Unique Private IP Address Translation for Overlapping VPN Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communications networks, the use of multiple VPN technologies with conflicting IP addresses leads to overlapping customer networks, preventing more than one VPN tunnel from being active simultaneously, which complicates management and requires complex systems to avoid IP address overlaps.

Innovation Solution

Defining a unique private IP address for each terminal in a remote customer network and translating it into a corresponding customer IP address for routing data packets through a virtual private network tunnel, allowing multiple VPNs to operate concurrently even with overlapping IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple VPN technologies with conflicting IP addresses are used, then VPN connectivity options are increased, but IP address overlapping prevents multiple VPN tunnels from being active simultaneously

Engineering Contradiction:
ImproveVPN connectivity optionsVSAvoidVPN tunnel availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the IP address space by introducing a unique private IP address for each terminal in the customer network, separate from the public IP addresses used for VPN routing. This segmentation allows multiple VPNs with overlapping public IP addresses to coexist by using the unique private IP addresses as identifiers within the customer network, eliminating the conflict that prevented multiple VPN tunnels from being active simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The unique private IP address acts as an intermediary between the public IP addresses of different VPNs and the actual terminal devices. This intermediary resolves the IP address overlap conflict by providing a unique identification mechanism that works within the customer network regardless of the public IP addresses used by different VPN technologies, enabling multiple VPN tunnels to operate concurrently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If non-overlapping IP addresses are defined for remote networks, then IP address conflicts are avoided, but system construction and management become complicated

Engineering Contradiction:
ImproveIP address conflict avoidanceVSAvoidsystem construction and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the IP address identification function from the public IP address space and creates a separate unique private IP address space for terminal identification within customer networks. This extraction eliminates the need for complex non-overlapping IP address configurations while maintaining reliable IP address conflict avoidance, as the unique private IP addresses are guaranteed to be distinct regardless of public IP address assignments.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter used for terminal identification from public IP addresses to unique private IP addresses. This parameter change simplifies system construction and management by decoupling terminal identification from public IP address assignments, allowing administrators to use any public IP addresses for VPN routing without worrying about overlaps or conflicts.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a single VPN tunnel is maintained, then IP address conflicts are avoided, but network connectivity flexibility is reduced

Engineering Contradiction:
ImproveIP address conflict avoidanceVSAvoidnetwork connectivity flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the networking functions by separating VPN tunnel management from terminal identification. Multiple VPN tunnels can be maintained simultaneously, each with its own public IP address, while terminals are uniquely identified by their private IP addresses. This segmentation enables network connectivity flexibility by allowing multiple active VPN tunnels without IP address conflicts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The unique private IP address serves as an intermediary that enables multiple VPN tunnels to coexist. It mediates between the different public IP addresses of various VPNs and the terminal devices, allowing the system to maintain multiple active VPN connections while avoiding IP address conflicts through the intermediary identification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8745722B2Managing remote network addresses in communications
Publication Date: 2014.06.03 WAPICE
  • US8745722B2 patent drawing
  • US8745722B2 patent drawing
  • US8745722B2 patent drawing

AI summary

A method for managing routing information in a communications system comprises-defining, in a client network apparatus, a unique private IP address, the unique private IP address uniquely identifying a terminal and the corresponding remote network. The client apparatus defines an IP routing address for the remote network. The client apparatus routes a data packet to a VPN tunnel having the IP routing address defined for the remote network, the data packet being directed to the remote network identified by the unique private IP address. The unique private IP address is translated into a corresponding customer IP address of the terminal in order the data packet to be routable to the terminal in the remote network.