IP Address Conflict Resolution in NAT-Protected VPNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a VPN environment, IP address conflicts between an IRAC behind a NAT and an IRAS can prevent access to internal networks due to overlapping IP addresses, causing communication failures and access issues.

Innovation Solution

A method and system that resolve IP address conflicts by comparing the IRAC's IP address information with internal network addresses of the IRAS, assigning conflict-resolving network addresses, and mapping these addresses to enable communication, using modified IKEv2 protocol negotiations and a conflict resolution module within the IRAS to dynamically assign non-conflicting virtual IP addresses and subnet addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IRAC uses a private IP address behind NAT, then connectivity flexibility is improved, but IP address conflicts with internal networks occur

Engineering Contradiction:
Improveconnectivity flexibilityVSAvoidaccess reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary IP address conflict detection during the IKEv2 connection establishment phase, before actual data communication begins. The IRAS compares the IRAC's private IP address with its internal network addresses and proactively identifies conflicts, then resolves them by assigning alternative IP addresses or configuring routing rules beforehand, preventing access failures during operational phase

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an IP address conflict resolution mechanism as an intermediary layer between the NAT device and the IRAS internal network. This intermediary performs address translation, conflict detection, and routing rule management to mediate communication between IRAC and internal resources, preventing direct IP conflicts while maintaining connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If IRAC tries to access internal networks directly using ARP, then access speed is improved, but routing errors occur due to IP conflicts

Engineering Contradiction:
Improveaccess speedVSAvoidrouting accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the IRAS monitors communication patterns and detects when IRAC attempts direct ARP-based access to conflicting internal networks. Upon detection, the IRAS sends routing rules or policy updates back to the IRAC, guiding it to route traffic through the tunnel instead, thereby correcting routing errors while maintaining efficient communication

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary routing rule management system that intercepts and redirects traffic between IRAC and internal networks. When IP conflicts are detected, the intermediary automatically configures routing rules to ensure traffic is properly directed through the VPN tunnel, preventing routing errors while maintaining fast access speeds

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8805977B2Method and system for address conflict resolution
Publication Date: 2014.08.12 NXP USA INC
  • US8805977B2 patent drawing
  • US8805977B2 patent drawing
  • US8805977B2 patent drawing

AI summary

A method and system for resolving a conflict between private internet protocol addresses assigned in a network between an internet protocol security remote access server (IRAS) and an internet protocol security remote access client (IRAC) arranged behind a network address translator (NAT) router in the network. By modifying internet key exchange version2 (IKEv2) and internet key exchange (IKE) protocol negotiations between IRAC and IRAS to include a private attribute used by IRAC to send all its internet protocol (IP) subnet addresses to IRAS, IRAS dynamically resolves any conflict of the IP addresses with that of its internal networks by mapping and assigning non-conflicting virtual IP addresses and network subnet addresses to IRAC for IRAC to access the internal networks of IRAS. The conflict resolving mechanism used in run time allows mobile virtual private networks (VPN) to access corporate networks employing IP routers implementing IP security (IPsec) remote access mechanism without access failure due to IP address conflicts.