CPE Address Pre-Binding for Private IP Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Network Address Translation (NAT) operations in CPEs are inefficient when networks assign private IP addresses, leading to increased processing load and unsatisfactory user experience, particularly in scenarios involving China's major telecom operators.

Innovation Solution

A network access control method that assigns a pre-bound client network address to a client device and sends it to a network-side device upon request, ensuring efficient access and improved user experience by using a CPE with modules for address binding, assignment, and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If NAT operations are used for network address translation in CPE, then network access is enabled, but processing load increases and access efficiency decreases

Engineering Contradiction:
Improvenetwork access efficiencyVSAvoidprocessing load
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent pre-establishes binding relationships between client device identifiers (such as MAC addresses) and network addresses (such as IP addresses) before actual network access occurs. The CPE maintains a binding table that maps these identifiers in advance, so when access requests arrive, the CPE can directly query and forward packets without performing complex real-time NAT operations, thereby reducing processing load and improving access efficiency.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If private IP addresses are assigned by telecom operators, then network resource utilization is improved, but network access control becomes difficult

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the network address management into two independent parts: the CPE handles private IP address allocation and binding relationship management internally, while the network-side device handles access control decisions. The CPE translates between private IPs and public IPs using pre-established bindings, allowing the network-side device to control access based on public addresses without needing to manage private address allocation, thus maintaining both resource utilization and access control ease.

Inventive Principle:
Principle #1Segmentation

3Reliability

If conventional NAT operations are performed, then network address translation is achieved, but user experience deteriorates due to access failures

Engineering Contradiction:
Improveaccess success rateVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the CPE to autonomously manage network address binding and translation without requiring external intervention or complex coordination with the network-side device. The CPE independently maintains binding tables, performs address translation using pre-established relationships, and handles forwarding decisions locally. This self-service capability ensures reliable access by eliminating coordination delays and reducing points of failure, thereby improving user experience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250365264A1Network access control method, and customer premise equipment and storage medium
Publication Date: 2025.11.27 ZTE CORP
  • US20250365264A1 patent drawing
  • US20250365264A1 patent drawing
  • US20250365264A1 patent drawing

AI summary

A network access control method, a Customer Premise Equipment (CPE), and a storage medium are disclosed. The network access control method may include: receiving a network address application request sent by a client device, and assigning a client network address to the client device, the client network address is a network address pre-bound to the client device; receiving, from a network-side device, an access request for accessing the client device; and sending the client network address to the network-side device according to the access request.