Relay CPE for NAT Traversal Management Session Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote management protocols, such as CWMP, face challenges in managing equipment behind NAT entities or firewalls due to the requirement for STUN client and server implementation, which is rare in CPEs, and incur scaling issues with permanent connections.

Innovation Solution

A method involving an intermediate piece of equipment within the local network, reachable by the management device, uses a standard download command to initiate a connection between the equipment and its management device, acting as a relay to establish a management session without modifying the equipment or requiring NAT traversal mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If STUN client and server implementation is used to manage equipment behind NAT, then equipment reachability is improved, but device complexity and implementation cost increase

Engineering Contradiction:
Improveequipment reachabilityVSAvoidSTUN client and server implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediate piece of equipment (relay CPE) that acts as a mediator between the managed CPE and the ACS server. This relay CPE is reachable by the ACS server and can forward management commands to the behind-NAT CPE, eliminating the need for STUN client/server implementation while maintaining equipment reachability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If permanent connections are maintained for NAT traversal, then equipment reachability is improved, but scalability deteriorates due to connection management overhead

Engineering Contradiction:
Improveequipment reachabilityVSAvoidscaling capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The relay CPE serves as a scalable intermediary that the ACS server can contact through standard HTTP protocols without maintaining permanent connections. The relay CPE handles the connection establishment and maintains the communication path to behind-NAT equipment, allowing the ACS server to scale without managing individual permanent connections to each CPE.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If STUN mechanism is implemented for NAT traversal, then equipment reachability is improved, but loss of substance increases due to infrastructure requirements

Engineering Contradiction:
Improveequipment reachabilityVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent eliminates the need for STUN infrastructure by using an intermediate relay CPE that leverages existing HTTP protocols and standard web browsing capabilities. This approach reduces infrastructure requirements while maintaining the ability to reach equipment behind NATs, as the relay CPE can be reached through standard HTTP connections without specialized NAT traversal infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11206172B2Method for establishing a management session between an item of equipment and a device for management of this item of equipment
Publication Date: 2021.12.21 ORANGE SA
  • US11206172B2 patent drawing
  • US11206172B2 patent drawing

AI summary

The invention provides a set-up method for setting up a management session between a first piece of equipment of a first network and a first management device for managing this piece of equipment that belongs to a second network, the method comprising:setting up (F70) a management session between a second piece of equipment of the first network that is reachable from the second network, and a second management device managing the second piece of equipment that belongs to the second network;the second management device acting during the management session to send (F80) a request to the second piece of equipment requesting the second piece of equipment to download a content at an address provided by the first piece of equipment in order to set up a management session therewith;the second piece of equipment executing (F110) the download request; andin response to this execution, the first piece of equipment initiating (F170) a connection with the first management device to set up a management session therewith.