Communication method for controlled data exchange between a client terminal and a host site network and protective server set therefor
35 claims: 10 independent, 25 dependent
- 1CLAIMS REVENDICATIONS 1. Communication method for exchanging data in a controlled manner between a client terminal (1) and a network of host sites (2), this method being characterized in that:1. Procédé de communication pour échanger de manière contrôlée des données entre un terminal client (1) et un réseau de sites (2) hôtes, ce procédé étant caractérisé par le fait que : - les données sont échangées, entre le terminal client (1) et le réseau, par l'intermédiaire d'un serveur de protection (6), - the data is exchanged between the client terminal (1) and the network, via a protection server (6), - l'identifiant du terminal client est masqué, vis à vis du réseau, au niveau du serveur de protection (6), - the identifier of the client terminal is masked from the network at the level of the protection server (6), - at least part of the data is protected from reading by any person not authorized to read this part of the data, when this data is communicated between the protection server (6) and the client terminal (D, - au moins une partie des données sont protégées de la lecture par toute personne non autorisée à lire cette partie des données, lorsque ces données sont communiquées entre le serveur de protection (6) et le terminal client (D , - un profil de préférences qualifiant un utilisateur du terminal client et agréé par cet utilisateur est comparé à des connaissances sur au moins un site hôte (2), et a preference profile qualifying a user of the client terminal and approved by this user is compared with knowledge of at least one host site (2), and - The exchange of data between the client terminal and this host site (2) is controlled as a function of information resulting from this comparison. - l'échange des données entre le terminal client et ce site (2) hôte est contrôlé en fonction d'informations issues de cette comparaison.
- 5Method according to one of the preceding claims, in which a part, comprising information on the identity of the client terminal (1), of a request formulated from the client terminal (1) to a site (2) host, is modified before going to the host site (2) for which the request is intended. 5. Procédé selon l'une des revendications précédentes, dans lequel une partie, comportant des informations sur l'identité du terminal client (1), d'une requête formulée à partir du terminal client (1) à destination d'un site (2) hôte, est modifiée avant de transiter vers le site (2) hôte auquel est destinée la requête.
- 6Method according to one of the preceding claims, comprising a filtering of witnesses coming from the network by the protection server (6) and a storage, at the level of the protection server (6), of at least some of these witnesses. 6. Procédé selon l'une des revendications précédentes, comprenant un filtrage de témoins en provenance du réseau par le serveur de protection (6) et un stockage, au niveau du serveur de protection (6), d'au moins une partie de ces témoins.
- 7Method according to one of the preceding claims, in which an electronic mail server (9) provides at least one disposable electronic mail address. 7. Procédé selon l'une des revendications précédentes, dans lequel un serveur de courrier électronique (9) fournit au moins une adresse de courrier électronique à usage unique.
- 9Method according to one of the preceding claims, in which a plurality of electronic mail accounts is assigned to a user, with a single portal, independent of the client terminal and personal to manage these accounts. 9. Procédé selon l'une des revendications précédentes, dans lequel une pluralité de comptes de messagerie électronique est attribuée à un utilisateur, avec un portail unique, indépendant du terminal client et personnel pour gérer ces comptes.
- 10Method according to one of the preceding claims, in which a trust status is associated with a host site (2), as a function of knowledge, stored in a knowledge base (14,15), on at least the protection policy of personal data by a third party operating this (2) host site. 10. Procédé selon l'une des revendications précédentes, dans lequel un statut de confiance est associé à un site (2) hôte, en fonction de connaissances, stockées dans une base de connaissances (14,15), sur au moins la politique de protection des données personnelles par un tiers exploitant ce site (2) hôte.
- 13Method according to one of the preceding claims, in which the user of the client terminal (1) is represented, vis-à-vis the network, by at least one avatar. 13. Procédé selon l'une des revendications précédentes, dans lequel l'utilisateur du terminal client (1) est représenté, vis-à-vis du réseau, par au moins un avatar.
- 17Method according to claims 10 and 16 taken in combination, in which the protection profile is confronted with the trust status to define an automatic processing of the data exchanged between this host site (2) and the client terminal (1), when the user wishes to establish a communication with a host site (2) and prior to this communication, and when a host site (2) wishes to enter into communication with the client terminal. 17. Procédé selon les revendications 10 et 16 prises en combinaison, dans lequel le profil de protection est confronté au statut de confiance pour définir un traitement automatique des données échangées entre ce site (2) hôte et le terminal client (1), lorsque l'utilisateur souhaite établir une communication avec un site (2) hôte et préalablement à cette communication, et lorsqu'un site hôte (2) souhaite entrer en communication avec le terminal client.
- 18Method according to claims 6 and 17 taken in combination, in which the automatic processing of the data exchanged between the host site (2) and the client terminal (1) comprises the filtering of witnesses coming from the network and the storage, at the server level. protection (6), of at least some of the filtered witnesses. 18. Procédé selon les revendications 6 et 17 prises en combinaison, dans lequel le traitement automatique des données échangées entre le site (2) hôte et le terminal client (1) comporte le filtrage de témoins en provenance du réseau et le stockage, au niveau du serveur de protection (6), d'au moins une partie des témoins filtrés.
- 19Protection server assembly for making the interface between a client terminal (1) and a network of host sites (2) and allowing a user of the client terminal to control the dissemination of information concerning him, on the network, this assembly protection server (6) comprising:19. Ensemble serveur de protection pour faire l'interface entre un terminal client (1) et un réseau de sites (2) hôtes et permettre à un utilisateur du terminal client de contrôler la diffusion d'informations qui le concernent, sur le réseau, cet ensemble serveur de protection (6) comportant : - des moyens, au niveau d'un serveur de protection (6), pour masquer l'identifiant du terminal client, vis à vis du réseau, - means, at the level of a protection server (6), for masking the identifier of the client terminal, with respect to the network, - des moyens pour protéger au moins une partie des données, de la lecture par toute personne non autorisée à lire cette partie des données, lorsque ces données sont communiquées entre le serveur de protection (6) et le terminal client (1), - means for protecting at least part of the data from reading by any person not authorized to read this part of the data, when these data are communicated between the protection server (6) and the client terminal (1), - comparison means for comparing, with knowledge of at least one host site (2), a preference profile qualifying last, and - des moyens de comparaison pour comparer, à des connaissances sur au moins un site hôte (2) , un profil de préférences qualifiant dernier, et - des moyens l'utilisateur et agréé par ce en pour contrôler, d'informations générées par les moyens de comparaison, l'échange des données entre le terminal client et ce site (2) hôte. - means the user and approved by this in to control, information generated by the comparison means, the exchange of data between the client terminal and this host site (2). fonction function
Independent claims10
177 paragraphs, as filed
i
Communication method for exchanging data in a controlled manner between a client terminal and a network of host sites and protection server assembly for the implementation of this method
The invention relates to a communication method for exchanging, in a controlled manner, data between a client terminal and a network of host sites, as well as to a protection server assembly for implementing this method.
In this document, the term “terminal” designates a microcomputer, a mobile telephone, or any other device capable of communicating with a network of data servers.
In a particular application, the method according to the invention is intended to allow an Internet user to control the dissemination on the Internet of information which concerns him.
On the one hand, an Internet user may, for example in order to benefit from personalized services, be required to transmit to a host site certain data on his identity, his income, his preferences in terms of leisure, shopping, etc., but nevertheless wish that this information will not be used for purposes other than those for which it has disclosed it.
On the other hand, some sites send cookies, also called “cookies”, to the terminals of Internet users who connect to them, to be automatically installed on these terminals. These cookies are files which, once stored in the memory of these terminals, allow the server of the site which issued them to receive information on the Internet user and his behavior. Internet users sometimes wish to avoid the installation of cookies on their terminal and to avoid, without necessarily losing all possibility of benefiting from personalized services, that information concerning them is collected and used without their knowledge.
We already know from document EP-A-1 017 205, a method for anonymously providing information on the Internet user, when he is browsing the Internet. In this method of the prior art, the information is recorded in a memory, a pseudonym is generated for the Internet user, this pseudonym is linked to the information contained in the memory, in a register and the register is transmitted, automatically or in response. at the controls of the Internet user, on the sites consulted by this one. These sites therefore only have access to the information in question in connection with the pseudonym. Such a pseudonym is generally linked to an avatar, that is to say a virtual representation created by the Internet user to move in cyberspace.
However, such a method does not make it possible in particular to prevent the Internet access provider (also called by a person skilled in the art "ISP", standing for Internet Service Provider), to which the Internet user is a subscriber, from knowing about the identity of the sites consulted by the latter.
Software is also known which, once installed on the user's terminal, allow the latter to select the cookies that he wants to see stored on his terminal.
However, such software does not offer any protection for data transmitted over the network, from the user's terminal, whether from data collected through cookies or others.
There is also a need for methods and devices for protecting the privacy of Internet users which may possibly allow personalized services to be offered.
An aim of the invention is in particular to provide a method of data communication between a client terminal and a network of host sites, allowing better protection of this data, vis-à-vis their use by unauthorized third parties and which , preferably, authorizes the offer of personalized services.
This object is achieved, according to the invention, by virtue of a communication method for exchanging data in a controlled manner between a client terminal and a network of host sites, this method being characterized in that:
- the data is exchanged between the client terminal and the network, via a protection server,
- the identifier of the client terminal is hidden from the network at the level of the protection server,
at least part of the data is protected from reading by any person not authorized to read this part of the data, when this data is communicated between the protection server and the client terminal;
a preference profile qualifying a user of the client terminal and approved by this user is compared with knowledge of at least one host site, and
the exchange of data between the client terminal and this host site is controlled as a function of information resulting from this comparison.
Indeed, according to this process:
- on the one hand, between the client terminal (an Internet user's terminal for example), and the protection server, the data exchanged is made, at least in part, or even totally, confidential by the protection of at least a part of these; thus when the user accesses the protection server thanks to a network access provider, the data exchanged between the protection server and the client terminal are at least partially protected from reading by the access provider; and
- on the other hand, the identifier of the client terminal (IP address for a terminal connected to the Internet; IP being the acronym for "Internet Protocol") is masked and the data transmitted between the client terminal and the rest of the
<td>network are subject to</td><td>a</td><td colspan="2">control, depending on</td><td>this</td><td>than</td>
<td>user wishes</td><td colspan="2">, among</td><td>information</td><td>who</td><td>the</td>
<td>concern, disseminate or</td><td>no</td><td>sure</td><td>the network.</td><td></td><td></td>
<td colspan="2">Thus, some</td><td>of</td><td colspan="3">data concerning</td>
<td>the user can,</td><td>if</td><td>this</td><td>last wishes,</td><td>not'</td><td>to be</td>
known, neither third parties operating the sites visited by it, nor third parties who send cookies to the user's terminal without the latter having chosen to connect to a site of these third parties (for example advertising agencies ), or even its access provider.
In preferred embodiments, the method according to the invention comprises one and / or the other of the following characteristics:
the addresses of host sites to which data are sent, from the client terminal, are concealed from the access provider; in the context of a connection to the Internet, these addresses are URL addresses (acronym of the English expression "Uniform Resource Locator");
the protection server supplies on request, in place of the access provider, a host site address identified by a name, corresponding to this name, using a domain name system; thus within the framework of a connection to the Internet, this domain name system is called DNS (Acronym of the Anglo-Saxon expression “Domain Naming System”);
a part, comprising information on the identity of the client terminal, of a request formulated from the client terminal to a host site, is modified, or even eliminated, before going to the host site for which the request is intended. request; thus in the context of a connection to the Internet, it is part of the header (also called “header” by those skilled in the art) of the request which is the subject of this modification;
- it comprises a filtering of witnesses (cookies) coming from the network by the protection server, and storage, at the level of the protection server, of at least some of these cookies; some cookies are deleted while others are saved at the protection server; no cookies are stored on the client terminal, but the user can nevertheless take advantage of the advantages provided by some of these cookies, such as the offer of personalized services according to the information profile directly attached to his identity or to 1 ' (to) avatar (s) who represent him (s);
- an electronic mail server provides at least one single-use electronic mail address;
- it includes a follow-up of the use of the single-use address, made by a third party to whom this e-mail address has been transmitted;
a plurality of electronic mail accounts is assigned to a user, with a single portal, independent of the client terminal and personal to manage these accounts;
a status of trust is associated with a host site, based on knowledge, stored in a knowledge base, on at least the personal data protection policy by a third party operating this host site; this policy is for example defined on the one hand, by a P3P (“Platform for Privacy Preference Project”) form qualifying a site, and on the other hand, by tests on the use of information by this site and / or by general knowledge (reputation for example) of the company that operates this site;
- a form for entering information on the user, provided by a host site and intended for recording the information entered, by this host site, is automatically completed by the protection server according to the status of trust, before '' be subject to user approval;
The approval by the user is carried out automatically according to a protection profile that he has predefined;
the user of the client terminal is represented, vis-à-vis the network, by at least one avatar; thus the user can disseminate qualifying data, for example on his preferences, without these necessarily being attached to his real identity;
- an information profile comprising the preference profile and associated with the real identity of the user or with each avatar is stored at the level of a knowledge base, this profile being determined, at least in part, by the behavior of the user when he communicates with the network using this avatar; thus, the preferences associated with the user's avatar can be taken into account in this profile; the information profile includes qualifying data on the user associated with this avatar;
by
- the
The user information profile configuration is modified through a server this allows the user to modify the data concerning him recorded in this information profile, for example, to refine this profile for the purpose of an improvement in the personalization of the services that may be offered to him or to remove from this profile information that he does not wish to be disseminated;
- an authorization to use, by a third party operating a host site, information attached to the real identity of the user or to the avatar under which the user accesses this host site is governed by the user, at the means of selecting and activating a predefined protection profile; for example, the user can thus choose a “paranoid” profile which allows him for example to automatically and systematically refuse the transmission of any information concerning him, a “normal” profile which allows him to accept that certain information is communicated only if the site for which they are intended enjoys a certain level of confidence, or a “flexible” profile which allows him to accept that any information attached to the avatar he uses is transmitted to the site (s) to which he connects;
- the protection profile is compared to the status of trust to define an automatic processing of the data exchanged between this host site and the client terminal, when the user wishes to establish a communication with a host site and prior to this communication, and / or when a host site wishes to enter into communication with the client terminal (for example, an advertising agency); and
the automatic processing of the data exchanged between the host site and the client terminal comprises the filtering of cookies coming from the network and the storage, at the level of the protection server, of at least some of the filtered cookies; for example, if the user chooses a "paranoid" profile, any cookie from a site with a low trust status is refused, while with a "normal" profile, he can automatically accept cookies from this host site which are destroyed at the end of the connection session with the latter, or a "flexible" profile which allows it to accept the storage of any cookie from this site.
According to another aspect, the invention proposes a protection server assembly for making the interface between a client terminal and a network of host sites and allowing a user of the client terminal to control the broadcasting of information concerning him, on the network. network, this protection server set comprising:
- means, at the level of a protection server, for masking the identifier of the client terminal, vis-à-vis the network,
means for protecting at least part of the data from reading by any person not authorized to read this part of the data, when this data is communicated between the protection server and the client terminal,
- comparison means for comparing, with knowledge of at least one host site, a preference profile qualifying last, and
means the user and approved by this in order to control, information generated by the comparison means, the exchange of data between the client terminal and this host site.
function
In preferred embodiments, the method according to the invention comprises one and / or the other of the following characteristics:
it comprises means for creating at least one avatar making it possible to represent the user vis-à-vis the network;
- it includes means for managing an information profile based on personal data and on the communications it establishes with the network;
it comprises means for protecting from reading by a network access provider, at least part of the data exchanged between the protection server and the client terminal;
<td>- he</td><td>behaves</td><td>of</td><td>means</td><td>for</td><td>hide,</td><td>at</td>
<td>provider</td><td>access,</td><td>of</td><td>addresses</td><td>of</td><td>host sites</td><td>at</td>
<td>destination</td><td colspan="5">from which data is sent, from</td><td>of</td>
client terminal;
the protection server supplies on request, in place of the access provider, a host site address identified by a name, corresponding to this name, using a domain name system;
- it comprises means for eliminating a part, comprising information on the identity of the client terminal, of a connection request, formulated from the client terminal to a host site, before transο this request passes through to the host site for which it is intended;
- it includes a knowledge base, associated with the real identity of the user or with an avatar of the user, in which are recorded information on the behavior of the user when communicating with the network using respectively his real identity or this avatar;
- it includes a database, intended to store at least one manifesto of the personal data protection policy of a host site, and means for comparing each manifesto with the information recorded in the knowledge base in association with a user's avatar or real identity; such a manifesto is for example a P3P form; the comparison means advantageously consist of an inference engine of the trust status; an inference engine makes it possible to produce new propositions from propositions taken for granted, by implementing inference rules; in the protection server set, the propositions taken for granted include the manifest of a host site's protection policy, the new propositions include the trust status, and the inference rules are defined from the information associated with the host site. 'user avatar;
it comprises means for filtering cookies coming from the network and means for storing, after approval by the user, at least some of the filtered cookies;
- it comprises a plurality of protection servers organized in a network of proxy servers (also called “proxy servers” by those skilled in the art) to allow greater proximity between the client terminal and at least one of these remote servers. protection;
it includes a central server to direct the user to the protection server closest to the client terminal; and
<td>- he</td><td>has a server</td><td>dedicated</td><td colspan="2">At the creation</td>
<td>avatars and</td><td>the storage of cookies,</td><td colspan="2">and comprising a</td><td>based</td>
<td colspan="2">of knowledge, associated with 1</td><td colspan="2"><sup>1</sup> real identity</td><td>of</td>
<td> 1<sup>1</sup> user</td><td>or to an avatar,</td><td>in</td><td>which</td><td>are</td>
<td>recorded</td><td>Informations about</td><td>the</td><td>behaviour</td><td>of</td>
<td>The user</td><td>when he communicates</td><td>with</td><td>the network</td><td>in</td>
<td>using his</td><td colspan="2">real identity or that avatar.</td><td></td><td></td>
<td>According to</td><td>yet another aspect,</td><td colspan="3">the invention provides a</td>
computer program loadable into a memory, associated with a processor, and comprising portions of codes for the implementation of a method as mentioned previously, during the execution of said program.
According to yet another aspect, the invention proposes a computer program that can be loaded into a memory, associated with a processor, and comprising portions of codes for managing the communication between the client terminal and the protection server assembly as mentioned above. , during the execution of said program.
According to yet another aspect, the invention proposes a data medium on which is recorded a computer program as mentioned above.
According to yet another aspect, the invention proposes a method for downloading a computer program as mentioned above.
Other aspects, aims and advantages of the invention will become apparent on reading the following detailed description of one of its embodiments. The invention will also be better understood with the aid of the references to the drawings in which:
- Figure 1 shows, schematically, the structure of the communication between a client terminal and a network of host sites, in an exemplary mode of implementation of the method according to the present invention;
FIG. 2 diagrammatically represents the architecture of a server assembly for the implementation of the exemplary method represented in FIG. 1; and
- Figure 3 shows, schematically, the architecture of the protection functions of the server assembly whose architecture is shown in Figure 2.
The invention is described below in the context of its implementation to confidentialize the communication between a client terminal, consisting of a personal computer 1, and a set of host sites 2 such as Internet sites.
As shown in Figure 1, the personal computer 1 is connected to the Internet via an access provider 3 and a protection server assembly 4.
The protection server set 4 offers many functions.
By way of illustration, FIG. 1 represents the case where the protection server assembly 4 allows the Internet user of the personal computer 1 to control and to accept or not the intervention of third parties during his communication with a site. 2 recipient. Indeed, when a user consults a page on this 2 recipient site, it may happen that this page contains insertions from third parties (advertising for example) and that, in addition, this third party sends a cookie to the computer. of the Internet user. Thanks to the protection server assembly 4 according to the invention, the Internet user can choose whether or not to accept the cookie sent by this third party.
The general architecture of a protection server assembly 4 such as that represented in FIG. 1 is illustrated by FIG. 2.
This protection server set 4 mainly comprises:
- an identification server 5, proxy servers 6, each 6 being associated with a server of the same associated with a server of
- a Network Configuration Agent, him
User Knowledge 8,
- a Services 9 server and
- a Supervisor server 10.
In the remainder of this document, for the sake of simplicity, the protection server assembly 4 is described with a single Proxy server 6, to which is associated a single Configuration server 7, itself associated with a single User Knowledge server 8, although these different servers are duplicated in the network.
As represented in this FIG. 2, the Internet user accesses the Internet network from his personal computer 1. In order to use the services of the protection server assembly 4, the Internet user uses access tools, configuration and report.
These access, configuration and reporting tools are computer programs 1 stored in the memory of the computer from a medium such as a CD-ROM or after downloading from an Internet site which distributes such programs.
These access, configuration and report tools are able to allow the Internet user:
- to be identified with the protection server unit 4,
- to receive in return an "access token" for a session,
- create avatars or modify an existing avatar,
- select an avatar to connect to the Internet network,
- select a predefined information profile, possibly modify this predefined information profile to personalize it and / or completely create an information profile,
- to attach to an avatar, the predefined information profile selected, modified or created,
- modify a profile preferably attached to an avatar,
- obtain a navigation report,
- activate a privacy protection service by the protection server assembly 4 on the basis of the information profile selected and
- access various other services accessible on the protection server set 4.
The Internet user connects to the protection server assembly 4, at the level of the identification server 5. The identification function of the identification server is implemented using the functions relating to the personal identification certificate of the Internet browser. of the Internet user. The identification server confronts the identity of the Internet user with data on the users having access to the protection server set 4, stored in a Users database 11. After identification, authorized Internet users receive an access token for a session.
The Internet user who has received an “access token” to a session, accesses the Proxy server 6. Advantageously and essentially for reasons of performance in terms of communication speeds and bandwidths, the Proxy server 6 is the “Proxy” server. located as close as possible to the Internet user.
The Proxy server 6 forms the interface between the Internet user, the other servers of the protection server set 4 and the Internet network. Its main functions are:
- filter and select cookies from the network;
- make a comparison between the expression of a privacy protection policy, of a site 2 and the information profile attached to the avatar used by the Internet user to access this site 2,
- derive and store cookies accepted by the Internet user,
- modify the header of connection requests,
- delete the identification address (IP address)
<td colspan="2">of the Internet user,</td><td>of</td><td colspan="3">data sent</td><td>to the sites</td><td> 2</td>
<td>recipients,</td><td colspan="2">so</td><td>than</td><td>The address</td><td>of</td><td>these sites</td><td> 2</td>
<td>recipients,</td><td>of</td><td colspan="2">data</td><td>transiting</td><td>through</td><td colspan="2">supplier</td>
access,
- automatically fill out forms according to the trust status associated with site 2 that issued this form
- make, according to the DNS table, the name / address of the 2 sites targeted by the Internet user, conversion
- analyze the content of the web pages consulted and remove from these pages the elements not desired by the Internet user, and
- establish the history of connection sessions and the preferences of the Internet user.
The filtering and the selection of cookies are carried out on the basis of data stored in a database of User information 12 which comprises, among other things, the wishes of the Internet user as regards the processing of cookies.
Cookies considered acceptable by the Internet user are stored in a memory. This memory is accessible to the Internet user and to the server of the site 2 which issued it, but is not located on the computer 1 of the Internet user.
The header of connection requests, whether this connection is established using the http protocol or another protocol, is modified, before passing through to site 2, according to criteria and rules for protection and compliance with the privacy defined by committees<sup>1</sup> ethnic.
The session history and the preferences of the Internet user are, according to their information profile, either destroyed or transferred to the User Knowledge server 8 associated with the Proxy server 6.
The Proxy server 6 is programmed using free programs well known to those skilled in the art (Squid °, Apache °, etc.).
The Configuration 5 server is used to:
- create, select or modify an avatar and / or an information profile,
- select, create and / or configure preference profiles,
- view cookies, download or destroy them, and
- access services such as "Help", "FAQ", electronic mail, etc., as well as the navigation report.
The Internet user has the possibility of creating several avatars. Each avatar is attached to one or more electronic address (es), a memory for storing cookies and connection files, an information profile, a preferences profile, etc. Information and preference profiles may be different from one avatar to another.
An information profile includes identifying information and qualifying information about the Internet user. Identifying information is, for example, his marital status, his address, etc. The qualifying information is, for example, his age, his centers of interest, etc. The identifying information can be real or virtual avatar. The process
They are recorded for each according to 1<sup>1</sup> invention allows controlled disclosure. The Internet user chooses to confer a greater or lesser degree of anonymity to a given avatar. With some avatars, he can associate a pseudonym, while he can reveal his identity with others (for example for online purchases). It can also, for example, indicate different centers of interest according to the avatars to obtain personalized and specialized services according to these centers of interest.
The management of information profiles, in relation to the avatars of each Internet user, is carried out at the level of the User Knowledge server 8, thanks to the information stored in the User Information database 10. The User Knowledge server 8 and the User Information database 10 are highly secure.
This management of information profiles is carried out by the Internet user, thanks to one or more Web page (s) edited and managed by the Configuration server 7 in connection with the User Knowledge server 8. Each Web page interfaces communication between the Internet user and this Configuration server 7.
To these information profiles are added one or more preference profile (s). The Internet user's preference profiles are generated from information provided directly by the Internet user or from consulted, analysis of his behavior (Web pages connection time, etc.). A separate preference profile can be associated with each avatar. User preference profiles are stored in a User Preferences 13 database directly accessible by the Configuration server 7.
The navigation report includes:
- the user's browsing history,
- the list of cookies received during these navigations,
- the status of the current connection session, which in particular informs the Internet user of the profiles attached to the avatar he is using and the site (s) 2 he (s) he is on connected,
- recent actions (for example: Inactivation of a cookie issued by 'The banner advertising server X' when consulting the 'Les assurances Y' site), and
- explanations on these (for example: "The host site wanted to access the history 'of your browser to use this data for the definition of a profile and to personalize or adapt its services to this profile").
The state of the current connection session changes over time and is recorded as it changes.
The navigation report is managed by the User Knowledge server 8 via an interface generated by the Configuration server 7. Access to this interface is via the Internet user's browser, thanks to the "access token. ". This access is launched from a specific application such as an icon or a command line (Systray® for a computer running Windows®, Menu Bar Icon® on a Mac ° ', an icon on a Linux ° box) .
The Proxy server 6 also provides access to the Services server 9.
This Services 9 server manages, among other things, information on host sites and their policies for protecting the privacy of Internet users. This information is used in the implementation of the protection functions of the protection server set 4. The set of protection functions is illustrated in FIG. 3.
The protection functions of the protection server set 4 are linked to the policies for the use of personal data by sites 2 of the Internet network, to knowledge of the threats, with regard to the privacy of Internet users, which are represented by some of the 2 sites (third-party cookies, advertising, etc.) and e-mail.
More specifically, the policies for the use of personal data by the sites 2 are listed and stored at the level of a Protection Policies 14 database. These policies correspond for example to the P3P policies of the host sites 2, advantageously supplemented by various information. This various information on the host sites 2 is for example collected by the protection server assembly 4 and stored in a Company Knowledge database 15. They concern, for example, the use of e-mail addresses made by sites 2, the reputation of these sites 2 and the relationships of these sites 2 with third-party sites. The sustainability of these policies and the information to which they correspond are regularly checked (for example with a checksum type check).
From the Business Knowledge database 15, the Services server:
- provides indications to the Proxy servers 6 which, supplemented by the information and preference profiles, define the automatic processing to be carried out on the data flows exchanged between the Internet user and the network,
- establishes lists of domains, IP addresses and other sources of information which may be used by advertising servers and other well-known servers to send to individual computers, tracking cookies, and
- controls the evolution of these lists.
The information thus listed, in the Protection 14 and Knowledge Policies databases
Companies 15 are compared with the preference profile selected in the User Preferences database 13 by the Internet user to automatically infer a status of trust on each site visited by the Internet user (see FIG. 3).
The Services server 9 also manages electronic messaging. The Services 9 server:
- provides e-mail addresses on request to the Internet user of the protection server set 4,
- substitutes single-use addresses for real addresses, for example after validation of a form offered to the Internet user,
- tracks the use of single-use addresses by the 2 sites for which they are intended, analyzes this tracking and records it in a log,
- filters incoming e-mails according to their origin and user preferences,
- optionally performs an anti-virus check of incoming e-mails and
- dispatches accepted e-mails after any previous filtering and checking.
All the servers in the protection server set are under the control of the Supervisor 10 server.
This Supervisor 10 server:
- manages the DNS table and directs the Internet user, via a central server (not shown), to the Proxy server 6 which is closest to him,
- provides an interface for auditors and traceability functions at the request of these auditors, and
- monitors, in near real time, the activity of each server in the protection server set 4, with recording of events in a log and monitoring the performance of the protection server set 4.
In addition to the use of the Internet network by controlling the protection of personal data and the configuration of management tools for this control, the protection server set 4 allows an authorized Internet user to access other Services such as than :
- programming of event alerts in discussion forums,
- secure interaction with banks, etc.
The environment relating to the communication functions with the protection server 4 and the network © ©
Internet is a program in Java or PHP (Hypertext Processor).
according to accounts of
3 sheets
Sheet 1 Sheet 2 Sheet 3
10 members in 7 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0110413 | France | A | |
| 0110413 | France | A | |
| FR20010010413 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| FR2828362A1 | France | A1 | |
| WO03013042A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2002334008A1 | Australia | A1 | |
| WO03013042A3 | World Intellectual Property Organization (WIPO) | A3 | |
| FR2828362B1This record | France | B1 | |
| EP1413120A2 | European Patent Office (EPO) | A2 | |
| US2004199767A1 | United States of America | A1 | |
| JP2004537819A | Japan | A | |
| EP1413120B1 | European Patent Office (EPO) | B1 | |
| DE60219477D1 | Germany | D1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Notification of lapseLapsedST | ST | |
| Decision of inpi director general to approve request for restorationFC | FC | |
| Application for restorationRN | RN | |
| Notification of lapseLapsedST | ST | |
| Transmission of propertyTP | TP |
Numbers
- Publication
- 2828362
- Publication, DOCDB
- 2828362
- Publication, EPODOC
- FR2828362
- Application
- 110413
- Application, DOCDB
- 0110413
- Application, EPODOC
- FR20010010413
Titles2
- French
- PROCEDE DE COMMUNICATION POUR ECHANGER DE MANIERE CONTROLEE DES DONNEES ENTRE UN TERMINAL CLIENT ET UN RESEAU DE SITES HOTES ET ENSEMBLE SERVEUR DE PROTECTION POUR LA MISE EN OEUVRE DE CE PROCEDE
- English
- COMMUNICATION METHOD FOR CONTROLLED EXCHANGE OF DATA BETWEEN A CLIENT TERMINAL AND A NETWORK OF HOST SITES AND PROTECTION SERVER ASSEMBLY FOR THE IMPLEMENTATION OF THIS METHOD
Classification
- CPC, 1
- H04L63/102
- IPC, 2
- H04L29 06
- G06F21 20
