SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT
Patent Information
- Application Number
- DE25163013
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2013-01-02
- Filing Date
- 2014-01-02
- Publication Date
- 2026-01-15
Abstract
Claims
[1] System for providing dual network address translation, comprising a Network Operations Center (NOC) comprising a memory component, wherein the memory component stores logic which, when executed by a processor, causes the system to perform at least the following: Receiving data from a user workstation over a wide area network, wherein the data is received via a first Virtual Private Network (VPN) tunnel, wherein the data is encrypted using VPN encryption, and wherein the data is assigned a Unique Private Internet Protocol (UPIP) address that overlaps with a customer-defined private IP address and includes a security barrier; Removing VPN encryption from the data; Using a Twin-NAT-Network Address Translation (NAT) component to remove the UPIP address and replace it with the customer-defined private IP address from a private network at a destination; Packaging the data with the customer-defined private IP address in a privately defined protocol that includes the public source address and the public destination address; and Using a second VPN tunnel to transmit the data to the destination. [2] System according to claim 1, wherein the logic further causes the system to allocate a family of IP addresses to a private range, wherein the family of IP addresses includes at least one of the following: IPv4 and IPv6. [3] System according to claim 1, wherein a plurality of IP addresses are assigned on the NOC, one for each of a plurality of private areas. [4] System according to claim 1, wherein the NOC assigns a single IP address to all computing devices in a private area, each with a unique address in the network. [5] System according to claim 4, wherein the NOC comprises at least one of the following: a conventional VPN component, a conventional plaintext processing component, a Twin-NAT and a VPN. [6] System according to claim 1, further comprising a Twin-NAT, wherein the Twin-NAT stores NAT relationships that support the translation from the client workstation in a private network to the remote computing device in a remote network, while the client workstation and the wide area network have no knowledge of the IP address conversion. [7] System according to claim 6, further comprising the client workstation, wherein the client workstation has a dual-twin-NAT client for correlating between customer-assigned private IP addresses and the assigned Unique Private Internet Protocol (UPIP) address, so that unique IP addresses are assigned to different private ranges. [8] Methods for dual network address translation, comprising: Receiving, via a processor at a Network Operations Center (NOC), data from a user workstation over a wide area network, wherein the data is received via an initial Virtual Private Network (VPN) tunnel, wherein the data is encrypted using VPN encryption, and wherein the data is assigned a Unique Private Internet Protocol (UPIP) address that overlaps with a customer-defined private IP address and includes a security barrier; Remove, via the processor on the NOC, the VPN encryption from the data; Use, via the processor on the NOC, a Twin-Network Address Translation (NAT) component to remove the UPIP address and replace the UPIP with the customer-defined private IP address from a private network at a destination; Packaging, via the processor at the NOC, the data with the customer-defined private IP address in a privately defined protocol that includes the public source address and the public destination address; and Use the processor on the NOC to establish a second VPN tunnel to transmit the data to the destination. [9] The method of claim 8, further comprising the allocation of a family of IP addresses to a private range, wherein the family of IP addresses includes at least one of the following: IPv4 and IPv6. [10] Method according to claim 8, wherein a plurality of IP addresses are assigned on the NOC, one for each of a plurality of private areas. [11] The method of claim 8, further comprising the assignment of a single IP address to all computing devices in a private area, each with a unique address in the network. [12] The method of claim 8, further comprising storing NAT relationships that support the translation from a client workstation in a private network to a remote computing device in a remote network, while the client workstation and the wide area network are unaware of the IP address conversion. [13] The method of claim 8, further comprising the correlation between customer-assigned private IP addresses and the assigned Unique Private Internet Protocol (UPIP) address, such that unique IP addresses are assigned for a plurality of different private ranges. [14] Non-volatile, computer-readable medium for providing dual network address translation, comprising logic which, when executed by a processor, causes the processor to perform at least the following: Receiving data from a user workstation over a wide area network, wherein the data is received via a first Virtual Private Network (VPN) tunnel, wherein the data is encrypted using VPN encryption, and wherein the data is assigned a Unique Private Internet Protocol (UPIP) address that overlaps with a customer-defined private IP address and includes a security barrier; Removing VPN encryption from the data; Using a Twin-Network Address Translation (NAT) component to remove the UPIP address and replace it with the customer-defined private IP address from a private network at a destination; Packaging the data with the customer-defined private IP address in a privately defined protocol that includes the public source address and the public destination address; and Using a second VPN tunnel to transmit the data to the destination; and Assigning a unique private address in the data to customer-defined private IP addresses. [15] Non-volatile computer-readable medium according to claim 14, wherein the logic further causes the processor to allocate a family of IP addresses to a private range, the family of IP addresses containing at least one of the following: IPv4 and IPv6. [16] Non-volatile computer-readable medium according to claim 14, wherein a plurality of IP addresses are assigned on the side of a Network Operations Center (NOC), one for each of a plurality of private areas. [17] Non-volatile computer-readable medium according to claim 14, wherein the logic causes the processor to assign a single IP address in a private range to all computing devices, each with a unique address in the network. [18] Non-volatile computer-readable medium according to claim 14, wherein the logic comprises at least one of the following: logic for implementing a conventional VPN component, logic for implementing a conventional plaintext processing component, logic for implementing a Twin-NAT and logic for implementing a VPN. [19] Non-volatile computer-readable medium according to claim 14, wherein the logic causes the processor to store NAT relationships that support the translation from a client workstation in a private network to a remote computing device in a remote network, while the client workstation and the wide area network have no knowledge of the IP address conversion. [20] Non-volatile computer-readable medium according to claim 14, wherein the logic comprises a dual-twin-NAT client for correlating between customer-assigned private IP addresses and the assigned Unique Private Internet Protocol (UPIP) address, such that unique IP addresses are assigned to a plurality of different private ranges.