Virtual Network Device Cloud Address Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for providing secure cloud-based communications fail to establish effective network address translation for packets requiring inner payload changes, leading to resource consumption and failed connections between endpoint and public server devices.

Innovation Solution

A virtual network device identifies a cloud provider, requests and receives public and private network addresses, generates a translation table, and uses it to translate source network addresses and control messages, enabling secure communication between endpoint and server devices by mapping public to private addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current techniques are used for providing secure cloud-based communications, then resource consumption is reduced, but secure communication establishment fails for packets requiring inner payload changes

Engineering Contradiction:
Improvesecure communication establishmentVSAvoidconnection success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an application layer gateway as an intermediary component that sits between the network device and endpoint devices. This gateway performs application layer processing and inner payload network address translation, mediating the communication between devices with different address schemes (private vs public IP addresses) and enabling secure cloud-based communications that current techniques cannot establish

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If network address translation is performed without translation table, then device complexity is reduced, but translation precision is insufficient for secure communications

Engineering Contradiction:
Improveaddress translation precisionVSAvoidtranslation table management
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing a translation table that maps public IP addresses to private IP addresses before communication occurs. The application layer gateway uses this pre-computed translation table to perform accurate inner payload address translation, ensuring translation precision required for secure communications while avoiding complex real-time address calculation

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If translation table is generated and maintained, then address translation accuracy is improved, but computing and storage resources are consumed

Engineering Contradiction:
Improveaddress mapping accuracyVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The application layer gateway performs self-service by automatically generating and maintaining the translation table without requiring manual configuration or external intervention. The gateway monitors communication patterns and dynamically updates the translation table, reducing the need for centralized management while maintaining high address mapping accuracy through localized intelligence

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4432605A1Providing cloud-aware security for an application level network device
Publication Date: 2024.09.18 JUNIPER NETWORKS INC
  • EP4432605A1 patent drawingFigure 1A
  • EP4432605A1 patent drawingFigure 1B
  • EP4432605A1 patent drawingFigure 1C

AI summary

A virtual network device may identify a cloud provider associated with the virtual network device, and may provide a request for public network addresses and private network addresses associated with the cloud provider. The virtual network device may receive the public network addresses and the private network addresses from the cloud provider based on the request, and may generate a translation table that maps the public network addresses and the private network addresses. The virtual network device may utilize the translation table to establish a secure communication between an endpoint device and a server device, where the secure communication is associated with at least one packet that requires an inner payload network address change.