IP Library › Granted Patent US 12,395,468
Granted Patent B2
US 12,395,468 · App. 18/146,342 · Granted Aug 19, 2025

Technique for eliminating ingress-proxy in the multi-relay approach for privacy

Inventors: Sri Gundavelli (San Jose, CA); Eric A. Voit (Bethesda, MD); Pradeep K. Kathail (Los Altos, CA); Ali Sajassi (San Ramon, CA); David Maluf (Mountain View, CA)
Assignee: Cisco Technology, Inc.
H04L63/0414H04L63/0435H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,468
App. No.
18/146,342
Granted
Aug 19, 2025
Kind
B2
Abstract

In one aspect, a method of IP obfuscation of a user device includes receiving, over an Extendible Authentication Protocol (EAP) session between a user device and a network access point, location preferences of the user device, generating, based on the location preferences or a network policy, a geohash for the user device, identifying, for the user device, an IP anchor, sending, over the EAP session, the geohash to the user device, and receiving, from the user device, network traffic, wherein the network access point utilizes the geohash and the IP anchor to route the network traffic for the user device and obfuscate IP address of the user device from third-party access.

Claims (48)

1. A method of IP obfuscation of a user device, comprising:

receiving, over an Extendible Authentication Protocol (EAP) session between a user device and a network access point, location preferences of the user device;

generating, based on the location preferences or a network policy, a geohash for the user device;

identifying, for the user device, an IP anchor;

sending, over the EAP session, the geohash to the user device; and

receiving, from the user device, a set of data for exchange between the user device and a destination point, wherein the network access point utilizes the geohash and the IP anchor to route the set of data for the user device and obfuscate IP address of the user device from third-party access.

2. The method of claim 1 , further comprising:

establishing a first Quick UDP Internet Connection (QUIC) session between the user device and an egress proxy, wherein the network access point provides a randomized IP address representative of the user device to the egress proxy associated with the geohash;

sending, over the connection between the user device and the egress proxy, a single connection request including an IP address of a destination, the egress proxy establishing one of a Transmission Control Protocol (TCP) session or a User Datagram Protocol (UDP) session between the egress proxy and the destination; and

establishing a second QUIC session between the user device and the destination through the egress proxy.

3. The method of claim 2 , further comprising:

facilitating, over the second QUIC session between the user device and the destination through the egress proxy, transmission of the set of data between the user device and the destination through the network access point and the egress proxy using the geohash and the IP anchor.

4. The method of claim 1 , wherein the user device connects to the network access point using one of a 3GPP access or an IEEE 802.11-based access to the network access point, and wherein the location preferences are included in a NAS signaling for the 3GPP access or in an 802.11 link layer protocol for the IEEE 802.11-based access.

5. The method of claim 1 , further comprising:

digitally signing the geohash and a Network Access Translation (NAT) translated IP address of the user device using a public key.

6. The method of claim 1 , wherein identifying the IP anchor is based on a location of the user device.

7. The method of claim 1 , wherein the network access point and the IP anchor do not have visibility into the IP address of a destination to which the set of data is being sent or received from.

8. A network access point, comprising:

one or more memories having computer-readable instructions stored therein; and

one or more processors configured to execute the computer-readable instructions to:

receive, over an Extendible Authentication Protocol (EAP) session and from a user device, location preferences of the user device;

generate, based on the location preferences or a network policy, a geohash for the user device;

identify, for the user device, an IP anchor;

send, over the EAP session, the geohash to the user device; and

receive, from the user device, a set of data for exchange between the user device and a destination point, wherein the network access point is configured to utilize the geohash and the IP anchor to route the set of data for the user device and obfuscate IP address of the user device from third-party access.

9. The network access point of claim 8 , wherein the one or more processors are configured to execute the computer-readable instructions to:

establish a first Quick UDP Internet Connection (QUIC) session between the user device and an egress proxy, wherein the network access point provides a randomized IP address representative of the user device to the egress proxy associated with the geohash;

send, over the connection between the user device and the egress proxy, a single connection request including an IP address of a destination, the egress proxy establishing one of a Transmission Control Protocol (TCP) session or a User Datagram Protocol (UDP) session between the egress proxy and the destination; and

establish a second QUIC session between the user device and the destination through the egress proxy.

10. The network access point of claim 9 , wherein the one or more processors are configured to execute the computer-readable instructions to facilitate, over the second QUIC session between the user device and the destination through the egress proxy, transmission of the set of data between the user device and the destination through the network access point and the egress proxy using the geohash and the IP anchor.

11. The network access point of claim 8 , wherein the user device is configured to connect to the network access point using one of a 3GPP access or an IEEE 802.11-based access to the network access point, and wherein the location preferences are included in a NAS signaling for the 3GPP access or in an 802.11 link layer protocol for the IEEE 802.11-based access.

12. The network access point of claim 8 , wherein the one or more processors are configured to execute the computer-readable instructions to digitally sign the geohash and a Network Access Translation (NAT) translated IP address of the user device using a public key.

13. The network access point of claim 8 , wherein identifying the IP anchor is based on a location of the user device.

14. The network access point of claim 8 , wherein the network access point and the IP anchor do not have visibility into the IP address of a destination to which the set of data is being sent or received from.

15. One or more non-transitory computer-readable media comprising computer-readable instructions, which when executed by one or more processors of a network access point, cause the network access point to:

receive, over an Extendible Authentication Protocol (EAP) session and from a user device, location preferences of the user device;

generate, based on the location preferences or a network policy, a geohash for the user device;

identify, for the user device, an IP anchor;

send, over the EAP session, the geohash to the user device; and

receive, from the user device, a set of data for exchange between the user device and a destination point, wherein the network access point is configured to utilize the geohash and the IP anchor to route the set of data for the user device and obfuscate IP address of the user device from third-party access.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the execution of the computer-readable instructions further cause the network access point to:

establish a first Quick UDP Internet Connection (QUIC) session between the user device and an egress proxy, wherein the network access point provides a randomized IP address representative of the user device to the egress proxy associated with the geohash;

send, over the connection between the user device and the egress proxy, a single connection request including an IP address of a destination, the egress proxy establishing one of a Transmission Control Protocol (TCP) session or a User Datagram Protocol (UDP) session between the egress proxy and the destination; and

establish a second QUIC session between the user device and the destination through the egress proxy.

17. The one or more non-transitory computer-readable media of claim 16 , wherein the execution of the computer-readable instructions further cause the network access point to facilitate, over the second QUIC session between the user device and the destination through the egress proxy, transmission of the set of data between the user device and the destination through the network access point and the egress proxy using the geohash and the IP anchor.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the user device is configured to connect to the network access point using one of a 3GPP access or an IEEE 802.11-based access to the network access point, and wherein the location preferences are included in a NAS signaling for the 3GPP access or in an 802.11 link layer protocol for the IEEE 802.11-based access.

19. The one or more non-transitory computer-readable media of claim 15 , wherein the execution of the computer-readable instructions further cause the network access point to digitally sign the geohash and a Network Access Translation (NAT) translated IP address of the user device using a public key.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the network access point and the IP anchor do not have visibility into the IP address of a destination to which the set of data is being sent or received from.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2022
From: GUNDAVELLI, SRI; VOIT, ERIC A.; KATHAIL, PRADEEP K.; SAJASSI, ALI; MALUF, DAVID
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062199/0209 →
Continuity (2)
Provisional Application 63369788 · Jul 29, 2022
Related Publication 20240039897A1 · Feb 1, 2024
References Cited (7)
US 8254382B1 · Wu et al. · 2012 [cited by applicant]
US 9641434B1 · Laurence et al. · 2017 [cited by applicant]
US 10778684B2 · Gupta · 2020 [cited by examiner]
US 20200068391A1 · Liu et al. · 2020 [cited by applicant]
Deshmukh et al., “Location Privacy in Android Smart Phone Using Obfuscation,” International Journal of Engineering Research & Technology, May 2013, pp. 1-8. [cited by applicant]
Yang et al., “A New Privacy-Preserving Authentication Anonymous Web Browsing,” researchgate.net, Sep. 2018, pp. 1-14. [cited by applicant]
Zekun Zhang et al., “LPPS-AGC: Location Privacy Protection Strategy Altgeohash Coding in Location-Based Services,” Hindawi, Feb. 27, 2022, pp. 1-17. [cited by applicant]