Gateway Address Translation for Overlapping IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a VPN between devices in local networks is challenging due to overlapping private IP addresses, making unambiguous addressing cumbersome and resulting in 'unroutable' addresses in public Internet, which requires the use of public IP addresses in data packets.

Innovation Solution

A method and apparatus that involve modifying the header of data packets by changing internal IP addresses to non-overlapping public IP addresses, using a gateway to encapsulate packets with public IP addresses of gateways, and establishing VPN tunnels based on unique internal destination addresses, with optional trust list management for secure tunnel establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If private IP addresses are used for devices in local networks, then devices can be freely assigned addresses within the network, but overlapping address spaces between different local networks cause unambiguous addressing to become cumbersome and addresses become unroutable in the public Internet

Engineering Contradiction:
Improveease of address assignmentVSAvoidaddressing unambiguity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a VPN gateway as an intermediary entity that mediates between devices using private IP addresses and the public Internet. The gateway performs address translation, converting private IP addresses to public IP addresses for external communication while maintaining the original private addressing scheme within local networks. This resolves the contradiction by allowing free address assignment locally while ensuring unambiguous routing globally through the gateway's translation function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the IP address parameter from private to public format when packets traverse the VPN tunnel. By dynamically transforming the address parameter based on the packet's origin and destination networks, the system maintains ease of local address assignment while ensuring global routing uniqueness. The gateway modifies the IP address parameter according to translation rules that prevent address conflicts between different local networks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If public IP addresses are used in data packets to ensure routability, then addresses remain unambiguous across the Internet, but the complexity of address management increases and private address spaces cannot be freely reused

Engineering Contradiction:
Improveaddress routing capabilityVSAvoidaddress management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple Virtual Private Networks (VPNs), each with its own isolated address space. By dividing the overall network infrastructure into separate VPN segments, each local network can independently manage its own private IP addresses without conflict. The VPN gateway handles the complexity of public address management externally, while internal networks maintain simple private addressing, thus reducing overall address management complexity while ensuring routing capability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If VPN tunnels are established between gateways of different local networks, then secure communication is achieved, but the process becomes cumbersome due to overlapping private IP addresses

Engineering Contradiction:
Improvecommunication securityVSAvoidtunnel establishment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where VPN gateways automatically perform address translation and tunnel establishment without manual configuration of individual device addresses. The gateways autonomously manage the mapping between private and public IP addresses, and automatically set up forwarding rules when VPN tunnels are created. This eliminates the need for manual address reconfiguration and simplifies tunnel establishment while maintaining security through encrypted channels.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2253123B1Method and apparatus for communication of data packets between local networks
Publication Date: 2013.08.07 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2253123B1 patent drawingFigure 1~2
  • EP2253123B1 patent drawingFigure 3~4
  • EP2253123B1 patent drawingFigure 5~6

AI summary

Method and arrangement for obtaining unambiguous addressing for data packets communicated between devices (E1B,E3A) in two different local networks (A,B) using potentially overlapping private IP address spaces. A VPN tunnel is initially established between gateways (102,104) in the two local networks and an internal IP address space is defined in each network for devices in the opposite network, not overlapping with an internal IP address space used for its own devices. When the gateway (102) of one network receives a data packet from a device (E1B) in the opposite network,the packet's header is modified by changing the destination and source addresses, which belong to address spaces valid in the opposite network, into addresses belonging to address spaces valid in the present network.