Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

29 results about "Private IP" patented technology

PIP in telecommunications and datacommunications stands for Private Internet Protocol or Private IP. PIP refers to connectivity into a private extranet network which by its design emulates the functioning of the Internet. Specifically, the Internet uses a routing protocol called border gateway protocol (BGP), as do most multiprotocol label switching (MPLS) networks. With this design, there is an ambiguity to the route that a packet can take while traversing the network. Wherein the Internet is a public offering, MPLS PIP networks are private. This lends a known, often used, and comfortable network design model for private implementation.

Method for Configuring Network Address Translation Gateway and Cloud Management Platform

A method for configuring a network address translation NAT gateway based on a public cloud service including: a cloud management platform obtains NAT gateway creation information that is input by a tenant; The cloud management platform creates the NAT gateway in the first VPC based on the NAT gateway creation information; The cloud management platform obtains configuration information that is input by the tenant and applied to the NAT gateway; The cloud management platform sets, based on the identifier of the second VPC, the NAT gateway to be connected to the second VPC, and sends the first NAT rule to the NAT gateway, where the first NAT rule is used to indicate the NAT gateway to: bind a first network segment in the first VPC to a first elastic IP address EIP; and bind the first network segment in the first VPC to a first transit private IP address.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Method and system for configuring management IP addresses for virtual security protection products

ActiveCN115801734BNetworks interconnectionPrivate IPVirtualization
This invention provides a method and system for configuring the management IP address of virtual security protection products, belonging to the field of virtualization protection technology. The method for configuring the management IP address of virtual security protection products includes the following steps: constructing a local area network (LAN) between a controller and multiple virtual security protection products; assigning a private IP address to each virtual security protection product; the controller establishing a connection with each virtual security protection product through the private IP address and issuing a management IP address configuration for each virtual security protection product; and the virtual security protection product configuring its management IP address according to the management IP address configuration. This method and system solve the problem of cumbersome and inefficient manual configuration of virtual security protection product management IP addresses in existing technologies that require entering a cloud environment.
Owner:BEIJING LIUFANG CLOUD TECH CO LTD

Sdwan data-plane resiliency for extended survivability

PendingUS20260135832A1TransmissionPrivate IPSurvivability
The present technology provides solutions for maintaining communications within a software-defined wide area network (SDWAN) when one or more devices in the SDWAN are isolated from one or more controllers. An example method includes receiving, at a static edge device associated with a static wide area network (WAN) Internet Protocol (IP) address in a data plane of the SDWAN, data from a first device communicating through an edge device of a first Internet service provider (ISP) of the SDWAN, where the first device is associated with a private IP address, associating, by the static edge device, the first device with the private IP address, and communicating, by the static edge device, with the first device at the private IP address. Systems and computer-readable media are also provided.
Owner:CISCO TECHNOLOGY INC

Freeswitch cluster capacity expansion system and device based on NAT (Network Address Translation) equipment

PendingCN121924012ATransmissionPrivate IPVoice communication
The invention discloses a freeswitch cluster capacity expansion system and device based on NAT (Network Address Translation) equipment, and relates to the technical field of cluster capacity expansion. The system comprises a virtual private cloud, an NAT (Network Address Translation) device, a freeswitch cluster and a port mapping configuration module, wherein the virtual private cloud is used for carrying out network planning and security configuration on the virtual private cloud according to actual requirements; the NAT equipment is deployed at a boundary position of the virtual private cloud and an external network, and a voice communication request sent by the external network to a specific public network IP and a port is converted into a private IP and a corresponding port of an internal freeswitch cluster node by configuring a DNAT rule of the NAT equipment; the freeswitch cluster consists of a plurality of freeswitch nodes, is uniformly distributed in a second subnet in the virtual private cloud, and is used for realizing call request processing of cluster load balance based on internal communication; and the port mapping configuration module is used for carrying out corresponding port mapping setting on the NAT equipment according to a service port provided by the freeswitch cluster node.
Owner:BEIJING HUBOTE ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Wireless broadband communication integration process for business IP phone system

PendingUS20260082282A1Wireless communicationPrivate IPWiBro
Systems and methods for a dual-functional modular system for providing Internet Protocol (IP) phones with wireless broadband capabilities and a handoff from public cellular networks to a private business system. The method may include providing a plurality of IP phones with one or more modular Long-Term Evolution (LTE) upgrade units, wherein the plurality of IP phones gain LTE endpoint features; configuring the one or more units to connect to a private IP network; continuously monitoring signal strength of a public LTE network and the private IP network; detecting a mobile device with an active call; when the private IP network provides a more stable connection, initiating a handoff from the public LTE network to the IP network; transferring the active call data to an available LTE-equipped IP phone; monitoring the IP network; and when the IP network becomes unstable, reverting service of the active call to the public LTE network.
Owner:MITEL CORP

Supplemental DNAT for communication within overlapping IP address space in a private network

ActiveUS12598159B2Securing communicationPrivate IPPrivate network
A system may receive, at a firewall, a data packet destined to a conflicting private IP address of the first private subnetwork and the second private subnetwork within the private network, the data packet including a destination IP address identifying the firewall. The system may evaluate, at the firewall, the data packet to determine whether a source IP address of the data packet satisfies a routing condition corresponding to a routing rule. The system may apply, at the firewall, the routing rule to determine a translated destination IP address of the first private subnetwork. The system may send the data packet to the first private subnetwork.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Generation of static and dynamic secret keys to prevent distributed denial-of-service attacks

A computer-implemented method performed at a processing server includes receiving, from a client device, a request to connect to an application server. The method further includes identifying a targeted application server from a set of application servers. The method further includes mapping a private internet protocol (IP) address for the targeted application server to a virtual IP (VIP) address associated with one or more demultiplexers. The method further includes generating a token based on a current secret key, wherein the token includes an indication of whether the token was generated using a static secret key or a particular dynamic secret key. The method further includes transmitting the VIP address, the private IP address, and the token to the client device.
Owner:ROBLOX CORP

Centralized IP address management and security access control in service access service edge (SASE)

PCT designated stageWO2026177886A1Private IPInternet privacy
Various techniques for centralized IP address management and secure access control in SASE are disclosed. In some embodiments, a system, a process, and / or a computer program product for centralized IP address management and secure access control in SASE includes receiving, at a gateway, a request for a secure tunnel connection for a mobile user endpoint to communicate with a secure access service edge (SASE) cloud environment; assigning a private IP address from a consistent IP address pool for the secure tunnel connection to the mobile user endpoint; and monitoring a plurality of active user sessions across the SASE cloud environment for a global view of private IP address assignments.
Owner:PALO ALTO NETWORKS INC

A method, apparatus, medium, device and product for data packet transmission

The application relates to the technical field of data transmission, and particularly provides a data packet transmission method, device, medium, equipment and product. The method can comprise the following steps: receiving a data packet conforming to an access control policy; wherein the access control policy represents a data packet type allowed to be sent by a network security engine; determining an application protocol type in a reverse proxy policy associated with the access control policy; wherein the reverse proxy policy comprises a private IP number, a private port number, a network protocol type and the application protocol type; the application protocol type comprises a general protocol, a multicast protocol or an audio / video protocol; calling a protocol interface function corresponding to the application protocol type to detect the data packet, and obtaining a detection result; wherein the detection result represents whether to block the data packet from continuing transmission. The application embodiment can improve the reverse proxy performance and realize effective transmission of various protocol data.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Linking resource instances to virtual network in provider network environments

ActiveUS12494997B2Securing communicationPrivate IPNetwork on
Methods and apparatus that allow clients to connect resource instances to virtual networks in provider network environments via private IP. Via private IP linking methods and apparatus, a client of a provider network can establish private IP communications between the client's resource instances on the provider network and the client's resource instances provisioned in the client's virtual network via links from the private IP address space of the virtual network to the private IP address space of the provider network. The provider network client resource instances remain part of the client's provider network implementation and may thus also communicate with other resource instances on the provider network and / or with entities on external networks via public IP while communicating with the virtual network resource instances via private IP.
Owner:AMAZON TECH INC

VPN CLIENT CREATION IN A SINGLE STACK IPv6

A method includes creating a virtual adapter at an endpoint that is configured for split tunneling of data traffic via a virtual private network (VPN) connection with an internet protocol version 6 (IPv6) only internal network. The method includes assigning only an IPv6 address to the virtual adapter, such that it does not have an internet protocol version 4 (IPv4) address or an automatic private IP address (APIPA) IPv4 address. The method includes blocking domain name server (DNS) traffic when a source internet protocol (IP) address of the DNS traffic being a physical adapter IP address of a physical adapter. The method includes accessing excluded resources configured for IPv4 and IPv6 split tunneling policies via the physical adapter, forcing access to excluded IPv4 only resources via the physical adapter in DNS64 / NAT64 environments, and forcing applications that prefer IPv4 over IPv6 to use IPv6 while accessing dual stack resources.
Owner:IVANTI INC

SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT

A system for providing dual network address translation, comprising a Network Operations Center (NOC) which has a memory component, wherein the memory component stores logic which, when executed by a processor, causes the system to perform at least the following: Receiving data from a user workstation over a wide area network, wherein the data is received via a first Virtual Private Network (VPN) tunnel, wherein the data is encrypted using VPN encryption, and wherein the data is assigned a Unique Private Internet Protocol (UPIP) address that overlaps with a customer-defined private IP address and includes a security barrier; Removing VPN encryption from the data; Using a Twin-NAT-Network Address Translation (NAT) component to remove the UPIP address and replace it with the customer-defined private IP address from a private network at a destination; Packaging the data with the customer-defined private IP address in a privately defined protocol that includes the public source address and the public destination address; and Using a second VPN tunnel to transmit the data to the destination.
Owner:E NAT TECHNOLOGIES LLC

A DPU-based cloud host live migration network scheme

ActiveCN118353956BTransmissionPrivate IPNetwork addressing
The application discloses a cloud host network migration scheme based on DPU, and comprises the following steps: S1, basic network configuration; S2, out direction traffic identification and forwarding flow table configuration; and S3, in direction traffic identification and forwarding configuration. The scheme does not need additional planning calculation of private IP addresses, does not involve SNAT, and does not additionally design vpc and overlay, so that network migration channels are realized by utilizing PF and reusing original calculation internal network addresses, and the bandwidth of the migration network is ensured.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method for obtaining information, communication device, and storage medium

PendingUS20250365351A1TransmissionPrivate IPTelecommunications
A method for obtaining information includes: receiving, by a first communication device, a first request, where the first request is used for requesting to obtain first information; and the first information comprises at least one of the following: a second internet protocol (IP) address corresponding to a first IP address; a mapping relationship between the first IP address and the second IP address; the second IP address; or a second port number, where the second port number is associated with the second IP address; and the first IP address is a private IP address, and the second IP address is a public IP address.
Owner:VIVO MOBILE COMM CO LTD

Method and system for managing internet protocol address of user equipment in a network

PCT designated stageWO2026033533A1TransmissionNetwork data managementQuality of servicePrivate IP
The disclosure provides a method for managing an internet protocol (IP) address of a user equipment (UE) 502 in a network 106. A first network element such as a control plane 506 assigns a first dynamic private IP address to the UE 502 upon session creation and creates session mapping between the first dynamic private IP and a static public IP address and a port address in a second network element, such as a Public Internet Protocol (IP) Gateway (PIG) 510. The session mapping is updated in real-time based on session events. The second network element routes uplink and downlink traffic according to the maintained mapping. Upon session termination, the mapping is deleted to release IP resources. This approach enables efficient reuse of static public IPs across multiple users, reduces signaling overhead, and improves IP address utilization without compromising session continuity or service quality.
Owner:JIO PLATFORMS LTD

Traffic control method and related device

Embodiments disclose methods and devices for traffic control. A border gateway protocol (BGP) route advertisement message is sent by a control management device, where the message advertises a virtual private network (VPN) route instructing a device to redirect a VPN route to iterate to a first next hop (a private IP address) of a private network (towards reaching an IP address prefix), the IP address prefix to a destination host, and a network address of the first next hop towards reaching the IP address prefix. A virtual routing and forwarding (VRF) entry, including the IP address prefix and outbound interface information connected to the first next hop, is generated based on the indication information. The outbound interface information is determined in a local VRF table based on the indication information and network address of the first next hop, and the VRF entry is generated and used for controlling network traffic.
Owner:HUAWEI TECH CO LTD

SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT

A system for providing a ReNAT Virtual Private Network (VPN), comprising: a ReNAT Virtual Private Network (VPN) component implemented in a Network Operations Center (NOC) and storing logic which, when executed by a processor, causes the system to perform at least the following: receive, at the NOC, external packets from a client workstation on a private network; provide source addressing for the external packets to identify the private network from which the external packets were received; receive data from the external packets from a ReNAT Twin NAT, wherein the ReNAT Twin NAT contains both a public destination address and a public source address for the data;and decrypting the data and forwarding the data with the public source address to the ReNAT Twin NAT, wherein the NOC provides a Virtual Private Network within the NOC to support communication of the data between a remote computing device over a wide area network and the client workstation in the private network; and wherein the ReNAT Twin NAT assigns a Unique Private IP Address (UPIP) that overlaps with a customer-assigned private IP address, and wherein the UPIP is unique within the NOC and is mapped to a public IP by a session manager.
Owner:E NAT TECHNOLOGIES LLC

Method, apparatus, device and medium for providing services for terminals in a local network

ActiveCN116389555BAvoid private IPAvoid the same private network IPPrivate IPTelecommunications
Embodiments of the present application provide a method, device, equipment and medium for providing services for terminals in a local area network, different port numbers are allocated to different home broadband account numbers by a cloud gateway device, a request message for requesting a certain service in the cloud gateway device is received from a terminal in a local area network corresponding to a home broadband account number, a destination IP address in the request message is an IP address of the cloud gateway device, and a destination port number is a port number corresponding to the home broadband account number corresponding to the terminal, thus the cloud gateway device can distinguish the request messages corresponding to different home broadband account numbers through the port number corresponding to the home broadband account number, and respond to the request messages to provide services for the terminals in the local area network corresponding to different home account numbers, so that the private IP of the terminals in the local area network corresponding to different home account numbers is the same, the corresponding terminal in the local area network cannot be responded to, and services cannot be provided.
Owner:WUHAN GREENET INFORMATION SERVICE

Secure address discovery for symmetric NAT functionality

In an enterprise having a local endpoint located behind a Symmetric NAT node, the local endpoint distributes its public IP address for endpoint packets to remote endpoints by generating probe packets having the local endpoint's private IP address as the source address in an outer IP header and the local endpoint's ID as the source address in an inner IP header. The Sym-NAT node replaces the private IP address with the public IP address for endpoint packets as the outer IP header's source address. Each remote endpoint uses the local endpoint's ID in the probe packet's inner IP header and uplink information from decrypted probe data to identify the source address in the probe packet's outer IP header as the local endpoint's public IP address for endpoint packets, thereby solving the problem of remote nodes receiving only the local endpoint's public IP address for controller packets from the enterprise controller.
Owner:NOKIA SOLUTIONS & NETWORKS OY

SYSTEMS AND METHODS FOR PROVIDING A RENAT COMMUNICATION ENVIRONMENT

System for providing Redundant Network Address Translation (ReNAT) communication, which includes a Network Operations Center (NOC), wherein the NOC includes: a computing device comprising a processor and a memory for storing logic, and comprising at least the following: a first private network component that initiates communication with a private network; a ReNAT Twin Network Address Translation (NAT) coupled with the first private network component, wherein the ReNAT Twin NAT translates between a customer-assigned private Internet Protocol (IP) address and a Unique Private IP (UPIP) address, the UPIP overlapping with a customer-assigned private IP address space and the UPIP being unique in the NOC; a private ReNAT network component coupled with the ReNAT Twin NAT, wherein the private ReNAT network component provides a source IP address to the ReNAT Twin NAT; and a communication logic that enables the system to support communication with a workstation that has a ReNAT Twin NAT client, wherein the address translation is performed by the ReNAT Twin NAT client, wherein the ReNAT Twin NAT addresses in the data are mapped to customer-defined private addresses, and wherein the private ReNAT network component transmits the data to the private network.
Owner:E NAT TECHNOLOGIES LLC

Communication method and communication apparatus

A communication method is provided. The method includes: An EES receives, from a terminal device, a first request message for obtaining an identifier of the terminal device, where the first request message includes a private IP address of the terminal device; the EES obtains a public IP address and a port number of the terminal device and sends, to an NEF, a second request message used to request the identifier of the terminal device, where the second request message includes the private IP address, and the public IP address and the port number of the terminal device; and the EES receives a response message from the NEF, where the response message includes the identifier of the terminal device, or the response message indicates that the obtaining fails.
Owner:HUAWEI TECH CO LTD

Traffic gateway method, system, device and medium based on same-intranet direct connection forwarding

PendingCN122293637APrivate IPWeb site
This invention provides a traffic gateway method, system, device, and medium based on direct intranet forwarding. The method includes: a client obtaining first proxy information and second proxy information, and sending traffic to be forwarded to the traffic gateway via a public network transmission channel according to the information; the traffic gateway receiving traffic carrying a target public IP address through the public network transmission channel corresponding to the first proxy information; replacing the target public IP address in the traffic with the private IP address of the corresponding business server in the intranet environment according to pre-configured network address translation rules; sending the replaced traffic to the business server via the intranet transmission channel corresponding to the second proxy information; and the business server receiving the traffic and forwarding it to the target website. This invention significantly reduces user traffic costs and greatly reduces enterprise operating costs by converting public network traffic into free intranet traffic.
Owner:FUJIAN ZIXUN INFORMATION TECH CO LTD

A data packet transmission method, device, apparatus and storage medium

PendingCN122179429ATransmissionPrivate IPData pack
This invention relates to a data packet transmission method, apparatus, device, and storage medium. The data packet transmission method includes: acquiring a first data packet to be transmitted to a first network device; wherein the first network device is located in an internal network environment; performing VXLAN encapsulation and first IP address translation on the first data packet through a leased line gateway module; wherein the leased line gateway module is a virtual software module located in a cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device; and transmitting the first data packet to the first network device through a leased line gateway device; wherein the leased line gateway device is a physical device located at the edge of the internal network environment. The method provided in this application achieves flexible routing configuration through a virtual software module, avoids IP conflicts, and reduces dependence on physical devices.
Owner:BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD +1

Air-ground unmanned cluster communication interaction and cooperative motion control method

The invention provides an air-ground unmanned cluster communication interaction and cooperative motion control method, which comprises the following steps of: 1, configuring a zerotier service, and constructing a logic local area network; step 2, distributing individual private IPs; 3, a DDS distributed communication system is built, and the unmanned cluster system publishes the state of the unmanned cluster system through a publishing / subscribing model provided by the DDS distributed communication system and subscribes other node information; 4, repeating the process, and automatically completing the allocation of the logic address by the cloud server; according to the invention, a software-defined network is utilized, a logic local area network is constructed on an operator public network, trunking communication without public network IP is realized, a DHCP service is utilized to automatically allocate an IP private IP address for a logic physical interface of each unmanned trunking system individual, the IP address hiding is realized, the security is increased, the own state is released, and other node information is subscribed. Direct communication between the nodes is realized, rapid large-scale deployment is realized, and the communication capability of the unmanned cluster system is improved.
Owner:EFY ZHIKONG (TIANJIN) TECH CO LTD

Wireless communication data acquisition method

The invention discloses a wireless communication data acquisition method, which relates to the technical field of wireless communication, and comprises the following steps of: deploying an edge acquisition node which supports dual-band communication and is internally provided with a network address translation gateway, performing logic subnet division on the edge acquisition node, and dynamically allocating a private IP (Internet Protocol) address; the normalized data packet in the JSON format is uploaded to a central scheduling server through an IPsec encryption tunnel; frequency bands are automatically switched or multi-path redundancy transmission is started in combination with link quality evaluation; data integrity verification, time sequence alignment and clock deviation compensation are carried out at the server side; and meanwhile, an electromagnetic interference suppression module and a lightweight anomaly detection model are integrated, so that the real-time state evaluation of the edge side is realized. According to the method, the stability, the integrity and the intelligent level of wireless data acquisition in a complex industrial environment are effectively improved, and low-cost digital upgrading of stock equipment is supported.
Owner:LIUZHOU INTELLIGENT MFG TECH SERVICE CENT (LIUZHOU AUTOMATION SCI INST)

Information reading system, method for setting scanner system, and method for setting information reading system

It is possible to easily execute a setting for reading information included in a target to be read without requiring a high-level technique related to a network. An IP address assignment unit that assigns private IP addresses to a configuration application for setting an imaging parameter, a decoding parameter, or a communication parameter and a client computer is provided. Then, when a communication system is connected to the client computer via a first communication interface (Steps S101 and S104), private IP addresses on the same private network are assigned to the client computer and a web server, respectively, by the IP address assignment unit (Step S105).
Owner:KEYENCE CORP

A method and system for communication penetration based on session initiation protocol

PendingCN122268852ATransmissionData packPrivate IP
The application discloses a communication penetration method and system based on a session initiation protocol, and the method comprises the following steps: forcibly intercepting a data packet sent by a SIP terminal to a SIP server, converting a source IP of the data packet into a public network IP, converting a source port of the data packet into a target port, replacing a private IP and a port carried in a header connection field in SIP signaling of the data packet with the public network IP and the target port, and replacing a private media IP and a port in SDP information with a public network IP and a target media port when the SIP signaling carries the SDP information. Therefore, it can be seen that a boundary device uniformly intercepts and processes SIP data packets, fixes a port conversion relationship during registration, synchronously modifies a private address and a port in a signaling header into boundary device public network information, realizes consistency of network layer and application layer address conversion, and avoids SIP signaling address mismatch in a NAT environment.
Owner:ZKTECO CO LTD

A method, device, and storage medium for client access to a multi-system server.

ActiveCN115941801BTransmissionPrivate IPEngineering
This invention relates to the field of network communication and discloses a method, device, and storage medium for a client to access a multi-system server, solving the problem that a client cannot access and operate server system resources simultaneously when requesting a multi-system server. The method includes: a processing device constructing a communication channel between a master system and slave systems, and assigning a fixed private IP address to each system; the processing device setting forwarding rules between the client request and the master system's private IP address in each system; according to the forwarding rules, the processing device redirecting the client request to the master system's private IP address; the master system querying the client request to determine whether it can be completed by the master system itself; when the client request cannot be completed by the master system itself, the master system parses the client request and sends the parsing result to the slave system through the communication channel, whereby the slave system processes the parsing result and returns it to the client.
Owner:SHENZHEN GONGJIN ELECTRONICS CO LTD