Patent · US Active

Enforcing data privacy policies for federated applications

US11727133B2 · kind B2 · utility

0Cited by
0References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 30, 2021
Grant dateAug 15, 2023
Priority date
Expiry dateAug 6, 2041

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/31
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Embodiments herein describe a pattern or syntax that can be used to convey or express the reason or purpose for a service provider to request user data in an identity federation. A service provider can request user data from the identity provider using an authentication process. If the authentication process is successful, the identity provider provides an authorization token to the service provider which it can use to retrieve the user data. The embodiments herein obtain user consent in the same authentication process used to provide the authorization token. In order to do so, the embodiments herein introduce a pattern or syntax that the service provider uses to convey the purpose for which it wants to use the user data to the identity provider.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.