NAT Gateway CPE Management via UDP Heartbeat

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing user-side devices through NAT gateways are complex, not adaptable for large internal networks, and incompatible with various protocols, leading to inefficient real-time management and difficulty in detecting NAT address mapping ageing times.

Innovation Solution

A method employing TR-069 and SNMP management protocols to initiate real-time management of CPE devices, using UDP heartbeat messages for NAT ageing time discovery and transparently managing devices through existing NAT gateways without altering configurations, ensuring security and adaptability across different protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If NAT gateway is used to translate multiple user device addresses to a single external address, then IP address resource exhaustion is solved, but management of user-side devices becomes difficult and real-time monitoring is blocked

Engineering Contradiction:
Improvenumber of accessible IP addressesVSAvoiddevice management capability
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing keep-alive connections before NAT address mapping expires. The management server proactively maintains communication channels with CPE devices through periodic ICMP or TCP packets, ensuring management capability is preserved before the NAT mapping actually expires. This prevents the management blockage that would otherwise occur when NAT translations are discarded.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary mechanism (keep-alive message system) between the management server and CPE devices through the NAT gateway. This intermediary maintains the NAT address mapping by generating periodic traffic, allowing management packets to pass through the NAT gateway successfully without requiring direct persistent connections that would be blocked by NAT expiration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If NAT address mapping is used for device communication, then network address translation is achieved, but detection of NAT address mapping ageing time becomes difficult

Engineering Contradiction:
Improveaddress translation stabilityVSAvoidNAT ageing time detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback mechanisms where the management server monitors the success or failure of keep-alive messages and management packets. By analyzing the timing and outcome of these communications, the system can infer NAT address mapping ageing times and adjust keep-alive intervals accordingly. This feedback loop enables automatic adaptation to different NAT gateway behaviors without requiring explicit NAT ageing time information.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The invention uses partial action by sending keep-alive packets at intervals that are excessive relative to the minimum needed for connectivity but optimized to detect NAT ageing patterns. By sending more keep-alive messages than strictly necessary for basic connectivity, the system can measure response times and detect when NAT mappings are approaching expiration, thereby inferring ageing times without needing direct NAT configuration access.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If existing NAT configurations are altered to enable management, then management capability is improved, but network security and existing device compatibility are compromised

Engineering Contradiction:
Improvemanagement capabilityVSAvoidnetwork security and compatibility
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The NAT gateway itself performs the management function by automatically responding to ICMP or TCP keep-alive packets without requiring configuration changes. The NAT gateway uses its existing address translation capability to forward these packets, and the management server leverages this self-service behavior to maintain management channels. This approach maintains network security and compatibility while enabling management functionality.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The keep-alive mechanism uses universal protocols (ICMP or TCP) that are already supported by all NAT gateways and firewalls, making the solution universally applicable without requiring NAT-specific configuration changes. The same mechanism works across different network environments and device types, maintaining compatibility while enabling management capability through the existing NAT infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2012502B1Method for managing user side device through NAT gateway
Publication Date: 2018.09.19 ZTE CORP
  • EP2012502B1 patent drawingFigure 1
  • EP2012502B1 patent drawingFigure 2~3
  • EP2012502B1 patent drawingFigure 4

AI summary

The present invention discloses a method for managing user side device through NAT gateway, comprising: when the user side device powering on, the management terminal determines whether the user side device is in the LAN side or not. The management terminal sets and turns on the NAT gateway through function switch of the user side device in the LAN side, and the user side device selects the ageing time discovery operation of network address translation or without any operation. The management terminal sets the parameter of the user side device. The user side device trasmits the heartbeat message to the management terminal according to the time interval. The management terminal sends the UDP management request to the user side device, the user side device associates with the management terminal using multiple protocol messages according to the management request, the management terminal accomplishes the initiative management to the user side device. The present invention ensures the real time management of the management terminal and adapts to manage the user side device using related technologies of the SNMP protocol or the TR-069 protocol.