Privacy-Protecting Relay Discovery and Assignment for Localized Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN services compromise user privacy by requiring tunneling all traffic to a central point, potentially exposing user data and causing performance issues due to hidden location, which disrupts content localization.

Innovation Solution

A network of privacy-protecting proxies/relays within a service provider network is used to obfuscate user IP and location information, allowing selective use of proxies based on trust and proximity to maintain performance and enable content localization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN is used to protect user privacy by tunneling all traffic to a central point, then user IP address and geographic location are protected, but user data may be exposed to the VPN provider and performance issues occur due to hidden location

Engineering Contradiction:
Improveprivacy protectionVSAvoidcontent delivery performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network traffic into different categories (privacy-sensitive traffic vs. location-dependent traffic) and applies different routing strategies to each segment. Privacy-sensitive traffic is routed through VPN tunnels to protect IP addresses, while location-dependent traffic is routed directly to maintain accurate geographic location information for content delivery networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality characteristics to different parts of the network traffic. Instead of uniformly applying VPN tunneling to all traffic, it selectively applies privacy protection only where needed while maintaining local location accuracy for services that require it, such as content delivery and location-based services.

Inventive Principle:
Principle #3Local quality

2Reliability

If all traffic is tunneled through a central VPN point, then user IP address is protected, but trust is centralized and user data can be observed and monetized

Engineering Contradiction:
ImproveIP address protectionVSAvoiddata exposure to provider
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the essential privacy protection function from the centralized VPN model and applies it selectively only to traffic that requires IP address protection. By taking out the VPN tunneling mechanism from being a universal solution and applying it only where needed, it eliminates the need for users to trust a centralized provider with all their data while maintaining IP address protection where necessary.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If location information is hidden behind a VPN, then privacy is protected, but content localization breaks causing slower access times and increased latency

Engineering Contradiction:
Improvelocation privacyVSAvoidcontent access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements dynamic routing that adapts to the requirements of different traffic types. For each data flow, it dynamically determines whether VPN tunneling is appropriate based on the service requirements, switching between privacy-protecting routed data flows and direct routed data flows as needed to optimize both privacy and performance.

Inventive Principle:
Principle #15Dynamics

4Reliability

If a proxy is used for all data flows, then privacy is protected, but services requiring location information may not function properly

Engineering Contradiction:
Improveprivacy protectionVSAvoidservice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments data flows into different categories based on their requirements. It identifies whether each data flow requires privacy protection or accurate location information and applies appropriate routing strategies accordingly, ensuring that services requiring location information can function properly while maintaining privacy protection for other traffic.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12438848B2Discovery and assignment of privacy-protecting relays in a network
Publication Date: 2025.10.07 COMCAST CABLE COMM LLC
  • US12438848B2 patent drawing
  • US12438848B2 patent drawing
  • US12438848B2 patent drawing

AI summary

Methods and systems are disclosed for discovery and assignment of privacy-protecting proxies/relays in a network. As an example, a gateway device located at a premises may send a request for data indicating one or more privacy-protecting proxies (PPPs) available to the gateway device, to a network device located external to the premises. The gateway device may select a PPP from the one or more PPPs available to the gateway device based on one or more predetermined criteria useful for selecting a PPP. The selected PPP may be assigned to a user device located at the premises by the gateway device. The assignment may be based on the selected PPP being trusted. Data associated with the user device may be routed via the assigned PPP. If the selected PPP is untrusted, data associated with the user device may be routed without using the selected and assigned PPP.