Bridged Virtual Tunnel with NAT for Heterogeneous Network Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data traffic management solutions require configuration of intermediate routers and network address renumbering when connecting networks with overlapping spaces, complicating data packet flow and VPN setups.

Innovation Solution

The system employs a bridged virtual tunnel combined with network address translation (NAT) to extend the headend network directly to a remote network, eliminating the need for intermediate routers and allowing seamless access without VPN configuration, using a NAT module to map IP addresses and enable communication between heterogeneous networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intermediate routers are configured to provide data packet flow paths between networks, then network connectivity is established, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidrouter configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes intermediate routers from the network path by implementing direct peer-to-peer tunneling between endpoints. The routing function is extracted and replaced with endpoint-based tunnel establishment, eliminating the need for intermediate routing devices and their complex configurations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary tunnel protocol that enables direct communication between endpoints without traditional routing. The tunnel acts as a virtual intermediary that encapsulates and transports packets directly between source and destination, bypassing the need for intermediate routers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network address renumbering is performed to handle overlapping network spaces, then network compatibility is achieved, but configuration complexity and time increase

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent uses IP address copying/translation at the tunnel endpoints to handle overlapping addresses. Instead of renumbering devices, the tunnel endpoint copies or translates addresses in the packet header, allowing devices to retain their original addresses while achieving compatibility across networks with overlapping address spaces.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple VPN interfaces and route paths are created between routers, then network flexibility increases, but route table management complexity increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidroute table management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the networking functions by separating tunnel establishment from routing. Each endpoint independently manages its own tunnel connections without requiring coordinated route table updates across multiple routers. This segmentation eliminates the complexity of managing distributed route tables while maintaining flexible multi-path connectivity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11799690B2Systems and methods for automatic network virtualization between heterogeneous networks
Publication Date: 2023.10.24 IP TECHNOLOGY LABS LLC
  • US11799690B2 patent drawing
  • US11799690B2 patent drawing

AI summary

The invention is that of systems and methods for communications between one or more networks and subsequently network devices configured with a networking application for processing network based communications when the devices are on different logical and physical networks. The methods herein involve translation of remote IP addresses of LAN devices to addresses comprising headend network prefixes, to allow for LAN extension of remote to headend networks and communications between devices on the disparate networks. Data packets from a remote LAN interface are transferred to an outbound interface once translated, then forwarded via a formed bridged tunnel link to a headend network device. A server comprising a local LAN and outbound interface is further configured with a NAT module for IP address translation and an optional security module for additional authenticity verification of remote devices attempting to penetrate the headend network.