Linking Address Communication Across NAT Without Trusted Relays
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems for IoT devices face challenges in providing efficient, reliable, and scalable direct connections across firewalls and routers using NAT protocols, and log storage mechanisms are impractical when owned by different parties, leading to increased costs and security complexities.
Innovation Solution
A system using a linking address, such as RCID and RSID, for secure communication and storage that is agnostic to device identities and content, ensuring privacy and security without requiring security associations or trust relationships, utilizing a sparse ID name space to minimize resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If NAT protocol is used for device connection, then device privacy is protected, but direct communication between devices is blocked
Solution Approach 1:
The patent introduces a linking address as an intermediary that enables direct peer-to-peer communication between devices while maintaining NAT protection. The linking address acts as a mediator that devices can exchange publicly without exposing their private IP addresses, allowing reliable direct communication through a mechanism that respects NAT boundaries.
Solution Approach 2:
The patent segments the communication address space into two distinct parts: private IP addresses (protected behind NAT) and public linking addresses (exchanged openly). This segmentation allows devices to maintain privacy of their actual network identities while enabling reliable communication through the public linking address component.
2Reliability
If relaying service (TURN) is used for direct connection, then communication reliability is improved, but server resources and trust requirements increase
Solution Approach 1:
The patent extracts the essential function of connection establishment from complex relaying services and implements it through simple linking address exchange. Instead of requiring full TURN/relaying infrastructure, the solution takes out only the address exchange mechanism, allowing devices to establish direct connections with minimal server involvement and no trust requirements.
Solution Approach 2:
The linking address serves as a disposable, stateless identifier that enables connection without requiring persistent server state or complex authentication. Each linking address is a simple, cheap data structure that can be exchanged and used once for connection establishment, eliminating the need for resource-intensive relaying services.
3Reliability
If every system has its own log storage mechanism, then security associations are maintained, but setup and maintenance complexity increases
Solution Approach 1:
The patent creates a universal log storage mechanism that works across different systems and ownership models. The linking address-based storage system is agnostic to device identities and can serve multiple log consumers from different parties, eliminating the need for each system to implement its own proprietary storage mechanism while maintaining security through the linking address abstraction.
Solution Approach 2:
The patent introduces a universal linking address-based storage intermediary that decouples log generators from log consumers. This mediator system allows any device to store and retrieve logs using linking addresses without requiring trust relationships or security associations between the storage mechanism, generators, and consumers.
4Adaptability or versatility
If linking address system is implemented, then scalability is improved, but address space management complexity increases
Solution Approach 1:
The patent adds a new dimension to device identification by introducing linking addresses as a separate layer above traditional IP addressing. This dimensional addition allows the system to scale to accommodate any number of devices without exhausting IP address space, as linking addresses can be generated from a much larger namespace (e.g., 128-bit or 256-bit identifiers).
Data Source
AI summary
Systems and methods for secure communication over a network using a linking address are disclosed. Systems for secure communication may include: a computer system in electronic communication over a network with a plurality of electronic devices; a database in electronic communication with the computer system, the database configured to electronically store at least a linking address and an associated payload of a data packet; and an engine stored on and executed by the computer system, the engine electronically receiving a data packet over the network from a first electronic device; processing the data packet to identify a linking address and a payload, the linking address being at least 32 bit; storing the linking address and payload in the database; electronically receiving a query from a second electronic device, the second electronic device identifying the linking address; and electronically transmitting the data packet over the network to the second electronic device.


