The invention is in the field of security and trustworthy computing. The
invention relates to a method for managing identities in a device
comprising a trusted platform module. In the method an identity related
command is used for performing identity related action; a delegation
agent, a storage key for secure storage, and a delegation for the
identity related command are created. Further, said delegation is sealed
using the created storage key to a trustworthy system state; and the
sealed delegation is delivered to the delegation agent.