Private Network Address Translation Across Multiple Local Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face difficulties in maintaining security and configuration information for network communications, especially when multiple local networks with different firewall and security measures are involved, complicating the setup and management of virtual local area networks (VLANs) and encryption.
Innovation Solution
A method is introduced to manage a private network across multiple local networks by advertising local IP addresses, determining destination computing elements, and replacing local destination addresses with private network addresses, using a coordination service to maintain and distribute communication rules and permissions among computing elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLANs and encryption are used to secure network communications, then security is improved, but configuration complexity and difficulty increase
Solution Approach 1:
The patent introduces a coordination service as an intermediary that automatically manages network address translation (NAT) rules, firewall configurations, and encryption settings. This service acts as a mediator between computing elements and the complex network infrastructure, handling security and routing tasks without requiring users to manually configure VLANs, encryption protocols, or NAT rules, thus maintaining security while eliminating configuration complexity
Solution Approach 2:
The system enables computing elements to automatically register with the coordination service and obtain the necessary network configuration information. The coordination service automatically creates NAT rules, manages address translations, and configures security parameters based on service requests, allowing the network infrastructure to self-configure and self-manage without human intervention, thereby resolving the contradiction between security requirements and configuration difficulty
2Reliability
If individual networks are configured with different firewall and security measures, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The coordination service provides a universal interface that works across different local networks with varying firewall and security configurations. It implements a standardized mechanism for address translation and security management that functions consistently regardless of the underlying network's specific security measures, allowing users to operate computing elements uniformly across diverse networks without needing to understand or configure each network's specific security protocols
Solution Approach 2:
The coordination service acts as a universal mediator that handles interactions between computing elements on different networks with diverse security configurations. It automatically adapts to and manages the specific firewall and security measures of each network while presenting a consistent, easy-to-use interface to users, thereby maintaining security diversity while improving ease of operation
3Adaptability or versatility
If computing elements are located outside the local network, then network flexibility is improved, but communication complexity increases
Solution Approach 1:
The patent segments the network communication into two distinct layers: a local network layer where computing elements communicate using simple local IP addresses, and a remote network layer managed by the coordination service. This segmentation allows computing elements to remain outside the local network (improving flexibility) while the coordination service handles the complexity of address translation and routing between layers, preventing communication complexity from reaching the end users
4Ease of operation
If local IP addresses are advertised on the home network, then ease of operation is improved, but security risks increase
Solution Approach 1:
The coordination service acts as an intermediary that enables local IP address advertising on the home network while protecting against security risks. It implements secure address translation and authentication mechanisms that allow computing elements to be easily discoverable and accessible via local IP addresses within the home network, while the coordination service mediates all external communications and enforces security policies, thus maintaining ease of operation while mitigating security risks
Data Source
AI summary
The technology described herein manages a private network over multiple local networks. In one example, a method includes, in a computing element on a home network of the multiple local networks, advertising local IP addresses on the home network. Each of the local IP addresses correspond to an outside computing element of outside computing elements on the private network located outside of the home network. The method further includes receiving a packet over the home network directed to a local destination address of the local IP addresses, determining a destination computing element of the outside computing elements, and replacing the local destination address in the packet with a private network address for the destination computing element on the private network. The method also includes transmitting an encapsulation of the packet to a public network address of the destination computing element.


