Anonymization Device Source IP Address Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for anonymizing IP traffic parameters, such as source IP addresses, are either unsatisfactory due to reliance on network termination equipment that reveals geolocation or require complex configurations like proxy servers and VPNs, which are not user-friendly and have limitations in applicability across different protocols and devices.

Innovation Solution

A method and device that detect and optionally anonymize the source IP address of IP packets without requiring configuration on the terminal device, using an anonymization device that can query subscription information and apply anonymization requests dynamically, ensuring that neither the terminal nor network equipment IP addresses are disclosed to the destination device, applicable across various protocols and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NAT or NAPT address translation function is implemented by network termination device, then source IP address can be translated, but the IP address of network termination device is revealed which provides geolocation information

Engineering Contradiction:
ImproveIP address anonymizationVSAvoidgeolocation information leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a proxy server as an intermediary between the terminal and the destination device. The proxy server receives IP packets from the terminal, replaces the source IP address with its own IP address, and forwards the modified packets to the destination device. This intermediary approach prevents the network termination device's IP address from being exposed while still enabling address translation functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent separates the address translation function from the network termination device and relocates it to a dedicated proxy server. This segmentation allows the network termination device to focus on its primary functions while the proxy server handles IP address anonymization, preventing geolocation information leakage through the termination device's IP address.

Inventive Principle:
Principle #1Segmentation

2Reliability

If proxy server is used to anonymize IP address, then source IP address can be hidden, but complex configuration is required at terminal level which is not user-friendly

Engineering Contradiction:
ImproveIP address anonymizationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the terminal to automatically select and use a proxy server for IP address anonymization without requiring manual configuration by the user. The terminal device autonomously determines when and how to route traffic through the proxy server, eliminating the need for users to configure proxy settings in their browsers or applications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures the proxy server with the necessary anonymization functionality and makes it available to terminal devices before any anonymization request occurs. The proxy server is prepared in advance to handle IP packets and perform address translation, so users don't need to perform any setup or configuration actions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If proxy server configuration is done at terminal level for each web browser, then IP address can be anonymized, but this solution only applies to browser applications and not mobile applications in WebView mode

Engineering Contradiction:
ImproveIP address anonymizationVSAvoidprotocol and application compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal anonymization mechanism that works across all application types and protocols, not just web browsers. The proxy server is designed to handle IP packets from any application, including mobile applications operating in WebView mode, by intercepting and modifying packets at the network layer rather than requiring application-specific configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent moves the anonymization function from the application layer (where browser-specific proxy settings reside) to the network layer (where IP packets are routed). This dimensional shift in the OSI model allows the proxy server to anonymize traffic from any application uniformly, regardless of the application type or protocol being used.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If VPN client software is installed to route all IP traffic through VPN server, then IP address can be anonymized, but encryption and decryption require additional memory, CPU capacity and computing time

Engineering Contradiction:
ImproveIP address anonymizationVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the essential anonymization functionality from the complex VPN protocol suite and implements only the necessary IP address replacement function in the proxy server. By removing unnecessary encryption, tunneling, and other VPN features, the solution achieves IP address anonymization with minimal computing resource consumption, avoiding the overhead of full VPN implementation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3970352B1Method and device for processing a request for anonymisation of a source IP address, method and device for requesting anonymisation of a source IP address
Publication Date: 2024.06.26 ORANGE SA
  • EP3970352B1 patent drawingFigure 1~2
  • EP3970352B1 patent drawingFigure 3~4
  • EP3970352B1 patent drawingFigure 5~7B

AI summary

Method for processing a request for anonymisation of a source IP address of an IP packet, the IP packet being transmitted by a transmitting device to a recipient device via a communications network, the transmitting device being connected to the network via a network terminal apparatus, the method being carried out by an anonymisation device which is positioned for cutting the flow between the network terminal apparatus and the recipient device, this method comprising: - a step of receiving the packet; - a verification step for establishing whether the source IP address has to be anonymised or not; - if a result of the verification is negative, a step of routing the packet to the recipient device; - if the result of the verification is positive and if the anonymisation device has an address translation function: - a step of replacing the source IP address with an IP address of the anonymisation device; and - a step of routing the IP packet to the recipient device; - if the result of the verification is positive and if the anonymisation device does not have an address translation function, a step of routing the IP packet to the recipient device via an apparatus of the network which has an address translation function.