Regional Anonymization Node Routing for Compliant Statistics Collection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data routing methods in client-server architectures require additional agents on user devices, making user interaction non-transparent and burdensome, or perform total encryption regardless of content, failing to consider jurisdictional data restrictions and client-server locations.

Innovation Solution

A method and system for data routing in a client-server architecture using a network node with an anonymization module in a different regional network, transforming critical data using one-way functions or asymmetrical encryption to ensure anonymity and compliance with jurisdictional regulations, while maintaining data completeness and representativeness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional agents are installed on user devices for data routing, then data transmission compliance is improved, but user interaction transparency deteriorates and device complexity increases

Engineering Contradiction:
Improvedata transmission complianceVSAvoiduser interaction transparency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a network node with an anonymization module as an intermediary component that operates transparently in the data transmission path between user devices and servers. This intermediary performs automated identification and transformation of critical data without requiring user installation or interaction, thereby maintaining compliance while preserving user experience transparency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If total encryption is performed on all data regardless of content, then data security is improved, but data processing efficiency deteriorates and device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments data into two categories: critical data requiring transformation and non-critical data that can be processed normally. The anonymization module identifies and transforms only the critical portions of data structures, leaving other data unchanged. This selective approach maintains security for sensitive information while preserving processing efficiency for the majority of data that does not require encryption.

Inventive Principle:
Principle #1Segmentation

3Reliability

If critical data is transformed using one-way functions, then user anonymity is improved, but data completeness for server analysis deteriorates

Engineering Contradiction:
Improveuser anonymityVSAvoiddata completeness for analysis
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent transforms critical data by changing its parameters through anonymization functions that modify identifying characteristics while preserving the statistical and analytical properties needed for server-side processing. The transformation alters data parameters such as personal identifiers but maintains the structural integrity and representativeness of the data for compilation of statistics and analysis.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If data is routed through a network node in a different regional network, then jurisdictional compliance is improved, but transmission complexity increases

Engineering Contradiction:
Improvejurisdictional complianceVSAvoidtransmission complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal anonymization module within the network node that can handle multiple data types, transformation methods, and routing scenarios through a single integrated system. This multi-functional design consolidates what would otherwise require separate complex mechanisms for each compliance scenario, thereby achieving jurisdictional compliance while minimizing transmission complexity through standardized processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3547638B1System and method of routing data during statistics collection
Publication Date: 2025.09.03 AO KASPERSKY LAB
  • EP3547638B1 patent drawingFigure 1
  • EP3547638B1 patent drawingFigure 2
  • EP3547638B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods for routing during statistics collection. A method is described of exchanging data in a client/server architecture across a node with an anonymization module situated in a regional network different from the network in which the server is located and not being in the same intranet as the server or the client when making the request.