State Database Correlating NAT Bindings for UE Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In fixed-line broadband access networks, it is challenging to differentiate and correlate User End devices (UEs) behind a Residential Gateway (RG) due to Network Address Translation (NAT) mechanisms, which randomize TCP/IP addresses and ports, making it difficult for Application Functions (AFs) to identify the originating UE from service flows.

Innovation Solution

Implementing a State Database (SDB) that receives NAT or NAPT binding information from the Gateway (GW) to correlate authenticated UEs with service flow requests, allowing the AF to identify and manage UEs reliably, enabling differentiated services and traffic management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NAT or NAPT mechanisms are used in the Residential Gateway to allow multiple devices to access the network, then network scalability and device connectivity are improved, but the ability to differentiate and correlate User End devices with service flows is deteriorated

Engineering Contradiction:
Improvedevice connectivityVSAvoidUE identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a State Database (SDB) as an intermediary component that maintains the mapping between private IP addresses assigned by the RG and the original UE identifiers. The SDB receives binding information from the RG and provides UE identification to the AF, enabling device differentiation while preserving NAT functionality. This mediator resolves the contradiction by decoupling the NAT address translation function from the device identification function.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the RG serves as the default gateway for all devices in the home network, then ease of operation and network management are improved, but the network's knowledge about which UE is causing which TCP/IP flow is lost

Engineering Contradiction:
Improvenetwork managementVSAvoidflow correlation information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements preliminary action by having the RG send binding information to the SDB before service flows are established. The SDB pre-establishes the mapping between private IP addresses and UE identifiers, so that when service flows occur, the AF can immediately correlate them with the correct UE without losing information. This prevents the information loss that would otherwise occur due to the RG's NAT functionality.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If random NAT port assignment is used to manage multiple devices, then device multiplexing capability is improved, but the reliability of service flow correlation with specific UEs is deteriorated

Engineering Contradiction:
Improvedevice multiplexingVSAvoidflow correlation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The SDB acts as a reliable intermediary that maintains accurate mapping information between random NAT port assignments and original UE identifiers. Even though the RG uses random port assignment for device multiplexing, the SDB reliably tracks which private IP and port combination belongs to which UE, enabling the AF to correlate service flows with specific UEs despite the randomization. This resolves the reliability issue while preserving multiplexing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2789152B1Method for providing access of an user end device to a service provided by an application function within a network structure and a network structure
Publication Date: 2018.06.27 NEC CORP
  • EP2789152B1 patent drawingFigure 1
  • EP2789152B1 patent drawingFigure 2
  • EP2789152B1 patent drawingFigure 3

AI summary

For allowing a simple and reliable differentiation of UEs behind a GW from an AF side a method for providing access of an User End device (UE) to a service provided by an Application Function (AF) within a network structure is claimed, wherein the UE is authenticated by a Gateway (GW) to which the UE is attached and which provides access to the AF via a Broadband Access Network (BB Access Network). The method is characterized in that the GW informs a state database (SDB) on service flow requests to or from the authenticated UE towards the AF, that the GW additionally sends NAT (Network Address Translation) or NAPT (Network Address and Port Translation) binding information of a respective NAT or NAPT binding created by the GW regarding the authenticated UE and a respective service flow request to the SDB and that the SDB sends the NAT or NAPT binding information or an UE identifier to the AF, so that the AF - after having received the service flow request from the GW - can correlate the authenticated UE with the service flow request. Further an according network structure is claimed, preferably for carrying out the above mentioned method.