Enterprise Anonymizer System for IP Address Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication protocols like SSL and TLS do not protect Internet Protocol (IP) addresses and Uniform Resource Locator (URL) links, making it possible for corporate spies to gather competitive intelligence by monitoring online activities, and existing anonymizers are either ineffective for enterprise use or require user configuration, which undermines corporate control and monitoring capabilities.

Innovation Solution

An enterprise anonymizer system that intercepts IP addresses and evaluates policies to select and chain anonymizers, establishing a secure connection to mask IP addresses and control access, ensuring that only the enterprise can manage and monitor Internet usage within its firewall environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL/TLS protocols are used to secure communication, then data content is protected, but IP addresses and URL links remain exposed to monitoring

Engineering Contradiction:
Improvedata content securityVSAvoidIP address exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an enterprise-controlled anonymizer as an intermediary component between the user's browser and the external Internet. This anonymizer intercepts HTTP requests, replaces the user's real IP address with a proxy IP address, and forwards the modified requests externally. The anonymizer acts as a mediator that preserves data security through SSL/TLS while simultaneously protecting IP address confidentiality by substituting the identifying information in the communication stream.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If traditional anonymizers are used to hide IP addresses, then anonymity is improved, but enterprise control and monitoring capabilities are lost

Engineering Contradiction:
ImproveIP address maskingVSAvoidenterprise control
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The enterprise-controlled anonymizer is integrated directly into the enterprise's firewall or gateway infrastructure, allowing it to automatically intercept and modify HTTP requests without requiring user configuration or awareness. The system serves itself by maintaining control over the anonymization process, automatically managing IP address substitution while logging user activities for enterprise monitoring. This self-service approach eliminates the need for users to manually configure anonymizers while preserving enterprise oversight capabilities.

Inventive Principle:
Principle #25Self-service

3Loss of information

If users manually configure anonymizers to achieve anonymity, then IP address protection is improved, but user control over Internet access is reduced

Engineering Contradiction:
ImproveIP address hidingVSAvoiduser autonomy
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The enterprise-controlled anonymizer is pre-configured and automatically deployed within the enterprise network infrastructure before users access the Internet. The system performs preliminary interception of HTTP requests at the gateway level, automatically substituting IP addresses without requiring users to take any action. This preliminary action ensures that anonymity is provided as a default service while users retain full autonomy in their Internet browsing activities without needing to understand or configure anonymization settings.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2093971B1Techniques for anonymous internet access
Publication Date: 2011.10.19 DELL EMC
  • EP2093971B1 patent drawingFigure 1
  • EP2093971B1 patent drawingFigure 2
  • EP2093971B1 patent drawingFigure 3~4

AI summary

Techniques are presented for anonymous Internet access. Internet requests are intercepted (111) within a firewalled environment before being routed (141) over the Internet to destination sites. Each Internet request is evaluated (120) in view of policy and one or more anonymizers are selected (130) in response to that evaluation. The Internet requests are then routed through the appropriate anonymizers for processing to the destination sites. A relationship between an Internet Protocol (IP) address associated with the firewalled environment and IP addresses of the destination sites is masked and hidden via the anonymizers from Internet observers. Moreover, a secure communication between the firewalled environment and the anonymizers is maintained.