Meshnet Gateway Partial LAN Access via IP Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mesh networks face difficulties in enabling partial access to a local area network (LAN) for external meshnet devices without full access, leading to inefficient resource utilization and communication delays, as they require a layer 1 connection to the LAN to communicate with specific devices.
Innovation Solution
A method where a first meshnet device connected to a LAN receives an initiation network packet from a second meshnet device, compares the subnet IP address with a stored address, and selectively transmits the packet to the appropriate LAN device, allowing partial access without a full layer 1 connection, using an MSP control infrastructure to manage access permissions and cryptographic keys for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a meshnet device requires a layer 1 connection to the LAN to communicate with specific devices, then communication reliability is improved, but device complexity and installation overhead increase
Solution Approach 1:
The patent introduces a meshnet gateway device as an intermediary between the mesh network and the LAN. This gateway maintains a layer 1 connection to the LAN and performs IP address translation and packet forwarding, allowing meshnet devices to communicate with LAN devices without requiring direct layer 1 connections. The gateway acts as a mediator that bridges the two networks, resolving the contradiction by eliminating complex direct connections while maintaining communication reliability through the intermediary.
2Adaptability or versatility
If full access to the LAN is provided to external meshnet devices, then adaptability is improved, but security and resource control worsen
Solution Approach 1:
The patent segments LAN access into different levels: full access for authorized devices and partial access for meshnet devices. The meshnet gateway implements access control lists (ACLs) that divide LAN resources into accessible and non-accessible segments for external devices. This allows specific LAN devices or IP address ranges to be selectively accessible by meshnet devices, providing adaptability for different access needs while maintaining security by preventing unauthorized access to other LAN resources.
Solution Approach 2:
The patent applies different access qualities to different meshnet devices or LAN devices. Rather than uniform full access or complete restriction, the system assigns specific access permissions to specific device pairs or groups. The gateway can configure different ACL entries for different meshnet devices, allowing each to access only the LAN resources they need, thus balancing adaptability with security through localized access control.
3Productivity
If partial access to specific LAN devices is enabled without layer 1 connection, then resource utilization is improved, but communication reliability may worsen
Solution Approach 1:
The meshnet gateway serves as a reliable intermediary that maintains the layer 1 connection to the LAN, ensuring communication reliability while enabling partial access. The gateway performs reliable packet forwarding, IP address translation, and error handling between the mesh network and LAN, allowing resource-efficient partial access without sacrificing the reliability provided by the physical layer connection at the gateway.
Data Source
AI summary
An infrastructure device associated with a first device and a second device in a mesh network, the first device being connected to a LAN, the infrastructure device configured to: configure the first device to receive, from the second device, an initiation network packet to be transmitted by the first device to a first LAN device connected to the LAN, the initiation network packet indicating a first subnet IP address as a destination address; configure the first device to compare the first subnet IP address with a stored subnet IP address that is stored in the memory in correlation with the second device; and configure the first device to selectively transmit the initiation network packet to the first LAN device based on a result of comparing the first subnet IP address with the stored subnet IP address is disclosed. Various other aspects are contemplated.


