Virtual Work Zones for Overlapping IP Address Conflict Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Merging data communication networks can lead to address conflicts due to overlapping IP addresses, causing data packets to be delivered incorrectly or not at all, and existing solutions require manual reconfiguration of network devices and scripts, which is time-consuming and affects performance.

Innovation Solution

A network management system that generates isolated virtual work zones with virtual firewalls and jump hosts, using a multiprotocol layer switching (MPLS) network system to establish communication paths and route data packets, thereby preventing address conflicts without global reassignment of IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple data communication networks are merged to form a global network, then communication between networks is enabled, but address conflicts occur due to overlapping IP addresses

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoiddata packet delivery accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the global network into multiple isolated virtual work zones, each corresponding to a remote network. Each work zone is assigned a unique public IP address, while devices within the work zone retain their original private IP addresses. This segmentation prevents address conflicts by creating isolated addressing spaces, allowing networks with overlapping IP addresses to coexist in the global network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network management system as an intermediary that includes virtual firewalls and virtual jump hosts. The virtual firewall receives data packets with public IP addresses, translates them to the corresponding work zone and private IP address, and routes them appropriately. This intermediary translation mechanism enables communication between networks with overlapping addresses without requiring global IP reassignment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IP addresses are reassigned across the global network to resolve address conflicts, then unique addressing is achieved, but manual reconfiguration of network devices and scripts is required

Engineering Contradiction:
Improveaddress uniquenessVSAvoidreconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automatic IP address translation through the network management system. When data packets are sent to public IP addresses, the virtual firewall automatically translates them to the corresponding private IP addresses within the appropriate work zone. This self-service translation mechanism eliminates the need for manual reconfiguration of network devices and scripts, as the system automatically handles address mapping.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the addressing parameter from requiring global uniqueness to allowing local uniqueness within isolated work zones. By introducing a translation layer that maps public IP addresses to private IP addresses, the system allows each work zone to maintain its own addressing scheme without conflicts, eliminating the need for global IP reassignment.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual updates are performed on scripts and applications with hard-coded IP addresses, then address accuracy is maintained, but service performance is affected

Engineering Contradiction:
Improveaddress accuracyVSAvoidservice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network management system acts as an intermediary that handles IP address translation transparently. Scripts and applications with hard-coded public IP addresses continue to function without modification, as the virtual firewall automatically translates these addresses to the correct private IP addresses. This maintains address accuracy while preserving service performance, eliminating the need for manual script updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If virtual work zones are created to isolate networks, then address conflicts are prevented, but system complexity increases

Engineering Contradiction:
Improveaddress conflict resolutionVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple remote networks into isolated virtual work zones within a single network management system. By combining the firewall, routing, and address translation functions into an integrated virtual infrastructure, the system prevents address conflicts while managing complexity through consolidation rather than proliferation of separate physical systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10735371B2Systems and methods for accessing computer networks using a virtual infrastructure
Publication Date: 2020.08.04 MASTERCARD INT INC
  • US10735371B2 patent drawing
  • US10735371B2 patent drawing
  • US10735371B2 patent drawing

AI summary

A network management (NM) computing system generates a first work zone associated with a first remote network and a second work zone associated with a second remote network. Each work zone includes a respective virtual firewall and a respective virtual jump host. The NM computing system establishes a first and second communication path between the first virtual jump host and the first remote network via a multiprotocol layer switching network system, receives a data packet including a firewall identifier associated with the first virtual firewall and a local address associated with a destination device within the first remote network, routes the data packet through the first firewall to the first virtual jump host based on the firewall identifier, and transmits, by the first virtual jump host, the data packet to the first remote network using the first communication path and/or the second communication path.