Cloud Network Packet Address Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security protocols, such as the tunneling mode of IPsec, expose internal private network addresses, leading to potential conflicts and inefficiencies in network address translation and identification, causing bandwidth congestion and timing issues in cloud computing platforms.

Innovation Solution

A method is introduced where network packets received at a cloud computing platform have network address translation information inserted, indicating the path to the actual client device's address, allowing virtual nodes to identify the client device without relying on centralized translation tables, thus enabling immediate application of security and management policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network address translation is performed using centralized translation tables, then client devices can be identified, but bandwidth congestion and timing issues occur in cloud computing platforms

Engineering Contradiction:
Improveclient device identification accuracyVSAvoidnetwork processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts the network address translation information from centralized translation tables and embeds it directly into each network packet's header. This allows virtual nodes to identify client devices immediately from packet metadata without querying centralized tables, eliminating bandwidth congestion and timing delays while maintaining accurate client identification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If tunneling network security protocol is used, then confidentiality and data integrity are assured, but internal private network addresses are exposed outside allowed boundary

Engineering Contradiction:
Improvedata confidentiality and integrityVSAvoidnetwork address exposure and conflict
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism where network address translation information is inserted into packet headers by a gateway device. This intermediary layer allows the system to maintain the tunneling protocol's confidentiality and integrity benefits while preventing direct exposure of private network addresses to external networks, as the translation information enables indirect identification without revealing actual private addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If network address translation information is inserted into every network packet, then client devices can be immediately identified, but packet size increases

Engineering Contradiction:
Improveclient identification speedVSAvoidnetwork packet size
Core Design Contradiction:
SpeedVSLength of moving object

Solution Approach 1:

The patent applies partial action by inserting network address translation information only in specific header fields of network packets where such information is needed for identification, rather than adding complete translation tables to every packet. This selective insertion provides sufficient client identification capability while minimizing the increase in packet size and avoiding unnecessary overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10880265B1Systems and methods for improving network efficiency
Publication Date: 2020.12.29 GEN DIGITAL INC
  • US10880265B1 patent drawing
  • US10880265B1 patent drawing
  • US10880265B1 patent drawing

AI summary

The disclosed computer-implemented method for improving network efficiency may include (i) receiving, from a client device, and at a publicly available on-demand cloud computing platform, a network packet that indicates an origination network address of an intermediary local network gateway that forwarded the network packet rather than an actual network address of the client device, and (ii) inserting, into the network packet, and at the publicly available on-demand cloud computing platform, network address translation information indicating a path to the actual network address of the client device to enable a virtual node within the publicly available on-demand cloud computing platform to identify the client device. Various other methods, systems, and computer-readable media are also disclosed.