Secondary Network Address Translation for Private Game Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In eSports and peer-to-peer gaming scenarios, the exposure of IP addresses and other identifying information leads to vulnerabilities such as DDOS attacks and side-channel attacks, compromising user privacy and safety.

Innovation Solution

Establishing a secondary network separate from the primary network to route gaming traffic, using DNS/NAT devices with rapidly-rotating, geographically-independent addresses to obscure the location of devices and prevent nefarious actors from identifying user locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP address and port configuration are communicated and exposed to other users in multiplayer competition, then connectivity and communication between devices is enabled, but user privacy and safety are compromised due to vulnerability to DDOS attacks and side-channel attacks

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secondary network as an intermediary between the primary network and gaming servers. This secondary network acts as a mediator that receives traffic from client devices, translates their IP addresses to dynamically assigned addresses, and routes the traffic to gaming servers. This intermediary structure enables connectivity while hiding the real IP addresses from both other players and attackers, thus resolving the contradiction between ease of connection and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into a primary network (where client devices are located), a secondary network (where traffic is routed through with hidden identities), and gaming servers. This segmentation isolates the client devices' real IP addresses from the gaming environment, allowing communication to occur without exposing vulnerable information. The segmentation creates distinct zones that protect user privacy while maintaining operational connectivity.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If IP address is translated to a second network address, then location obfuscation and security are improved, but network complexity increases due to the need for DNS/NAT devices and address translation mechanisms

Engineering Contradiction:
Improvelocation obfuscationVSAvoidnetwork complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The secondary network performs multiple functions simultaneously: it translates IP addresses, obfuscates user locations, routes traffic to gaming servers, and dynamically assigns addresses. By consolidating these multiple functions into a single network layer, the patent reduces overall system complexity compared to having separate systems for each function, while still achieving comprehensive location obfuscation and security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter of network address assignment from static to dynamic. Instead of using fixed IP addresses that directly reveal location, the system dynamically assigns second network addresses that can change over time. This parameter change enables location obfuscation while the dynamic nature of address assignment simplifies the system compared to complex static mapping mechanisms, as the system automatically adapts to different users and sessions.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If rapidly-rotating addresses are used to obscure device location, then security against identification attacks is enhanced, but information loss occurs as real IP address mapping is obscured

Engineering Contradiction:
Improveattack preventionVSAvoidIP address mapping information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent extracts the real IP address information from the network communication flow by introducing a secondary network layer. The original IP addresses are taken out of the direct communication path and translated into second network addresses. This extraction allows the system to maintain security through address rotation while preserving the ability to map addresses for legitimate traffic management and billing purposes, as the mapping information is maintained in the secondary network's translation tables rather than being lost.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250286854A1Apparatuses and methods for facilitating a generation and utilization of networks associated with events
Publication Date: 2025.09.11 AT&T INTELLECTUAL PROPERTY I L P
  • US20250286854A1 patent drawing
  • US20250286854A1 patent drawing
  • US20250286854A1 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, obtaining first traffic from a first communication device; analyzing the first traffic to classify the first traffic as being associated with an execution of a first application; based on the classification of the first traffic as being associated with the execution of the first application, translating an address associated with the first traffic from a first address associated with a first network to a second address associated with a second network, the second network being different from the first network; and conveying the first traffic to a second communication device of the second network using the second address. Other embodiments are disclosed.