Virtual CPE IP Mapping for DMZ Host Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In broadband access scenarios, the utilization efficiency of IP addresses at the WAN side is limited when accessing a DMZ host in a LAN, as CPEs typically obtain only one IP address, restricting port mapping and hindering efficient access.

Innovation Solution

A method and system that configure a mapping relationship between public IP addresses from the WAN side and private IP addresses of DMZ hosts at the LAN side, modifying destination and source IP addresses in access requests and replies to enhance IP address utilization and convenience for WAN side access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a CPE obtains only one IP address at the WAN side, then the configuration is simple, but the IP address utilization efficiency is low and port mapping is restricted

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidIP address utilization efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent segments the IP address resource by introducing multiple virtual CPE instances, where each virtual CPE can obtain and utilize IP addresses independently. This segmentation allows the system to achieve better IP address utilization while maintaining the simplicity of individual CPE configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes a single physical CPE capable of serving multiple functions by creating multiple virtual CPE instances within it. Each virtual CPE can perform DMZ host access functions independently, allowing the system to achieve high IP address utilization efficiency without requiring multiple physical devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If ports at the CPE WAN side are reserved for external services, then external service access is enabled, but not all ports can be mapped to the DMZ host

Engineering Contradiction:
Improveexternal service access capabilityVSAvoidDMZ host access convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the port mapping function by creating multiple virtual CPE instances, each capable of independent port mapping. This allows external services to be accessed on certain virtual CPEs while other virtual CPEs can map all necessary ports to DMZ hosts without conflict.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual CPE instances as intermediaries between the physical CPE and DMZ hosts. These virtual instances mediate the port mapping process, allowing comprehensive port mapping to DMZ hosts while still enabling external service access through other virtual instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple devices are placed in the SOHO office area for WAN access, then access capability is improved, but IP address utilization efficiency cannot be improved

Engineering Contradiction:
Improveaccess capabilityVSAvoidIP address utilization efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges multiple virtual CPE instances within a single physical CPE device. This combination allows multiple devices in the SOHO office to access the WAN through different virtual CPE instances, each with its own IP address resources, thereby improving both access capability and IP address utilization efficiency without requiring multiple physical CPEs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the physical CPE universally functional by enabling it to host multiple virtual CPE instances. Each virtual instance can serve different access needs while sharing the same physical hardware, improving IP address utilization efficiency without adding more physical devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10171418B2Method and apparatus for accessing demilitarized zone host on local area network
Publication Date: 2019.01.01 XIAN ZHONGXING NEW SOFTWARE
  • US10171418B2 patent drawing
  • US10171418B2 patent drawing
  • US10171418B2 patent drawing

AI summary

A method for accessing a demilitarized zone (DMZ) host in a local access network (LAN) includes: configuring a mapping relationship between public IP addresses obtained from a wide area network (WAN) side and private IP addresses of demilitarized zone hosts at a LAN side; after receiving an access request sent by a client at the WAN side, modifying a destination IP address in the access request to the private IP address of a corresponding demilitarized zone host at the LAN side according to the configured mapping relationship, and sending the modified access request to the demilitarized zone host; receiving a reply message returned by the demilitarized zone host, modifying a source IP address contained in the reply message to a public IP address of a client at the WAN side, and sending the modified reply message to the WAN side. The present document also discloses a corresponding apparatus.