NAT Gateway Updates for Isolated Security Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for providing software updates to isolated security systems are inefficient, inconvenient, expensive, and risky, as they often require manual installation, break the design of private networks, or are impractical for secure connections over the Internet.

Innovation Solution

A method and system that utilize network address translation (NAT) data structures and proxy settings to allow secure, real-time software updates over a public network by configuring an isolated security system to connect through a first firewall to an internet web gateway, ensuring only outbound connections are allowed, and translating IP addresses to ensure secure communication with a security system update manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual download and installation from external machine is used, then software updates can be provided to isolated systems, but the process is time-consuming, inconvenient, and expensive

Engineering Contradiction:
Improveease of update installationVSAvoidupdate installation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces a NAT gateway as an intermediary component that enables automated update delivery to isolated systems. The gateway acts as a mediator between the external update source and the isolated security system, allowing updates to be pushed automatically without manual intervention while maintaining network isolation. This resolves the contradiction by enabling automated updates (reducing time and effort) while preserving the isolated architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If additional NIC is added to connect to public network, then isolated security system can access Internet for updates, but private network design is compromised and security risk increases

Engineering Contradiction:
Improvenetwork connectivity capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network communication path by introducing a dedicated NAT gateway that handles all external communications. The isolated security system remains in its private network segment without direct public network interfaces, while the NAT gateway forms a separate segment that manages external connections. This segmentation allows the system to gain Internet access capability through the gateway without compromising the security of the private network segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The NAT gateway serves as an intermediary that enables the isolated system to receive updates without direct public network connectivity. All external communications are routed through this mediator, which translates and forwards packets appropriately while maintaining the isolation boundary. This resolves the contradiction by providing adaptability for updates while preserving security through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If local update server is used to connect cloud and distribute updates, then updates can be provided to multiple systems, but the setup is impractical, expensive, and may not handle large numbers of simultaneous updates

Engineering Contradiction:
Improveupdate distribution efficiencyVSAvoidupdate server infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a self-service update mechanism where the NAT gateway automatically manages update distribution to multiple isolated systems without requiring a dedicated local update server. The gateway autonomously handles update reception, translation, and distribution to multiple clients simultaneously, eliminating the need for complex server infrastructure while maintaining high productivity in update delivery.

Inventive Principle:
Principle #25Self-service

4Reliability

If VPN is used to secure connection between security system and cloud, then secure communication is achieved, but it only works if cloud has VPN gateway which is not the case for regular software updates

Engineering Contradiction:
Improveconnection securityVSAvoidcompatibility with update systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the network communication parameters by implementing NAT translation instead of VPN encryption. The system modifies how connections are established and routed through IP address translation and port forwarding, enabling secure communication without requiring VPN gateway infrastructure. This parameter change resolves the contradiction by maintaining reliability through alternative security mechanisms while improving adaptability to work with standard update systems that don't have VPN capabilities.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12500939B2Secure real-time updates for isolated security systems
Publication Date: 2025.12.16 SAUDI ARABIAN OIL CO
  • US12500939B2 patent drawing
  • US12500939B2 patent drawing
  • US12500939B2 patent drawing

AI summary

Methods and systems provide secure, real-time software updates over a public network to an isolated security system. A method includes the steps of setting up a network address translation (NAT) data structure for allowing outbound connections only through a first firewall between the isolated security system and the public network, and configuring the isolated security system to identify an internet web gateway address to get a software update from a security system update manager over a predetermined protocol and port. A further step involves configuring a proxy setting in the isolated security system to identify an internet web gateway address of a proxy server in a NAT subnet.