MSL Twin NAT for Multi-VPN Address Conflict Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN technologies restrict a client workstation to connect to only one VPN due to potential address conflicts, as internal private IP addresses are not guaranteed to be unique across different VPNs, leading to unreliable packet routing.

Innovation Solution

The Multiple Secure Link (MSL) architecture employs a twin network address translator (NAT) and virtual private network (VPN) components to create a unique private IP address realm, allowing multiple simultaneous VPN connections by translating between VPN owner-defined private IP addresses and unique private IP addresses, ensuring unique IP addressing within the MSL private IP realm.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a client workstation connects to multiple VPNs using traditional address translation, then connectivity to multiple networks is enabled, but address conflicts occur because internal private IP addresses are not guaranteed to be unique across different VPNs

Engineering Contradiction:
Improveability to connect to multiple VPNsVSAvoidpacket routing reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a new dimension to IP addressing by creating a hierarchical structure where global IP addresses are composed of multiple components including organization-specific and network-specific identifiers. This dimensional expansion allows unique addressing across multiple VPNs without address conflicts, enabling reliable packet routing while maintaining connectivity to multiple networks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The global IP address space is segmented into multiple hierarchical levels including organization identifiers and network identifiers. This segmentation allows each VPN to have its own unique address space within the global structure, eliminating address conflicts while enabling multi-VPN connectivity and reliable routing through hierarchical address matching.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If traditional NAT is used to translate addresses in multi-VPN environments, then address hiding is achieved, but routing ambiguity arises when multiple VPNs use overlapping private IP address ranges

Engineering Contradiction:
Improveaddress conflictVSAvoidpacket routing
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent introduces global IP addresses as an intermediary layer between private IP addresses of different VPNs. This intermediary addressing scheme resolves routing ambiguity by providing a unique hierarchical path for packets traversing multiple VPNs, eliminating address conflicts while simplifying routing operations through hierarchical address matching.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

By adding hierarchical dimensions to the IP address structure (organization identifier, network identifier, host identifier), the patent creates a multi-dimensional address space that eliminates overlaps between different VPNs. This dimensional expansion resolves address conflicts while providing clear routing paths through hierarchical address decomposition.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Quantity of substance

If private IP addresses are reused across different VPNs to conserve address space, then address efficiency improves, but routing reliability deteriorates due to inability to distinguish packet destinations

Engineering Contradiction:
ImproveIP address utilization efficiencyVSAvoiddestination identification
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the IP address into hierarchical components including organization-specific and network-specific identifiers. This segmentation allows efficient reuse of address space across different organizations and networks while maintaining unique global addresses for each host, enabling both high address utilization efficiency and reliable destination identification through hierarchical routing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By expanding the address space into multiple hierarchical dimensions, the patent enables efficient address reuse at lower levels (host identifiers can be reused across different organizations) while maintaining unique global addresses through higher-level identifiers. This dimensional structure simultaneously improves address efficiency and ensures reliable destination identification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3103221B1Systems and methods for providing a multiple secure link architecture
Publication Date: 2020.07.01 E NAT TECH LLC
  • EP3103221B1 patent drawingFigure 1
  • EP3103221B1 patent drawingFigure 2
  • EP3103221B1 patent drawingFigure 3

AI summary

Some embodiments disclosed herein include a MSL twin network address translator (NAT) that includes logic that, when executed by a processor, causes the MSL twin NAT to receive inbound datagram from MSL VPN and record a new VPN owner private IP address from a source IP address in the inbound datagram. In some embodiments the logic causes the MSL twin NAT to assign a new UPIP for the inbound datagram and client workstation and facilitate sending the inbound datagram to the client workstation.