System for controlled access to information contained in a terminal un terminal
Abstract
Problem to be solved.To provide a control access system having advantages such as solving various problems existing in a conventional solution and ensuring homogeneity of services.
Solution.In a control access system that performs controlled access to information contained in a terminal (10) of a subscriber of a telecommunications network (R), the information is provided in the terminal (10). One information server (11) suitable for the above, one confidential server (20) in the network (R), and the information defined in the confidential server (20) by the subscriber in the confidential server. A security module (12) that stores access conditions to the system and is suitable for receiving the access conditions from a confidential server (20) on the first request for access to the information in the terminal (10) of the system. To be equipped. [Selection diagram] Fig. 1
Term
Term ended
Projected expiry passed 24 June 2025, 1.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
18 claims: 3 independent, 15 dependent
- 1電気通信ネットワーク(R)の加入者の端末(10)に含まれる情報に対して制御されたアクセスを行う制御アクセスシステムであって、 -端末(10)内に、前記情報を提供するのに適したインフォメーションサーバ(11)を一つ備え、 -ネットワーク(R)内に、機密サーバ(20)を一つ備え、該機密サーバ内には加入者が前記機密サーバ(20)内に定義した、前記情報へのアクセス条件がストアされており、前記システムはさらに、端末(10)内に、前記情報への最初のアクセス要求時に機密サーバ(20)から前記アクセス条件を受信するのに適したセキュリティーモジュール(12)を備えることを特徴とする、制御アクセスシステム。
- 2前記セキュリティーモジュール(12)が、前記アクセス条件が有効である限り、後のアクセス要求の管理を確実にすることを特徴とする、請求項1に記載のシステム。
- 3前記機密サーバ(20)が、前記アクセス条件の変更時、セキュリティーモジュール(12)を自動的にアップデートするのに適していることを特徴とする、請求項1または2に記載のシステム。
- 4前記セキュリティーモジュール(12)が、最初のアクセス要求時または加入者による前記アクセス条件の変更時、排他的にアクセス条件を受信することを特徴とする、請求項1~3のいずれか一つに記載のシステム。
- 5前記アクセス条件には、前記情報の全部または一部へのアクセス許可が含まれることを特徴とする、請求項1~4のいずれか一つに記載のシステム。
- 6前記アクセス条件には、前記情報の全部または一部へのアクセス方式が含まれることを特徴とする、請求項1~5のいずれか一つに記載のシステム。
- 7機密サーバ(20)内のアクセス条件の定義および変更は、ネットワーク(R)上で、機密サーバ(20)との同期を伴って、通信手段を介して端末(10)から実行されることを特徴とする、請求項1~6のいずれか一つに記載のシステム。
- 8端末(10)が、前記情報へのアクセスを直接禁止するインターフェースを備えることを特徴とする、請求項1~7のいずれか一つに記載のシステム。
- 9前記インターフェースが、また、機密サーバ(20)との同期を伴う、アクセス条件の変更インターフェースでもあることを特徴とする、請求項8に記載のシステム。
- 10前記通信手段が、ショートメッセージ、ウェブページ、WAPページ、GPRSタイプのデータ接続の中から選択されることを特徴とする、請求項7~9のいずれか一つに記載のシステム。
- 11前記情報が、端末(10)の地理的位置情報に関することを特徴とする、請求項1~10のいずれか一つに記載のシステム。
- 12前記情報が、加入者のアベイラビリティに関することを特徴とする、請求項1~11のいずれか一つに記載のシステム。
- 13前記情報が、加入者のアドレス帳に関することを特徴とする、請求項1~12のいずれか一つに記載のシステム。
- 14アクセスが制御された情報を含む電気通信ネットワーク(R)の加入者の端末であって、前記端末(10)が、前記情報への最初のアクセス要求時に前記ネットワーク(R)の機密サーバ(20)から前記情報へのアクセス条件を受信するのに適したセキュリティーモジュール(12)を備えることを特徴とする端末。
- 15前記情報へのアクセス禁止インターフェースを備えることを特徴とする、請求項14に記載の端末。
- 16前記インターフェースが、また、機密サーバ(20)との同期を伴う、アクセス条件の変更インターフェースでもあることを特徴とする、請求項15に記載の端末。
- 17アクセスが制御された情報を含む前記ネットワーク(R)の加入者の端末(10)のセキュリティーモジュール(12)に、前記情報への最初のアクセス要求時に前記情報へのアクセス条件を提供するのに適していることを特徴とする、電気通信ネットワーク(R)の機密サーバ。
- 18セキュリティーモジュール(12)へ提供したアクセス条件の通信履歴を含むことを特徴とする、請求項17に記載の機密サーバ。
Independent claims18
37 paragraphs, as filed
The present invention relates to a controlled access system that provides controlled access to information contained in a terminal of a subscriber of a telecommunications network. The present invention also relates to terminals containing information whose access is controlled, and confidential servers of telecommunications networks.
The present invention has advantageous applications, especially in the field of mobile phones.
Currently, portable terminals may contain information for which it is desired that the subscriber can control access to the information in order to limit its spread. Most of the time, this information has a personal character, as it is generally about the subscriber's personal life.
Information that can be placed under controlled access includes the geolocation of the terminal, subscriber availability, or even an address book.
In the continuation of this document, the present invention will be described with reference to controlling access to geolocation information. Of course, this choice is not restrictive and naturally extends to all other types of information contained in the terminal that the subscriber wants to put under its control.
Today, there are multiple ways to locate mobile terminals within a telecommunications network.
The first method consists of locating the terminal by identifying the cell in which the terminal is currently located. This position-fixing is relatively crude, and to refine it, triangulation can be performed using multiple cells in close proximity.
The second method is to equip the terminal with an artificial satellite positioning device, such as a GPS system (Geographical Positioning System). In this case, the position of the terminal is not determined in relation to the telecommunications network itself, but is determined with reference to a plurality of artificial satellites. This positioning system is accurate, but difficult to implement.
The third method is mixing. It is network-assisted GPS position-fixing in the sense that the terminal's GPS system receives approximate location information from the network that allows it to expedite GPS-based position-fixing.
Of course, the present invention is not limited to one of these three methods and extends to all other positioning techniques.
Mobile network subscriber positioning standards recommend that the consent of the located person be confirmed prior to providing this information to any third party requesting the location information. There is. The term "third party" refers to a list of applications, individuals or legal entities that need to know the subscriber's geolocation, such as locations near the subscriber's current location (restaurants, cinemas, etc.). There is something about the services we provide.
Specification 3GPP-TS 23.271 Version 6.7.0 Release 6 provides information about the subscriber's private life and, in particular, the geolocation of the subscriber if established by the telecommunications network itself according to the first positioning method described above. This is an example of a standard that defines an architecture type for managing information.
In fact, the above standard stipulates that a confidential server exists in the network, and the access conditions for the information defined by the subscriber in the confidential server are stored in the server. .. This server is also referred to as PPR, which stands for "Privacy Profile Register".
Further, the "access condition" indicates an access permission to all or a part of the information, and an access method to all or a part of the information in the case of permission.
According to the 3GPP standard above, when an application requests a location server in the network to provide the location of a subscriber, the server asks if this application is allowed to access this information. Confirm. This is based on the access conditions predefined by the subscriber in the confidential server. If the application is actually allowed to know the subscriber's location, then the location server will actually locate the subscriber and communicate the result to the application that requested the subscriber's location. To do.
However, in addition to the above situation that belongs to the 3GPP standard where the information server (here, the location information server) and the confidential server are located in the network, if an equivalent server is installed on the terminal itself at the suggestion of the manufacturer. There is. As described above, this is the case of the location information server relating to the second and third position determination methods, which are present at least partially in the terminal. The same applies to a confidential server that can be expected to be embedded in a terminal from the beginning.
However, this solution, called embedded, presents a risk of incongruity between one terminal and another in that different manufacturers may have different levels of access to information.
In addition, the coexistence of two control access systems for specific information in a network and in a terminal in different and independent states shows many inconveniences.
First of all, the subscriber must manage two independent databases, each corresponding to one of the sensitive servers, which is expected to enter access conditions twice. It should be noted that.
Then, if the subscriber changes the access conditions on his terminal, this is not taken into account on the network side, and vice versa. The result is heterogeneity in service quality. For example, if a subscriber declares to the network that they do not want to receive regional advertising messages and omits declaring it on their device, the subscriber will still send this type of message through the device. It will be received from the side of the application that has access to the information.
Furthermore, from the operator's point of view, there is a problem that the responsibility may be cited even when the operator is not involved in the service chain, that is, even when the access control to information belongs only to the terminal. ..<nplcit num="1"><text>Specification 3GPP-TS 23.271 Version 6.7.0 Release 6</text></nplcit>
<p> A technical problem to be solved by an object of the present invention is to propose a control access system for information contained in a terminal of a subscriber of a telecommunications network, the system-in which the information is contained in the terminal. It has one information server suitable for providing-one confidential server in the network, and the confidential server stores the access conditions for the information defined by the subscriber in the confidential server. This allows access conditions to be centralized in a single database, and as a result, avoids having to enter the conditions twice, ensuring service homogeneity. is there.</p>
<p> A solution to the technical problem raised is, according to the invention, a security suitable for the system to further receive the access conditions from a sensitive server in the terminal on the first request for access to the information. It consists of having a module.</p><p> Therefore, as detailed below, access conditions to information are centralized within a single database, i.e. within the database of sensitive servers in the network. To define these conditions, the subscriber communicates with the network operator by the most suitable means. The means can be, among other things, SMS-type short messages, web or WAP pages, or even GPRS-type data connections, or subscriptions. Therefore, as long as the access control information is provided to the confidential server of the network, there is no need to duplicate the information.</p><p> Moreover, the service is homogeneous as a whole, as the service is independent of manufacturer-to-manufacturer variability in the level of confidentiality incorporated into the terminal.</p><p> Further, in the control access system according to the present invention, following the first access request coming from an application, the access conditions combined with this application are transferred to the security module of the terminal, at which time, according to the present invention, the access. As long as the conditions are valid, the security module is specifically optimized in that it ensures the management of subsequent access requests, thereby inevitably referencing a sensitive server on the network with each access request. And it is recognized that the overload on the network is avoided.</p><p> According to the present invention, the confidential server is suitable for automatically updating the security module when the access conditions are changed. In this way, the terminal security module is fully synchronized with the sensitive servers in the network.</p><p> The present invention also assumes that the security module receives the access conditions exclusively when the first access request is made or when the subscriber changes the access conditions.</p><p> Further, according to the present invention, a terminal of a subscriber of a telecommunications network including information whose access is controlled can access the information from a confidential server of the network when the terminal first requests access to the information. Of particular note is that it has a security module suitable for receiving conditions.</p><p> Similarly, according to the present invention, a telecommunications network sensitive server accesses the information at the first request for access to the security module of the terminal of the subscriber of the network, which contains the information whose access is controlled. Of particular note is that it is suitable for providing conditions.</p>
The following description, provided with reference to the accompanying drawings, will help you understand what the invention is made up of and how it is realized, but the drawings are exemplary and the present invention is described. There is no limitation.
FIG. 1 is a schematic diagram of a control access system according to the present invention that performs controlled access to information.
FIG. 1 shows a control access system to information that can be provided by the information server 11 of the terminal 10 of a subscriber of a telecommunications network R such as a mobile phone network. The information contained in Server 11 is that the geolocation of Terminal 10, the subscriber's address book or its availability, and more generally the subscriber knows all or part of third parties, especially this information. It concerns all the information that you want to be able to control access to your application 30. Also note that the application can be remote or implemented directly within terminal 10.
In the first step, indicated by arrow 1 in Figure 1, the subscriber attempts to impose on a third party the confidential server 20 of Network R when requesting access to specific information contained in server 11. Give information. Accessing Confidential Server 20 from Terminal 10 Ergonomics can be trivial, usually in the form of forms to fill out (web pages, SMS messages, GPRS, etc.).
These access conditions consist of, on the one hand, permission to access all or part of the information, and, on the other hand, the method of access to this information in the case of permission, for each third party or application. .. For example, in the case of position-fixing information, the access method is as follows: -the total number of consecutive position-fixing allowed, -the time during which the position-fixing takes place-for example, the accuracy of position-fixing, such as over 100 m, -permission. 1 unit time of position-fixing to be done, -places of position-fixing allowed, etc., but these are not limited.
Next, upon the first access request to server 11 information coming from a third party or application 30, indicated by arrow 2 in FIG. 1, terminal 10 forwards the request to sensitive server 20. In response, the server 20 informs the terminal 10 of the access conditions for the requesting application 30, as shown by the arrow 3 in FIG. These conditions are stored in the security module 12 of the terminal 10.
Therefore, at the time of the subsequent access request indicated by the arrow 4, the terminal 10 can directly contact the security module 12 locally and know the access condition of this request without referring to the confidential server 20 of the network R again. As a result, the terminal then responds to this access request, at least as long as the access conditions are confirmed (arrow 5).
Of course, the subscriber can change the originally imposed access terms to a third party or an application at any time. To do so, the subscriber queries the sensitive server 20 again using the same ergonomics as described above and communicates the new access conditions to the sensitive server. Security module 12 updates, or synchronizations, are performed automatically and immediately by server 20 to be taken into account when new access requests are made.
If the access request arises from an application for which no access conditions are registered with the sensitive server 20, then the sensitive server asks the subscriber to define the conditions that the subscriber intends to impose on this application. You can return the form.
It is also envisioned that access can be banned directly on the terminal if the subscriber so desires. At that time, the simple interface in the terminal 10 allows the subscriber to stop the application from accessing the information contained in the server 11. Similarly, this simple interface within the terminal allows the user to change access conditions in a limited way. In this case, synchronization with the confidential server 20 is started.
Preferably, the confidential server 20 keeps a history of all communications of the access conditions implemented towards the security module 12.
<figref num="1">It is the schematic of the control access system which performs controlled access to information by this invention.</figref>
Code description
10 Terminal 11 Information Server 12 Security Module 20 Confidential Server 30 Application
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2012113634A | Cited by | Japan | Examiner |
| WO03058994A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2001359148A | Cites | Japan | Examiner |
| US2002174073A1 | Cites | United States of America | Search report |
| WO2004028070A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JP2004151163A | Cites | Japan | Search report |
| JP2004152251A | Cites | Japan | Examiner |
| JP2004507845A | Cites | Japan | Search report |
| US2006040677A1 | Cites | United States of America | Search report |
| JP2006500657A | Cites | Japan | Search report |
| JPH05314032A | Cites | Japan | Examiner |
11 members in 7 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 0451484 | France | A | |
| 0451484 | France | A | |
| 0451484 | France | – | |
| 2005001614 | France | W | |
| 2005001614 | France | W | |
| 2004200451484 | – | – | – |
| 2005001614 | – | – | – |
| FR20040051484 | – | – | – |
| WO2005FR01614 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| FR2872979A1 | France | A1 | |
| WO2006016025A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20070030942A | Republic of Korea | A | |
| EP1769653A1 | European Patent Office (EPO) | A1 | |
| CN1985537A | China | A | |
| US2008046979A1 | United States of America | A1 | |
| JP2008506175AThis record | Japan | A | |
| CN101860851A | China | A | |
| KR101119206B1 | Republic of Korea | B1 | |
| US8316419B2 | United States of America | B2 | |
| EP1769653B1 | European Patent Office (EPO) | B1 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2008506175
- Publication, DOCDB
- 2008506175
- Publication, EPODOC
- JP2008506175
- Application
- 2007519830
- Application, DOCDB
- 2007519830
- Application, EPODOC
- JP20070519830
Titles2
- Japanese
- 端末に含まれる情報に対して制御されたアクセスを行うシステム
- English
- A system that provides controlled access to the information contained in the terminal
Classification
- CPC, 2
- H04W8/20
- H04W12/08
- IPC, 10
- G06F21 24
- H04Q7 38
- H04Q7 34
- H04M11 00
- H04B7 26
- G06F13 00
- G06F21 31
- G06F21 62
- H04W8 20
- H04W12 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo