Packet Transfer Device Address Replacement for Shared Harmful Packet Removal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for preventing obstruction access in networks, such as harmful packet removal, require either expensive customer-specific solutions or shared apparatuses that burden service providers with additional costs and performance degradation due to software processing or hardware installation, and involve complex routing changes.

Innovation Solution

A packet transfer apparatus with multiple network interfaces, storage for attack target patterns, and Ethernet address replacement capabilities, allowing packets to be routed to a harmful packet removal apparatus without altering routing information, thereby eliminating the need for tunnels and reducing operational costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a harmful packet removal apparatus is inserted into each customer's connection line, then harmful packets can be effectively removed, but the service becomes expensive

Engineering Contradiction:
Improveharmful packet removal effectivenessVSAvoidservice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The harmful packet removal apparatus is designed to serve multiple customers simultaneously through a shared infrastructure. The apparatus can identify and filter harmful packets for different customer networks based on destination address patterns, eliminating the need for separate dedicated apparatuses for each customer while maintaining effective harmful packet removal.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If routing information is rewritten to guide packets to the harmful packet removal apparatus, then harmful packets can be filtered, but the network complexity and operational costs increase

Engineering Contradiction:
Improveharmful packet filteringVSAvoidrouting configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A packet transfer apparatus is introduced as an intermediary between the customer network and the harmful packet removal apparatus. This intermediary handles the packet forwarding and address translation functions, allowing the harmful packet removal apparatus to operate independently without requiring complex routing changes in the customer network. The packet transfer apparatus translates destination addresses and forwards packets appropriately.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a tunnel is established from the harmful packet removal apparatus to the customer network, then packets can be returned to the intended destination, but additional hardware and software processing are required

Engineering Contradiction:
Improvepacket return capabilityVSAvoidtunnel termination requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The packet transfer apparatus serves as an intermediary that handles the packet return function without requiring tunnel establishment. Instead of creating a tunnel from the harmful packet removal apparatus to the customer network, the packet transfer apparatus simply forwards packets based on translated destination addresses, eliminating the need for complex tunnel termination hardware and software processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If software processing is used to terminate the tunnel, then no additional hardware is needed, but router performance deteriorates

Engineering Contradiction:
Improvehardware costVSAvoidrouter performance
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The packet transfer apparatus acts as a dedicated intermediary device that handles packet forwarding and address translation functions. By offloading these functions to a specialized apparatus rather than using software processing on general-purpose routers, the solution avoids performance deterioration while not requiring additional expensive hardware at customer premises.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1998520B1Packet transfer device, packet transfer method, and program
Publication Date: 2017.11.08 NTT COMM CORP
  • EP1998520B1 patent drawingFigure 1
  • EP1998520B1 patent drawingFigure 2
  • EP1998520B1 patent drawingFigure 3

AI summary

A packet transfer apparatus is provided with: storage means configured to store a predetermined search pattern and an address identifying a predetermined apparatus; determination means configured to determine whether predetermined data in a packet received from a network interface matches the search pattern; determination means configured to determine a network interface for outputting the packet using the determination result; replacement means configured to replace an address identifying a destination apparatus of the packet with an address identifying the predetermined apparatus when outputting the packet from a network interface connected to the predetermined apparatus; and packet sending means configured to send the packet to the determined network interface.