Direct NAT Penetration via STUN Port Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for enabling direct communication between devices under different NATs are inefficient, often requiring external third-party proxies that consume significant network resources, particularly due to the prevalence of Symmetric NATs which do not consistently exhibit Cone NAT properties.
Innovation Solution
A method and device that allow direct penetrating communication between user devices under different NATs by selecting a local source port, obtaining corresponding NAT external-network addresses and ports, and using a notifying device to exchange port information, enabling direct communication through the local source port and received NAT external-network addresses and ports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external third-party proxies are used to enable direct communication between devices under different NATs, then communication capability is achieved, but network resources are consumed significantly
Solution Approach 1:
The invention extracts the communication function from the third-party proxy and enables direct peer-to-peer communication between devices under different NATs by utilizing Cone NAT properties and STUN protocol mechanisms, thereby eliminating the need for continuous proxy resource consumption
Solution Approach 2:
The invention uses a STUN server as a temporary intermediary to help devices discover their public IP addresses and ports, and to establish direct communication paths. The STUN server mediates the initial setup and port mapping discovery, after which direct communication occurs without continuous intermediary involvement
2Reliability
If Symmetric NATs are used to protect internal devices, then security is enhanced, but direct communication between devices under different NATs becomes difficult
Solution Approach 1:
The invention changes the communication approach by using UDP protocol with specific port number mappings and STUN protocol mechanisms to work around Symmetric NAT restrictions. By changing the parameters of communication (using specific port mappings and STUN discovery), direct communication becomes possible despite Symmetric NAT security measures
3Loss of energy
If Cone NAT properties are leveraged for direct communication, then network resources are conserved, but not all NATs consistently exhibit these properties
Solution Approach 1:
The invention uses STUN protocol to obtain feedback information about the actual NAT type and port mapping from the network. By querying the STUN server and receiving feedback about the real IP address and port assignments, the system can adapt its communication parameters to work with the specific NAT configuration, whether Cone or Symmetric
Solution Approach 2:
The invention makes the communication system dynamic by allowing it to detect and adapt to different NAT types in real-time. The system dynamically adjusts its behavior based on the feedback from STUN protocol queries, enabling it to work with various NAT configurations without requiring static compatibility assumptions
Data Source
AI summary
The present invention discloses a user device for implementing direct penetrating communication between a user device under a NAT and another user device under a different NAT and a method for the same. Detection message is sent to an auxiliary detecting device in an external network through a selected local port. Then the reply message from said auxiliary detecting device will be received and the NAT-translated NAT source port of said detection message can be obtained. By comparing the NAT source ports of a plurality of detection messages, it can be determined whether or not the selected port is a penetrated port. After that, the corresponding NAT source address and NAT penetrated port will be informed to another user device under a different NAT (also, the NAT penetrated port and NAT source port determined by said another user device will be received via said external-network device).


