Identity Resolution via Identifier Segmentation in IP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In traditional IP networks, maintaining connectivity between mobile entities while ensuring optimal routing paths and low latencies is challenging, as existing technologies face difficulties in managing identities and identifiers effectively for anonymity and obfuscation.
Innovation Solution
An apparatus and method in an IP network that obtains and associates unique identifiers with identities, using a combination of publicly known designated identifiers and ephemeral identifiers for anonymity, and stores these associations in a database to facilitate secure data retrieval and transmission, ensuring connectivity and identity resolution across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IP networks use fixed identifiers for entities, then routing paths can be optimized, but maintaining connectivity for mobile entities becomes difficult when they change locations
Solution Approach 1:
The identity system is segmented into multiple identifiers (first identifier, second identifier, third identifier) that can be independently managed and mapped. This allows the system to maintain connectivity by updating individual identifier mappings without affecting the entire identity system, thus supporting mobile entities while managing complexity through modular identifier handling.
Solution Approach 2:
A service node acts as an intermediary between entities and the network, managing the mapping between multiple identifiers and identities. This intermediary handles the complexity of identity management centrally, allowing mobile entities to maintain connectivity through identifier remapping without requiring complex distributed identity management across the network.
2Object-affected harmful factors
If multiple identifiers are associated with a single identity for anonymity and obfuscation, then entity privacy is protected, but data retrieval and authentication become more complex
Solution Approach 1:
The system performs preliminary actions by pre-establishing mappings between multiple identifiers (first, second, third identifiers) and identities before data retrieval operations. The service node maintains these mappings in advance, allowing complex identifier resolution to be handled through pre-computed associations rather than real-time complex queries, thus protecting anonymity while simplifying data retrieval.
Solution Approach 2:
Multiple identifier copies (first identifier, second identifier, third identifier) are created for each identity, allowing the system to protect anonymity by using different identifier copies for different operations. The service node manages these identifier copies and their mappings, enabling simplified resolution through copy-based authentication and data retrieval without exposing the primary identity.
3Object-affected harmful factors
If ephemeral identifiers are used instead of permanent identifiers, then entity anonymity is enhanced, but maintaining consistent routing paths becomes difficult
Solution Approach 1:
The system implements dynamic identifier mapping where ephemeral identifiers (second identifier, third identifier) can be associated with a base identity through a first identifier. This dynamic structure allows entities to change their ephemeral identifiers for enhanced anonymity while the service node maintains the mapping relationships, enabling consistent routing through the first identifier even as other identifiers change over time.
Solution Approach 2:
The system adds an additional dimension to identifier management by introducing hierarchical mapping relationships (first identifier → second identifier → third identifier). This multi-dimensional identifier structure allows routing to operate at the stable first identifier level while ephemeral second and third identifiers provide anonymity, thus maintaining routing efficiency through the stable dimension while enhancing privacy through the ephemeral dimensions.
Data Source
AI summary
An apparatus in an IP network, the apparatus comprises: a receiver configured to: obtain an identity of a first entity, the identity is a unique identification of the first entity at a given time, obtain a first identifier of the identity, and obtain a second identifier of the identity, the first identifier and the second identifier are identifications of the identity; and a processor coupled to the receiver and configured to: create an association of the first identifier and the second identifier with the identity, and instruct storage of the association in a database.


