Anonymity Proxy for IoT Service Node Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for anonymous access to service nodes in IoT networks fail to provide adequate privacy and security for both users and service nodes, particularly in resource-constrained environments, as they require heavy cryptography and cannot effectively hide the service node's location or maintain anonymity when communicating with resource-constrained devices.

Innovation Solution

A method and apparatus that utilize an anonymity proxy to enable anonymous access and control of service nodes by generating and managing privacy-enabled URIs, allowing service nodes to communicate through a privacy network without needing to implement heavy protocols, using protocols like Tor for secure communication between user equipment and the anonymity proxy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If heavy cryptography protocols are implemented to ensure anonymity and security, then privacy protection is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improveprivacy protectionVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an anonymity proxy server as an intermediary between users and service nodes. The proxy server handles the complex cryptographic operations and anonymity routing, while resource-constrained devices only need to communicate with the proxy using simple protocols. This mediator approach resolves the contradiction by centralizing complexity in a powerful server while keeping client devices simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service node location is hidden to protect anonymity, then privacy is improved, but accessibility and connectivity to the service node deteriorate

Engineering Contradiction:
ImproveanonymityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The anonymity proxy server acts as a mediator that receives requests from users and forwards them to the hidden service node using its knowledge of the service node's real location. The service node's actual IP address remains hidden from users, maintaining anonymity, while the proxy enables seamless connectivity by translating between the hidden service address and the real network location.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by having service nodes register with the anonymity proxy server in advance, providing the proxy with the mapping between hidden service addresses and real network locations. This pre-established knowledge base enables the proxy to quickly and efficiently route requests without exposing service node locations, resolving the contradiction between hiding location and maintaining accessibility.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If anonymity proxy is used to protect service node location, then privacy is improved, but network traffic routing complexity increases

Engineering Contradiction:
Improvelocation privacyVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The anonymity proxy server consolidates routing complexity in a single intermediary point. Instead of each user device implementing complex routing logic to reach hidden services, all routing decisions are centralized in the proxy server, which maintains a simplified routing table mapping hidden service addresses to real network locations. This dramatically reduces routing complexity on user devices while maintaining location privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3195639B1Method and apparatus for anonymous access and control of a service node
Publication Date: 2024.08.28 NOKIA TECHNOLOGIES OY
  • EP3195639B1 patent drawingFigure 1
  • EP3195639B1 patent drawingFigure 2
  • EP3195639B1 patent drawingFigure 3

AI summary

A method, apparatus and computer program product are provided for anonymous access and control of a service node. In the context of a method, the method includes causing the transmission of a privacy proxy URI in response to the privacy proxy URI request, and establishing a privacy connection with user equipment in response to receiving a request to connect including the URI. The URI is a portion of the privacy enabled URI based at least in part on the privacy proxy URI. The method further includes causing the transmission of a request message to a service node in response to receiving a request message from the user equipment through the privacy connection.