FIELD: data processing.
SUBSTANCE: invention relates to control and monitoring of various personal identification data. Method of controlling and monitoring of certain person various identifying data, wherein said data correspond to multiple identification domains, organized in structured plurality, wherein to form domain identification data of identification derivative, to which required identification data for one or more parent domain, for each of parent domains identification is performed authentication of said person on domain derivative identification control server based on identification data of said person for parent domain, wherein during such operation: - to domain derivative identification control server information is transmitted based on identification data in parent domain, and at least one element of acknowledgement information validity of such data, - identification derivative control server performs authentication of said person for parent domain and controls validity of transmitted information using said acknowledgement information, and by results of authentication and control: - server generates identification derivative control for said person, based on transmitted information, at least some part of identification data, allowing said person to carry out its authentication with domain derivative identification provider, - said identification derivative control server stores derivative information, including all information transmitted in authentication operation, or its part, for possible later establishing communication between data identifying domain derivative identification and identification data of parent domain, based on binding information transmitted by parent domain, wherein forming operation performed by different identification servers, arranged so, that in the absence of such binding information any communication based on authentication in two different domains cannot be established, wherein person identification data for authentication domain contain secret key and marker annulment for said authentication domain; during person authentication on domain derivative identification control server derivative identification information is transmitted on above domain control server
EFFECT: creation of derivative identification on the basis of parent identification, wherein between these two identification is impossible to monitor in practice.
19 cl, 6 dwg
Title | Year | Author | Number |
---|---|---|---|
SERVICE FOR DETERMINING WHETHER DIGITAL CERTIFICATE HAS BEEN ANNULLED | 2006 |
|
RU2430412C2 |
BIOMETRIC DATA SAFE HANDLING SYSTEMS AND METHODS | 2016 |
|
RU2718226C2 |
METHOD OF THE DOCUMENT CERTIFICATION WITH AN IRREVERSIBLE DIGITAL SIGNATURE | 2017 |
|
RU2647642C1 |
METHOD AND SYSTEM FOR SAFE DISTRIBUTION OF DATA TRANSFERRED THROUGH PUBLIC DATA NETWORK | 2003 |
|
RU2300845C2 |
SYSTEM FOR PROTECTING INFORMATION CONTAINING STATE SECRETS FROM UNAUTHORISED ACCESS | 2012 |
|
RU2504834C1 |
SEPARATED RIGHTS IN AUTHORISED DOMAIN | 2003 |
|
RU2385491C2 |
METHOD AND DEVICE FOR AUTHORISATION OF OPERATIONS WITH CONTENT | 2003 |
|
RU2352985C2 |
CONTENT PROCESSING METHOD AND SYSTEM | 2007 |
|
RU2413980C2 |
SYSTEM FOR PROTECTING INFORMATION CONTAINING STATE SECRETS FROM UNAUTHORISED ACCESS | 2012 |
|
RU2504835C1 |
METHODS AND DEVICE FOR LARGE-SCALE PROPAGATION OF ELECTRONIC ACCESS CLIENTS | 2013 |
|
RU2595904C2 |
Authors
Dates
2016-11-20—Published
2012-08-02—Filed