Location-Based NAT Filtering in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless networks face security risks due to unsatisfactory Network Address Translation (NAT) methods, which can be exploited by malicious users, especially with the increased use of various wireless devices associating with access points, leading to potential network vulnerabilities.

Innovation Solution

Implementing an on-board locationing engine within a network switch to determine the location of mobile units and selectively enable or disable NAT based on predefined regions, thereby enhancing security by restricting NAT operations in sensitive areas.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NAT is enabled to allow multiple hosts to access networks using a single public IP address, then network connectivity and resource sharing are improved, but network security deteriorates due to administrative holes being exploitable by malicious users

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by differentiating NAT permissions based on spatial location. Different regions within the wireless network are assigned different NAT policies - some regions allow NAT while others restrict it. This is achieved through location-based NAT filtering that examines the geographic or spatial context of each connection request, enabling selective application of NAT rules to specific locations rather than applying a uniform policy across the entire network.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If wireless access points are configured to communicate with multiple mobile devices, then mobile connectivity and network coverage are improved, but security risks increase due to more devices being able to associate with access ports

Engineering Contradiction:
Improvemobile connectivityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the wireless network into distinct location-based zones or regions. Each segment has its own security policies and NAT permissions. Mobile devices are assigned to specific segments based on their location, and NAT operations are controlled at the segment level. This allows the network to support multiple devices while maintaining security by isolating devices into location-based segments with appropriate access controls.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7876737B2Methods and apparatus for locationing based NAT access in wireless networks
Publication Date: 2011.01.25 SYMBOL TECHNOLOGIES LLC
  • US7876737B2 patent drawing
  • US7876737B2 patent drawing
  • US7876737B2 patent drawing

AI summary

Methods and systems are provided for location-based network address translation (NAT). The system allows an administrator to logically partition an environment into a plurality of spatial regions. The method then includes specifying, for each of the spatial regions, whether network address translation (NAT) is allowed or not allowed for that spatial region, then performing a locationing procedure to determine in which spatial region the mobile unit is located. NAT is allowed for wireless data communication from the mobile unit if the mobile unit is within one of the spatial regions for which NAT is allowed, and is not allowed for wireless data communication from the mobile unit if the mobile unit is within one of the spatial regions for which NAT is not allowed. The systems and methods are applicable, for example, to networks operating in accordance with 802.11, RFID, WiMax, WAN, Bluetooth, Zigbee, UWB, and the like.