Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Network address translation" patented technology

Network address translation (NAT) is a method of remapping one IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device. The technique was originally used as a shortcut to avoid the need to readdress every host when a network was moved. It has become a popular and essential tool in conserving global address space in the face of IPv4 address exhaustion. One Internet-routable IP address of a NAT gateway can be used for an entire private network.

Application-agnostic puncturing of network address translation (NAT) services

Two electronic devices attempt to communicate and exchange Internet Protocol (IP) packets over a cellular communication network, and at least one of the two devices is behind a symmetric Network Address Translation (NAT) service. At least one of the two devices executes a Session Traversal Utilities for NAT (STUN) protocol, which provides to that device a pair of external IP address and port of that device; which that device then informs to a Message Broker Unit that is accessible to both devices via the public Internet. The Message Broker Unit provides the external IP address and port of that device, to the other device; which then connects to a Virtual Private Network (VPN) server and sends to the first device one or more User Datagram Protocol (UDP) packets that penetrate or puncture the NAT service in an application-agnostic manner.
Owner:LIVEU

External network access method and apparatus, and computer device, readable storage medium and product

PCT designated stageWO2026108800A1TransmissionAccess methodNetwork addressing
The present application relates to an external network access method and apparatus, and a computer device, a readable storage medium and a product. The method comprises: upon receiving an external network access request sent by at least one internal network device, acquiring the priority with which each external network access request is transmitted to each of at least two gateway servers, wherein the priority is determined on the basis of connection attributes between the gateway servers and the internal network device (S202); sending the external network access request to a first gateway server having the highest priority, and performing network address translation (S204); when an anomaly occurs in the first gateway server during the process of network address translation, sending the external network access request to a second gateway server having the highest priority among the gateway servers other than the first gateway server (S206); performing network address translation (S208); and when the second gateway server converts an internal network address of the internal network device into a public network address of an external network indicated by the external network access request, obtaining an external network access result (S210).
Owner:CHINA TELECOM CLOUD TECH CO LTD

A method of processing and a routing device for controlling a session

ActiveCN117675753BTransmissionEngineeringNetwork address translation
The specification provides a processing method and a routing device for controlling a session, the method comprising: an NPU receiving a first control packet, converting a first source address in the first control packet into a second source address according to a network address translation (NAT) rule, the NPU uploading the first control packet and the second source address to a CPU kernel state, the NPU receiving a second control packet sent by the CPU kernel state, converting a first destination address in the second control packet into a second destination address according to the NAT rule, the NPU uploading the second control packet and the second destination address to the CPU kernel state, and the NPU receiving a takeover notification sent by the CPU kernel state and a control packet converted by a user state to process a session. By the method, the technical problem that the processing logic is limited by the NPU hardware and that the IP can be converted only once in each flow processing and the twice NAT conversion in the NAT hairpin scene cannot be implemented is avoided.
Owner:NEW H3C TECH CO LTD

Client IP persistence for traffic egressing from a distributed service access service edge (SASE) infrastructure for language localization

Techniques for providing language localization for traffic egressing from a distributed Service Access Service Edge (SASE) infrastructure are disclosed. In some embodiments, a system, a process, and / or a computer program product for providing client IP persistence for traffic egressing from a distributed SASE infrastructure includes receiving traffic associated with a user application (app) session at a Secure Access Service Edge (SASE) cloud network via a proxy node; processing the traffic associated with the user app session using a security processing node (SPN), and wherein a source network address translation (SNAT) rule is configured for the SPN; and egressing the traffic associated with the user app session from the SASE cloud network to its original destination using a fixed public IP address based on the SNAT rule to facilitate language localization for all network connections associated with the user app session.
Owner:PALO ALTO NETWORKS INC

Low-altitude blind area access method and system based on multi-network fusion unmanned aerial vehicle network

This invention discloses a method and system for low-altitude blind zone access based on a multi-network converged UAV network. The system includes an embedded device configured with a cellular communication module and a self-organizing network interface card (NIC) as a gateway node, an embedded device configured with a self-organizing NIC as a relay node, and an embedded device configured with multiple self-organizing NICs as access nodes. The system operates by including the following steps: after power-on, nodes automatically perform network configuration, identify new nodes, and assign IP addresses; access nodes achieve transparent forwarding of user data by setting up special connections between NICs; the topology is maintained using self-organizing network protocols, enabling seamless roaming and session persistence for terminals between access points; and the gateway node forwards internal traffic to the cellular network for internet access through network address translation and routing rules. This invention addresses the problems of high cost and difficult deployment of traditional low-altitude blind zone access solutions by employing low-cost equipment and self-organizing network technology, achieving rapid, self-organizing, stable, and reliable network access.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Multifactor authentication using network address translation data

The present disclosure describes a device, computer-readable medium, and method for multifactor authentication using network address translation data. A method performed by a processing system includes receiving, from a host device in a communication network, a request to authenticate a user, wherein the request includes a purported identity of the user and a public internet protocol address assigned to a user endpoint device from which a request to access a resource at the host device was sent, querying a provider edge server for a verification that the purported identity matches an identity associated with a private internet protocol address that is mapped to the public internet protocol address, receiving a first response from the provider edge server, determining whether to authenticate the user based on the first response from the provider edge server, and sending a second response to the host device indicating a result of the determining.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Client IP persistence for traffic egressing from a distributed service access service edge (SASE) infrastructure

In some embodiments, a system, a process, and / or a computer program product for providing client IP persistence for traffic egressing from a distributed SASE infrastructure includes receiving traffic associated with a user application (app) session at a Secure Access Service Edge (SASE) cloud network via a proxy node; processing the traffic associated with the user app session using a security processing node (SPN), and wherein a network address translation (NAT) rule is configured for the SPN; and egressing the traffic associated with the user app session from the SASE cloud network to its original destination using a fixed public IP address based on the NAT rule to facilitate client IP persistence for all network connections associated with the user app session (e.g., the NAT rule is used in selecting the Cloud NAT with a fixed public IP address to egress the traffic).
Owner:PALO ALTO NETWORKS INC

Communication method performed at an AP device, AP device, and computer program product

PendingCN122420950AEngineeringNetwork address translation
The present disclosure relates to a communication method for performing at an access point (AP) device, comprising: monitoring a status of a first link through which the AP device accesses a wide area network; establishing a second link through which the AP device accesses the wide area network based at least in part on the status of the first link reaching a pre-warning range, wherein the establishing the second link comprises synchronously mirroring entries in a network address translation (NAT) mapping table of the first link that are greater than a first priority to a NAT mapping table of the second link; and in response to the status of the first link reaching at least one of a switching condition, switching traffic of the AP device from the first link to the second link and stopping transmission of the traffic of the AP device through the first link. The present disclosure also relates to an AP device and a computer program product.
Owner:TP-LINK INT SHENZHEN CO LTD

Android cloud phone virtual WiFi implementation method

The embodiment of the present disclosure provides a kind of Android cloud mobile phone virtual WiFi implementation method of simulation, belong to communication technical field, specifically include: the identification of target container is acquired and its network namespace is determined;Virtual wireless entity is created and registered, including the wiphy / radio of binding and the visible wlan0 interface;Create and start hotspot side AP simulation entity, configure SSID and authentication parameter, and generate 802.11 management frame;In target Android container, start wpa_supplicant, complete association authentication by nl80211 interface and host computer interaction;After authentication succeeds, network address is allocated by AP simulation entity;Configuration network address conversion and forwarding rule, traffic is mapped to the physical external interface of host computer, and the network connectivity of container is realized.The simulation degree, interface consistency, compatibility and migratability are improved by the scheme of the present disclosure.
Owner:HUNAN XIAOSUAN TECH INFORMATION CO LTD

SNMP MIB-based firewall NAT policy automatic perception and port health degree closed-loop monitoring method and system

The application belongs to the technical field of network security operation and maintenance, network address translation monitoring, software defined network and intelligent operation and maintenance, and specifically discloses a firewall NAT policy automatic perception and port health degree closed-loop monitoring method and system based on SNMP MIB: the firewall NAT MIB is periodically collected through the SNMP protocol to obtain a current actual effective NAT entry set; the set is compared with a local monitoring configuration file to identify new and invalid entries, and an incremental update is performed on the configuration file according to a preset conflict arbitration strategy; the updated configuration file is read, survival detection is performed on a target port, and the result is pushed to a time sequence monitoring system. The application solves the problems of configuration drift, perception blind area and lack of closed-loop automation caused by the disconnection between monitoring configuration and NAT policy in the prior art, realizes automatic perception of NAT entries, incremental synchronization of configuration and closed-loop visual monitoring of port health degree, and improves operation and maintenance efficiency and monitoring accuracy.
Owner:SUZHOU INST OF ARTIFICIAL INTELLIGENCE SHANGHAI JIAOTONG UNIV

NAT route distribution based on tag information in an SDWAN overlay network

A process can include determining a plurality of Network Address Translation (NAT) routes associated with respective edge routers included in a same virtual private network (VPN) for communicating with a software-defined wide area network (SDWAN). A process can include identifying a first subset of the plurality of NAT routes as mapped to a first public NAT address included in a NAT pool associated with the VPN. A process can include tagging each NAT route of the first subset with a tag value indicative of a preferred router for receiving return traffic of the respective NAT route. A process can include routing traffic on a respective NAT route of the plurality of NAT routes based on applying, at an SDWAN controller, a corresponding control policy matching the tag value of the respective NAT route.
Owner:CISCO TECHNOLOGY INC

Multicast Network Address Translation Security

PendingUS20260180862A1TransmissionMulticast networkNetwork address translation
A broadcasting aware edge-device network product comprising two or more NMOS nodes, a look-up table and an SDP file re-writer. Each NMOS node is connected to a different network segment and receives SDP files from the network segment to which the NMOS node is connected. The look-up table stores network address translation rules between a first and a second network segment. The SDP file re-writer generates a modified SDP file by re-writing an SDP file received from one of the NMOS nodes by modifying the destination address according to the look-up table. The SDP file re-writer forwards the modified SDP file to the other NMOS node. The other NMOS node registers the modified SDP file with another network segment.
Owner:EVS BROADCAST EQUIP SA

Data transmission method, system and storage medium

ActiveCN114884919BRealize time travelTransmissionInternet communicationData stream
The application relates to the technical field of Internet communication, and discloses a data transmission method, a system and a storage medium, and the method applied to a public network device comprises the following steps: receiving a data request forwarded by a network address translation device through a first port; the first port is a data transmission port bound by an extensible virtual local area network tunnel between a private network device and the public network device, the destination port and the source port of the tunnel have the same port number; converting the source port of the data request into the first port, and obtaining data stream tracking information of the data request; converting a destination port of a response message into a second port according to a reverse source address translation rule and the data stream tracking information of the data request, and transmitting the response message to the network address translation device, so that the network address translation device forwards the response message to the private network device which initiates the data request; wherein the second port is a port used by the network address translation device to forward the data request to the public network device. The VXLAN message can simply and efficiently pass through the NAT device.
Owner:CHINANETCENT TECH

A network address acquisition method and device, electronic equipment and storage medium

The application discloses a network address acquisition method and device, electronic equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: a network address translation (Nat) server receives an intranet binding request sent by a streaming media request unit in a base station streaming media platform, wherein the intranet binding request carries an intranet IP address of a target edge gateway; an external network port is allocated for the streaming media request unit based on the intranet binding request; the intranet IP address is bound with the external network port to obtain a binding result; the binding result is sent to the streaming media request unit, and the binding result is used for the streaming media request unit to splice the intranet IP address and port information of the external network port to form an access URL, so that the streaming media request unit acquires streaming media of at least one streaming media camera by accessing the URL. The application can effectively reduce resource consumption when the base station streaming media platform acquires a network address.
Owner:CHINA TOWER CO LTD

Methods, devices, equipment, media, and products for tracing and locating abnormal behavior of containers.

This application provides a method, apparatus, device, medium, and product for tracing and locating abnormal behavior in containers, which can be applied to the field of cloud computing technology. The method includes: in response to receiving an abnormal behavior prompt for a container host, determining a first connection identifier corresponding to the abnormal behavior prompt; the first connection identifier represents the host-side network connection information after source network address translation; retrieving a corresponding second connection identifier from a mapping table based on the first connection identifier; the second connection identifier represents the container-side network connection information before source network address translation; querying the container runtime environment based on the second connection identifier to determine the container instance identifier that triggered the abnormal behavior prompt; wherein, the mapping table is generated by a target program mounted on the kernel network address translation processing path; the target program is executed in response to a source network address translation event.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Method and system for adding members to a door lock

PendingCN122369147APathPingInternet privacy
This invention discloses a method and system for adding members to a door lock. The method includes: constructing a non-network address translation (NAT) traversal path from the visitor terminal to the door lock based on a local connection established between the visitor terminal and the offline door lock; generating an encrypted authorization instruction payload after the management terminal confirms the visitor's identity based on a video call and public network address exchange established between the visitor terminal and the management terminal; reconstructing a new message based on the encrypted instruction payload intercepted by the visitor terminal and sending it to the door lock along the original path; and decrypting and verifying the administrator's biometric features upon receiving the reconstructed message, comparing the visitor's biometric features in the message with biometric features collected in real time on-site, destroying the visitor's features in the message after successful comparison, and saving the biometric features collected on-site as a temporary unlock template. Using this invention, secure remote injection of visitor permissions can be achieved under conditions without internet access, improving adaptability to network environments and the security of the authorization process.
Owner:DESSMANN CHINA MACHINERY & ELECTRONICS

Device type discovery based on network address translated network traffic

ActiveUS12652224B2TransmissionPattern recognitionSecurity solution
Device type discovery for a private network can be performed based on network address translated (NAT′d) network traffic generated from the network. A security solution analyzes data of network traffic from network devices using a binary classifier to determine whether the network traffic is from a NAT device. A network traffic dataset for a first time interval is preprocessed to generate a feature vector for the binary classifier, the output of which indicates whether the traffic is NAT′d. For NAT′d traffic, the security solution analyzes subsets of the network traffic dataset of smaller intervals within the first time interval. The security solution determines feature values from each network traffic data subset and generates feature vectors which are input to a multiclass classifier to obtain a device classification for each network traffic data subset.
Owner:PALO ALTO NETWORKS INC

Communication method and a branch apparatus

The present disclosure provides a network communication method and a branch apparatus. The method is applied to a branch apparatus which communicates with a central apparatus through a public network. The method includes: receiving a public IP address sent by the central apparatus after determining that a network address translation, NAT, gateway exists between the branch apparatus and the public network, wherein the public IP address is an internet protocol, IP, address of a target interface included in a target NAT gateway; sending a probe request packet to the target interface, the probe request packet including a destination IP address, the destination IP address being different from the public IP address and in the same network segment as the public IP address; obtaining the number of network apparatuses in a forwarding path for forwarding the probe request packet based on a probe result; sending a NAT keepalive packet to the central apparatus based on a preset period, the NAT keepalive packet including a first time to live, TTL, the first TTL being a sum of the number and a first value. Implementing the method provided in the present disclosure may avoid the impact on traffic forwarding of the central apparatus caused by the NAT keepalive packets.
Owner:NEW H3C TECH CO LTD

Traffic gateway method, system, device and medium based on same-intranet direct connection forwarding

PendingCN122293637APrivate IPWeb site
This invention provides a traffic gateway method, system, device, and medium based on direct intranet forwarding. The method includes: a client obtaining first proxy information and second proxy information, and sending traffic to be forwarded to the traffic gateway via a public network transmission channel according to the information; the traffic gateway receiving traffic carrying a target public IP address through the public network transmission channel corresponding to the first proxy information; replacing the target public IP address in the traffic with the private IP address of the corresponding business server in the intranet environment according to pre-configured network address translation rules; sending the replaced traffic to the business server via the intranet transmission channel corresponding to the second proxy information; and the business server receiving the traffic and forwarding it to the target website. This invention significantly reduces user traffic costs and greatly reduces enterprise operating costs by converting public network traffic into free intranet traffic.
Owner:FUJIAN ZIXUN INFORMATION TECH CO LTD

Methods, systems, and computer readable media for preserving network bandwidth during network address translation (NAT) device unavailability or after NAT device reboot

ActiveUS12652324B2TransmissionSession Initiation ProtocolInternet privacy
A method for preserving network bandwidth during NAT device unavailability or after a NAT device reboot includes receiving, by a session initiation protocol (SIP) proxy, messages from SIP endpoints, determining, by the SIP proxy, that at least some of the SIP endpoints are located behind a NAT device. The method further includes determining, by the SIP proxy, that the NAT device is potentially unavailable or has potentially rebooted, testing, by the SIP proxy, reachability of at least some of the SIP endpoints located behind the NAT device and determining that the at least some of the SIP endpoints are unreachable, classifying, by the SIP proxy, all of the SIP endpoints located behind the NAT device as unreachable, and rejecting, by the SIP proxy, SIP messages directed towards the SIP endpoints located behind the NAT device.
Owner:ORACLE INT CORP

Protocol independent multicast (PIM) across transport network

ActiveUS12652241B2Special service provision for substationEngineeringNetwork address translation
Techniques are disclosed for sending Protocol Independent Multicast (PIM) messages across a Layer-3 (L3) transport network. In one example, a first network device receives, via an L2 network from a multicast sender device, a multicast packet for a multicast group associated with a multicast service. The first network device generates, based on the multicast packet, a unicast L3 packet comprising a PIM register request configured to register the first network device as a multicast source for the multicast group. A header of the unicast L3 packet specifies a source address comprising a network address translation (NAT) to an address of a virtual loopback interface of a second network device. The virtual loopback interface is associated with a PIM service between the first and second network devices for the multicast service. The first network device forwards the unicast L3 packet across an L3 transport network to the second network device.
Owner:JUNIPER NETWORKS INC

Regional network address translation gateways for cloud computing resources

A regional network address translation gateway (RNG) is established for traffic of a virtual private cloud (VPC) of a customer of a cloud computing environment. In response to detecting that an application resource has been activated in an availability zone (AZ) of a region for which the RNG is established, and that the RNG does not include resources for processing traffic of that AZ, a set of resources is allocated to the RNG for traffic of the AZ. The set of resources of the RNG is used to cause a network address assigned to the RNG to be set as a source address of a packet originating at the application resource before the packet is delivered to a destination.
Owner:AMAZON TECH INC

Session management method and apparatus, electronic device, and storage medium

ActiveCN116886753BData packSession management
The application provides a session management method and device, electronic equipment and storage medium, relates to the technical field of communication, and the method comprises the following steps: receiving a session request for a target device; obtaining a target network address translation (NAT) session to which the session request belongs; determining a timeout duration of the target NAT session according to a target data transmission protocol corresponding to the session request; updating a timeout time of the target NAT session according to the timeout duration and a current time; adding the updated target NAT session into a double-linked list corresponding to the target data transmission protocol; and deleting a NAT session that is timed out in the double-linked list corresponding to the target data transmission protocol. By setting the double-linked list and the corresponding timeout duration according to the data transmission protocol, the deleted session can be deleted in time, and the retained session exists in the session all the time, so that the data packet forwarding efficiency is effectively improved, and resource waste is reduced.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +2