Transparent Network Devices Inner Connection Establishment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transparent network devices face challenges in establishing and maintaining communications due to interference from middle devices like firewalls and NATs, leading to potential data corruption and misinterpretation of network traffic, which can hide actual network problems from administrators.
Innovation Solution
Transparent network devices modify messages to establish inner connections using encoded information that appears as part of outer connection messages, and employ techniques such as invalid error detection data, timestamp modifications, and sequence window management to prevent data corruption and ensure transparent operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If transparent network devices use the same source and destination network addresses and ports for inner channel traffic as outer channel traffic, then transparency is maintained and little reconfiguration is needed, but middle devices like firewalls and NATs cannot distinguish inner channel traffic from outer channel traffic leading to potential data corruption and misinterpretation
Solution Approach 1:
The patent segments the network traffic identification by separating outer channel identification (source/destination addresses and ports) from inner channel identification (encoded transparency indicators within packet data). This allows middle devices to see only outer channel information while transparent devices can identify and process inner channel traffic using the embedded indicators, thus maintaining transparency while ensuring reliable traffic differentiation and preventing data corruption
Solution Approach 2:
The patent implements nesting by embedding transparency indicator information within the existing packet data structure of outer channel traffic. The inner channel identification is nested inside the outer channel packets, allowing transparent network devices to extract and process the embedded indicators while middle devices continue to handle packets based on their outer channel addresses and ports without being affected by the nested inner channel information
2Adaptability or versatility
If transparent network devices intercept inner channel network traffic before it reaches destination addresses, then communication between transparent devices is enabled, but network monitoring and security devices cannot detect or inspect this traffic
Solution Approach 1:
The patent applies the color changes principle by modifying the appearance of inner channel traffic packets through encoding transparency indicators that change the visual or structural characteristics of the packets. These encoded indicators allow transparent network devices to identify and process inner channel traffic while maintaining the outer channel address structure that monitoring devices rely on, thus enabling communication while preserving detectability through the encoded indicators
3Reliability
If transparent network devices modify messages to establish inner connections using encoded information, then inner connections can be established without disruption by middle devices, but the device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-encoding transparency indicators into the packet data structure before traffic interception occurs. This preliminary encoding of identification information within the packet stream allows transparent network devices to efficiently identify and process inner channel traffic without requiring complex real-time analysis, thus establishing reliable connections while managing device complexity through advance preparation of the traffic identification mechanism
Data Source
AI summary
Transparent network devices intercept messages from non-transparent network devices that establish a connection. Transparent network devices modify these messages to establish an inner connection with each other. The transparent network devices mimic at least some of the outer connection messages to establish their inner connection. The mimicked messages and any optional reset messages are intercepted by the transparent network devices to prevent them from reaching the outer connections. Transparent network devices modify network traffic, using error detection data, fragmentation data, or timestamps, so that inner connection network traffic inadvertently received by outer connection devices is rejected or ignored by the outer connection network devices. Transparent network devices may use different sequence windows for inner and outer connection network traffic. To prevent overlapping sequence windows, transparent network devices monitor the locations of the inner and outer connection sequence windows and may rapidly advance the inner connection sequence window as needed.


