H04L61/2539

Protecting communication link between content delivery network and content origin server
11711340 · 2023-07-25 · ·

A privatized link between an origin server and a content delivery network is provided. A privatized link can be a direct connection that does not route over the internet. Another privatized link is one that rotates IP addresses. An origin server may be assigned to use a set of multiple IP addresses for communication with the content delivery network. However, at any given time, the origin server is only using a small number of IP addresses. When one of the IP addresses being used to communicate with the content delivery network comes under attack, the origin server switches to another IP address in the set in order to continue serving content to the content delivery network via an IP address that is not under attack.

Protecting communication link between content delivery network and content origin server
11711340 · 2023-07-25 · ·

A privatized link between an origin server and a content delivery network is provided. A privatized link can be a direct connection that does not route over the internet. Another privatized link is one that rotates IP addresses. An origin server may be assigned to use a set of multiple IP addresses for communication with the content delivery network. However, at any given time, the origin server is only using a small number of IP addresses. When one of the IP addresses being used to communicate with the content delivery network comes under attack, the origin server switches to another IP address in the set in order to continue serving content to the content delivery network via an IP address that is not under attack.

Method and device for processing a request for anonymisation of a source IP address, method and device for requesting anonymisation of a source IP address
11706187 · 2023-07-18 · ·

A method for processing a request for anonymisation of a source IP address of an IP packet is described, the IP packet being transmitted by a transmitting device to a recipient device via a communications network, the transmitting device being connected to the network via a network terminal apparatus. The method is carried out by an anonymisation device positioned for cutting the flow between the network terminal apparatus and the recipient device, and comprises receiving the packet; establishing whether the source IP address has to be anonymised or not; if a result of the verification is negative, routing the packet to the recipient device; if the result of the verification is positive and if the anonymisation device has an address translation function: replacing the source IP address with an IP address of the anonymisation device; and. If the result of the verification is positive and if the anonymisation device does not have an address translation function, a step of routing the IP packet is routed to the recipient device via an apparatus of the network which has an address translation function.

Method and device for processing a request for anonymisation of a source IP address, method and device for requesting anonymisation of a source IP address
11706187 · 2023-07-18 · ·

A method for processing a request for anonymisation of a source IP address of an IP packet is described, the IP packet being transmitted by a transmitting device to a recipient device via a communications network, the transmitting device being connected to the network via a network terminal apparatus. The method is carried out by an anonymisation device positioned for cutting the flow between the network terminal apparatus and the recipient device, and comprises receiving the packet; establishing whether the source IP address has to be anonymised or not; if a result of the verification is negative, routing the packet to the recipient device; if the result of the verification is positive and if the anonymisation device has an address translation function: replacing the source IP address with an IP address of the anonymisation device; and. If the result of the verification is positive and if the anonymisation device does not have an address translation function, a step of routing the IP packet is routed to the recipient device via an apparatus of the network which has an address translation function.

Enhanced privacy-preserving access to a VPN service
11611536 · 2023-03-21 · ·

Systems and methods for effectively managing security and privacy measures during a user's connectivity session with a VPN service are provided. The systems and methods use a computer program that introduces a double-NAT feature at the network layer and a temporary hash table containing the minimally necessary temporary data to link two NAT sessions together in a secure manner. The systems and methods avoid including the dynamic management of IP addresses or requiring each client to have an IP address assigned beforehand to avoid compromising the user's identity by hard linking the session traces with the client.

Enhanced privacy-preserving access to a VPN service
11611536 · 2023-03-21 · ·

Systems and methods for effectively managing security and privacy measures during a user's connectivity session with a VPN service are provided. The systems and methods use a computer program that introduces a double-NAT feature at the network layer and a temporary hash table containing the minimally necessary temporary data to link two NAT sessions together in a secure manner. The systems and methods avoid including the dynamic management of IP addresses or requiring each client to have an IP address assigned beforehand to avoid compromising the user's identity by hard linking the session traces with the client.

Solution for trustworthy and security compliant edge computing infrastructure

Systems and method directed to providing a framework for a trustworthy and security compliant edge computing infrastructure are described. Such framework allows self-built edge datacenters to continue providing enhanced service quality in regions where user data and user privacy are of top concerns. In examples, the systems and methods may include an edge router configured to route a communication received from a mobile device to a network address translation appliance, the network address translation appliance associates an anonymous internet protocol address with an internet protocol address associated with the mobile device, and provides the request to an edge datacenter. The edge data center may request content and/or services from a technology partner datacenter via an application gateway for security and privacy that is configured to receive the request for content from the edge datacenter and determine if the request for content is associated with user protected information.

METHOD AND SYSTEM FOR REALIZING NETWORK DYNAMICS, TERMINAL DEVICE AND STORAGE MEDIUM
20220337546 · 2022-10-20 ·

The present disclosure provides a method and system for realizing network dynamics, a terminal device, and a computer readable storage medium. The method includes: a domain name system request being sent to a security control center after a requester initiates the request to access a requestee; the security control center selecting an IP address from each of dynamic address pools of the requester and the requestee respectively as a dynamic source IP address and a dynamic destination IP address, and sending both the dynamic source IP address and the dynamic destination IP address to the security modules of the requester and the requestee; the security module of the requester changing a source address of a data packet generated by the requester to the dynamic source IP address, and sending the data packet to the security module of the requestee; and in response to verifying that the source address and the destination address of the data packet are respectively consistent with the dynamic source IP address and the dynamic destination IP address, the security module of the requestee forwarding the data packet to the requestee.

ANONYMIZING SERVER-SIDE ADDRESSES

Techniques for using Network Address Translation (NAT), Mobile Internet Protocol (MIP), and/or other techniques in conjunction with Domain Name System (DNS) to anonymize server-side addresses in data communications. Rather than having DNS provide a client device with an IP address of an endpoint device, such as a server, the DNS instead returns a virtual IP (VIP) address that is mapped to the client device and the endpoint device. In this way, IP addresses of servers are obfuscated by a virtual network of VIP addresses. The client device may then communicate data packets to the server using the VIP address as the destination address, and a virtual network service that works in conjunction with DNS can convert the VIP address to the actual IP address of the server using NAT and forward the data packet onto the server.

INFRASTRUCTURE DISTRIBUTED DENIAL OF SERVICE (DDOS) PROTECTION

A method of providing infrastructure protection for a network that includes IP addresses as low as a single IP address. An end user sends traffic to an IP address of a projected server publicly available as an anycast address, and sends traffic to the protected network. The traffic is routed via one of several scrubbing centers using the public IP address as anycast address, and the scrubbing center provides infrastructure protection by scanning and filtering the incoming traffic for illegitimate data. After filtering, the legitimate traffic is encapsulated, e.g., via including virtual GRE tunnel information that includes a secret IP address known only to the scrubbing center and the protected server that receives the network traffic. The protected server decapsulates the network packet and responds back to the end user via the scrubbing network.