NAT Port Detection via Bubble Packets for Secure P2P Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in securely establishing peer-to-peer communications between information processors traversing Network Address Translators (NATs), particularly when the combination of NATs involves Symmetric (a) NAT (Sa NAT) or Symmetric (c) NAT (Sc NAT), as they require knowledge of port number differentials and the latest port positions to facilitate communication.
Innovation Solution
A communication system that includes a reference port receiver, bubble packet transmitter, detection packet transmitter, and reply packet receiver to detect and establish the range of ports allowing communication, using a server to facilitate the detection of reference and bubble packet transmitting ports through reference and port detection packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If peer-to-peer communication is established between information processors traversing NATs, then communication autonomy is improved, but communication reliability deteriorates due to uncertainty in NAT port assignments
Solution Approach 1:
The invention performs preliminary detection of the information processor's own port and the communication partner's port before establishing peer-to-peer communication. By using detection packets to query port information in advance, the system eliminates uncertainty about NAT port assignments, thereby improving communication reliability while maintaining automation.
2Reliability
If port detection packets are transmitted to detect bubble packet transmitting ports, then communication reliability is improved, but communication time is increased due to additional detection steps
Solution Approach 1:
The invention transmits port detection packets to query port information before establishing communication. This preliminary detection action ensures that the correct ports are identified in advance, improving communication reliability by avoiding failed connection attempts.
Solution Approach 2:
The invention uses a feedback mechanism where detection packets are sent to query port information, and the received port information is used to adjust and confirm the communication path. This feedback loop ensures accurate port identification while minimizing unnecessary communication attempts.
3Adaptability or versatility
If bubble packets are transmitted to leave transmission records in NAT, then communication capability is improved, but network traffic is increased due to additional control packets
Solution Approach 1:
The invention extracts only the essential port information from the communication process by using dedicated detection packets. Instead of relying on multiple bubble packets to infer port information, the system directly queries and extracts the necessary port data, reducing unnecessary network traffic while maintaining communication capability.
4Reliability
If NAT port filter rules are configured to allow reception from specific ports, then communication security is improved, but communication flexibility deteriorates due to restricted port ranges
Solution Approach 1:
The invention performs preliminary detection of the information processor's own port and the communication partner's port before establishing communication. By knowing the exact ports in advance through detection packets, the system can configure NAT port filter rules to allow only the necessary ports, improving security without sacrificing flexibility.
Solution Approach 2:
The invention applies port filter rules selectively to specific detected ports rather than using broad port ranges. By configuring filters based on the locally detected port information, the system achieves both security (through restricted access) and flexibility (by allowing the specific needed communication).
Data Source
AI summary
A first information processor transmits a bubble packet to a port assigned after assignment of specified port from reference port in a second communication control unit, a server detects the position of the bubble packet transmitting port in a first communication control unit used in transmission of this bubble packet, and a second information processor transmits a reply packet to the detected bubble port transmitting port. In this configuration, the invention presents a communication system capable of establishing more securely communication between plural information processors for communicating by way of communication control unit (NAT). In this configuration, the invention presents a communication system capable of establishing more securely communication between plural information processors for communicating by way of communication control unit (NAT).


