Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Private IP" patented technology

PIP in telecommunications and datacommunications stands for Private Internet Protocol or Private IP. PIP refers to connectivity into a private extranet network which by its design emulates the functioning of the Internet. Specifically, the Internet uses a routing protocol called border gateway protocol (BGP), as do most multiprotocol label switching (MPLS) networks. With this design, there is an ambiguity to the route that a packet can take while traversing the network. Wherein the Internet is a public offering, MPLS PIP networks are private. This lends a known, often used, and comfortable network design model for private implementation.

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Method for Configuring Network Address Translation Gateway and Cloud Management Platform

A method for configuring a network address translation NAT gateway based on a public cloud service including: a cloud management platform obtains NAT gateway creation information that is input by a tenant; The cloud management platform creates the NAT gateway in the first VPC based on the NAT gateway creation information; The cloud management platform obtains configuration information that is input by the tenant and applied to the NAT gateway; The cloud management platform sets, based on the identifier of the second VPC, the NAT gateway to be connected to the second VPC, and sends the first NAT rule to the NAT gateway, where the first NAT rule is used to indicate the NAT gateway to: bind a first network segment in the first VPC to a first elastic IP address EIP; and bind the first network segment in the first VPC to a first transit private IP address.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Method and system for configuring management IP addresses for virtual security protection products

ActiveCN115801734BNetworks interconnectionPrivate IPVirtualization
This invention provides a method and system for configuring the management IP address of virtual security protection products, belonging to the field of virtualization protection technology. The method for configuring the management IP address of virtual security protection products includes the following steps: constructing a local area network (LAN) between a controller and multiple virtual security protection products; assigning a private IP address to each virtual security protection product; the controller establishing a connection with each virtual security protection product through the private IP address and issuing a management IP address configuration for each virtual security protection product; and the virtual security protection product configuring its management IP address according to the management IP address configuration. This method and system solve the problem of cumbersome and inefficient manual configuration of virtual security protection product management IP addresses in existing technologies that require entering a cloud environment.
Owner:BEIJING LIUFANG CLOUD TECH CO LTD

Dynamically scalable application firewall deployment for cloud native applications

A configuration of a cloud application exposed via a public IP address is duplicated with modifications to include a private IP address to expose the application internally. The original configuration is updated so that external network traffic sent to the application is redirected to and distributed across agents running on nodes of a cloud cluster by which web application firewalls (WAFs) are implemented. A set of agents for which the respective WAFs should inspect the redirected network traffic are selected based on cluster metrics, such as network and resource utilization metrics. The redirected network traffic targets a port allocated to the agents that is unique to the application, where ports are allocated on a per-application basis so each of the agents can support WAF protection for multiple applications. Network traffic which a WAF allows to pass is directed from the agent to the application via its private IP address.
Owner:PALO ALTO NETWORKS INC

Sdwan data-plane resiliency for extended survivability

PendingUS20260135832A1TransmissionPrivate IPSurvivability
The present technology provides solutions for maintaining communications within a software-defined wide area network (SDWAN) when one or more devices in the SDWAN are isolated from one or more controllers. An example method includes receiving, at a static edge device associated with a static wide area network (WAN) Internet Protocol (IP) address in a data plane of the SDWAN, data from a first device communicating through an edge device of a first Internet service provider (ISP) of the SDWAN, where the first device is associated with a private IP address, associating, by the static edge device, the first device with the private IP address, and communicating, by the static edge device, with the first device at the private IP address. Systems and computer-readable media are also provided.
Owner:CISCO TECHNOLOGY INC

Freeswitch cluster capacity expansion system and device based on NAT (Network Address Translation) equipment

PendingCN121924012ATransmissionPrivate IPVoice communication
The invention discloses a freeswitch cluster capacity expansion system and device based on NAT (Network Address Translation) equipment, and relates to the technical field of cluster capacity expansion. The system comprises a virtual private cloud, an NAT (Network Address Translation) device, a freeswitch cluster and a port mapping configuration module, wherein the virtual private cloud is used for carrying out network planning and security configuration on the virtual private cloud according to actual requirements; the NAT equipment is deployed at a boundary position of the virtual private cloud and an external network, and a voice communication request sent by the external network to a specific public network IP and a port is converted into a private IP and a corresponding port of an internal freeswitch cluster node by configuring a DNAT rule of the NAT equipment; the freeswitch cluster consists of a plurality of freeswitch nodes, is uniformly distributed in a second subnet in the virtual private cloud, and is used for realizing call request processing of cluster load balance based on internal communication; and the port mapping configuration module is used for carrying out corresponding port mapping setting on the NAT equipment according to a service port provided by the freeswitch cluster node.
Owner:BEIJING HUBOTE ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Mobile terminal roaming communication method and system and mobile terminal

The embodiment of the invention relates to the technical field of DECT, and discloses a mobile terminal roaming communication method and system and a mobile terminal. The method comprises the following steps: starting a wireless local area network mode so as to send a first mode switching notification to a main base station through a wireless local area network; adjacent station information sent by the main base station through the wireless local area network is received; determining a roaming base station according to the adjacent station information so as to initiate and successfully complete a registration request to the roaming base station; when the terminal initiates or responds to a DECT voice call through the roaming base station, a cross-base-station voice communication link is established through private IP network connection established based on an IP address between the roaming base station and the main base station; wherein the mobile terminal, the main base station and the roaming base station are located in the coverage range of the same local area network. The roaming of the mobile equipment between the base stations can be realized at least under the condition that time synchronization between the DECT base stations is not needed and additional equipment is not needed.
Owner:SHENZHEN GRANDSTREAM NETWORKS TECH

Internet of Things private network flow processing method and related equipment

The invention discloses an Internet of Things private network flow processing method and related equipment. The method comprises the following steps: acquiring session flow between a base station and a terminal and flow direction of the session flow; determining the flow type of the session flow based on the flow direction; when the flow type of the session flow is uplink three-layer session flow, converting a target IP of the session flow into a local private IP, executing downlink packet receiving processing on a flow message, and sending the flow message to the terminal; and when the flow type of the session flow is the downlink three-layer session flow, replacing the local private IP with the target IP of the session flow, and sending the flow data to the terminal. The method can be widely applied to the technical field of network resource scheduling.
Owner:E SURFING IOT CO LTD

Managing internet protocol (IP) address allocation to tenants in a computing environment

Described herein are systems, methods, and software to manage internet protocol (IP) address allocation for tenants in a computing environment. In one implementation, a logical router associated with a tenant in the computing environment requests a public IP address for a new segment instance from a controller. In response to the request, the controller may select a public IP address from a pool of available IP addresses and update networking address translation (NAT) on the logical router to associate the public IP address with a private IP address allocated to the new segment instance.
Owner:VMWARE INC

Wireless broadband communication integration process for business IP phone system

PendingUS20260082282A1Wireless communicationPrivate IPWiBro
Systems and methods for a dual-functional modular system for providing Internet Protocol (IP) phones with wireless broadband capabilities and a handoff from public cellular networks to a private business system. The method may include providing a plurality of IP phones with one or more modular Long-Term Evolution (LTE) upgrade units, wherein the plurality of IP phones gain LTE endpoint features; configuring the one or more units to connect to a private IP network; continuously monitoring signal strength of a public LTE network and the private IP network; detecting a mobile device with an active call; when the private IP network provides a more stable connection, initiating a handoff from the public LTE network to the IP network; transferring the active call data to an available LTE-equipped IP phone; monitoring the IP network; and when the IP network becomes unstable, reverting service of the active call to the public LTE network.
Owner:MITEL CORP

Supplemental DNAT for communication within overlapping IP address space in a private network

ActiveUS12598159B2Securing communicationPrivate IPPrivate network
A system may receive, at a firewall, a data packet destined to a conflicting private IP address of the first private subnetwork and the second private subnetwork within the private network, the data packet including a destination IP address identifying the firewall. The system may evaluate, at the firewall, the data packet to determine whether a source IP address of the data packet satisfies a routing condition corresponding to a routing rule. The system may apply, at the firewall, the routing rule to determine a translated destination IP address of the first private subnetwork. The system may send the data packet to the first private subnetwork.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Generation of static and dynamic secret keys to prevent distributed denial-of-service attacks

A computer-implemented method performed at a processing server includes receiving, from a client device, a request to connect to an application server. The method further includes identifying a targeted application server from a set of application servers. The method further includes mapping a private internet protocol (IP) address for the targeted application server to a virtual IP (VIP) address associated with one or more demultiplexers. The method further includes generating a token based on a current secret key, wherein the token includes an indication of whether the token was generated using a static secret key or a particular dynamic secret key. The method further includes transmitting the VIP address, the private IP address, and the token to the client device.
Owner:ROBLOX CORP

Region-based network address translation

ActiveUS12457190B1TransmissionData packPrivate IP
Apparatus and methods are disclosed for geographic region-based network address translation (NAT) between a public network and a private network. In certain examples, region-based NAT may assist to reduce latency, enhance quality, enhance security, and / or improve efficiency of network communications. In response to a data packet from a first port of a private IP address, of an endpoint in the private network, a region of the private network that includes an endpoint identified by the private IP address is determined. A public IP address is selected that is mapped to the determined region in the database. An available port of the selected public IP address is assigned for NAT. NAT is performed for data communicated between the public and private networks using a mapping of the first port of the first IP address to the second port of the second IP address.
Owner:8X8 INC

Centralized IP address management and security access control in service access service edge (SASE)

PCT designated stageWO2026177886A1Private IPInternet privacy
Various techniques for centralized IP address management and secure access control in SASE are disclosed. In some embodiments, a system, a process, and / or a computer program product for centralized IP address management and secure access control in SASE includes receiving, at a gateway, a request for a secure tunnel connection for a mobile user endpoint to communicate with a secure access service edge (SASE) cloud environment; assigning a private IP address from a consistent IP address pool for the secure tunnel connection to the mobile user endpoint; and monitoring a plurality of active user sessions across the SASE cloud environment for a global view of private IP address assignments.
Owner:PALO ALTO NETWORKS INC

A method, apparatus, medium, device and product for data packet transmission

The application relates to the technical field of data transmission, and particularly provides a data packet transmission method, device, medium, equipment and product. The method can comprise the following steps: receiving a data packet conforming to an access control policy; wherein the access control policy represents a data packet type allowed to be sent by a network security engine; determining an application protocol type in a reverse proxy policy associated with the access control policy; wherein the reverse proxy policy comprises a private IP number, a private port number, a network protocol type and the application protocol type; the application protocol type comprises a general protocol, a multicast protocol or an audio / video protocol; calling a protocol interface function corresponding to the application protocol type to detect the data packet, and obtaining a detection result; wherein the detection result represents whether to block the data packet from continuing transmission. The application embodiment can improve the reverse proxy performance and realize effective transmission of various protocol data.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Linking resource instances to virtual network in provider network environments

ActiveUS12494997B2Securing communicationPrivate IPNetwork on
Methods and apparatus that allow clients to connect resource instances to virtual networks in provider network environments via private IP. Via private IP linking methods and apparatus, a client of a provider network can establish private IP communications between the client's resource instances on the provider network and the client's resource instances provisioned in the client's virtual network via links from the private IP address space of the virtual network to the private IP address space of the provider network. The provider network client resource instances remain part of the client's provider network implementation and may thus also communicate with other resource instances on the provider network and / or with entities on external networks via public IP while communicating with the virtual network resource instances via private IP.
Owner:AMAZON TECH INC

VPN CLIENT CREATION IN A SINGLE STACK IPv6

A method includes creating a virtual adapter at an endpoint that is configured for split tunneling of data traffic via a virtual private network (VPN) connection with an internet protocol version 6 (IPv6) only internal network. The method includes assigning only an IPv6 address to the virtual adapter, such that it does not have an internet protocol version 4 (IPv4) address or an automatic private IP address (APIPA) IPv4 address. The method includes blocking domain name server (DNS) traffic when a source internet protocol (IP) address of the DNS traffic being a physical adapter IP address of a physical adapter. The method includes accessing excluded resources configured for IPv4 and IPv6 split tunneling policies via the physical adapter, forcing access to excluded IPv4 only resources via the physical adapter in DNS64 / NAT64 environments, and forcing applications that prefer IPv4 over IPv6 to use IPv6 while accessing dual stack resources.
Owner:IVANTI INC

SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT

A system for providing dual network address translation, comprising a Network Operations Center (NOC) which has a memory component, wherein the memory component stores logic which, when executed by a processor, causes the system to perform at least the following: Receiving data from a user workstation over a wide area network, wherein the data is received via a first Virtual Private Network (VPN) tunnel, wherein the data is encrypted using VPN encryption, and wherein the data is assigned a Unique Private Internet Protocol (UPIP) address that overlaps with a customer-defined private IP address and includes a security barrier; Removing VPN encryption from the data; Using a Twin-NAT-Network Address Translation (NAT) component to remove the UPIP address and replace it with the customer-defined private IP address from a private network at a destination; Packaging the data with the customer-defined private IP address in a privately defined protocol that includes the public source address and the public destination address; and Using a second VPN tunnel to transmit the data to the destination.
Owner:E NAT TECHNOLOGIES LLC

A DPU-based cloud host live migration network scheme

ActiveCN118353956BTransmissionPrivate IPNetwork addressing
The application discloses a cloud host network migration scheme based on DPU, and comprises the following steps: S1, basic network configuration; S2, out direction traffic identification and forwarding flow table configuration; and S3, in direction traffic identification and forwarding configuration. The scheme does not need additional planning calculation of private IP addresses, does not involve SNAT, and does not additionally design vpc and overlay, so that network migration channels are realized by utilizing PF and reusing original calculation internal network addresses, and the bandwidth of the migration network is ensured.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method for obtaining information, communication device, and storage medium

PendingUS20250365351A1TransmissionPrivate IPTelecommunications
A method for obtaining information includes: receiving, by a first communication device, a first request, where the first request is used for requesting to obtain first information; and the first information comprises at least one of the following: a second internet protocol (IP) address corresponding to a first IP address; a mapping relationship between the first IP address and the second IP address; the second IP address; or a second port number, where the second port number is associated with the second IP address; and the first IP address is a private IP address, and the second IP address is a public IP address.
Owner:VIVO MOBILE COMM CO LTD

Method and system for managing internet protocol address of user equipment in a network

PCT designated stageWO2026033533A1TransmissionNetwork data managementQuality of servicePrivate IP
The disclosure provides a method for managing an internet protocol (IP) address of a user equipment (UE) 502 in a network 106. A first network element such as a control plane 506 assigns a first dynamic private IP address to the UE 502 upon session creation and creates session mapping between the first dynamic private IP and a static public IP address and a port address in a second network element, such as a Public Internet Protocol (IP) Gateway (PIG) 510. The session mapping is updated in real-time based on session events. The second network element routes uplink and downlink traffic according to the maintained mapping. Upon session termination, the mapping is deleted to release IP resources. This approach enables efficient reuse of static public IPs across multiple users, reduces signaling overhead, and improves IP address utilization without compromising session continuity or service quality.
Owner:JIO PLATFORMS LTD

Cloud infrastructure resources for connecting a service provider private network to a customer private network

PendingUS20250317415A1TransmissionPrivate IPPrivate network
Techniques for providing, to a resource on a private network of a service provider, access to a resource on a private network of a customer. Service to customer (S2C) resources deployed on a cloud infrastructure to facilitate the access. Whereas IP address ranges may overlap between private networks and / or private IP addresses may be used in one or more of the private networks, the S2C resources enable the data exchange between the private networks. For example, the S2C resources translate between IP addresses such that data within each private network uses IP addresses that can be properly processed by the private network.
Owner:ORACLE INT CORP

Traffic control method and related device

Embodiments disclose methods and devices for traffic control. A border gateway protocol (BGP) route advertisement message is sent by a control management device, where the message advertises a virtual private network (VPN) route instructing a device to redirect a VPN route to iterate to a first next hop (a private IP address) of a private network (towards reaching an IP address prefix), the IP address prefix to a destination host, and a network address of the first next hop towards reaching the IP address prefix. A virtual routing and forwarding (VRF) entry, including the IP address prefix and outbound interface information connected to the first next hop, is generated based on the indication information. The outbound interface information is determined in a local VRF table based on the indication information and network address of the first next hop, and the VRF entry is generated and used for controlling network traffic.
Owner:HUAWEI TECH CO LTD

SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT

A system for providing a ReNAT Virtual Private Network (VPN), comprising: a ReNAT Virtual Private Network (VPN) component implemented in a Network Operations Center (NOC) and storing logic which, when executed by a processor, causes the system to perform at least the following: receive, at the NOC, external packets from a client workstation on a private network; provide source addressing for the external packets to identify the private network from which the external packets were received; receive data from the external packets from a ReNAT Twin NAT, wherein the ReNAT Twin NAT contains both a public destination address and a public source address for the data;and decrypting the data and forwarding the data with the public source address to the ReNAT Twin NAT, wherein the NOC provides a Virtual Private Network within the NOC to support communication of the data between a remote computing device over a wide area network and the client workstation in the private network; and wherein the ReNAT Twin NAT assigns a Unique Private IP Address (UPIP) that overlaps with a customer-assigned private IP address, and wherein the UPIP is unique within the NOC and is mapped to a public IP by a session manager.
Owner:E NAT TECHNOLOGIES LLC

Method, apparatus, device and medium for providing services for terminals in a local network

ActiveCN116389555BAvoid private IPAvoid the same private network IPPrivate IPTelecommunications
Embodiments of the present application provide a method, device, equipment and medium for providing services for terminals in a local area network, different port numbers are allocated to different home broadband account numbers by a cloud gateway device, a request message for requesting a certain service in the cloud gateway device is received from a terminal in a local area network corresponding to a home broadband account number, a destination IP address in the request message is an IP address of the cloud gateway device, and a destination port number is a port number corresponding to the home broadband account number corresponding to the terminal, thus the cloud gateway device can distinguish the request messages corresponding to different home broadband account numbers through the port number corresponding to the home broadband account number, and respond to the request messages to provide services for the terminals in the local area network corresponding to different home account numbers, so that the private IP of the terminals in the local area network corresponding to different home account numbers is the same, the corresponding terminal in the local area network cannot be responded to, and services cannot be provided.
Owner:WUHAN GREENET INFORMATION SERVICE

Secure address discovery for symmetric NAT functionality

In an enterprise having a local endpoint located behind a Symmetric NAT node, the local endpoint distributes its public IP address for endpoint packets to remote endpoints by generating probe packets having the local endpoint's private IP address as the source address in an outer IP header and the local endpoint's ID as the source address in an inner IP header. The Sym-NAT node replaces the private IP address with the public IP address for endpoint packets as the outer IP header's source address. Each remote endpoint uses the local endpoint's ID in the probe packet's inner IP header and uplink information from decrypted probe data to identify the source address in the probe packet's outer IP header as the local endpoint's public IP address for endpoint packets, thereby solving the problem of remote nodes receiving only the local endpoint's public IP address for controller packets from the enterprise controller.
Owner:NOKIA SOLUTIONS & NETWORKS OY

DNS traffic routing for ues with the same IP address

PCT designated stageWO2025181117A1Connection managementTransmissionPrivate IPTelecommunications
Disclosed herein is at least a method performed by a V-SMF) in a VPLMN for Home Routed (HR) Session Breakout (SBO) for a PDU session of a UE using a private Internet Protocol, IP, address. The method comprises: obtaining tunneling information for establishing a tunnel between a V-UPF and a V-EASDF (e.g., for HR-SBO of the PDU session of the UE using the private IP address); and performing one or more operations based on the obtained tunneling information, the one or more operations being related to establishing a tunnel between the V-UPF and the V-EASDF (e.g., for HR-SBO of the PDU session of the UE using the private IP address).
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT

System for providing Redundant Network Address Translation (ReNAT) communication, which includes a Network Operations Center (NOC), wherein the NOC includes: a computing device comprising a processor and a memory for storing logic, and comprising at least the following: a first private network component that initiates communication with a private network; a ReNAT Twin Network Address Translation (NAT) coupled with the first private network component, wherein the ReNAT Twin NAT translates between a customer-assigned private Internet Protocol (IP) address and a Unique Private IP (UPIP) address, the UPIP overlapping with a customer-assigned private IP address space and the UPIP being unique in the NOC; a private ReNAT network component coupled with the ReNAT Twin NAT, wherein the private ReNAT network component provides a source IP address to the ReNAT Twin NAT; and a communication logic that enables the system to support communication with a workstation that has a ReNAT Twin NAT client, wherein the address translation is performed by the ReNAT Twin NAT client, wherein the ReNAT Twin NAT addresses in the data are mapped to customer-defined private addresses, and wherein the private ReNAT network component transmits the data to the private network.
Owner:E NAT TECHNOLOGIES LLC

Management of domain name system (DNS) queries in computing systems

PendingUS20250317416A1Networks interconnectionDomain namePrivate IP
The technology described herein manages the direction of domain name system (DNS) queries to different DNS servers. In one implementation, a method of operating a computing system includes receiving, from a coordination service for a private network, a private Internet Protocol (IP) address of a destination on the private network, a public IP address of the destination on a public network, and an indication that a domain name corresponding to the private IP address should be resolved at a local Domain Name System (DNS) executing on the computing element. The method further includes identifying a DNS request generated by an application executing on the computing element and, in response to that identification, forwarding the DNS request to the local DNS rather than an external DNS. In response to receiving the private IP address from the local DNS, the method includes passing the private IP address to the application.
Owner:TAILSCALE INC