Privacy-Protecting Relay Discovery and Assignment for Localized Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN services compromise user privacy by requiring tunneling all traffic to a central point, potentially exposing user data and causing performance issues due to hidden location, which disrupts content localization.
Innovation Solution
A network of privacy-protecting proxies/relays within a service provider network is used to obfuscate user IP and location information, allowing selective use of proxies based on trust and proximity to maintain performance and enable content localization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a VPN is used to protect user privacy by tunneling all traffic to a central point, then user IP address and geographic location are protected, but user data may be exposed to the VPN provider and performance issues occur due to hidden location
Solution Approach 1:
The patent segments the network traffic into different categories (privacy-sensitive traffic vs. location-dependent traffic) and applies different routing strategies to each segment. Privacy-sensitive traffic is routed through VPN tunnels to protect IP addresses, while location-dependent traffic is routed directly to maintain accurate geographic location information for content delivery networks.
Solution Approach 2:
The patent applies different quality characteristics to different parts of the network traffic. Instead of uniformly applying VPN tunneling to all traffic, it selectively applies privacy protection only where needed while maintaining local location accuracy for services that require it, such as content delivery and location-based services.
2Reliability
If all traffic is tunneled through a central VPN point, then user IP address is protected, but trust is centralized and user data can be observed and monetized
Solution Approach 1:
The patent extracts the essential privacy protection function from the centralized VPN model and applies it selectively only to traffic that requires IP address protection. By taking out the VPN tunneling mechanism from being a universal solution and applying it only where needed, it eliminates the need for users to trust a centralized provider with all their data while maintaining IP address protection where necessary.
3Reliability
If location information is hidden behind a VPN, then privacy is protected, but content localization breaks causing slower access times and increased latency
Solution Approach 1:
The patent implements dynamic routing that adapts to the requirements of different traffic types. For each data flow, it dynamically determines whether VPN tunneling is appropriate based on the service requirements, switching between privacy-protecting routed data flows and direct routed data flows as needed to optimize both privacy and performance.
4Reliability
If a proxy is used for all data flows, then privacy is protected, but services requiring location information may not function properly
Solution Approach 1:
The patent segments data flows into different categories based on their requirements. It identifies whether each data flow requires privacy protection or accurate location information and applies appropriate routing strategies accordingly, ensuring that services requiring location information can function properly while maintaining privacy protection for other traffic.
Data Source
AI summary
Methods and systems are disclosed for discovery and assignment of privacy-protecting proxies/relays in a network. As an example, a gateway device located at a premises may send a request for data indicating one or more privacy-protecting proxies (PPPs) available to the gateway device, to a network device located external to the premises. The gateway device may select a PPP from the one or more PPPs available to the gateway device based on one or more predetermined criteria useful for selecting a PPP. The selected PPP may be assigned to a user device located at the premises by the gateway device. The assignment may be based on the selected PPP being trusted. Data associated with the user device may be routed via the assigned PPP. If the selected PPP is untrusted, data associated with the user device may be routed without using the selected and assigned PPP.


