Secondary Network Address Translation for Online Gaming IP Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online gaming and eSports, users' IP addresses are exposed, making them vulnerable to attacks like DDOS and SWATing, as their geographic location can be correlated with their online activity, compromising their security and safety.

Innovation Solution

Implementing a secondary network with address translation using DNS/NAT devices to map gaming traffic to a different, geographically-independent address, shielding the user's actual IP address and location from nefarious actors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP address and port configuration is exposed for peer-to-peer gaming, then gaming functionality is enabled, but user security and privacy are compromised

Engineering Contradiction:
Improvegaming functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a relay server as an intermediary component that mediates all communication between gaming clients. Instead of direct peer-to-peer connections that expose IP addresses, the relay server forwards game data packets between clients, hiding their actual IP addresses while maintaining gaming functionality. The relay server acts as a buffer that enables communication without revealing identifying information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates virtual IP addresses and port configurations on the relay server that copy or simulate the functionality of direct connections. The relay server maintains mapping tables that associate virtual addresses with actual client addresses, allowing games to operate withfake IP addresses that don't reveal real location information while maintaining connection functionality.

Inventive Principle:
Principle #26Copying

2Speed

If direct peer-to-peer connection is used, then low latency is achieved, but IP address exposure enables attacks

Engineering Contradiction:
Improveconnection latencyVSAvoidattack vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The relay server is positioned as a trusted intermediary that minimizes additional latency by implementing efficient packet forwarding mechanisms. While an extra hop is introduced, the patent optimizes the relay server's performance through hardware acceleration and intelligent routing to keep latency additions minimal while providing security benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If IP address is correlated with geographic location, then location-based services are enabled, but user safety is compromised through SWATing and other attacks

Engineering Contradiction:
Improvelocation-based functionalityVSAvoidphysical safety risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements virtual IP address assignment where each client is assigned a fake IP address from the relay server's pool. These virtual addresses are not correlated with the client's actual geographic location, breaking the link between online activity and physical location while allowing location-based game features to function within the game's virtual environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11918918B2Apparatuses and methods for protecting users and devices from nefarious actors via a use of secondary networks and address translation
Publication Date: 2024.03.05 AT&T INTELLECTUAL PROPERTY I L P
  • US11918918B2 patent drawing
  • US11918918B2 patent drawing
  • US11918918B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, analyzing data to identify that the data is associated with an online game, translating, based on the analyzing, a first address associated with the data to a second address that is different from the first address, and transmitting the data to a communication device using the second address. Other embodiments are disclosed.