Firewall NAT Connectivity via Central Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communications systems located behind firewalls face challenges in establishing direct communication with each other due to security measures that prevent unsolicited traffic, especially when Network Address Translation (NAT) devices are involved, leading to decreased accessibility.
Innovation Solution
A central communications station assists remote systems in establishing direct communication by providing connection information, allowing them to 'spoof' the central station as the source, and facilitating a three-way TCP handshake to bypass firewall restrictions, even with NAT devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls are implemented to prevent unsolicited traffic, then security is improved, but accessibility between communications systems behind firewalls deteriorates
Solution Approach 1:
The patent introduces a central communications station as an intermediary that facilitates connections between remote systems behind firewalls. The station receives connection requests from one system, validates them through authentication, and forwards them to the destination system, thereby enabling communication while maintaining firewall security rules.
Solution Approach 2:
The patent implements preliminary authentication and connection establishment at the central communications station before actual data transmission occurs. The station verifies the legitimacy of connection requests and pre-establishes secure channels, allowing subsequent communication to proceed without requiring the firewalls to be configured for direct peer-to-peer connectivity.
2Reliability
If Network Address Translation (NAT) is used to protect private addresses, then security is improved, but the ability to establish direct communication deteriorates
Solution Approach 1:
The central communications station acts as an intermediary that handles NAT translation and address management. It receives packets from private addresses, translates them to public addresses for external communication, and manages the mapping relationships, thereby enabling direct communication between systems behind NAT devices without requiring complex configuration at each system.
Solution Approach 2:
The central communications station provides multiple functions including authentication, connection management, address translation, and packet forwarding. This multi-functional approach consolidates what would otherwise require complex individual system configurations, simplifying the overall communication establishment process while maintaining security.
3Ease of operation
If direct communication is enabled between systems behind firewalls, then accessibility is improved, but security control deteriorates
Solution Approach 1:
The central communications station serves as a security gateway that maintains control over all communications between systems behind firewalls. It authenticates connection requests, validates destination addresses, and filters packets before allowing them through, thereby enabling direct communication while preserving security control that would otherwise be lost in peer-to-peer connections.
Solution Approach 2:
The patent implements feedback mechanisms where the central communications station receives authentication responses and connection status information from both remote systems. This feedback loop allows the station to verify the legitimacy of communication attempts, manage connection states, and terminate connections that fail security validation, thereby maintaining security control while enabling accessibility.
Data Source
AI summary
A communications scheme enables a central communications station to assist two communications systems located behind firewalls that prevent communication initiated from an external data network to establish direct communication with each other. In one embodiment, the systems separately establish communications with the central communications station and obtain from it the connection information (e.g., IP address, port, etc.) of the other. The systems then directly communicate with each other using the obtained connection information while pretending to be the central communications station. In another embodiment in which the firewalls include NAT devices that implement network address translation, the systems exchange connection information for establishing a new connection through the central communications station and then complete a three-way handshake with the assistance of the central communications station, thereby allowing the central communications station to remove itself from the communication.


