NAT-Based User Data Matching for Privacy-Safe Targeting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user notification systems face challenges in collecting and matching user data in real-time, especially when users disable data collection methods like cookies or use HTTPS, limiting the ability to target advertisements effectively and identify genuine users, particularly in mobile applications and scenarios where data security is paramount.
Innovation Solution
A system that utilizes Network Address Translation (NAT) to receive and match user data and device data from various sources, including browsers and applications, using a query reception unit, data matching and collection unit, and data direction unit to provide targeted informational messages, even in conditions where traditional data collection is restricted, and operates effectively with HTTPS protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If cookies and third-party tracking cookies are used to collect user data, then user identification and targeting capability is improved, but data security and user privacy protection deteriorates
Solution Approach 1:
The patent introduces an intermediary system (the matching system with NAT service) that acts as a mediator between user devices and notification systems. Instead of direct tracking via cookies, the system uses IP address matching through NAT translation to indirectly identify users. This intermediary approach maintains targeting capability while reducing direct exposure of personal data, thus balancing measurement precision with privacy protection.
2Loss of information
If traditional cookie-based tracking is used, then user data collection capability is improved, but compatibility with HTTPS and mobile applications deteriorates
Solution Approach 1:
The patent changes the identification parameter from cookie-based identifiers to IP address-based identifiers. By utilizing NAT (Network Address Translation) to map internal IP addresses to external visible IP addresses, the system creates a cookie-independent identification mechanism. This parameter change enables compatibility with HTTPS (which blocks cookies) and mobile applications while maintaining user data collection capability through IP address matching.
3Object-affected harmful factors
If user data collection is restricted by user settings or browser security tools, then user privacy protection is improved, but user identification capability deteriorates
Solution Approach 1:
Instead of trying to collect user data directly from user devices (which is blocked by security tools and user settings), the patent inverts the approach by having the NAT service provide IP address information to the notification system. The identification is performed indirectly through IP address matching rather than direct data collection, thus maintaining identification capability while respecting user privacy settings and browser security restrictions.
4Reliability
If third-party cookies are blocked or deleted by security tools, then data security is improved, but advertising targeting effectiveness deteriorates
Solution Approach 1:
The patent creates a copy mechanism through NAT address translation. Instead of relying on third-party cookies that are blocked, the system copies identification functionality to the network infrastructure level. The NAT service maintains a mapping (copy) between internal user IP addresses and external visible IP addresses, allowing advertising targeting to function through IP address matching rather than cookie-based tracking, thus maintaining effectiveness while respecting data security measures.
Data Source
AI summary
The present invention relates to systems and methods for matching and collecting user data and/or user device data within a current Internet access session of a user for use by user notification systems that generate, distribute and display informational messages over the Internet. The system comprises a source data reception unit configured to receive a source IP address and a source user device port matched with the translated IP address and with the translated port of the operator or the provider from the NAT service, and a data matching unit configured to match user data and/or user device data from all available sources, including but not limited to operator or provider databases, using the received source IP address and the received user device port. Advantageously, the invention provides delivery of informational messages based on collected/matched user data and/or user device data provided according to the present system to the maximum number of real identified users.


