NAPT Session Fairness via Virtual Server Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing network address translation (NAPT) function, used to manage a shortage of global IP addresses by sharing a single global address among multiple users, leads to unfairness among users due to limited port numbers, causing some users to be unable to connect to the Internet.
Innovation Solution
A packet transfer device and method that includes an address conversion unit for allocating global addresses to multiple private networks, a transfer unit for converting address information and port numbers, and a session restriction unit that manages sessions in predetermined groups, restricting sessions when the number exceeds available limits to ensure fairness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If a single global address is shared by multiple users using NAPT function, then the shortage of global IP addresses is alleviated, but the total port numbers are limited to 65,535 causing unfairness among users
Solution Approach 1:
The patent segments the port number space by creating multiple virtual server addresses from a single global IP address. Each virtual server address is allocated to specific users or user groups, dividing the limited port resources into manageable segments. This allows multiple users to share the global address fairly without competing for the same port numbers, as each user has dedicated port ranges through their assigned virtual server addresses.
Solution Approach 2:
The patent introduces virtual server addresses as intermediary elements between the single global IP address and user terminals. These virtual server addresses act as mediators that translate and manage port number allocations, allowing the system to maintain a single global address while providing fair port number distribution to multiple users through the intermediary virtual address layer.
2Productivity
If many port numbers are used exclusively by a single user, then that user can maintain multiple sessions, but terminals of other users cannot secure port numbers and cannot connect to the Internet
Solution Approach 1:
The patent segments the session capacity by allocating specific virtual server addresses to different users or user groups. Each user's session capacity is bounded by the port numbers available through their assigned virtual server address, preventing any single user from monopolizing all port numbers. This segmentation ensures that each user has a guaranteed portion of the total session capacity while still allowing high productivity for users with larger allocations.
Solution Approach 2:
The patent changes the parameter of address allocation from a single global address shared by all users to multiple virtual server addresses derived from the global address. By changing the address space parameters and creating a hierarchical structure, the system allows flexible control over session capacity distribution while maintaining overall connectivity reliability for all users.
3Quantity of substance
If IPv6 addresses are used as global addresses, then the shortage of IP addresses is solved, but IPv4-compliant devices cannot connect without forcing a switch to IPv6
Solution Approach 1:
The patent makes the single global IPv4 address universal by enabling it to serve multiple users and purposes simultaneously through NAPT and virtual server address techniques. Instead of requiring separate addresses for each user or forcing a transition to IPv6, the system allows one IPv4 address to function as multiple addresses, providing IPv6-level scalability while maintaining IPv4 compatibility and supporting both IPv4 and IPv6 devices.
Data Source
AI summary
A packet transfer device includes: an address conversion unit that allocates a global address to a plurality of private addresses of the plurality of private networks and converts address information and a port number included in a header of a received packet; a transfer unit that transfers a packet having the address information and the port number which are converted by the address conversion unit; and a session restriction unit that manages a number of sessions between a user terminal in the plurality of private networks and a device in the global network for each predetermined group and, when the number of sessions is greater than a number of available sessions which is set to each group, restricts the session of the user terminal which belongs to the group having the excess number of sessions.


