Friendly Man-in-the-Middle Router for Privacy Data Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for controlling the disclosure of private information in Internet-connected devices lack fine-grain controls and centralized management, making it difficult to protect against unintended disclosure of sensitive data, especially with the increasing number of devices and data logged.

Innovation Solution

Implementing a 'friendly man-in-the-middle' (FMITM) system in network environments, such as routers, to perform contextual analysis on data streams, encrypt or remove privacy-related information before it is transmitted, using a combination of inspection, analysis, and transformation modules to enforce policies and protect sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a 'friendly man-in-the-middle' system is implemented to perform contextual analysis and encrypt privacy-related information in data streams, then data privacy protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata privacy protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a 'friendly man-in-the-middle' system that acts as an intermediary between data sources and destinations. This intermediary performs contextual analysis of data streams, identifies privacy-related information, and applies encryption or removal selectively. The system includes inspection modules to analyze data context, analysis modules to determine privacy sensitivity, and transformation modules to encrypt or remove identified information, thereby protecting privacy without requiring changes to all endpoint devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The privacy protection system is divided into distinct functional modules: inspection modules for data stream analysis, analysis modules for privacy sensitivity determination, and transformation modules for encryption or removal. This segmentation allows each component to perform its specific function efficiently, managing overall system complexity through modular design while achieving comprehensive privacy protection

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If centralized control is implemented for managing Internet access and data transmission policies, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvecentralized controlVSAvoidcontrol system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal control system that can be deployed in various network environments (home networks, enterprises, service providers) and handles multiple functions: policy enforcement, data stream inspection, privacy analysis, and transformation. This multi-functional approach consolidates control capabilities into a single system that can manage diverse data types and privacy requirements across different contexts, improving ease of operation through centralized management

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If contextual analysis is performed on all data streams to identify privacy-related information, then measurement precision is improved, but use of energy increases

Engineering Contradiction:
Improveprivacy information identification accuracyVSAvoidprocessing energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs contextual analysis selectively rather than uniformly on all data. The inspection modules analyze data streams to identify those containing privacy-related information, and the transformation modules apply encryption or removal only to identified privacy-sensitive portions. This partial action approach maintains high identification accuracy for privacy information while reducing overall energy consumption by avoiding unnecessary processing of non-privacy data

Inventive Principle:
Principle #16Partial or excessive action

4Loss of information

If encryption is applied to privacy-related portions of data streams, then loss of information is reduced, but productivity decreases

Engineering Contradiction:
Improveprivacy information protectionVSAvoiddata transmission efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies encryption or removal selectively to specific privacy-related portions of data streams rather than encrypting entire data streams. The transformation modules identify and process only the portions containing privacy-sensitive information, leaving the rest of the data in plaintext. This local quality approach maintains data transmission efficiency by minimizing encryption overhead while providing robust protection for privacy information

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10462105B1Method and apparatus for encryption with viewer identity—and content address-based identity protection
Publication Date: 2019.10.29 EMC IP HLDG CO LLC
  • US10462105B1 patent drawing
  • US10462105B1 patent drawing
  • US10462105B1 patent drawing

AI summary

Private information is frequently made public or semi-public, often without foresight as to the consequences of such a divulgence. Additionally, intentionally divulged information that is intended to be maintained as private is routinely sold to advertisers and information brokers. Example embodiments of the present invention relate to a method, an apparatus and a computer-program product for encrypting privacy-related information in a data stream. The method includes receiving a data stream transmitted from a source. A contextual analysis is then performed on the content of privacy-related portions of the data stream. The privacy-related portions of the data stream are then encrypted according to the contextual analysis before being forwarded to the intended destination.