Edge-based IP system for metadata collection in edge devices

By allowing edge devices to locally store IP metadata and eliminating server-side data retention, the system addresses inefficiencies and compliance challenges, enhancing user experience and scalability while maintaining privacy.

WO2026115537A1PCT designated stage Publication Date: 2026-06-04ANAGOG

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ANAGOG
Filing Date
2025-10-30
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Edge devices lack direct access to their own public IP addresses and associated metadata, leading to inefficient utilization, excessive network traffic, and privacy and regulatory compliance challenges in centralized infrastructures.

Method used

Edge devices transmit network messages to a server to obtain IP metadata from a metadata server, which is then stored locally and deleted from the server, enabling context-aware functionality without persistent server access.

Benefits of technology

This approach reduces network traffic, enhances user experience, and improves scalability by enabling edge devices to store and reuse IP metadata, minimizing server reliance and maintaining privacy and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IL2025050955_04062026_PF_FP_ABST
    Figure IL2025050955_04062026_PF_FP_ABST
Patent Text Reader

Abstract

A method and system for identifying IP addresses of an edge device, obtaining associated IP metadata, and storing both the IP address and IP metadata locally is disclosed. The method comprises receiving, by a server, a network message from an edge device that includes an Internet Protocol (IP) address of the edge device, wherein the edge device is not privy to its own IP address. The server extracts the IP address from the network message and obtains associated IP metadata from an IP metadata server. The IP metadata is then transmitted from the server to the edge device for local storage, after which the server deletes the IP metadata to ensure it is not persistently accessible to the server while remaining persistently accessible to the edge device. The edge device utilizes the locally stored IP metadata in executing predefined functionality. The invention also encompasses a system comprising a server, metadata server, and edge device configured to perform these operations. Both the method and system aspects enable efficient IP metadata management while addressing privacy concerns and reducing server-side storage requirements through distributed edge-based storage architecture.
Need to check novelty before this filing date? Find Prior Art

Description

EDGE-BASED IP SYSTEM FOR METADATA COLLECTION IN EDGE DEVICESCROSS-REFERENCE TO RELATED APPLICATION

[0001] This application is a non-provisional of and claims the benefit of U.S. Provisional Application No. 63 / 726,351 filed 29 November 2024, entitled “EDGE-BASED IP METADATA COLLECTION” which is hereby incorporated by reference in its entirety without giving rise to disavowment.TECHNICAL FIELD

[0002] The present disclosure relates to data collection of Internet Protocol (IP) metadata, particularly to edge device-based storage and utilization of the same.BACKGROUND

[0003] Enterprises that interact with clients, customers, or users through edge devices typically collect user data to support interaction functions between the enterprise and the edge device. Internet Protocol (IP) addresses serve as fundamental identifiers in network communications, enabling data routing and device identification across interconnected networks.

[0004] Typically, when edge devices such as smartphones, tablets, laptops, and desktop computers connect to networks, they are assigned IP addresses that facilitate communication with servers and other networked resources.BRIEF SUMMARY

[0005] According to an aspect of the present disclosure, there is a method comprising: receiving, by a server, a network message from an edge device, the network message including an Internet Protocol (IP) address of the edge device, wherein the edge device is not privy to the IP address of the edge device; extracting, by the server, the IP address of the edge device from the network message; obtaining, by the server, from an IP metadata server, an IP metadata associated with the IP address of the edge device; transmitting the IP metadata from the server to the edge device for local storage on the edge device; deleting the IP metadata from the server after said transmitting the IP metadata to the edge device; storing, by the edge device, the IP metadata at a local storage, thereby the IP metadata is not persistently accessible to the server and is persistently accessible to the edge device; and utilizing, by the edge device, the locally stored IP metadata in executing a predefined functionality.

[0006] Further, the method may comprise: determining, by the edge device, that the edge device is connected to a local network; in response to a determination, by the edge device, that the local storage of the edge device lacks any IP metadata about the local network, transmitting the network message to the server, whereby the IP address is associated with the local network and the IP metadata is descriptive of properties of the local network. The method wherein the local network is at least one of: a workplace network, a home network, or a cellular network. The method wherein the local network is a workplace network of a user of the edge device, based on monitoring, by the edge device, user locations over time, the edge device identifies that the local network is located at a workplace of the user.

[0007] According to another aspect of the present disclosure, the local network utilized in the method may a home network of a user of the edge device, based on monitoring, by the edge device, user locations over time, the edge device identifies that the local network is located at a home of the user. The method may further comprise: determining, by the edge device, that the edge device is connected to a second local network; in response to a determination, by the edge device, that the local storage of the edge device lacks any IP metadata about the second local network, transmitting a second network message to theserver, receiving, by the server, the second network message from the edge device, the second network message including a second IP address of the edge device, wherein the edge device is not privy to the second IP address of the edge device, wherein the second IP address is associated with the second local network; extracting, by the server, the second IP address of the edge device from the second network message

[0008] The method may continue by obtaining, by the server, from the metadata server, a second IP metadata associated with the second IP address of the edge device, wherein the second IP metadata is descriptive of properties of the second local network; transmitting the second IP metadata from the server to the edge device for local storage on the edge device; deleting the second IP metadata from the server after said transmitting the second IP metadata to the edge device; storing, by the edge device, the second IP metadata at a local storage, thereby the second IP metadata is not persistently accessible to the server and is persistently accessible to the edge device; and wherein said utilizing comprises, utilizing the locally stored IP metadata and locally stored second IP metadata in executing the predefined functionality.

[0009] Further, the IP metadata may comprise at least one of: Internet Service Provider(ISP) information, a range of associated IP address, continent information, country information, city information, time zone, connection type information, Autonomous System (AS) information or organization information. The IP metadata may indicate messages originating from the IP address are transmitted by a bot and not a human user, and may comprise a country where the edge device is located and wherein the predefined functionality is based on the country. The method may include deleting the IP metadata from the server occurs within a predetermined time period after transmitting the IP metadata to the edge device, and wherein the IP metadata comprises a country where the edge device is located and wherein the predefined functionality is implementing one or more cyber-security tasks based on the country.

[0010] According to a further aspect of the present disclosure, there is a method performed in a computerized environment comprising an edge device, a server and a metadata server, the method comprising: determining, by the edge device, that the edge device is connected to a local network; in response to a determination, by the edgedevice, that a local storage of the edge device lacks any IP metadata about the local network, transmitting a network message to the metadata server; receiving, by the metadata server, the network message transmitted from the edge device, the network message comprising an Internet Protocol (IP) address of the edge device, the IP address is associated with the local network, wherein the edge device is not privy to the IP address of the edge device; extracting, by the IP metadata server, the IP address of the edge device from the network message.

[0011] The method may continue by obtaining, by the IP metadata server, an IP metadata associated with the IP address of the edge device, wherein the IP metadata is descriptive of properties of the local network; transmitting the IP metadata from the metadata server directly to the edge device for local storage on the edge device, wherein a delivery path of the IP metadata excludes the server, thereby the IP metadata is not accessible to the server; storing, by the edge device, the IP metadata at a local storage, thereby the IP metadata is persistently accessible to the edge device; and utilizing, by the edge device, the locally stored IP metadata in executing a predefined functionality, wherein the predefined functionality involves the server.

[0012] In yet another aspect of the present disclosure, there is a system comprising: a server; a metadata server; and an edge device. Ther server may be configured to; receive a network message from said edge device, the network message including an Internet Protocol (IP) address of said edge device, wherein said edge device is not privy to the IP address of said edge device; extract the IP address of said edge device from the network message; obtain, from said metadata server, an IP metadata associated with the IP address of said edge device; transmit the IP metadata to said edge device for local storage on said edge device; and delete the IP metadata from said server after transmitting the IP metadata to said edge device, thereby the IP metadata is not persistently accessible to said server. The edge device may be configured to: store the IP metadata at a local storage, thereby the IP metadata is persistently accessible to said edge device; and utilize the locally stored IP metadata in executing a predefined functionality.

[0013] The edge device may be further configured to: determine that the edge device is connected to a local network; and in response to a determination that the local storagelacks any IP metadata about the local network the edge device transmits the network message to the server, whereby the IP address is associated with the local network and the IP metadata is descriptive of properties of the local network.

[0014] Further, the local network may be at least one of: a workplace network, a home network, or a cellular network. The server may be configured to: receive a second network message from the edge device, wherein the edge device determines it is connected to a second local network and lacks any IP metadata about the second local network including a second IP address associated to the second local network; extract, the second IP address of the edge device from the second network message; obtain, from the metadata server, a second IP metadata associated with the second IP address of the edge device, wherein the second IP metadata is descriptive of properties of the second local network; and delete the second IP metadata from the server after said transmitting the second IP metadata to the edge device, wherein the edge device stores the second IP metadata in local storage. In addition, the edge device may be configured to utilize the locally stored IP metadata and locally stored second IP metadata in executing the predefined functionality.

[0015] In a final aspect, the IP metadata may comprise at least one of: Internet Service Provider (ISP) information, a range of associated IP address, continent information, country information, city information, time zone, connection type information, Autonomous System (AS) information or organization information. The IP metadata may indicate messages originating from the IP address are transmitted by a bot and not a human user and may comprise a country where the edge device in located and wherein the predefined functionality is based on the country. The IP metadata may be deleted from the server within a predetermined time period after transmitting the IP metadata to the edge device.THE BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS

[0016] The present disclosed subject matter will be understood and appreciated more fully from the following detailed description taken in conjunction with the drawings in which corresponding or like numerals or characters indicate corresponding or like components. Unless indicated otherwise, the drawings provide embodiments or aspects of the disclosure and do not limit the scope or the disclosure. In the drawings:

[0017] Figs. 1 A- 1 D show schematic illustrations of a system in accordance with some embodiments of the disclosed subject matter;

[0018] Fig. 2 shows a block diagram of another implementation of the system in accordance with some embodiments of the disclosed subject matter;

[0019] Fig. 3 shows a flowchart diagram of a method in accordance with some embodiments of the disclosed subject matter;

[0020] Fig. 4 shows a flowchart diagram of a method in accordance with some embodiments of the disclosed subject matter; and

[0021] Figs. 5 A and 5B show sequence diagrams in accordance with some embodiments of the disclosed subject matter.DETAILED DESCRIPTION

[0022] One technical problem dealt with by the disclosed subject matter is the limited ability of edge devices to access their own public IP addresses and associated metadata for local processing and decision-making. Typically, edge devices cannot directly access the public IP address that the edge devices are using or retrieve related IP metadata to that IP address. This challenge is exacerbated by the fact that edge devices often operate behind Network Address Translation (NAT) systems, corporate firewalls, or residential gateways, which further hinder their access to such information. As a result, edge devices are unable to make context-aware decisions — such as enabling location-based content delivery, optimizing performance based on connection type, or enforcing security policies — without external assistance. Conventional approaches require constant communication with external services to obtain this information, creating a dependency on both network connectivity and the availability of those external services.

[0023] A further technical challenge addressed by the disclosed subject matter is the inefficient utilization of IP metadata in conventional enterprise centralized infrastructures. In such infrastructures, the same metadata may be repeatedly retrieved and processed for each user interaction, which generates unnecessary network traffic and increases processing overhead. This redundancy in accessing identical IP metadata leads to excessive database queries, infrastructure bottlenecks, and heightened latency.

[0024] Another technical problem is the substantial storage and operational resources associated with maintaining large-scale IP metadata databases. Servers may require persistent storage of IP metadata for millions of users and transactions, requiring significant technical infrastructure for database maintenance, backup infrastructures, and data archival. The storage requirements grow continuously as users expand and transaction volumes increase, leading to escalating operational requirements. Additionally, the complexity of managing these large datasets requires specialized database administration, security monitoring, and compliance tracking infrastructures that further increase operational overhead and technical complexity.

[0025] In yet another technical problem, there is the significant privacy and regulatory compliance risks associated with large-scale storage of IP metadata. In conventionalinfrastructures, servers collect and store IP metadata including geolocation information, Internet Service Provider details, organization names, and connection characteristics. Consequently, organizations and enterprises face complex compliance management requirements when maintaining large repositories of IP metadata that may contain personal data. These requirements include fulfilling data subject rights, preparing for audits, and responding to regulatory scrutiny.

[0026] Y et another technical problem is enabling the use of IP metadata for improving user experience while protecting users' privacy. User experience may be improved such as by improving content targeting, UI personalization, tailoring functionality to properties of the users, or the like. It is therefore desired to enable IP metadata-based functionality without the service provider having access to the IP metadata itself.

[0027] An additional technical problem, is typically encountered when a server of a centralized infrastructure is utilized for targeting decisions which may require the servers to make targeting decisions for millions of users simultaneously. This centralized targeting decision creates a scalability problem wherein the server-side targeting decisions must be made for a large number of edge devices simultaneously, creating bottlenecks and latency issues.

[0028] One technical solution provided by the disclosed subject matter is a system in which edge devices transmit network messages to a server, causing the server to obtain IP metadata for the IP of the edge device from a metadata server. The IP metadata is then transmitted to the edge device for local storage on the edge device. The server may delete the IP metadata from the server after the IP metadata is transmitted. The edge device can then utilize the locally stored IP metadata in executing a predefined functionality. In some embodiments, the IP metadata is not persistently accessible to the server but is persistently accessible to the edge device. Additionally or alternatively, the edge device may communicate directly with the metadata server without having the server gaining any access to the IP metadata.

[0029] Another technical solution provided by the disclosed subject matter is using an edge device-based storage architecture for a system. The IP metadata in the system is stored on the edge device which eliminates persistent server-side data retention. An edge device determines it is connecting to new network and checks if it already stores the correspondingIP metadata. If the IP metadata of the network is not locally stored (e.g., a due to the network being a newly encountered network), the edge device sends and a server receives a network message. The server may extract the IP addresses of the edge device from the network message. The server then retrieves the associated metadata from specialized metadata servers and immediately transmits it back to the requesting edge device for local storage. The server deletes all IP metadata from its central storage immediately after successful transmission, ensuring that sensitive location and network association data is never persistently stored by the servers. In some embodiments, metadata requests occur only when necessary — that is, when the IP metadata of a network is not already known to the edge device — thereby avoiding redundant data collection while still ensuring information availability.

[0030] The disclosed subject matter provides an additional technical solution for handling multiple network contexts by enabling edge devices to store and maintain separate IP metadata profiles for different connection types and locations. The system can differentiate between multiple different networks such as home Wi-Fi network, workplace Wi-Fi network, cellular connections, or the like, obtaining and storing distinct IP metadata for each network context. This context-aware approach enables functionality decisions based on the specific characteristics of each network environment.

[0031] The disclosed subject matter provides another technical solution to the inefficient utilization of IP metadata. Enabling edge devices to locally store and reuse IP metadata reduces reliance on centralized infrastructure and servers, decreases network traffic, and improves response times for location-aware operations. Stored IP metadata can be leveraged across multiple applications and sessions without requiring repeated server communications, thereby increasing an enterprise centralized infrastructure throughput and enhancing the overall user experience.

[0032] The disclosed subject matter provides a technical solution to storage and operational resource challenges by shifting metadata storage responsibility from server infrastructure to distributed edge devices. Instead of maintaining large-scale centralized databases, the system leverages the storage capacity of user edge devices to maintain IP metadata locally. This distributed storage model eliminates the need for enterprise-gradedatabase infrastructure, reduces backup and archival requirements, and minimizes ongoing operational overhead associated with large-scale metadata management. The system maintains functionality while significantly reducing infrastructure requirements and operational complexity for service providers.

[0033] Another technical solution provided by the disclosed subject matter is provisioning of IP metadata storage architecture that eliminates persistent server-side data retention. This approach enables full utilization of IP metadata while maintaining minimal data on the server. Further, the edge devices can leverage stored metadata containing comprehensive network context — such as region, country, state, or city — to implement region-specific functionality. Examples include adapting cyber-security policies according to network characteristics, enforcing GDPR compliance for EU users, applying content restrictions based on geographic licensing, customizing user experience based on region, country, state or city, or the like. In some embodiments, these capabilities are achieved without exposing sensitive data to servers.

[0034] One technical effect obtained by the disclosed subject matter is enabling organizations to maintain full IP metadata functionality while reducing data breach exposure. The server avoids maintaining a centralized repository of sensitive user IP metadata without surrendering the ability to utilize the IP metadata information in the system’s functionality.

[0035] Another technical effect obtained by the disclosed subject matter is providing an efficient solution to the inefficient utilization of IP metadata in conventional centralized infrastructures. Enabling edge devices to locally store and reuse IP metadata reduces reliance on centralized servers, decreases network traffic, and improves response times for location-aware operations. Stored IP metadata can be leveraged across multiple applications and sessions without requiring repeated server communications, thereby increasing centralized enterprise infrastructure throughput and enhancing the overall user experience. In some embodiments, the disclosed subject matter enables reduction in server communication and improves scalability. Instead of requiring centralized servers to make functionality decisions for millions of users simultaneously, this distributed processing model reduces server load, enhances responsiveness, and preserves consistent functionalityacross edge devices. Additionally, or alternatively, edge devices receive IP metadata that enables implementation of predefined functionality, targeting decisions, security analysis, and compliance enforcement without requiring ongoing server-side data retention.

[0036] In yet another technical effect obtained by the disclosed subject matter, privacy and regulatory compliance management is addressed. The disclosed subject matter may resolve the conflict between functionality requirements and privacy as well as compliance obligations by enabling full utilization of IP metadata while maintaining minimal data on the server. The edge devices can leverage stored metadata containing comprehensive network context to implement region-specific functionality, enforce GDPR compliance for EU users, apply content restrictions based on geographic licensing, or adapt security policies according to network characteristics without exposing sensitive location data to servers.

[0037] A further technical effect enables coordinated functionality and decisionmaking at the enterprise server level by relying on IP metadata stored on edge devices, thereby eliminating the need for additional server communication and improving scalability. Instead of requiring centralized servers to make decisions required for implementing predetermined functionality for millions of users simultaneously, this distributed processing model reduces server load, enhances responsiveness, and preserves consistent functionality and targeting effectiveness across users.

[0038] The disclosed subject matter may provide for one or more technical improvements over any preexisting technique and any technique that has previously become routine or conventional in the art. Additional technical problem, solution and effects may be apparent to a person of ordinary skill in the art in view of the present disclosure.

[0039] An edge device may refer to any computing device, stationary or mobile, capable of sending and receiving IP packets, that directly interacts with a user. In some non-limiting embodiments, the edge device may be a mobile phone, desktop computer, a laptop computer, a smartwatch, a tablet, or the like.

[0040] The IP metadata may include Personally Identifiable Information (PII). The IP metadata may include, for example, a range of associated IP address (e.g., first IP addressand last IP address that are all associated with the same entity / organization as the IP data that is analyzed), continent information (e.g., continent code, continent name), country information (e.g., name, code, EU membership), state or province information (e.g., state / province code, state / province name), city information (e.g., name, ZIP code), geolocation (e.g., approximated latitude / longitude information), time zone, Internet Service Provider (ISP), nearest international weather station code, connection type (e.g., cable, fiber), usage type (e.g., private, corporate), Autonomous System (AS) information (e.g., AS number, AS organization), organization name, or the like.

[0041] In some embodiments, IP metadata may associate an IP address with a specific business, a type of physical connection, and the like. IP metadata may associate several IP addresses with one or more individuals, and may further associate each IP address with a specific location, a relationship of the individual to the location, or the like. For example, an individual may be associated with a first IP address which is associated with a home residence. A second IP address associated with an individual may be associated with a workplace, for example GOOGLE™, thereby enabling the deduction that the individual is an employee of GOOGLE™. A third IP addresses may be associated with other locations visited by the individual, for example a car, train, or other form of transportation, a place of recreation, for example a health club or a cafe, a place of congregation, for example a house of worship or a social club. The edge device may identify the location without exposing the information to the server as is disclosed in U.S. Patent 11,966,496, entitled "Privacy Preserving Location Tracking", dated April 23, 2024, which is hereby incorporated by reference in its entirety for all purposes without giving rise to disavowment.

[0042] In some embodiments, IP metadata may reveal the employer of an individual, and thereby an indication of the individual’s intent. For example, the employment status of visitors to a web site may reveal the identity of individuals, companies, or the like that are potential customers, competitors fishing for information, regulators investigating the business, and the like.

[0043] Figures 1A-1D show schematic illustrations of a system, in accordance with some embodiments of the disclosed subject matter.

[0044] In some embodiments as shown in Figure 1 A, Edge Device 110 may transmit a network message, hereinafter Device Message 115, to Server 120, e.g., via the Internet. Server 120 may be that of an enterprise or company that interact with clients, customers, or users through edge devices and typically collect user data to support interaction functions. For example, Server 120 may host web pages, and Device Message 115 may be a request to view a web page. As another example, Server 120 may be an enterprise server operating a SaaS offering and Edge Devices 110 may connect therewith to receive the SaaS offering. Device Message 115 may comprise the IP address of Edge Device 110. In some embodiments, Edge Device 110 may first determine that it is connecting to new IP address / network and checks if it already stores the corresponding IP metadata. If the IP address / network is unknown or the corresponding IP metadata is unknown, Edge Device 110 then sends Device Message 115. It is noted that Edge Device 110 may be unaware of its own public IP address as seen by Server 120, such as due to Edge Device 110 having a local IP address within a Local Access Network (LAN). Additionally, or alternatively, if Edge Device 110 is on a private network connected to the Internet by a router, for example a Wi-Fi or wired LAN (not shown), the IP address of Device Message 115 may be the public IP address of the router that connects the private network to the Internet, or otherwise be based thereon.

[0045] In some embodiments, and as illustrated in Figure IB, Server 120 may extract the public IP address of Edge Device 110 from Device Message 115. Server 120 may transmit a Server Message 125 to IP Metadata Server 130. Server Message 125 may include the public IP address of Edge Device 110. Optionally, Server Message 125 may comprise some or all IP message packets of Device Message 115, portions thereof, additional data calculated by Server 120, additional data received by Server 120, or any combination thereof. IP Metadata Server 130 may be for example a web server configured to receive an IP address and reply with relevant IP Metadata. Optionally, IP Metadata Server 130 may be integrated with Server 120. Optionally, Server 120 may send Server Message 125 to a plurality of IP Metadata Servers 130. Optionally, Server 120 may receive Device Message 115, and forward some or all of the received data to additional IP metadata servers in additional network messages.

[0046] In some embodiments, and as Figure 1C shows, IP Metadata Server 130 may assemble a network message of metadata, hereinafter Metadata Message 135 and sending it to Server 120. IP Metadata Message 135 may comprise data associated with the received IP address of Server Message 125, for example the company that uses the IP address, the city, state, and country in which the edge device is located, a link type of the Internet connection, usage type of the connection (e.g., private, government, or corporate usage), and the like. In some cases, the same information may be applicable to a range of IP addresses and the range may be indicated.

[0047] Additionally, or alternatively, Metadata Message 135 may indicate whether the originator of Device Message 115 is not a person, for example a bot. Optionally, Metadata Message 135 may provide information from the HTTP header of Device Message 115, for example the HTTP Agent string, the browser type, hardware platform, “Robot Exclusion Standard”, and the like.

[0048] Additionally, or alternatively, Metadata Message 135 may indicate whether or not Edge Device 110 is located within the EU or any specific region. Optionally, IP Metadata Server 130 may format the IP Metadata of Metadata Message 135 into a data structure, for example a derivative of SQL, with field headers that are consistent with data fields recognized by Edge Device 110.

[0049] In some embodiments, and as Figure ID illustrates, Server 120 may transmit a network message of Device Receive Message 126 to Edge Device 110 and subsequently delete the IP metadata information (e.g., indicated by Metadata Message 135). In some embodiments, Server 120 may compose Device Receive Message 126 so as to comprise some or all of the data from Metadata Message 135. Additionally, or alternatively, Server 120 may edit, add, delete data or any combination thereof from Metadata Message 135. Additionally, or alternatively, Server 120 may reformat the data from Metadata Message 135 before including said data in Device Receive Message 126.

[0050] In some embodiments, Server 120 may delete Metadata Message 135 and all metadata associated with Metadata Message 135 from its own storage, thereby eliminating the need to store, secure, backup or any combination thereof, the IP metadata. In some embodiments, Edge Device 110 may receive Device Receive Message 126 and store theIP metadata locally. Optionally, as a data security measure Edge Device 110 may encode, encrypt, or otherwise secure, obfuscate or any combination thereof, the IP metadata.

[0051] In some embodiments, IP Metadata Server 130 may encrypt Metadata Message 135 to prevent Server 120 from gaining access to the information. For example, using a public key of Edge Device 110, IP Metadata Server 130 may encrypt Metadata Message 135, thereby enabling Edge Device 110 to decrypt Metadata Message 135 using its private key but preventing Server 120 from being able to do so. In some embodiments, Device Receive Message 126 may be a copy of Metadata Message 135.

[0052] In some embodiments, Edge Device 110 may receive IP metadata from several IP addresses associated with the same user, edge device or any combination thereof. For example, multiple IP addresses may be ascribed to the same user, edge device or any combination thereof, and specific IP addresses may be associated with a relationship of the user to a location, for example a workplace or home / residence.

[0053] Referring now to Figure 2, showing a schematic illustration of a system, in accordance with some embodiments of the disclosed subject matter. Edge Device 110 may transmit Device Message 115 directly to IP Metadata Server 130 (e.g., without using Server 120 as an intermediate actor). IP Metadata Server 130 may respond with Metadata Message 135 directly to Edge Device 110. In this embodiment, the functionality of Server 120, as disclosed hereinabove, may be implemented locally on Edge Device 110. In this example, the IP metadata never reaches Server 120 (not shown), and it need not be deleted therefrom.

[0054] It is noted, that in both the embodiments of Figures 1A-1D and of Figure 2, Server 120 may be utilized to provide a predefined functionality, regardless of whether Metadata Message 135 is transmitted to it or not.

[0055] Referring now to Figure 3 which shows a flowchart of Process 300 performed by the system, in accordance with some embodiments described herein.

[0056] At Step 310, an edge device may determine if the edge device is connected to a network. For example, the network may be a Wi-Fi network, a LAN, a cellular connection to a network (e.g., cellular data connection), or the like.

[0057] At Step 320, the edge device may determine if the edge device locally retains IP metadata associated with the network. If the edge device does have IP metadata associated with the network, then edge device need not perform additional steps. Step 310 may be repeated when a connection to a new network is determined. Additionally, or alternatively, in some cases it may be desired to refresh the retained information to ensure it is up-to-date. For example, if the information was obtained over a predetermined time thresholds such as 7 days, 30 days, 60 days, 120 days, or the like, the old data may be dropped and the process may proceed to Step 330.

[0058] If the edge device determined at Step 320 that the edge device does not have the IP metadata associated with the network, then the process moves to Step 330. At Step 330, the edge device may send a network message, similar to the Device Message 115 of Figure 1A, from the edge device to the server, e.g., Server 120 of Figures 1A-1D.

[0059] At Step 340, the server may extract the IP address of the edge device from the received network message.

[0060] At Step 350, the server may obtain IP metadata associated with the IP address of the edge device. The IP metadata may be obtained from an IP metadata server, such as IP Metadata Server 130 of Figures 1A-1D and 2.

[0061] At Step 360, the server may send the IP metadata to the edge device. The edge device may receive the IP metadata and store the IP metadata locally. The IP metadata may be stored in a local persistent storage that is accessible to the edge device but not to the server.

[0062] At Step 370, the sever may delete the IP metadata after transmitting the IP metadata to the edge device. In some embodiments, the IP metadata may be deleted from the server within a predetermined time period after transmitting the IP metadata to the edge device, such as within no more than 1 hour, 10 minutes, 1 minute, 30 seconds, 10 seconds, 5 seconds, 1 second, 500 milliseconds, or the like.

[0063] At Step 380, the edge device may use the locally stored IP metadata to execute a predefined functionality. In some embodiments, the predefined functionality may be processed by an application, referred to herein as the IP Metadata (IPMD) app.Optionally, the IPMD app may be a computer program running on an edge device. The IPMD app may be configured to utilize the IP metadata as an input to an algorithm; accept as an input direction from a server, or any combination thereof. In some embodiments, the IPMD app may involve the server. As one example, the IPMD app may perform the predefined functionality based on inputs provided by the server. As another example, the IPMD app may transmit a request to the server to receive feedback or further instructions therefrom.

[0064] In some embodiments, the IPMD app may implement a predefined functionality of a targeted content algorithm that receives as an input a targeted content or portion thereof that is received by the edge device. The output of a targeted content algorithm may be a decision of whether or not to display the content, and if displayed, under what circumstances. By way of specific example, the circumstances may be the time of day, current activity of the user, and the like. An example of such a system is disclosed in U.S. Patent Application Publication No. 2023 / 0093267, entitled "Distributed content serving", dated March 23, 2023, which is hereby incorporated by reference in its entirety for all purposes without giving rise to disavowment. In some embodiments, the algorithm may calculate, based at least in part on the IP metadata, whether the user of the edge device belongs to the targeted population.

[0065] Additionally or alternatively, the predefined functionality may be that the server configures the edge device to execute location-based service functionalities, where the IPMD app utilizes the stored IP metadata to determine appropriate services or content based on the geographic location indicated by the IP metadata. For example, the edge device may automatically adjust language settings, currency displays, or regional compliance requirements based on the country information contained within the IP metadata.

[0066] In some embodiments, the predefined functionality may be a server deploying security-related predefined functionalities on the edge device. The IPMD app may implement access control mechanisms that utilize the IP metadata to determine whether certain features or data should be accessible based on the connection type, organization information, or geographic location. The edge device may apply differentauthentication requirements or security protocols depending on whether the IP metadata indicates a corporate network, public network, or residential connection. Additionally or alternatively, the predefined functionality is the server enabling performance optimization predefined functionalities on the edge device. The IPMD app may utilize connection type information from the IP metadata to adjust data compression levels, content quality, or synchronization frequencies. For example, when the IP metadata indicates a cellular connection, the edge device may implement data-saving measures, while fiber or cable connections may enable higher quality content delivery.

[0067] Additionally, or alternatively, the server may deploy network-aware predefined functionalities where the IPMD app adjusts communication protocols or connection parameters based on the Internet Service Provider information or connection characteristics contained in the IP metadata. The edge device may optimize network requests, implement different retry mechanisms, or adjust timeout values based on the known performance characteristics of the detected network infrastructure.

[0068] In some embodiments, the predefined functionality is the server configuring fraud detection or anomaly detection predefined functionalities on the edge device. The IPMD app may utilize the IP metadata to identify unusual patterns, such as detecting when bot traffic is indicated in the metadata or when the connection originates from unexpected geographic locations or organization types that may indicate suspicious activity.

[0069] At Step 390, the edge device may monitor locations over time to identify a type of local network associated with the IP address and determine Points of Interest (POI). In some embodiments, the system may track the user location over time to identify the user's home location, work location or the like. The POI determination may be based on the IP metadata. In some embodiments, the POI determination may be based on geolocation or continuous tracking of the edge device. Different IP metadata may be relevant to the user's work location and to the user's home location. As can be appreciated, both information sets may be obtained and retained locally together with the indication of their contextual meaning.

[0070] In some embodiments, the disclosed subject matter may maintain data accuracy on the edge device through a refresh mechanism. The edge device may determinewhen stored IP metadata is outdated and requires a refresh based on network changes, time elapsed, or functionality requirements. In some embodiments, the edge device may request updated IP metadata from the server based on at least one of the refresh mechanism requirements. By way of specific example, the system initiates a refresh of IP metadata in a predetermined time period. In some embodiments, the system may implement differential updates where only changed IP metadata fields are transmitted, reducing network overhead while ensuring data accuracy.

[0071] In some embodiments, the IP metadata may comprise a country where the edge device is located and wherein the predefined functionality is based on the country. In some embodiments, the IP metadata may comprise a country where the edge device is located and wherein the predefined functionality (e.g., implemented by IPMD app) is implementing one or more cyber-security tasks as based on the country. The edge device may apply differentiated security measures based on the identified country's associated threat profile or regulatory requirements. For example, the edge device may implement enhanced authentication procedures, additional encryption protocols, or stricter access controls when the IP metadata indicates the device is located in a country with elevated security risk classifications. Conversely, the edge device may apply standard security protocols for locations identified as lower-risk regions.

[0072] In some aspects, the cyber-security tasks may include blocking or restricting certain network communications based on country-specific sanctions lists or regulatory compliance requirements. The IP metadata may enable the edge device to automatically enforce export control regulations by preventing data transmission to restricted countries or implementing additional verification steps for sensitive information transfers. In some cases, the edge device may use the country information to configure firewall rules, intrusion detection parameters, or malware scanning protocols that are tailored to known threat patterns associated with specific geographical regions. The IP metadata may further enable the edge device to implement country-based content filtering, access restrictions, or compliance monitoring functions that align with local cybersecurity regulations and organizational security policies.

[0073] The edge device may also utilize country information from the IP metadata to apply region-specific data protection measures, such as implementing GDPR-compliant data handling procedures when the IP metadata indicates the device is located within the European Union.

[0074] Figure 4 shows a flowchart of Process 400 illustrating a use of the system, in accordance with some embodiments described herein. In Process 400, and by way of specific example, a targeted content campaign is performed by an enterprise.

[0075] At Step 410, an advertisement server (e.g., Server 120 of Figures 1A-1D), may distribute a targeted campaign. The server may initiate and manage a targeted campaign without having access to previously obtained IP metadata. The campaign may comprise content for presentation, matching logic for determining to which population the content is to be displayed, logic for determining timing of presentation of the content, combination thereof, or the like. The advertisement server may transmit, in push or pull methodology, the targeted campaign to a plurality of edge devices that may potentially participate in the campaign.

[0076] At Step 420, the edge device may receive the targeted campaign. The edge device may be one of many edge devices of the system that receive the targeted campaign from the advertisement server.

[0077] At Step 430, the edge device may implement the campaign in view of stored IP metadata. The campaign may be processed by an IPMD app. Optionally, the IPMD app may be a computer program running on an edge device that is configured to receive and store IP metadata from the messages, similar to Message 126 of Figures 1 A-1D. A deciding algorithm of the IPMD app may accept as an input: the target campaign, other sources of data, or any combination thereof. For example, the IPMD may accept the IP metadata and output a decision to the edge device regarding display of the content.

[0078] At Step 440, the edge device may decide on whether or not to display the content. The display decision may be informed at least in part by whether the IP metadata stored by the edge device meets the criteria for display from the targeted campaign. That is, the targeting decision on the edge device may be performed based on the IP metadata (and potentially based on additional private information locally stored or accessible fromthe edge device). Additionally, or alternatively, the IPMD app may decide on timing of the display (e.g., when the user of the edge device is performing a specific activity, when certain environmental conditions occur, at a specific timing, or the like) based on the IP metadata.

[0079] At Step 450, the edge device may send a report message to the server (e.g., Server 120). For example, the edge device may report on the display of the content, number of views, types of display, user engagement and interaction, or the like. Additionally, or alternatively, the server may collect the display reports from the relevant edge devices to facilitate compute and display statistics and Key Performance Indicatiors (KPIs) of the campaign, to facilitate billing the initiator of the targeted content, for determining whether the campaign should end, or the like.

[0080] In some embodiments, the server may transmit a request to edge devices for anonymous information. Additionally, or alternatively, the server does not have access to the IP metadata stored on the edge devices but may request the edge devices to provide general information that does not identify the user, for example whether the user is an employee of Google, a resident of Florida, and the like. The received information may be aggregated into a statistic, but the PII of the user is never associated with the received information. In another embodiment, the server may request edge devices to measure the amount of time required to complete a download in order to measure the speed of the Internet Service Provider (ISP). The edge devices may respond with the recorded speed, location of the test, and the identity of the ISP. By aggregating the responses from a plurality of edge devices, it may be possible to rate the download speed of various ISPs in various locations.

[0081] Figure 5A shows a sequence diagram 500A in accordance with some embodiments of the disclosed subject matter. Typically, Edge Device 110 may not be aware of its own public IP address. In some embodiments, Edge Device 110, may transmit a device message, Msg 510A, similar to Device Message 115, to Server 120. Server 120 may obtain the IP Address 520A from Msg 510A and obtain IP Metadata 530A thereof from IP Metadata Server 130. In some embodiments, Server 120 may then send IP Metadata 540 A, similar to Received Message 126, to Edge Device 110. The messages sentbetween Edge Device 110 and Server 120 may be a message that has another purpose and the device message, Msg 510A may be accordingly analyzed and handled by Server 120. Additionally or alternatively, Msg 510A may be a dedicated message configured to cause Server 120 to provide Edge Device 110 with IP Metadata 530A. At 550A, the IP metadata is deleted from Server 120, and at 560A the IP metadata is locally stored on Edge Device 110. The locally stored IP metadata may then be used for Predefined Functionality 570A. In some embodiments, Predefined Functionality 570A may involve the Server 120 (e.g., by being based on input therefrom, by providing output thereto, or the like).

[0082] As is shown in Figure 5 A, the IP metadata is persistently stored only on Edge Device 110 and not on Server 120. Server 120 may retain the IP metadata for a relative short period (e.g., less than 10 seconds, less than a minute, less than an hour) before deleting the information.

[0083] Referring now to Figure 5B, a sequence diagram 500B is shown in accordance with some embodiments of the disclosed subject matter. In particularly and in some embodiments, sequence diagram 500B is a similar process of obtaining the IP metadata for Edge Device 110 of 5 A, in this sequence a POI is determined and the process is repeated twice. This may happen when the system determines at least two POIs, e.g., workplace of the user and home of the user. In some embodiments, Edge Device 110 may be aware there is a new IP address as it is connected to a new network, even if Edge Device 115 is not aware of the IP address itself.

[0084] In some embodiments, Edge Device 110 may transmit a first message, Msgl 510B, to Server 120. Msgl 510B, is similar to Msg 510A of Figure 5A and Device Message 115 of Figures 1A-1D and 2. Server 120 may obtain a first IP address, IP Addressl 520B, from Msgl 510B and obtain IP metadata of the first IP address, IP Metadatal 530B, from IP Metadata Server 130. In some embodiments, Server 120 may then send IP Metadatal 540B to Edge Device 110. At 550B, the IP metadatal is deleted from Server 120. At 555B a determination of a first POI for the first IP address, e.g. POI1 for the IP addressl, is made for the IP metadatal. IP metadatal with the corresponding POI1 is stored 560B on Edge Device 110. The IP metadatal and POI1 may be used for predefined functionality.

[0085] In some embodiments, Edge Device 110 may transmit a second message, Msg2610B, to Server 120. Server 120 may obtain a second IP address, IP Address2620B, from the Msg2 610B and obtain second IP metadata, IP Metadata2 630B, thereof from IP Metadata Server 130. In some embodiments, Server 120 may then send 640B, the IP Metadata2 to Edge Device 110. At 650B, IP metadata2 is deleted from Server 120, and at 655B the determination of a POI is made for the IP metadata2. At 660B, the IP metadata2 and the corresponding POI2 are stored on Edge Device 110. The IP metadata2 may be used for predefined functionality. In some embodiments, depending on which network connection is being utilized, the corresponding IP metadata may be retrieved and utilized for the predefined functionality. Additionally, or alternatively, the IP metadatal and the IP metadata2 now stored on Edge Device 110 may both utilized in executing the predefined functionality. For example, workplace IP metadata information may indicate workplace (e.g., a government employee, an employee of GOOLGE™, etc.). Such information may be utilized for the predefined functionality even in cases where the edge device is connected to the user’s home network. The user’s home network may indicate other relevant information in its corresponding IP metadata, such as country / state / city information, connection type, ISP provider, or the like.

[0086] The present invention may be a system, a method, and / or a computer program product. The computer program product may include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present invention.

[0087] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, afloppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.

[0088] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.

[0089] Computer readable program instructions for carrying out operations of the present invention may be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitryincluding, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) may execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present invention.

[0090] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0091] These computer readable program instructions may be provided to a processor of a general-purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions may also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including instructions which implement aspects of the function / act specified in the flowchart and / or block diagram block or blocks.

[0092] The computer readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0093] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Inthis regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the block may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.

[0094] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0095] The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of the present invention has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the invention in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the invention. The embodiment was chosen and described in order to best explain the principles of the invention and the practical application, and to enable others of ordinary skill in the art to understand the invention for various embodiments with various modifications as are suited to the particular use contemplated.

Claims

CLAIMSWhat is claimed is:

1. A method, comprising: receiving, by a server, a network message from an edge device, the network message including an Internet Protocol (IP) address of the edge device, wherein the edge device is not privy to the IP address of the edge device; extracting, by the server, the IP address of the edge device from the network message; obtaining, by the server, from an IP metadata server, an IP metadata associated with the IP address of the edge device; transmitting the IP metadata from the server to the edge device for local storage on the edge device; deleting the IP metadata from the server after said transmitting the IP metadata to the edge device; storing, by the edge device, the IP metadata at a local storage, thereby the IP metadata is not persistently accessible to the server and is persistently accessible to the edge device; and utilizing, by the edge device, the locally stored IP metadata in executing a predefined functionality.

2. The method of Claim 1, further comprises: determining, by the edge device, that the edge device is connected to a local network; in response to a determination, by the edge device, that the local storage of the edge device lacks any IP metadata about the local network, transmitting the network message to the server, whereby the IP address is associated with the local network and the IP metadata is descriptive of properties of the local network3. The method of claim 2, wherein the local network is at least one of: a workplace network, a home network, or a cellular network.

4. The method of claim 2, wherein the local network is a workplace network of a user of the edge device, based on monitoring, by the edge device, user locations over time, the edge device identifies that the local network is located at a workplace of the user.

5. The method of claim 2, wherein the local network is a home network of a user of the edge device, based on monitoring, by the edge device, user locations over time, the edge device identifies that the local network is located at a home of the user.

6. The method of claim 2, further comprises: determining, by the edge device, that the edge device is connected to a second local network; in response to a determination, by the edge device, that the local storage of the edge device lacks any IP metadata about the second local network, transmitting a second network message to the server, receiving, by the server, the second network message from the edge device, the second network message including a second IP address of the edge device, wherein the edge device is not privy to the second IP address of the edge device, wherein the second IP address is associated with the second local network; extracting, by the server, the second IP address of the edge device from the second network message; obtaining, by the server, from the metadata server, a second IP metadata associated with the second IP address of the edge device, wherein the second IP metadata is descriptive of properties of the second local network; transmitting the second IP metadata from the server to the edge device for local storage on the edge device; deleting the second IP metadata from the server after said transmitting the second IP metadata to the edge device; storing, by the edge device, the second IP metadata at a local storage, thereby the second IP metadata is not persistently accessible to the server and is persistently accessibleto the edge device; and wherein said utilizing comprises, utilizing the locally stored IP metadata and locally stored second IP metadata in executing the predefined functionality.

7. The method of Claim 1, wherein the IP metadata comprises at least one of: Internet Service Provider (ISP) information, a range of associated IP address, continent information, country information, city information, time zone, connection type information, Autonomous System (AS) information or organization information.

8. The method of Claim 1, wherein the IP metadata indicates messages originating from the IP address are transmitted by a hot and not a human user.

9. The method of Claim 1, wherein the IP metadata comprises a country where the edge device is located and wherein the predefined functionality is based on the country.

10. The method of Claim 1, wherein deleting the IP metadata from the server occurs within a predetermined time period after transmitting the IP metadata to the edge device.

11. The method of Claim 1, wherein the IP metadata comprises a country where the edge device is located and wherein the predefined functionality is implementing one or more cyber-security tasks based on the country.

12. A method performed in a computerized environment comprising an edge device, a server and a metadata server, the method comprising: determining, by the edge device, that the edge device is connected to a local network; in response to a determination, by the edge device, that a local storage of the edge device lacks any IP metadata about the local network, transmitting a network message to the metadata server; receiving, by the metadata server, the network message transmitted from the edge device, the network message comprising an Internet Protocol (IP) address of the edge device, the IP address is associated with the local network, wherein the edge device is not privy to the IP address of the edge device; extracting, by the IP metadata server, the IP address of the edge device from the network message;obtaining, by the IP metadata server, an IP metadata associated with the IP address of the edge device, wherein the IP metadata is descriptive of properties of the local network; transmitting the IP metadata from the metadata server directly to the edge device for local storage on the edge device, wherein a delivery path of the IP metadata excludes the server, thereby the IP metadata is not accessible to the server; storing, by the edge device, the IP metadata at a local storage, thereby the IP metadata is persistently accessible to the edge device; and utilizing, by the edge device, the locally stored IP metadata in executing a predefined functionality, wherein the predefined functionality involves the server.

13. A system comprising: a server; a metadata server; and an edge device; wherein said server is configured to; receive a network message from said edge device, the network message including an Internet Protocol (IP) address of said edge device, wherein said edge device is not privy to the IP address of said edge device; extract the IP address of said edge device from the network message; obtain, from said metadata server, an IP metadata associated with the IP address of said edge device; transmit the IP metadata to said edge device for local storage on said edge device; and delete the IP metadata from said server after transmitting the IP metadata to said edge device, thereby the IP metadata is not persistently accessible to said server; and wherein said edge device is configured to: store the IP metadata at a local storage, thereby the IP metadata is persistently accessible to said edge device; andutilize the locally stored IP metadata in executing a predefined functionality.

14. The system of Claim 13, wherein the edge device is further configured to: determine that the edge device is connected to a local network; and in response to a determination that the local storage lacks any IP metadata about the local network the edge device transmits the network message to the server, whereby the IP address is associated with the local network and the IP metadata is descriptive of properties of the local network.

15. The system of Claim 14, wherein the local network is at least one of: a workplace network, a home network, or a cellular network.

16. The system of claim 14, wherein said server is configured to: receive a second network message from the edge device, wherein the edge device determines it is connected to a second local network and lacks any IP metadata about the second local network including a second IP address associated to the second local network; extract, the second IP address of the edge device from the second network message; obtain, from the metadata server, a second IP metadata associated with the second IP address of the edge device, wherein the second IP metadata is descriptive of properties of the second local network; and delete the second IP metadata from the server after said transmitting the second IP metadata to the edge device, wherein the edge device stores the second IP metadata in local storage; and wherein said edge device is configured to utilize the locally stored IP metadata and locally stored second IP metadata in executing the predefined functionality.

17. The system of Claim 13, wherein the IP metadata comprises at least one of: Internet Service Provider (ISP) information, a range of associated IP address, continentinformation, country information, city information, time zone, connection type information, Autonomous System (AS) information or organization information.

18. The system of Claim 13, wherein the IP metadata indicates messages originating from the IP address are transmitted by a hot and not a human user.

19. The system of Claim 13, wherein the IP metadata comprises a country where the edge device in located and wherein the predefined functionality is based on the country.

20. The system of Claim 13, wherein deleting the IP metadata from the server occurs within a predetermined time period after transmitting the IP metadata to the edge device.