The present invention relates to the transmission of user profiles in the mobile Internet, and more particularly, to the use of a minimal user profile within mobile Internet transactions.
Recent advances in wireless telecommunications have enabled the mobile Internet to grow by leaps and bounds. The mobile Internet provides users access to Internet services and other service based applications using mobile devices such as mobile telephones, portable computers, pagers, personal digital assistants, etc., and makes new services such as location based and context aware applications available to users of the mobile Internet. Presently, wireless application protocol (WAP), iMode, and standard HTML over modified TCP/IP (used in most Personal Digital Assistants) are the most frequently used protocols on the mobile Internet.
Along with the greater uses provided by mobile web services have also arisen greater privacy risks due to the ability of third parties to track the position, capability, preferences information, and other data pertaining to users of the mobile Internet. This raises the issue of appropriate data protection and privacy safeguards for Mobile Internet users who desire to be protected from being under permanent surveillance due to their use of wireless technology without resorting to protecting their privacy by not using mobile Internet services at all.
Existing recommendations with respect to the Platform for Privacy Preferences Project (P3P) specifies a protocol that provides an automated way for users to gain control over the use of personal data on web sites they visit. The proposal enables web sites to express their privacy practices in a machine readable XML format that can be automatically retrieved and compared with a user's privacy preferences. Using this information, a user can make informed decisions on whether or not to submit a certain piece of personal information to a web site.
In order to protect a user's right for informational self-determination, users should have control over their CPI (Capabilities and Preferences Information), represented by means of a profile, and determine how far and to what extent to communicate profile information to other web sites. The proposed protocol can enhance the user's privacy by transmitting the CPI only if there is an informed consent by the user about the origin server's site data collection and use practices.
However, the existing exchange protocol CC/PP (Composite Capability/Preferences Profile) uses a modified WSP or HTTP GET request already containing the profile information or profile difference. The proposed P3P standard requires a first check as to whether there is sufficient match between the user's privacy preferences and the remote server's privacy policy before any personal data is transmitted. Thus, some manner for overcoming this conflict is necessary.
The present invention overcomes the foregoing and other problems with a system and method for contacting an origin server from a node associated with a user. A minimal user profile containing only user designated CPI is generated by the user and stored within a node associated with the user. The minimal user profile is used to establish a connection with an origin server such that a determination may be made if the privacy policy of the origin server meets the privacy policy of the user. If the privacy policy of the origin server meets the privacy preferences of the user, the origin server may then be provided with a second user profile containing more detailed CPI. In a first embodiment, the node provides the second user profile within each request to the origin server. In an alternative embodiment, a single second user profile is forwarded to a WAP gateway interconnecting the node and the origin server, and this information is cached within the WAP gateway to replace the minimal user profile previously cached in this location.
A more complete understanding of the method and apparatus of the present invention may be obtained by reference to the following Detailed Description when taken in conjunction with the accompanying Drawings wherein:
Referring now to the drawings, and more particularly to
Referring now to
After receipt of the policy reference file at the user agent 30, the user agent 30 requests the privacy policy from the origin server 46 using the minimal CPI stored within the minimal user profile of the WAP gateway 36. The request 60 passes from the user agent 30 to the WAP gateway 36 and on to the origin server 46 at 65. The privacy policy is forwarded back from the origin server 46 to the WAP gateway 36 to the user agent at 70 and 75, respectively. The communications requesting the policy reference file and the privacy policy are referred to as the Safe Zone since only minimal profile information is forwarded by the WAP gateway 36 to the origin server 46. Thus, only minimal privacy information is provided to the origin server about a user.
The user agent 30 compares at 76 the web sites privacy policy with the preferences of the user to determine whether further CPI should be transmitted to the web site. Users have the option to choose the level of protection by defining privacy preferences for the whole CPI or different preferences for various CPI components and/or attributes. If the user or user agent 30 accepts the origin servers privacy policy, the CPI may be transmitted to the origin server 46 by a first embodiment wherein the user agent 30 includes complete client profile information including profile-diff headers within each subsequent WSP request 80 in the WSP session. The WAP gateway 36 overrides the cached minimal profile with the provided complete profile information for each request and forwards this to the origin server 46 within an HTTP request 85. The response from the origin server 46 is forwarded back to the WAP gateway 36 at 90 and from the WAP gateway 36 to the user agent 30 at 95. While the present description has been made with respect to the use of only two profiles, it should be understood that three or more profiles may be similarly implemented.
If a user agrees that certain CPI attributes may be augmented by the WAP gateway 36, the WSP request or resume messages should include a flag/attribute set that authorizes the WAP gateway 36 to add information to the CPI. By sending the complete profile information with each subsequent request, the complete CPI profile of the user will not be cached within the WAP gateway. However, in contrast to the embodiment illustrated in
Referring now to
The previous description is of a preferred embodiment for implementing the invention, and the scope of the invention should not necessarily be limited by this description. The scope of the present invention is instead defined by the following claims.
Number | Name | Date | Kind |
---|---|---|---|
6189101 | Dusenbury, Jr. | Feb 2001 | B1 |
6253203 | O'Flaherty et al. | Jun 2001 | B1 |
6308203 | Itabashi et al. | Oct 2001 | B1 |
6317718 | Fano | Nov 2001 | B1 |
6330610 | Docter et al. | Dec 2001 | B1 |
6480850 | Veldhuisen | Nov 2002 | B1 |
6581059 | Barrett et al. | Jun 2003 | B1 |
6678516 | Nordman et al. | Jan 2004 | B1 |
6711682 | Capps | Mar 2004 | B1 |
6735186 | Leppinen | May 2004 | B1 |
6959420 | Mitchell et al. | Oct 2005 | B1 |
20020147766 | Vanska et al. | Oct 2002 | A1 |
20020174073 | Nordman et al. | Nov 2002 | A1 |
20030233461 | Mariblanca-Nieves et al. | Dec 2003 | A1 |
20050096016 | Tervo et al. | May 2005 | A1 |
Number | Date | Country |
---|---|---|
1 081 916 | Mar 2002 | EP |
107511 | Apr 2002 | EP |
WO 0052900 | Sep 2000 | WO |
WO 0150299 | Jul 2001 | WO |
Number | Date | Country | |
---|---|---|---|
20030041100 A1 | Feb 2003 | US |