Controller-Based Remote Access via NAT Hole Punching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote access (RA) headends are often unreachable and statically provisioned, leading to poor quality of service and increased operational costs due to the use of static public IP addresses, which are expensive and vulnerable to DDoS attacks, and the selection of RA headends is not based on current load conditions.
Innovation Solution
A controller-based architecture is implemented to eliminate the need for static public IPs, enabling dynamic and optimal distribution of RA clients across RA headends using geolocation and load-based policies, with edge devices performing hole punching to traverse NAT gateways and connecting to a centralized controller for secure onboarding and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static public IP addresses are assigned to RA headends, then the headends are always reachable and can provide stable remote access services, but the operational costs increase and the network becomes vulnerable to DDoS attacks
Solution Approach 1:
The patent introduces a controller as an intermediary component that manages RA headend connections and client routing. The controller receives client connection requests, determines the appropriate RA headend based on current conditions, and establishes connections dynamically. This intermediary architecture allows the system to avoid exposing individual headends to direct external traffic, thereby reducing DDoS vulnerability while maintaining reliable access through the controller's coordinated management.
2Reliability
If static public IP addresses are assigned to RA headends, then the headends can be reliably accessed, but the operational costs increase due to the expense of static public IPs and DDoS protection services
Solution Approach 1:
The controller acts as a cost-effective intermediary that enables reliable RA headend access without requiring expensive static public IP addresses on each headend. The controller can use a single static IP or dynamic IP with NAT traversal techniques to manage connections to multiple headends, significantly reducing the cost of public IP addresses and associated DDoS protection services while maintaining accessibility.
Solution Approach 2:
The system uses virtualization and software-defined networking concepts where the controller creates virtual access points and manages multiple headends through software abstraction. This allows the deployment of RA services on commodity hardware with dynamic IPs, copying the functionality of expensive static IP configurations at a fraction of the cost through software-based management.
3Ease of manufacture
If RA headends are statically provisioned, then the network configuration is simple, but the quality of service deteriorates because headend selection is not based on current load conditions
Solution Approach 1:
The patent implements dynamic headend selection where the controller continuously monitors load conditions, geographic location, and other attributes of both clients and headends. Based on real-time conditions, the controller dynamically determines the optimal headend for each client connection, considering factors such as current load, proximity, and service requirements. This dynamic approach maintains simple network configuration from a user perspective while achieving optimal QoS through automated, condition-based decision-making.
Solution Approach 2:
The system incorporates feedback mechanisms where the controller receives status information from headends regarding current load, availability, and performance metrics. This feedback loop enables the controller to make informed decisions about client-to-headend assignments, continuously optimizing service quality based on actual network conditions while maintaining configuration simplicity through automated management.
4Productivity
If RA headends are deployed closer to users to meet increased scale requirements, then the service coverage and responsiveness improve, but the complexity of managing distributed headends increases
Solution Approach 1:
The patent segments the RA service management into two distinct layers: a centralized controller that handles global coordination, authentication, and dynamic decision-making, and distributed headend devices that execute local connection functions. This segmentation allows headends to be deployed close to users for improved responsiveness while the controller manages the overall system complexity, providing centralized control over distributed resources and simplifying deployment and management.
Data Source
AI summary
A method of implementing controller-based distributed remote access may include connecting a plurality of edge devices to a controller via a network. The plurality of edge devices may perform hole punching to traverse a network address translation (NAT) gateway to create a NAT hole. The method may also include connecting a client device to the controller. The client device may be directly connected to one of the plurality of edge devices via the NAT hole in the network. The method may further include directly connecting the client device to one of the plurality of edge devices by receiving a query from the client device and returning public IP/ports of a most relevant edge device to the client device, the most relevant edge device being based on attributes of the client device, attributes of the plurality of edge devices, or combinations thereof.


