being encrypted by the smart meter source entity (SE1, SE2,...SEn) with a category key (KC1, KC2, ...KCn) pertaining to the category (C1, C2, ...Cn) of the metering data. CA 2834785 2018-06-18
  8. 13
    The method according to any one of claims 1 to 12 wherein the at least one source entity (SE1, SE2,...SEn) and the at least one entity (CE1, CE2, ...Cn) are combined in a same physical entity.
  9. 14
    The method according to any one of claims 1 to 12 wherein the at least one source entity (SE1, SE2,...SEn) or the at least one entity (CE1, CE2, ...Cn) is combined with at least one database controlling entity (DBCE) in a same physical entity.
  10. 16
    A system configured to control access, via an open communication network (C), to user private data (dC1, dC2,...dCn), the system comprising:a plurality of source entities (SE1, SE2, ...SEn) each configured to: provide the user private data (dC1, dC2,...dCn);divide the user private data (dC1, dC2,...dCn) into a plurality of categories <C1, C2,...Cn), each category (C1, C2,...Cn) defining a privacy level of the user private data (dC1, dC2,...dCn);and encrypt the user private data (dC1, dC2,...dCn) of each category (C1, C2, ...Cn) with a category key (KC1, KC2, ...KCn) pertaining to the category (C1, C2, ...Cn) of the user private data (dC1, dC2, ...dCn), each category key (KC1, KC2,... KCn) being independent of other category keys;