Network Address Privacy Protection via Gateway Suppression

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of IEEE EUI-64 IPv6 addresses in network devices can lead to privacy infringement as they can be easily monitored, revealing device and user activities, and not all devices utilize temporary anonymous addresses, leaving them vulnerable to privacy breaches.

Innovation Solution

A method and apparatus that acquire identification data from network devices and send messages to prevent the use of network addresses generated based on this data, ensuring privacy by either generating alternative addresses or blocking data transfer containing unique identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IEEE EUI-64 IPv6 addresses are used for network devices, then network addressing and identification are simplified, but device privacy is compromised due to easy monitoring of device and user activities

Engineering Contradiction:
Improvenetwork addressingVSAvoidprivacy infringement
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway performs preliminary actions by sending suppression messages to devices before they can establish communication using their IEEE EUI-64 addresses. This preemptive blocking prevents the harmful effect of privacy infringement while allowing the device to maintain its standard address configuration for local identification purposes

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The gateway acts as an intermediary between the network and the device, intercepting and suppressing packets that would otherwise reveal device identity. This mediator approach allows the device to use its standard IEEE EUI-64 address locally while preventing external monitoring and privacy infringement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If temporary anonymous addresses are used instead of IEEE EUI-64 addresses, then device privacy is protected, but system complexity increases due to address generation and validation protocols

Engineering Contradiction:
Improveprivacy protectionVSAvoidaddress management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The device continues to use its own IEEE EUI-64 address for identification purposes without needing to generate or manage temporary addresses. The privacy protection is achieved through the gateway's suppression mechanism rather than through device-side address management, thereby avoiding increased device complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway serves as an intermediary that handles the privacy protection function centrally, eliminating the need for complex address generation and validation protocols at the device level. This centralizes the complexity in the gateway while keeping device operations simple

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If all devices are required to use anonymous addresses, then network-wide privacy is improved, but device compatibility and system operability may be compromised

Engineering Contradiction:
Improvenetwork privacyVSAvoidsystem operability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Privacy protection is applied selectively at the network level through the gateway's packet suppression function, rather than requiring uniform implementation across all devices. This allows devices to maintain their standard addressing behavior while still achieving network-wide privacy protection through localized intervention

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The gateway performs multiple functions: it maintains network addressing operations using standard IEEE EUI-64 addresses while simultaneously providing privacy protection through packet suppression. This multi-functional approach ensures system operability is maintained while achieving network-wide privacy improvement

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7530100B2Apparatus for limiting use of particular network address
Publication Date: 2009.05.05 CANON KK
  • US7530100B2 patent drawing
  • US7530100B2 patent drawing
  • US7530100B2 patent drawing

AI summary

An apparatus for limiting the use of a network address acquires identification data specific to a device connected to the network and generates a message preventing the device from using a network address generated based on the identification data. An apparatus for limiting data transfer detects that a device connected to a network sends data containing a network address generated based on an identifier specific to the device and prevents such data from being transferred.