Pseudo Email Suffix Segmentation for DoS Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing concern for privacy on the Internet due to tracking and profiling by sellers, along with the risk of Denial of Service (DoS) attacks on privacy servers, necessitates effective generation and management of pseudo email addresses to protect user privacy and prevent service disruptions.

Innovation Solution

A privacy server system that generates and manages pseudo email addresses by organizing a large number of suffixes into multiple threads across different trust zones, assigning users to threads based on trust levels, and calculating a confidence level to determine zone assignments, thereby making it difficult for hackers to launch successful DoS attacks and allowing users to maintain privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a privacy server generates pseudo e-mail addresses for consumers, then user privacy is protected and tracking is prevented, but the server becomes vulnerable to Denial of Service attacks

Engineering Contradiction:
Improveprivacy protectionVSAvoidDoS attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the suffix space into multiple threads (e.g., Thread 1, Thread 2, Thread 3) with different trust levels. Legitimate users are assigned suffixes from high-trust threads while malicious users are confined to low-trust threads. This segmentation prevents a single DoS attack from compromising the entire system, as attacks are isolated to specific threads rather than affecting all pseudo e-mail addresses simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different threads are assigned different trust qualities based on their usage patterns. Threads with high legitimate usage receive higher trust levels and are less likely to be blocked, while threads showing malicious patterns are downgraded to lower trust levels. This local quality differentiation allows the system to protect legitimate traffic while blocking attacks on specific threads without affecting overall system functionality.

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple pseudo e-mail addresses are generated for each user, then privacy is enhanced and profiling is prevented, but the complexity of managing and organizing suffixes increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidsuffix management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent organizes the large suffix space into segmented threads with clear trust level classifications. Each thread is managed independently with its own trust level, making it easier to control and monitor. This segmentation reduces the complexity of managing thousands of suffixes by grouping them into manageable threads with uniform trust characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes the trust level parameter of threads based on their usage patterns and legitimacy assessments. By adjusting this single parameter, the system can automatically manage the complexity of suffix organization without requiring manual intervention for each individual suffix, thereby reducing operational complexity while maintaining privacy protection.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If trust levels and confidence calculations are implemented to manage suffix threads, then DoS attacks are mitigated, but the computational overhead and system complexity increase

Engineering Contradiction:
ImproveDoS attack resistanceVSAvoidtrust management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system uses confidence level calculations to dynamically change the trust level parameter of threads. By monitoring usage patterns and adjusting this single parameter, the system achieves DoS attack resistance without requiring complex manual management of each thread, thereby balancing security with operational simplicity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The trust management system operates autonomously by automatically calculating confidence levels and adjusting thread trust levels based on observed usage patterns. This self-service mechanism reduces the need for manual intervention and complex administrative overhead, mitigating DoS attacks while keeping system complexity manageable through automated decision-making.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8250225B1Generation of suffixes for pseudo e-mail addresses
Publication Date: 2012.08.21 BENHOV GMBH LLC
  • US8250225B1 patent drawing
  • US8250225B1 patent drawing
  • US8250225B1 patent drawing

AI summary

An electronic system provides a plurality of address components arranged in a plurality of mutually exclusive groups, and maintains for each of a plurality of electronic network users a respective group assignment specifying one of the groups that is determined by assignment criteria. Each such group assignment can change over time as a function of the assignment criteria, and the assignment criteria is configured so that every user is initially assigned to a predetermined one of the groups. The electronic system allocates to each user over time a sequence of address components from the group specified by the current group assignment of that user.