IP Flow Controller Dynamic Pinhole for Mobile-Terminated Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in enabling Mobile-Terminated (MT) communications over networks while managing the scarcity of IPv4 addresses and mitigating vulnerabilities to malware, as static IPv4 addresses can leave devices exposed and dynamic assignments are difficult to manage for MT traffic.

Innovation Solution

An IP flow controller is introduced to instruct network devices or firewalls to allow traffic flow by dynamically assigning ephemeral public IPv4 addresses and ports, using network address and port translation (NAPT) to create a 'pinhole' for MT communications, thereby enhancing security and addressing address scarcity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static IPv4 addresses are assigned to devices for MT communications, then network security is improved, but device vulnerability to malware increases and address scarcity worsens

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice vulnerability to malware
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic assignment of public IPv4 addresses and ports for MT communications. The system creates temporary pinholes in the firewall that allow incoming traffic only during the duration of the MT communication session. This dynamic approach replaces static address assignment, ensuring that devices are exposed to incoming traffic only when necessary, thereby maintaining security while reducing vulnerability to malware that exploits static addresses.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the temporal parameters of address and port assignment. Instead of permanent static assignments, the patent implements time-bound assignments where public IPv4 addresses and ports are allocated for specific durations corresponding to MT communication sessions. This parameter change allows the system to maintain security controls while enabling legitimate MT communications.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If dynamic IPv4 address assignment is used to address scarcity, then address conservation is improved, but management complexity for MT traffic increases

Engineering Contradiction:
Improvepublic IPv4 address availabilityVSAvoidfirewall management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the external network and the private network. This gateway maintains a translation table that maps public IPv4 addresses and ports to private IPv4 addresses. The gateway automatically manages the dynamic assignment and translation processes, reducing the complexity burden on firewalls while enabling efficient use of public IPv4 addresses through NAT mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway device performs multiple functions: it acts as a NAT translator, maintains translation tables, manages pinhole creation in firewalls, and handles MT communication routing. By consolidating these functions in a single multi-functional device, the system reduces overall network complexity while enabling dynamic IPv4 address usage for MT communications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If firewalls block all incoming traffic by default, then network security is improved, but MT communications capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidMT communications capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The firewall transitions from a static blocking state to a dynamic state that selectively allows incoming traffic. The system creates temporary pinholes in the firewall during MT communication sessions, allowing incoming traffic only for the duration and scope of authorized communications. This dynamic behavior maintains security by default while enabling MT communications when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-configuring the gateway and translation tables before MT communications occur. The gateway is prepared to translate addresses and manage pinhole creation in advance, so that when MT traffic arrives, the firewall can immediately allow the necessary traffic flow without compromising security. This preliminary preparation enables seamless MT communications while maintaining security posture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10623378B2Dynamically allowing traffic flow through a firewall to allow an application server device to perform mobile-terminated communications
Publication Date: 2020.04.14 VERIZON PATENT & LICENSING INC
  • US10623378B2 patent drawing
  • US10623378B2 patent drawing
  • US10623378B2 patent drawing

AI summary

A network device may receive, a flow control request for a first device that is registered for an internet protocol (IP) pinhole service. The flow control request may include a device identifier associated with the first device and a private IP address. The network device may identify at least one of IP address information, port information, and pinhole rules. The network device may provide, to another network device, a flow control response that includes at least one of the IP address information, the port information, and the pinhole rules. The flow control response may cause the other network device to allow traffic flow through the firewall using at least one of the IP address information and the port information. The network device may provide a public IP address and a port identifier to a second device, allowing the second device to provide traffic to the first device.