System and method for joint privacy management
Through multi-layer joint privacy management networks and data processing technologies, the problem of difficulty in protecting user privacy in online activities has been solved, data security transmission and transparency of privacy management have been achieved, and the protection effect of user privacy has been improved.
Patent Information
- Application Number
- CN202510822864.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-30
- Filing Date
- 2020-12-09
- Publication Date
- 2025-09-19
AI Technical Summary
In existing technologies, user privacy is difficult to effectively protect during online activities, and trust is transferred from one entity to another, resulting in uncertainty in the security of private data and privacy management.
It adopts a multi-layer joint privacy management network, through the collaborative work of user management nodes, first-layer nodes and second-layer nodes, uses device identifiers and session identifiers for data processing and encryption, provides privacy services such as data packet inspection, device fingerprint obfuscation, web security, etc., to ensure the secure transmission and management of data.
It achieves effective protection of user privacy, ensures that data is not fully controlled by any node in the multi-layer network, improves the security of data transmission and the transparency of privacy management, and reduces the risk of data abuse.
Smart Images

Figure CN120675765A_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese patent application 202080093421.7, entitled “System and Method for Joint Privacy Management”, with a filing date of December 9, 2020. Technical Field
[0002] Embodiments generally relate to systems and methods for federated privacy management. Background Art
[0003] In order to protect the privacy of users' online activities (such as browsing and application usage), the entities providing such services must have access to the data traffic itself. Therefore, users must trust the entity not to misuse their personal data, rather than trusting the web host or application server to do so. This actually just transfers the user's trust from one place to another. Summary of the Invention
[0004] Systems and methods for federated privacy management are disclosed. In one embodiment, a method for federated privacy management may include: (1) receiving, at a user management node, a device identifier from a client application executing on an electronic device; (2) receiving, by the user management node, data comprising at least one of browsing data and application data from a web host or server from a second-tier node in a multi-tier federated privacy management network, wherein the data is responsive to an Internet Protocol request from the client application to the web host or server via the first-tier node and the second-tier node, and the data is associated with the device identifier; (3) receiving, at the user management node, a request for data from the client application using the device identifier; and (4) transmitting the data to the client application.
[0005] In one embodiment, the data from the second-tier nodes may include at least one of browsing data and application data from a web host or server.
[0006] In one embodiment, the first-tier node may receive an Internet Protocol request and a first IP address associated with an electronic device from a client application, may convert the first IP address into a second IP address, and may transmit the Internet Protocol request and the second IP address to a second-tier node.
[0007] In one embodiment, the second layer nodes may perform privacy services on Internet Protocol requests.
[0008] In one embodiment, privacy services may include packet inspection, device fingerprint obfuscation, web security, anti-malware application activity, logging of browsing / application history, etc.
[0009] In one embodiment, the second tier node may translate the second IP address into a third IP address and may transmit the Internet Protocol request and the third IP address to the web host or server.
[0010] In one embodiment, the data may be encrypted using a private key for the client application.
[0011] In one embodiment, the second layer node may include multiple second layer nodes.
[0012] In one embodiment, the method may further include: receiving registration information from a client application at a user management node; requesting an entitlement token from a first-tier node or a second-tier node by the user management node; receiving the entitlement token from the user management node and the first-tier node or the second-tier node; and transmitting the entitlement token to the client application by the user management node, wherein the client application registers with the first-tier node or the second-tier node using the entitlement token.
[0013] According to another embodiment, a method for federated privacy management may include: (1) receiving, by a user management node, data from a second-tier node in a multi-tier federated privacy management network, the data associated with a session identifier, wherein the data may be responsive to an Internet Protocol request from a client application to a web host or server via the first-tier node and the second-tier node; (2) receiving, at the user management node, a request for data from the client application using the session identifier; and (3) transmitting the data to the client application.
[0014] In one embodiment, the data from the second-tier nodes may include at least one of browsing data and application data from a web host or server.
[0015] In one embodiment, the first-tier node may receive an Internet Protocol request and a first IP address associated with an electronic device from a client application, may convert the first IP address into a second IP address, and may transmit the Internet Protocol request and the second IP address to a second-tier node.
[0016] In one embodiment, the second layer nodes may perform privacy services on Internet Protocol requests.
[0017] In one embodiment, privacy services may include packet inspection, device fingerprint obfuscation, web security, anti-malware application activity, logging of browsing / application history, etc.
[0018] In one embodiment, the second tier node may translate the second IP address into a third IP address and may transmit the Internet Protocol request and the third IP address to the web host or server.
[0019] In one embodiment, the data may be encrypted using the client application's private key.
[0020] In one embodiment, the second layer node may include multiple second layer nodes.
[0021] In one embodiment, the method may further include: receiving registration information from a client application at a user management node; requesting an entitlement token from a first-tier node or a second-tier node by the user management node; receiving the entitlement token from the user management node and the first-tier node or the second-tier node; and transmitting the entitlement token to the client application by the user management node, wherein the client application registers with the first-tier node or the second-tier node using the entitlement token.
[0022] According to another embodiment, a system for federated privacy management may include: a multi-tier federated privacy management network comprising first-tier nodes and second-tier nodes; a user management node in communication with at least one of the first-tier nodes and the second-tier nodes; and a client application executed by an electronic device. The user management node may receive a device identifier of the electronic device from the client application. The first-tier node may receive an Internet Protocol request and a first IP address associated with the electronic device from the client application, convert the first IP address into a second IP address, and transmit the Internet Protocol request and the second IP address to the second-tier node. The second-tier node may convert the second IP address into a third IP address and transmit the Internet Protocol request and the third IP address to a web host or server. The second-tier node may receive data including at least one of browsing data and application data from the web host or server, associate the data with a device identifier or a session identifier, and transmit the data and the association with the device identifier or session identifier to the user management node. The user management node may receive and store the data. The user management node may receive a request for data from the client application using the device identifier or the session identifier. The user management node may transmit the data to the client application.
[0023] In one embodiment, the second layer node may further perform privacy services on Internet protocol requests, including at least one of packet inspection, device fingerprint obfuscation, web security, anti-malware application activity, recording of browsing / application history, etc.
[0024] In one embodiment, the system may further include a plurality of second-layer nodes. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to facilitate a more complete understanding of the present invention, reference is now made to the accompanying drawings which are not to be construed as limiting the present invention but are merely intended to illustrate various aspects and embodiments.
[0026] Figure 1A and Figure 1B depicts a system for federated privacy management according to an embodiment;
[0027] Figure 2 A system for federated privacy management according to another embodiment is depicted; and
[0028] Figure 3 A method for federated privacy management according to an embodiment is described. DETAILED DESCRIPTION
[0029] Embodiments relate to systems and methods for federated privacy management.
[0030] In an embodiment, the processing of online browsing or application data may be distributed among multiple independent nodes at multiple levels of the privacy management network. Each node may have different and independent responsibilities, and no node may have access to all of an individual's personal data and / or online browsing or application data. One or more nodes may be controlled by a user-managed node.
[0031] refer to Figure 1A and Figure 1B According to an embodiment, a system for federated privacy management is provided. The system may include a client electronic device 110 executing a client application 115, a plurality of nodes 120, 130, 140 (e.g., a user management node 140, a first-tier node 120, a second-tier node 130), a web host or server 160, and a network connection 150 (e.g., an Internet connection) between one of the nodes (e.g., the second-tier node 130) and the web host or server 160.
[0032] In an embodiment, the client application 115 can communicate with a user management node 140, which can provide user management services. In an embodiment, the user management node 140 can maintain the true user identity and can manage the user interface, experience, and / or billing. The user's browsing or application data may not be visible to the user management node 140.
[0033] In one embodiment, the user management node 140 may receive a device identifier of the electronic device 110 through the client application 115. In one embodiment, the device identifier may be associated with the electronic device 110 (e.g., a serial number, a device fingerprint, etc.), and may be generated by an operating system, the client application 115, etc. Any suitable device identifier may be used as needed and / or desired.
[0034] The user management node 140 can communicate with the second layer node 130 ( Figure 1A ) or first layer node 120 ( Figure 1B ) interaction to obtain a rights token or the like. For example, after the client application 115 contacts the user management node 140, the user management node 140 may obtain the rights token or the like from the first layer node 120 ( Figure 1B ) or second layer node 130 ( Figure 1A ) requests an entitlement token or the like, and the user management node 140 may return an entitlement token or the like to the client application 115. The entitlement token may allow the client application 115 to access the first layer node 120 ( Figure 1B ) or second layer node 130 ( Figure 1A ) for initial registration purposes.
[0035] In one embodiment, the entitlement token may expire after a certain amount of time, or may expire after it is used. For example, the entitlement token may be valid for a long enough time for the user to register with the first node layer 120 or the second node layer 130.
[0036] The client application 115 may register with the first tier node 120 or the second tier node 130 using an entitlement token or the like, and the first tier node 120 or the second tier node 130 may collect and maintain the device identifier of the client application 115 and use it as authorization for future data traffic through browsing or using the application.
[0037] The client application 115 may maintain a secret key, such as a private key.
[0038] Client applications 115 may route data traffic (e.g., browsing data, application data, etc.) to first tier nodes 120. First tier nodes 120 may receive data traffic from client applications 115 having a first IP address (i.e., IP1) and may provide pass-through, where data traffic leaving first tier nodes 120 is associated with a second IP address (i.e., IP2).
[0039] First-tier nodes 120 may route data traffic to second-tier nodes 130, which may provide data privacy services (e.g., packet inspection, device fingerprint obfuscation, web security, anti-malware application activity, logging of browsing / application history, etc.). In one embodiment, the privacy services may be associated with a user reference, such as a reference to a user, a device (e.g., a device identifier), etc. The data traffic may leave the second-tier node 130 associated with a third IP address (IP3).
[0040] like Figure 2As shown, multiple second-layer nodes 1301, 1302, ... 130 may be provided. n For example, in response to an Internet protocol request from a client application, a first-tier node may call multiple second-tier nodes (e.g., second-tier node 1 1301, second-tier node 2 1302, ..., second-tier node n 1303). n ) to perform data privacy services. Therefore, each second-layer node 1301, 1302, ... 130 n Only a portion of the browsing / application history of the client application 115 may be exposed to or contained.
[0041] The first layer node 120 may select multiple second layer nodes 1301, 1302, ... 130 in any suitable manner. n For example, it can randomly select the second layer nodes 1301, 1302, ... 130 n , it may rotate the selection (e.g., the first request goes to second-tier node 1 1301, the second request goes to second-tier node 2 1302, etc.), it may switch periodically (e.g., it uses second-tier node 1 1301 for a certain number of interactions or a period of time, then switches to second-tier node 2 1302, etc.).
[0042] The second tier node 130 may receive data from the web host or server 160 and may store the data in the database 135. In one embodiment, the second tier node 130 may use the public key of the client application 115 to encrypt the data.
[0043] Second-tier node database 135 may store browsing history, application data (including application data from web host or server 160), etc., and may encrypt the data using the public key of client application 115. Second-tier node 130 may store the encrypted data in database 145. In one embodiment, the data may be associated with a session identifier for a session established by client application 115 and first-tier node 120 or second-tier node 130.
[0044] refer to Figure 3 According to one embodiment, a method for federated privacy management is provided.
[0045] In step 305, the user may register with the user management node through the client application to use the privacy service. The user management node may know the user's real user identity.
[0046] In one embodiment, the user management node can capture the device identifier of the electronic device on which the client application is executed. Any suitable device identifier can be used as needed and / or desired.
[0047] The user management node may authenticate the user in step 310. For example, the user management node may perform know-your-customer authentication and / or any other suitable authentication as needed and / or desired.
[0048] In step 315, the user management node may request an entitlement token or similar identifier from the first-tier node or the second-tier node. In one embodiment, the entitlement token may indicate that the user is authorized to use the routing service of the first-tier node or the privacy management service of the second-tier node.
[0049] In step 320 , the first-tier node or the second-tier node may return the entitlement token to the user management node, and in step 325 , the user management node may transmit the entitlement token to the client application.
[0050] In step 330, the client application may request registration from the first-tier node or the second-tier node using the entitlement token, and in step 335, the first-tier node or the second-tier node may register the client application. In one embodiment, the first-tier node and / or the second-tier node may store a device identifier of the device or user executing the client application.
[0051] In one embodiment, as part of the registration process, the client application can provide its public key to the first-tier node or the second-tier node. The user management node can also provide the client's public key to the first-tier node or the second-tier node during the rights request in step 315.
[0052] In step 340, the client application may establish a session with the second tier node, and the second tier node may return a session identifier to the client application.
[0053] In one embodiment, a session identifier may not be used.
[0054] In one embodiment, if multiple second-tier nodes are available for use, the first-tier node may select one of the second-tier nodes for the session. In one embodiment, the first-tier node may select the second-tier node in any suitable manner, such as randomly, by rotation, by periodic switching, etc. Each second-tier node may relay its respective session identifier back to the client application via the first-tier node.
[0055] In step 345, the client application may submit an Internet protocol (e.g., HTTP, HTTPS, HTTP / 2, QUIC, etc.) request to a first-tier node having a first IP address. In one embodiment, the first IP address may be the IP address of the electronic device hosting the client application.
[0056] In step 350, the first-tier node may convert the first IP address into a second IP address and may route the Internet Protocol request to the selected second-tier node. For example, the first-tier node may replace the first IP address with the second IP address.
[0057] In step 355, the second-tier node may perform one or more privacy services on the Internet Protocol request, such as packet inspection, device fingerprinting, web security, anti-malware application activity, and recording of browsing / application history. The second-tier node may translate the second IP address and use a third IP address for browsing. Any suitable method for translating the second IP address may be used as needed and / or desired.
[0058] In another embodiment, the second-tier node may convert the second IP address into a third IP address instead of creating the second IP address.
[0059] The second-tier node may interact with the web host or server via the Internet using the third IP address in step 360. The second-tier node may receive data from the web host or server.
[0060] In step 365, the second-tier node may encrypt some, all, or none of the user's browsing and / or application data, including data from a web host or server, using the client application's public key, and in step 370, may push the encrypted browsing and / or application data to the user management node using the device identifier and / or session identifier. If the data is pushed using the device identifier, the user management node will know the client application associated with the data. If the data is pushed using the session identifier, the user management node will not know the client application associated with the session identifier until the client application requests the data associated with the session identifier.
[0061] In step 375 , the client application may request the encrypted browsing / application history from the user management node using the session identifier and / or device identifier, and the user management node may provide the encrypted data to the client application.
[0062] In step 380 , the client application may decrypt the encrypted browsing and / or application data using the client application's private key.
[0063] In the following, general aspects of implementation of the systems and methods of the embodiments will be described.
[0064] An embodiment of a system or portion of a system may be in the form of a "processor," such as a general-purpose computer. As used herein, the term "processor" should be understood to include at least one processor utilizing at least one memory. The at least one memory stores an instruction set. The instructions may be permanently or temporarily stored in one or more memories of the processor. The processor executes the instructions stored in the one or more memories to process data. The instruction set may include various instructions for performing one or more specific tasks, such as those described above. Such an instruction set for performing specific tasks may be characterized as a program, a software program, or simply software.
[0065] In one embodiment, the processing machine may be a special purpose processor.
[0066] As described above, the processing machine executes instructions stored in one or more memories to process data. Such processing of data may, for example, be in response to commands of one or more users of the processing machine, in response to previous processing, in response to a request from another processing machine, and / or any other input.
[0067] As described above, the processing machine used to implement the embodiments can be a general-purpose computer. However, the processing machine can also utilize any of a variety of other technologies, including special-purpose computers, computer systems including, for example, microcomputers, minicomputers, or mainframes, programmed microprocessors, microcontrollers, peripheral integrated circuit components, CSICs (customer-specific integrated circuits) or ASICs (application-specific integrated circuits) or other integrated circuits, logic circuits, digital signal processors, programmable logic devices (such as FPGAs, PLDs, PLAs, or PALs), or any other device or arrangement of devices capable of implementing the steps of the processes disclosed herein.
[0068] The processor used to implement the embodiments may utilize a suitable operating system. Thus, embodiments may include operating systems such as iOS, OS X, Android, Microsoft Windows, and the like. TM (Microsoft Windows) operating system, Unix operating system, Linux operating system, Xenix operating system, IBM AIX TM Operating system, Hewlett-Packard UX TM Operating system, Novell Netware TM Operating system, Sun Microsystems Solaris TM Operating system, OS / 2T TM Operating system, BeOS TM Operating system, Macintosh operating system, Apache operating system, OpenStep TMoperating system or another operating system or platform processor.
[0069] It should be understood that in order to practice the methods of the embodiments described above, the processors and / or memory of the processing machine need not be physically located in the same geographic location. That is, each of the processors and memory used by the processing machine can be located in geographically different locations and connected for communication in any suitable manner. Furthermore, it should be understood that each of the processors and / or memory can be comprised of different physical pieces of equipment. Thus, the processor need not be a single piece of equipment in one location, and the memory a separate piece of equipment in another location. That is, it is contemplated that the processors can be two pieces of equipment located in two different physical locations. The two different pieces of equipment can be connected in any suitable manner. Furthermore, the memory can comprise two or more portions of memory located in two or more physical locations.
[0070] For further explanation, as described above, processing is performed by various components and various memories. However, it should be understood that, according to another embodiment, as described above, processing performed by two different components can be performed by a single component. In addition, as described above, processing performed by one different component can be performed by two different components.
[0071] In a similar manner, according to another embodiment, as described above, memory storage performed by two different memory portions can be performed by a single memory portion. In addition, as described above, memory storage performed by one different memory portion can be performed by two memory portions.
[0072] In addition, various technologies may be used to provide communication between the various processors and / or memories, as well as to allow the processors and / or memories to communicate with any other entity; i.e., for example, to obtain further instructions or to access and use remote memory storage. Such technologies for providing such communication may include, for example, a network, the Internet, an intranet, an extranet, a local area network, an Ethernet, wireless communication via a cellular tower or satellite, or any client-server system that provides communication. Such communication technologies may use any suitable protocol, such as TCP / IP, UDP, or OSI.
[0073] As described above, an instruction set may be used in the processing of the embodiments. The instruction set may be in the form of a program or software. The software may be, for example, in the form of system software or application software. The software may also be in the form of, for example, a collection of separate programs, a program module within a larger program, or a portion of a program module. The software used may also include modular programming in the form of object-oriented programming. The software tells the processor how to process the data being processed.
[0074] In addition, it should be understood that the instructions or instruction sets used in the implementation and operation of the embodiments can be in a suitable form so that the processing machine can read the instructions. For example, the instructions forming the program can be in the form of a suitable programming language, which is converted into machine language or object code to allow one or more processors to read the instructions. That is, a compiler, assembler or interpreter is used to convert the programming code or source code written lines in a specific programming language into machine language. Machine language is a binary-coded machine instruction that is specific to a particular type of processing machine (i.e., a particular type of computer). The computer understands machine language.
[0075] According to various embodiments, any suitable programming language may be used. Illustratively, the programming languages used may include, for example, assembly language, Ada, APL, Basic, C, C++, COBOL, dBase, Forth, Fortran, Java, Modula-2, Pascal, Prolog, REXX, Visual Basic, and / or JavaScript. Furthermore, it is not necessary to utilize a single type of instruction or a single programming language in conjunction with the operation of the systems and methods. Rather, any number of different programming languages may be utilized as needed and / or desired.
[0076] Likewise, the instructions and / or data used in the practice of the embodiments can utilize any compression or encryption technology or algorithm as needed. An encryption module can be used to encrypt data. Additionally, for example, a suitable decryption module can be used to decrypt files or other data.
[0077] As described above, the embodiments can be illustratively embodied in the form of a processing machine (including, for example, a computer or computer system) including at least one memory. It should be understood that, as needed, the instruction set (i.e., software) that enables the computer operating system to perform the above-mentioned operations can be included in any of a variety of one or more media. In addition, the data processed by the instruction set can also be included in any of a variety of one or more media. That is, the specific medium (i.e., the memory in the processing machine) for storing the instruction set and / or data used in the embodiment can, for example, take any of a variety of physical forms or transmissions. Illustratively, the medium can be paper, paper transparency, optical disc, DVD, integrated circuit, hard disk, floppy disk, optical disc, magnetic tape, RAM, ROM, PROM, EPROM, wire, cable, optical fiber, communication channel, satellite transmission, memory card, SIM card or other remote transmission and any other medium or data source that may be read by the processor.
[0078] Furthermore, the one or more memories used in a processor implementing an embodiment may be in any of a variety of forms to allow the memory to store instructions, data, or other information as needed. Thus, the memory may take the form of a database to store data. The database may use any desired file arrangement, such as a flat file arrangement or a relational database arrangement.
[0079] In the system and method, various "user interfaces" can be utilized to allow the user to dock with one or more processing machines for realizing the embodiment. As used herein, the user interface includes any hardware, software or combination of hardware and software that the user and the processing machine use that the processing machine uses. The user interface can, for example, be in the form of a dialogue screen. The user interface can also include any one of a mouse, touch screen, keyboard, keypad, voice reader, voice recognizer, dialogue screen, menu box, list, check box, toggle switch, button or any other device that allows the user to receive information about the operation of the processing machine when processing an instruction set and / or provide information to the processing machine. Therefore, the user interface is any device that provides communication between the user and the processing machine. The information that the user provides to the processing machine through the user interface can, for example, be a form of command, data selection or some other input.
[0080] As mentioned above, the processing machine that performs instruction set utilizes user interface so that processing machine processes data for user.User interface is usually used by processing machine to interact with user to transmit information or receive information from user.But should be understood that according to some embodiments of system and method, human user does not actually have to interact with the user interface that processing machine uses.On the contrary, it can also be expected that user interface can interact (that is, transmit and receive information) with another processing machine rather than human user.Therefore, another processing machine can be characterized as user.In addition, it can be expected that the user interface utilized in system and method can partially interact with another or multiple processing machines, and also partially interact with human user.
[0081] Those skilled in the art will readily appreciate that the embodiments are susceptible to widespread use and application. Many embodiments and adaptations of the invention in addition to those described herein, as well as many variations, modifications, and equivalent arrangements, will be apparent from the foregoing description or reasonably suggested by the foregoing description without departing from the spirit or scope.
[0082] Therefore, although exemplary embodiments related to embodiments of the present invention have been described in detail herein, it should be understood that the present disclosure is merely illustrative and exemplary of the present invention and provides an enabling disclosure of the present invention. Therefore, the foregoing disclosure is not intended to interpret or limit the present invention, or otherwise exclude any other such embodiments, adaptations, variations, modifications, or equivalent arrangements.
Claims
1. A method for joint privacy management, comprising: receiving, at a user management node and from a client application executing on an electronic device, a device identifier; receiving, by the user management node, data from a second-tier node in the multi-tier federated privacy management network, the data comprising at least one of browsing data and application data from a web host or server, wherein the data is in response to an Internet Protocol request from the client application to the web host or server via the first-tier node and the second-tier node, and the data is associated with the device identifier; receiving, at the user management node, a request for the data from the client application using the device identifier; as well as The data is transmitted to the client application.
2. The method of claim 1, wherein the data from the second-tier node comprises at least one of browsing data and application data from the web host or the server.
3. A method according to claim 1, wherein the first-layer node receives the Internet Protocol request and a first IP address associated with the electronic device from the client application, converts the first IP address into a second IP address, and transmits the Internet Protocol request and the second IP address to the second-layer node.
4. The method of claim 3, wherein the second layer node performs privacy services on the Internet Protocol request.
5. The method of claim 4, wherein the privacy service comprises at least one of packet inspection, device fingerprint obfuscation, web security, anti-malware application activity, and logging of browsing / application history.
6. The method of claim 3, wherein the second-tier node converts the second IP address into a third IP address and transmits the Internet Protocol request and the third IP address to the web host or the server. The method of claim 1 , wherein the data is encrypted using a private key for the client application.
8. The method of claim 1, wherein the second-layer node comprises a plurality of second-layer nodes.
9. The method according to claim 1, further comprising: receiving, at the user management node, registration information from the client application; The user management node requests a rights token from the first layer node or the second layer node; receiving the entitlement token from the user management node and the first layer node or the second layer node; as well as The entitlement token is transmitted by the user management node to the client application, wherein the client application registers with the first-tier node or the second-tier node using the entitlement token.
10. A method for joint privacy management, comprising: receiving, by the user management node, data from a second tier node in the multi-tier federated privacy management network, the data being associated with a session identifier, wherein the data is in response to an internet protocol request from a client application to a web host or server via the first tier node and the second tier node; receiving, at the user management node, a request for the data from a client application using the session identifier; as well as The data is transmitted to the client application.
Citation Information
Patent Citations
Privacy aware dhcp service
CN105052069A
Method for establishing and / or configuring an Internet Protocol network connection between a Customer Premises Equipment and a telecommunications network
EP2887577A1
Mapping Between User Interface Fields and Protocol Information
US20160034442A1
Dynamic switching between edge nodes in autonomous network system
US20170366426A1
Mobile phone used within a client-server system
WO2007135627A2