Virtual Tunnel Router NAT Traversal via Mapping Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Internet architecture with NATs and firewalls restricts direct communication between terminals, leading to limitations in peer-to-peer communication and mobility, as most terminals are connected to these networks, and existing methods require frequent handling procedures for each Layer 4 session, making it difficult to provide end-to-end communication and mobility in virtual network environments.
Innovation Solution
A method utilizing virtual tunnel routers and a tunnel mapping controller to establish direct communication by exchanging virtual network prefix information, creating tunnels, and enabling direct communication between virtual tunnel routers, even when connected to NATs or firewalls, through the use of virtual IP addresses and tunnel relays.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NAT or firewall is used to block external access or due to IP shortage, then network security and IP conservation are improved, but direct peer-to-peer communication between terminals is restricted
Solution Approach 1:
The patent introduces a server as an intermediary that facilitates direct communication between terminals behind NATs or firewalls. The server acts as a mediator that helps terminals exchange connection information and establish direct peer-to-peer connections, resolving the contradiction by enabling communication without compromising the NAT/firewall protection.
Solution Approach 2:
The patent segments the communication process into distinct phases: connection information gathering, connection type determination, and direct communication establishment. This segmentation allows the system to handle different NAT types and firewall configurations systematically, enabling direct communication while maintaining security restrictions.
2Ease of operation
If hole punching is performed to enable direct communication through NAT, then communication capability is improved, but compatibility across different NAT types (especially symmetric NAT) remains limited
Solution Approach 1:
The patent implements dynamic adaptation to different NAT types by determining the connection type first and then selecting appropriate communication methods. The system dynamically adjusts its behavior based on whether the NAT is full cone, restricted cone, port restricted cone, or symmetric, thereby improving compatibility across all NAT types including symmetric NAT where traditional hole punching fails.
Solution Approach 2:
The patent changes communication parameters such as IP addresses and port numbers dynamically based on the determined NAT type. By adjusting these parameters according to the specific NAT configuration, the system achieves broader compatibility while maintaining direct communication capability.
3Device complexity
If traditional IP-based communication is used in NAT environments, then network addressing is simplified, but mobility and end-to-end communication are compromised due to IP changes
Solution Approach 1:
The patent creates a virtual copy of the network environment by assigning virtual IP addresses to terminals. This virtual IP copying allows terminals to maintain consistent addressing identifiers even when physical IP addresses change due to mobility or NAT reconfiguration, thereby supporting end-to-end communication and mobility while keeping addressing relatively simple.
Data Source
AI summary
In a plurality of virtual tunnel routers including a first virtual tunnel router and a second virtual tunnel router, the first virtual tunnel router and the second virtual tunnel router request virtual network prefix information from a tunnel mapping controller. When the tunnel mapping controller generates virtual network prefix information of the first virtual tunnel router and the second virtual tunnel router, respectively, and transmits the same along with information of a list of adjacent virtual tunnel routers, the first virtual tunnel router and the second virtual tunnel router create a tunnel. With the tunnel established, the virtual network prefix information received by the first virtual tunnel router and second virtual tunnel router, respectively, is linked so that direct communication can be performed between the first virtual tunnel router and the second virtual tunnel router.


