Tunnel Access Server IP Address Reservation for Seamless Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
User terminals must restart applications when moving between access networks due to changes in IP addresses assigned by network resources or proxies, which is inconvenient and does not allow for seamless communication with protected network resources without obtaining a new IP address.
Innovation Solution
A tunnel access server facilitates communication by reserving and reassigning a target network address to user terminals when they move between access networks, allowing applications to maintain a common IP address without restarting, using a tunneling session and user authentication to secure and encrypt data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the user terminal moves to a new access network, then the terminal can access new network resources, but the application must be restarted due to IP address changes
Solution Approach 1:
The patent introduces a tunnel access server as an intermediary between the user terminal and protected network resources. This server maintains a persistent tunnel connection that preserves the IP address mapping, allowing applications to continue communicating without restart while the terminal moves between access networks. The tunnel server acts as a mediator that decouples the terminal's physical location from its logical network identity.
Solution Approach 2:
The system performs preliminary authentication and tunnel establishment before the user terminal needs to access protected resources. By pre-establishing the tunnel connection and IP address mapping, the system ensures that when the terminal moves to a new access network, the application can seamlessly continue using the pre-configured IP address without requiring restart or reconfiguration.
2Adaptability or versatility
If different IP addresses are assigned via different access networks, then network resource access is enabled, but application communication is disrupted
Solution Approach 1:
The tunnel access server serves as a stable intermediary that maintains consistent IP address mapping regardless of which access network the terminal uses. The server receives packets from protected resources destined for the terminal's IP address and forwards them through the appropriate access network, ensuring communication session stability while allowing access network flexibility.
Solution Approach 2:
The tunnel access server provides universal access to protected network resources through multiple access networks. It maintains a single IP address mapping that works across different access networks, making the tunneling mechanism universally applicable regardless of the specific access network being used by the terminal.
3Reliability
If tunneling sessions are established for each access network, then network security is maintained, but equipment complexity increases
Solution Approach 1:
The tunnel access server provides a universal solution that handles multiple access networks through a single infrastructure. Instead of requiring separate tunneling equipment for each access network, the server universally supports tunneling across all access networks, reducing overall equipment complexity while maintaining security through centralized authentication and tunnel management.
Data Source
AI summary
The present invention provides a tunnel access server facilitating communications between a user element and protected network resources, wherein a tunneling session is established between the tunnel access server and the user element. To allow the user element to send packets to a protected network resource, the tunnel access server will send a target network address to the user element, and the user element will use the target network address for sending packets to the protected network resource. The packets intended for the protected network resource are initially sent to the tunnel access server via the existing tunneling session. When the user element moves from one access network to another, the tunnel access server will reserve the target network address previously assigned to the user element and reassign the target network address to the user element over a second tunneling session established over the new access network.


