Virtual IP Address Selection for Server Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to effectively anonymize destination IP addresses of servers, making them vulnerable to attacks such as distributed denial-of-service (DDOS) and allowing malicious entities to observe and correlate client and server locations, compromising user privacy.
Innovation Solution
The use of virtual IP (VIP) addresses, mapped to actual server IP addresses through techniques like Network Address Translation (NAT) and Mobile IP version 6 (MIPv6), in conjunction with the Domain Name System (DNS), to anonymize server-side addresses and protect privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If actual server IP addresses are used in DNS responses, then routing and networking decisions can be made accurately, but server addresses become visible to malicious entities enabling attacks and privacy compromise
Solution Approach 1:
The patent introduces virtual IP addresses as an intermediary layer between client devices and actual server IP addresses. DNS responses contain virtual IP addresses instead of real server addresses, acting as a mediator that enables routing while protecting the actual server identity. This intermediary layer allows networks to make routing decisions based on virtual addresses while the actual server addresses remain hidden from malicious entities.
2Ease of operation
If source IP addresses are kept visible in packet headers, then firewall and routing decisions can be made, but client device privacy is compromised and correlation attacks become possible
Solution Approach 1:
The patent employs virtual IP addresses as intermediaries for source addresses in outgoing packets. Instead of using the client's actual IP address, the system assigns virtual IP addresses that act as mediators. This allows firewall and routing decisions to be made based on virtual addresses while protecting the client's real IP address from exposure to destination servers and potential eavesdroppers.
3Loss of information
If destination IP addresses are obfuscated to protect privacy, then attacker correlation capability is reduced, but legitimate routing decisions become more difficult
Solution Approach 1:
The system uses virtual IP addresses as intermediaries that preserve routing capability while obfuscating actual server identities. Virtual IP addresses maintain the structure needed for routing decisions (allowing networks to forward packets correctly) while hiding the mapping to real server addresses. This intermediary approach enables legitimate routing without exposing information that would allow attackers to correlate traffic patterns with specific servers.
4Reliability
If virtual IP addresses are used to anonymize addresses, then server and client privacy is protected, but network infrastructure complexity increases
Solution Approach 1:
The patent implements virtual IP address functionality that serves multiple purposes simultaneously: it provides privacy protection, enables routing decisions, supports firewall operations, and maintains network addressing structure. This multi-functional approach consolidates what could be separate complex systems into a unified virtual addressing framework that handles privacy and networking requirements together.
Data Source
AI summary
Techniques for varying locations of virtual networks associated with endpoints using Network Address Translation (NAT), Mobile Internet Protocol (MIP), and/or other techniques in conjunction with Domain Name System (DNS). Rather than having DNS provide a client device with an IP address of an endpoint device, such as a server, the DNS instead returns a virtual IP (VIP) address that is mapped to the client device and the endpoint device. The VIP address may be selected based on a number of factors (e.g., power usage, privacy requirements, virtual distances, etc.). In this way, IP addresses of servers are obfuscated by a virtual network of VIP addresses that can be periodically rotated and/or load balanced. The client device may then communicate data packets to the server using the VIP address as the destination address, and a virtual network service that works in conjunction with DNS can convert the VIP address to the actual IP address of the server using NAT and forward the data packet onto the server.


