IP Flow Controller Dynamic Pinhole for Mobile-Terminated Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in enabling Mobile-Terminated (MT) communications over networks while managing the scarcity of IPv4 addresses and mitigating vulnerabilities to malware, as static IPv4 addresses can leave devices exposed and dynamic assignments are difficult to manage for MT traffic.
Innovation Solution
An IP flow controller is introduced to instruct network devices or firewalls to allow traffic flow by dynamically assigning ephemeral public IPv4 addresses and ports, using network address and port translation (NAPT) to create a 'pinhole' for MT communications, thereby enhancing security and addressing address scarcity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static IPv4 addresses are assigned to devices for MT communications, then network security is improved, but device vulnerability to malware increases and address scarcity worsens
Solution Approach 1:
The patent implements dynamic assignment of public IPv4 addresses and ports for MT communications. The system creates temporary pinholes in the firewall that allow incoming traffic only during the duration of the MT communication session. This dynamic approach replaces static address assignment, ensuring that devices are exposed to incoming traffic only when necessary, thereby maintaining security while reducing vulnerability to malware that exploits static addresses.
Solution Approach 2:
The system changes the temporal parameters of address and port assignment. Instead of permanent static assignments, the patent implements time-bound assignments where public IPv4 addresses and ports are allocated for specific durations corresponding to MT communication sessions. This parameter change allows the system to maintain security controls while enabling legitimate MT communications.
2Quantity of substance
If dynamic IPv4 address assignment is used to address scarcity, then address conservation is improved, but management complexity for MT traffic increases
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the external network and the private network. This gateway maintains a translation table that maps public IPv4 addresses and ports to private IPv4 addresses. The gateway automatically manages the dynamic assignment and translation processes, reducing the complexity burden on firewalls while enabling efficient use of public IPv4 addresses through NAT mechanisms.
Solution Approach 2:
The gateway device performs multiple functions: it acts as a NAT translator, maintains translation tables, manages pinhole creation in firewalls, and handles MT communication routing. By consolidating these functions in a single multi-functional device, the system reduces overall network complexity while enabling dynamic IPv4 address usage for MT communications.
3Reliability
If firewalls block all incoming traffic by default, then network security is improved, but MT communications capability deteriorates
Solution Approach 1:
The firewall transitions from a static blocking state to a dynamic state that selectively allows incoming traffic. The system creates temporary pinholes in the firewall during MT communication sessions, allowing incoming traffic only for the duration and scope of authorized communications. This dynamic behavior maintains security by default while enabling MT communications when needed.
Solution Approach 2:
The system performs preliminary actions by pre-configuring the gateway and translation tables before MT communications occur. The gateway is prepared to translate addresses and manage pinhole creation in advance, so that when MT traffic arrives, the firewall can immediately allow the necessary traffic flow without compromising security. This preliminary preparation enables seamless MT communications while maintaining security posture.
Data Source
AI summary
A network device may receive, a flow control request for a first device that is registered for an internet protocol (IP) pinhole service. The flow control request may include a device identifier associated with the first device and a private IP address. The network device may identify at least one of IP address information, port information, and pinhole rules. The network device may provide, to another network device, a flow control response that includes at least one of the IP address information, the port information, and the pinhole rules. The flow control response may cause the other network device to allow traffic flow through the firewall using at least one of the IP address information and the port information. The network device may provide a public IP address and a port identifier to a second device, allowing the second device to provide traffic to the first device.


