Gateway Address Translation for Overlapping IP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a VPN between devices in local networks is challenging due to overlapping private IP addresses, making unambiguous addressing cumbersome and resulting in 'unroutable' addresses in public Internet, which requires the use of public IP addresses in data packets.
Innovation Solution
A method and apparatus that involve modifying the header of data packets by changing internal IP addresses to non-overlapping public IP addresses, using a gateway to encapsulate packets with public IP addresses of gateways, and establishing VPN tunnels based on unique internal destination addresses, with optional trust list management for secure tunnel establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If private IP addresses are used for devices in local networks, then devices can be freely assigned addresses within the network, but overlapping address spaces between different local networks cause unambiguous addressing to become cumbersome and addresses become unroutable in the public Internet
Solution Approach 1:
The patent introduces a VPN gateway as an intermediary entity that mediates between devices using private IP addresses and the public Internet. The gateway performs address translation, converting private IP addresses to public IP addresses for external communication while maintaining the original private addressing scheme within local networks. This resolves the contradiction by allowing free address assignment locally while ensuring unambiguous routing globally through the gateway's translation function.
Solution Approach 2:
The patent changes the IP address parameter from private to public format when packets traverse the VPN tunnel. By dynamically transforming the address parameter based on the packet's origin and destination networks, the system maintains ease of local address assignment while ensuring global routing uniqueness. The gateway modifies the IP address parameter according to translation rules that prevent address conflicts between different local networks.
2Reliability
If public IP addresses are used in data packets to ensure routability, then addresses remain unambiguous across the Internet, but the complexity of address management increases and private address spaces cannot be freely reused
Solution Approach 1:
The patent segments the network into multiple Virtual Private Networks (VPNs), each with its own isolated address space. By dividing the overall network infrastructure into separate VPN segments, each local network can independently manage its own private IP addresses without conflict. The VPN gateway handles the complexity of public address management externally, while internal networks maintain simple private addressing, thus reducing overall address management complexity while ensuring routing capability.
3Reliability
If VPN tunnels are established between gateways of different local networks, then secure communication is achieved, but the process becomes cumbersome due to overlapping private IP addresses
Solution Approach 1:
The patent implements self-service mechanisms where VPN gateways automatically perform address translation and tunnel establishment without manual configuration of individual device addresses. The gateways autonomously manage the mapping between private and public IP addresses, and automatically set up forwarding rules when VPN tunnels are created. This eliminates the need for manual address reconfiguration and simplifies tunnel establishment while maintaining security through encrypted channels.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Method and arrangement for obtaining unambiguous addressing for data packets communicated between devices (E1B,E3A) in two different local networks (A,B) using potentially overlapping private IP address spaces. A VPN tunnel is initially established between gateways (102,104) in the two local networks and an internal IP address space is defined in each network for devices in the opposite network, not overlapping with an internal IP address space used for its own devices. When the gateway (102) of one network receives a data packet from a device (E1B) in the opposite network,the packet's header is modified by changing the destination and source addresses, which belong to address spaces valid in the opposite network, into addresses belonging to address spaces valid in the present network.