NAT Port Detection via Bubble Packets for Secure P2P Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in securely establishing peer-to-peer communications between information processors traversing Network Address Translators (NATs), particularly when the combination of NATs involves Symmetric (a) NAT (Sa NAT) or Symmetric (c) NAT (Sc NAT), as they require knowledge of port number differentials and the latest port positions to facilitate communication.

Innovation Solution

A communication system that includes a reference port receiver, bubble packet transmitter, detection packet transmitter, and reply packet receiver to detect and establish the range of ports allowing communication, using a server to facilitate the detection of reference and bubble packet transmitting ports through reference and port detection packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If peer-to-peer communication is established between information processors traversing NATs, then communication autonomy is improved, but communication reliability deteriorates due to uncertainty in NAT port assignments

Engineering Contradiction:
Improvecommunication autonomyVSAvoidcommunication reliability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The invention performs preliminary detection of the information processor's own port and the communication partner's port before establishing peer-to-peer communication. By using detection packets to query port information in advance, the system eliminates uncertainty about NAT port assignments, thereby improving communication reliability while maintaining automation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If port detection packets are transmitted to detect bubble packet transmitting ports, then communication reliability is improved, but communication time is increased due to additional detection steps

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The invention transmits port detection packets to query port information before establishing communication. This preliminary detection action ensures that the correct ports are identified in advance, improving communication reliability by avoiding failed connection attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention uses a feedback mechanism where detection packets are sent to query port information, and the received port information is used to adjust and confirm the communication path. This feedback loop ensures accurate port identification while minimizing unnecessary communication attempts.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If bubble packets are transmitted to leave transmission records in NAT, then communication capability is improved, but network traffic is increased due to additional control packets

Engineering Contradiction:
Improvecommunication capabilityVSAvoidnetwork traffic
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The invention extracts only the essential port information from the communication process by using dedicated detection packets. Instead of relying on multiple bubble packets to infer port information, the system directly queries and extracts the necessary port data, reducing unnecessary network traffic while maintaining communication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If NAT port filter rules are configured to allow reception from specific ports, then communication security is improved, but communication flexibility deteriorates due to restricted port ranges

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention performs preliminary detection of the information processor's own port and the communication partner's port before establishing communication. By knowing the exact ports in advance through detection packets, the system can configure NAT port filter rules to allow only the necessary ports, improving security without sacrificing flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention applies port filter rules selectively to specific detected ports rather than using broad port ranges. By configuring filters based on the locally detected port information, the system achieves both security (through restricted access) and flexibility (by allowing the specific needed communication).

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8239541B2Bidirectional connection setup between endpoints behind network address translators (NATs)
Publication Date: 2012.08.07 PANASONIC HOLDINGS CORP
  • US8239541B2 patent drawing
  • US8239541B2 patent drawing
  • US8239541B2 patent drawing

AI summary

A first information processor transmits a bubble packet to a port assigned after assignment of specified port from reference port in a second communication control unit, a server detects the position of the bubble packet transmitting port in a first communication control unit used in transmission of this bubble packet, and a second information processor transmits a reply packet to the detected bubble port transmitting port. In this configuration, the invention presents a communication system capable of establishing more securely communication between plural information processors for communicating by way of communication control unit (NAT). In this configuration, the invention presents a communication system capable of establishing more securely communication between plural information processors for communicating by way of communication control unit (NAT).