Fragmented IP Address Transmission via Distributed Proxy Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication protocols fail to adequately combine anonymization and data security, relying on trust in third-party proxies and suffering from single points of failure, while also being inefficient due to multiple encryption levels that degrade user experience.
Innovation Solution
A method and device that use a distributed server architecture to segment and protect the triplet of user, service, and data, employing shared secret mechanisms to ensure that no third party can access more than one element at a time, thereby isolating each component and reducing reliance on trust in intermediaries, and using fewer encryption levels to improve performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional proxy-based services or Tor network are used for anonymization, then the IP address of the proxy is displayed instead of the user's IP address, but these solutions rely on trust in third-party proxies and have single points of failure that can be compromised
Solution Approach 1:
The user's IP address is segmented into multiple fragments and distributed across different proxy servers. Each proxy receives only a portion of the IP address information, making it impossible for any single proxy to reconstruct the complete IP address or identify the user, thereby eliminating the trust dependency while maintaining anonymization security
Solution Approach 2:
The patent introduces a coordinator server as an intermediary that manages the distribution of IP fragments to proxies without having access to the complete IP address. This intermediary facilitates the anonymization process while ensuring that no single entity (including the coordinator) can compromise the user's identity, resolving the trust dependency issue
2Reliability
If multiple encryption levels are applied in Tor network for security, then data confidentiality is improved, but user experience degrades due to increased latency
Solution Approach 1:
Instead of applying full encryption at each proxy level, the patent applies encryption only to the IP address fragments and uses selective encryption for data packets. This partial encryption approach maintains data security for the critical identifier information while reducing the computational overhead and latency experienced by users
Solution Approach 2:
The patent changes the encryption parameter from encrypting entire data packets at multiple levels to encrypting only essential fragments (IP address portions) and using more efficient encryption algorithms. This parameter optimization maintains security requirements while significantly reducing processing time and latency
3Productivity
If IP addresses are transmitted in clear text for routing purposes, then network routing efficiency is improved, but user anonymity is compromised as IP addresses can be observed and traced
Solution Approach 1:
The IP address is segmented into multiple fragments that are distributed across different proxies. Each proxy receives encrypted fragment information necessary for routing decisions, allowing efficient routing while maintaining anonymity since no single proxy obtains the complete IP address in clear text
Solution Approach 2:
The coordinator server acts as an intermediary that manages the encrypted fragment distribution for routing purposes. It enables efficient routing decisions to be made based on encrypted fragment information without exposing the complete IP address, thus maintaining both routing efficiency and anonymity protection
Data Source
AI summary
An enhanced device and method for anonymization also offering improved security properties of data exchanged bidirectionally between a client and a server in a communication network. A protocol in respect of data exchange between client and server which relies on a two-level third-party servers architecture as well as on a system for bidirectional communication between the client and the server through these two levels of third-party servers.


