VPN Router Bypassing Carrier Grade NAT Limitations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies face limitations due to the use of Network Address Translation (NAT) technologies, such as Carrier Grade NAT, which block direct VPN connections requiring static IP addresses and port numbers, making it difficult to establish VPN connections over various internet access types.

Innovation Solution

A system and method that includes a VPN router and server capable of monitoring communication and obtaining information about accessible IP addresses and port numbers via the Internet, allowing connections to be made through these addresses, thereby bypassing network limitations and establishing VPN connections independently of VPN protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If Network Address Translation (NAT) technologies are used to provide internet access, then the number of IP addresses required is reduced, but direct VPN connections requiring static IP addresses and port numbers are blocked

Engineering Contradiction:
Improvenumber of IP addressesVSAvoidVPN connection capability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces a VPN server as an intermediary that mediates between the VPN client and the destination. The server receives connections from clients behind NAT, establishes the connection, and forwards traffic to the destination, thereby enabling VPN connections without requiring static public IP addresses or port numbers on the client side.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the VPN connection establishment process into two independent phases: a connection establishment phase where the VPN server coordinates with the destination to reserve resources, and a data transmission phase where actual data flows occur. This segmentation allows the connection to be set up through the NAT network while maintaining end-to-end VPN functionality.

Inventive Principle:
Principle #1Segmentation

2Productivity

If Carrier Grade NAT is implemented to dynamically allocate private IP addresses, then IP address utilization is improved, but VPN connections are blocked due to lack of static accessibility

Engineering Contradiction:
ImproveIP address utilizationVSAvoidVPN connection establishment
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent performs preliminary actions during the connection establishment phase by having the VPN server contact the destination system in advance to reserve connection resources and establish the necessary routing paths. This preliminary coordination ensures that when actual data transmission occurs, the path is already prepared and accessible, overcoming the dynamic allocation limitations of CGNAT.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The VPN server acts as an intermediary that bridges the dynamic private IP addressing of CGNAT with the static connection requirements of VPN. The server maintains persistent connections to both the client and the destination, translating between the dynamic client assignments and the stable VPN tunnel requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If direct VPN connection attempts are made over public network, then connection simplicity is maintained, but connection success rate decreases due to network blocking

Engineering Contradiction:
Improveconnection configurationVSAvoidconnection success rate
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a VPN server as an intermediary that simplifies the client-side configuration while improving connection success. The client only needs to connect to the server's known address, and the server handles the complex tasks of destination discovery, resource reservation, and connection establishment, thereby maintaining simplicity while improving reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the VPN server receives information about the client's network configuration and NAT setup, and uses this feedback to adapt the connection establishment process. The server adjusts its behavior based on the client's capabilities and the network conditions, thereby improving connection success rates while maintaining configuration simplicity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11265296B1System and method to create and implement virtual private networks over internet for multiple internet access types
Publication Date: 2022.03.01 ROQOS INC
  • US11265296B1 patent drawing
  • US11265296B1 patent drawing
  • US11265296B1 patent drawing

AI summary

A system and method are disclosed for making Virtual Private Network (VPN) connections in networks, which currently cannot have VPNs due to technical limitations and some practices by network operators. The system and method are a solution that may be independent of VPN protocols used for making secure connections. The system and method can be used in a public cloud on the internet or a in a private network. The system and method are capable of providing VPN connections “everywhere” and in all connection scenarios.