State Database Correlating NAT Bindings for UE Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In fixed-line broadband access networks, it is challenging to differentiate and correlate User End devices (UEs) behind a Residential Gateway (RG) due to Network Address Translation (NAT) mechanisms, which randomize TCP/IP addresses and ports, making it difficult for Application Functions (AFs) to identify the originating UE from service flows.
Innovation Solution
Implementing a State Database (SDB) that receives NAT or NAPT binding information from the Gateway (GW) to correlate authenticated UEs with service flow requests, allowing the AF to identify and manage UEs reliably, enabling differentiated services and traffic management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NAT or NAPT mechanisms are used in the Residential Gateway to allow multiple devices to access the network, then network scalability and device connectivity are improved, but the ability to differentiate and correlate User End devices with service flows is deteriorated
Solution Approach 1:
The patent introduces a State Database (SDB) as an intermediary component that maintains the mapping between private IP addresses assigned by the RG and the original UE identifiers. The SDB receives binding information from the RG and provides UE identification to the AF, enabling device differentiation while preserving NAT functionality. This mediator resolves the contradiction by decoupling the NAT address translation function from the device identification function.
2Ease of operation
If the RG serves as the default gateway for all devices in the home network, then ease of operation and network management are improved, but the network's knowledge about which UE is causing which TCP/IP flow is lost
Solution Approach 1:
The patent implements preliminary action by having the RG send binding information to the SDB before service flows are established. The SDB pre-establishes the mapping between private IP addresses and UE identifiers, so that when service flows occur, the AF can immediately correlate them with the correct UE without losing information. This prevents the information loss that would otherwise occur due to the RG's NAT functionality.
3Adaptability or versatility
If random NAT port assignment is used to manage multiple devices, then device multiplexing capability is improved, but the reliability of service flow correlation with specific UEs is deteriorated
Solution Approach 1:
The SDB acts as a reliable intermediary that maintains accurate mapping information between random NAT port assignments and original UE identifiers. Even though the RG uses random port assignment for device multiplexing, the SDB reliably tracks which private IP and port combination belongs to which UE, enabling the AF to correlate service flows with specific UEs despite the randomization. This resolves the reliability issue while preserving multiplexing capability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
For allowing a simple and reliable differentiation of UEs behind a GW from an AF side a method for providing access of an User End device (UE) to a service provided by an Application Function (AF) within a network structure is claimed, wherein the UE is authenticated by a Gateway (GW) to which the UE is attached and which provides access to the AF via a Broadband Access Network (BB Access Network). The method is characterized in that the GW informs a state database (SDB) on service flow requests to or from the authenticated UE towards the AF, that the GW additionally sends NAT (Network Address Translation) or NAPT (Network Address and Port Translation) binding information of a respective NAT or NAPT binding created by the GW regarding the authenticated UE and a respective service flow request to the SDB and that the SDB sends the NAT or NAPT binding information or an UE identifier to the AF, so that the AF - after having received the service flow request from the GW - can correlate the authenticated UE with the service flow request. Further an according network structure is claimed, preferably for carrying out the above mentioned method.