{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T13:33:10Z","timestamp":1780493590153,"version":"3.54.1"},"reference-count":39,"publisher":"Wiley","license":[{"start":{"date-parts":[[2021,6,22]],"date-time":"2021-06-22T00:00:00Z","timestamp":1624320000000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2021,6,22]]},"abstract":"<jats:p>This paper presents an efficient user-centric consent management system to access online services of the Territorial Collectivities and Public Administration (TCPA) as well as user-authorized third parties. It defines a novel PII manager that supports a set of sources obeying to different authorization and PII retrieval protocols. This contribution is motivated by the necessity to interface TCPA services with remote sources that provide Personally Identifiable Information (PII). Hence, the originality of our solution is multifold. First, the burden for enforcing the interoperability between the sources and the TCPA services collecting the PII is reduced from the point of view of the user, the administrator of the User-Relationship Management (URM) platform, and the territorial agent responsible for processing the user\u2019s queries. Second, it defines a unified consent model supporting four types of sources. Third, it goes into details of practical implementations. Fourth, the relevance of the proposed PII manager for a relevant TCPA use case is demonstrated through a functional analysis.<\/jats:p>","DOI":"10.1155\/2021\/5512075","type":"journal-article","created":{"date-parts":[[2021,6,22]],"date-time":"2021-06-22T19:50:10Z","timestamp":1624391410000},"page":"1-19","source":"Crossref","is-referenced-by-count":5,"title":["An Efficient User-Centric Consent Management Design for Multiservices Platforms"],"prefix":"10.1155","volume":"2021","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2834-9004","authenticated-orcid":true,"given":"Paul","family":"Marillonnet","sequence":"first","affiliation":[{"name":"Entr\u2019ouvert, Paris 75014, France"},{"name":"SAMOVAR, T\u00e9l\u00e9com SudParis, Institut Polytechnique de Paris, \u00c9vry 91000, Paris, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5545-1245","authenticated-orcid":true,"given":"Mika\u00ebl","family":"Ates","sequence":"additional","affiliation":[{"name":"Entr\u2019ouvert, Paris 75014, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7256-3721","authenticated-orcid":true,"given":"Maryline","family":"Laurent","sequence":"additional","affiliation":[{"name":"SAMOVAR, T\u00e9l\u00e9com SudParis, Institut Polytechnique de Paris, \u00c9vry 91000, Paris, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1045-6445","authenticated-orcid":true,"given":"Nesrine","family":"Kaaniche","sequence":"additional","affiliation":[{"name":"SAMOVAR, T\u00e9l\u00e9com SudParis, Institut Polytechnique de Paris, \u00c9vry 91000, Paris, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","reference":[{"key":"1","unstructured":"SakimuraN.BradleyJ.JonesM.De MedeirosB.MortimoreC.Openid connect core 1.0 incorporating errata set 12014San Ramon, CA, USAOpenIDhttps:\/\/openid.net\/specs\/openid-connect-core-1_0.html Technical Report"},{"key":"2","unstructured":"HardtD.The OAuth 2.0 authorization framework2012Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc6749.txt Technical Report 6749"},{"key":"3","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2020.102807"},{"key":"4","doi-asserted-by":"crossref","unstructured":"AtesM.RavetS.Mohamat AhmatA.FayolleJ.An identity-centric Internet: Identity in the cloud, identity as a service and other delights2011Vienna, AustriaIEEEhttps:\/\/ieeexplore.ieee.org\/document\/6045976 Technical Report","DOI":"10.1109\/ARES.2011.85"},{"key":"5","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0098790"},{"key":"6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-19728-9_20"},{"key":"7","article-title":"Personal data: thinking inside the box","author":"H. Haddadi","year":"2015"},{"key":"8","article-title":"Fargo document manager presentation page","author":"Entr\u2019ouvert","year":"2021"},{"key":"9","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-014-0230-4"},{"key":"10","article-title":"The authentic 2 identity manager presentation page","author":"Entr\u2019ouvert","year":"2021"},{"key":"11","unstructured":"ForgeRockOpenidm (documentation)2021San Francisco, CA, USAForgeRockhttps:\/\/backstage.forgerock.com\/docs\/openidm Technical Report"},{"key":"12","unstructured":"The OpenStack FoundationKeystone, the openstack identity service (documentation)2021Austin, TX, USAOpenStackhttps:\/\/docs.openstack.org\/keystone\/pike\/ Technical Report"},{"key":"13","unstructured":"KeycloakR.H..Iam Documentation2021Raleigh, NC, USARedHatTechnical Report"},{"key":"14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-69861-6_15"},{"key":"15","article-title":"U-prove technology overview v1.1 (revision 2)","author":"C. Paquin","year":"2013"},{"key":"16","unstructured":"MalerE.MachulakM.RicherJ.HardjonoT.User-Managed Access (UMA) 2.0 Grant for OAuth 2.0 Authorization2019Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/datatracker.ietf.org\/doc\/html\/draft-maler-oauth-umagrant-00 Internet-Draft draft-maler-oauth-umagrant-00"},{"key":"17","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/898\/10\/102016"},{"key":"18","article-title":"Regulation (eu) 2016\/679 of the european parliament and of the council of 27 4 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing directive 95\/46\/ec (general data protection regulation)","author":"European Parliament","year":"2016"},{"key":"19","doi-asserted-by":"publisher","DOI":"10.5220\/0009828401420154"},{"key":"20","unstructured":"Organization for the Advancement of Structured Information StandardsSecurity assertion markup language (Saml) v2.02005Burlington, MA, USAOASIShttp:\/\/docs.oasis-open.org\/security\/saml\/Post2.0\/sstc-saml-tech-overview-2.0.html Technical Report"},{"key":"21","unstructured":"Roy Thomas FieldingREST: architectural styles and the design of network-based software architectures2000Berkeley, CA, USAUniversity of Californiahttp:\/\/www.ics.uci.edu\/\u223cfielding\/pubs\/dissertation\/top.htm Doctoral dissertation"},{"key":"22","unstructured":"ReschkeJ.The \u201cbasic\u201d HTTP authentication scheme2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7617.txt Technical Report 7617"},{"key":"23","unstructured":"NeumanC.HartmanS.RaeburnK.TaylorYThe kerberos network authentication service (V5)2005Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc4120.txt Technical Report 4120"},{"key":"24","unstructured":"WolfM.WicksteedC.Date and time formats1997Cambridge, MA, USAW3Chttps:\/\/www.w3.org\/TR\/NOTE-datetime Technical Report"},{"key":"25","unstructured":"NewmanC.GrahamK.Date and time on the internet: timestamps2002Fremont, CA, USAInternet Engineering Task ForceTechnical Report 3339 URL https:\/\/rfc-editor.org\/rfc\/rfc3339.txt"},{"key":"26","unstructured":"SchulzrinneH.The tel URI for telephone numbers2004Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc3966.txt Technical Report 3966"},{"key":"27","unstructured":"Kantara Consent & Information Sharing Work GroupConsent receipt specification2018Lonavla, IndiaKantara Initiativehttps:\/\/kantarainitiative.org\/file-downloads\/consent-receipt-specification-v1-1-0\/ Technical Report"},{"key":"28","unstructured":"HodderM.LizarM.SabadelloM.WunderlichJ.Minimum viable consent receipt (Mvcr) specification v.052014Lonavla, IndiaKantara Initiativehttps:\/\/kantarainitiative.org\/confluence\/display\/archive\/Minimum+Viable+Consent+Receipt+%28MVCR%29+Specification+v.05 Technical Report"},{"key":"29","doi-asserted-by":"crossref","unstructured":"Shekh-YusefR.AhrensD.BremerS.HTTP digest access authentication2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7616.txt Technical Report 7616","DOI":"10.17487\/RFC7616"},{"key":"30","doi-asserted-by":"crossref","unstructured":"RicherJ.JonesM.BradleyJ.MachulakM.HuntP.OAuth 2.0 dynamic client registration protocol2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7591.txt Technical Report 7591","DOI":"10.17487\/RFC7592"},{"key":"31","doi-asserted-by":"crossref","unstructured":"CampbellB.MortimoreC.JonesM.YaronY.Goland. assertion framework for OAuth 2.0 client authentication and authorization grants2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7521.txt Technical Report 7521","DOI":"10.17487\/RFC7521"},{"key":"32","doi-asserted-by":"crossref","unstructured":"CampbellB.MortimoreC.JonesM.Security assertion markup language (SAML) 2.0 profile for OAuth 2.0 client authentication and authorization grants2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7522.txt Technical Report 7522","DOI":"10.17487\/RFC7522"},{"key":"33","article-title":"JSON web token (JWT). RFC 7519","author":"M. Jones","year":"2015"},{"key":"34","unstructured":"ScottC.MorehJ.PhilpottR.MalerE.Metadata for the oasis security assertion markup language (Saml) V2. 02005Burlington, MA, USAOASIShttps:\/\/docs.oasis-open.org\/security\/saml\/v2.0\/saml-metadata-2.0-os.pdf Technical Report"},{"key":"35","unstructured":"JonesM.AnthonyN.CampbellB.BradleyJ.MortimoreC.OAuth 2.0 token exchange2020Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc8693.txt Technical Report 8693"},{"key":"36","doi-asserted-by":"crossref","unstructured":"RicherJ.JonesM.BradleyJ.MachulakM.OAuth 2.0 dynamic client registration management protocol2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7592.txt Technical Report 7592","DOI":"10.17487\/RFC7592"},{"key":"37","unstructured":"RicherJ.OAuth 2.0 token introspection2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7662.txt Technical Report 7662"},{"key":"38","unstructured":"HuntP.KellyG.WahlstroemE.MortimoreC.System for cross-domain identity management: core schema2015Fremont, CA, USAInternet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc7643.txt Technical Report 7643"},{"key":"39","doi-asserted-by":"crossref","unstructured":"JonesM.HardtD.The OAuth 2.0 authorization framework: bearer token usage2012Internet Engineering Task Forcehttps:\/\/rfc-editor.org\/rfc\/rfc6750.txt Technical Report 6750","DOI":"10.17487\/rfc6750"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/5512075.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/5512075.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/5512075.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T06:04:34Z","timestamp":1672553074000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2021\/5512075\/"}},"subtitle":[],"editor":[{"given":"Ahmad Samer","family":"Wazan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2021,6,22]]},"references-count":39,"alternative-id":["5512075","5512075"],"URL":"https:\/\/doi.org\/10.1155\/2021\/5512075","relation":{},"ISSN":["1939-0122","1939-0114"],"issn-type":[{"value":"1939-0122","type":"electronic"},{"value":"1939-0114","type":"print"}],"subject":[],"published":{"date-parts":[[2021,6,22]]}}}