Hierarchical Network Address Translation for M2M Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network address translation (NAT) solutions are complex, cumbersome, and lack scalability and security features, particularly in multi-computer data transfer systems, leading to inefficiencies and vulnerabilities, especially in machine-to-machine (M2M) applications where dynamic and asynchronous polling is common, and mobile networks often do not provide externally routable IP addresses.

Innovation Solution

A method and apparatus for forwarding data packets between networks using data-forwarding rules (DFRs) that map source and destination addresses and port numbers, enabling scalable and secure communication by reconfiguring data packets and providing port and address scalability, as well as improved routing and malware security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional NAT solutions are used to enable network address translation, then network connectivity is provided, but device complexity and operational complexity increase while scalability and security features are insufficient

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments network address translation into multiple hierarchical levels: network-level translation and host-level translation. This division allows each layer to handle specific translation tasks independently, reducing the complexity burden on any single device while maintaining comprehensive connectivity capabilities across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary host device that acts as a bridge between end devices and the network. This intermediary handles complex translation operations and coordination, allowing simple end devices to achieve network connectivity without requiring complex NAT functionality built into each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional NAT solutions are used to enable network address translation, then network connectivity is provided, but ease of operation deteriorates due to cumbersome configuration and management

Engineering Contradiction:
Improvenetwork connectivityVSAvoidoperational simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The host device automatically performs address translation and route management without requiring manual configuration. The system self-configures translation rules based on observed traffic patterns and network conditions, eliminating the need for operators to manually manage complex NAT rule sets and improving operational simplicity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-establishes translation capabilities and routing information in advance through automatic discovery and configuration processes. By preparing translation rules and routing tables before actual data transmission begins, the system eliminates the need for complex real-time configuration operations during network usage.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If traditional NAT solutions are used with time-limited translation rules, then address space is conserved, but productivity and usefulness are limited due to rule expiration and reconfiguration requirements

Engineering Contradiction:
Improveaddress space utilizationVSAvoiddata transfer efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The system implements translation rules that extend beyond traditional time limits when data transfer is actively needed. By maintaining translation bindings longer than conventional NAT solutions and using selective rule extension based on traffic patterns, the system preserves address space efficiency while preventing premature rule expiration that would disrupt ongoing data transfers.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent ensures continuous translation capability for active data sessions by implementing mechanisms to extend translation rule validity periods. This continuity prevents interruption of data flows due to rule expiration, maintaining productivity while still conserving address space through selective rather than universal permanent bindings.

Inventive Principle:
Principle #20Continuity of useful action

4Adaptability or versatility

If traditional NAT solutions are used, then network address translation is achieved, but security features are insufficient against malware and unauthorized access

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements security measures at specific local levels: host-based security policies, device-specific translation rules, and localized access control lists. This granular approach to security allows tailored protection for each device and traffic flow, improving overall security reliability while maintaining network connectivity functionality.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8812730B2Method and apparatus for network port and network address translation
Publication Date: 2014.08.19 SEMTECH CORP
  • US8812730B2 patent drawing
  • US8812730B2 patent drawing
  • US8812730B2 patent drawing

AI summary

The present invention provides a method and apparatus for network port and network address translation. Several problems with limited addressability may occur when transmitting data packets between a terminal in a first network and a terminal in a second network that is outside the first network. Data forwarding rules are used to define if and how identifiers of data packets to be forwarded between the two networks correlate with each other. According to embodiments, a data forwarding rule includes a first identifier associated with the first network and a second identifier associated with the second network, wherein each identifier has two parts: a source address and source port number corresponding to a source network node, and a destination address and destination port number corresponding to a destination network node.