Anonymous Data Exchange via Substructure Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data routing solutions in client-server architectures face challenges in ensuring anonymity while complying with data protection regulations, often requiring additional agents or total encryption, which complicates user interactions and are not transparent, and fail to consider the location of the client and server effectively.

Innovation Solution

The solution involves dividing data structures into substructures and routing them through different network nodes with anonymization and storage modules, using one-way functions and asymmetrical encryption to ensure anonymity, with critical data transformed to prevent inverse transformation by either the client or server, and using regional networks in different jurisdictions to comply with data protection laws.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional agents are installed on user devices to ensure anonymity, then data protection is improved, but user interaction complexity and device complexity increase

Engineering Contradiction:
Improvedata protectionVSAvoiduser device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intermediary network nodes (anonymization nodes and storage nodes) that mediate between clients and servers. These nodes perform anonymization and data storage functions, eliminating the need for complex agents on user devices. The client simply interacts with the network infrastructure, which handles anonymity preservation through its architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If total encryption is applied to all data regardless of content, then data protection is improved, but operational convenience and processing efficiency deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different processing treatments to different parts of the data based on their sensitivity. Critical data (personally identifiable information) is anonymized through one-way functions, while non-critical data is processed normally. This selective approach maintains operational convenience while protecting only the necessary data elements.

Inventive Principle:
Principle #3Local quality

3Productivity

If data is centralized on the server for processing, then processing efficiency is improved, but compliance with data protection regulations deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidregulatory compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the data processing architecture into multiple specialized nodes: clients that generate data, anonymization nodes that transform critical data, storage nodes that hold data subsets, and servers that process data. This segmentation allows efficient distributed processing while ensuring that personally identifiable information is anonymized before centralized processing, achieving both productivity and compliance.

Inventive Principle:
Principle #1Segmentation

4Reliability

If data is anonymized using traditional methods, then anonymity is improved, but information completeness and representativeness are lost

Engineering Contradiction:
ImproveanonymityVSAvoidinformation completeness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent creates multiple copies of data distributed across different storage nodes, where each copy contains different subsets of information. The anonymization nodes transform critical data using one-way functions that preserve statistical properties. This allows the server to receive complete information for processing while individual nodes hold only anonymized subsets, maintaining both anonymity and information completeness.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3547733B1System and method for anonymous data exchange between server and client
Publication Date: 2024.03.27 AO KASPERSKY LAB
  • EP3547733B1 patent drawingFigure 1
  • EP3547733B1 patent drawingFigure 2
  • EP3547733B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods for exchanging data in a client-server architecture. At the client side, a first data structure intended for dispatch to a server is divided into at least two substructures including a first substructure and a second substructure. The substructure is dispatched from the client to the server across a first network node with an anonymization module, wherein data of the first substructure is transformed by the anonymization module. The second substructure from the client is dispatched to a second network node with a storage module. The second substructure is received by the server from the network node with the storage module, and the obtained data substructures are combined into a second data structure by the server.