Anonymization Module for Client-Server Data Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data routing solutions in client-server architectures face challenges in ensuring anonymity while complying with data protection regulations, often requiring additional agents or total encryption, which complicates user interactions and burdens users with inconvenient processes.

Innovation Solution

A method and system that utilize an anonymization module in a network node to transform and route data between a client and a server, separating critical and non-critical data into substructures, using one-way functions and asymmetrical encryption to ensure anonymity without losing information completeness, and allowing inverse transformations only by authorized parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If total encryption of original data is performed regardless of content, then data anonymity is improved, but information completeness and representativeness are lost

Engineering Contradiction:
Improvedata anonymityVSAvoidinformation completeness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The data structure is divided into multiple substructures, where only those containing critical data are encrypted. This selective segmentation approach maintains information completeness by leaving non-critical data unencrypted while still achieving anonymity for sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the data structure receive different treatment based on their content. Critical data substructures are encrypted to provide anonymity, while non-critical substructures remain unencrypted to preserve information completeness. This local differentiation resolves the contradiction between anonymity and information retention.

Inventive Principle:
Principle #3Local quality

2Extent of automation

If an additional agent is installed on user's device, then data routing control is improved, but ease of operation and transparency are worsened

Engineering Contradiction:
Improvedata routing controlVSAvoiduser interaction simplicity
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

Instead of installing an agent on the user's device, the patent introduces an intermediary anonymization module deployed on remote servers. This mediator performs data structure analysis, substructure identification, and encryption operations remotely, maintaining automated data routing control while eliminating the need for user-side software installation and preserving operational transparency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If critical data is encrypted selectively, then data protection compliance is improved, but device complexity increases

Engineering Contradiction:
Improvedata protection complianceVSAvoidanonymization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The anonymization module automatically performs data structure analysis, identifies critical data substructures, and applies encryption without requiring complex manual configuration or user intervention. This self-service approach handles the complexity internally while presenting a simple interface to users, thereby achieving data protection compliance without increasing apparent system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11063913B2System and method for anonymously routing data between a client and a server
Publication Date: 2021.07.13 AO KASPERSKY LAB
  • US11063913B2 patent drawing
  • US11063913B2 patent drawing
  • US11063913B2 patent drawing

AI summary

Disclosed are systems and methods for routing during statistics collection. A method is described of exchanging data in a client/server architecture across a node with an anonymization module situated in a regional network different from the network in which the server is located and not being in the same intranet as the server or the client when making the request.