IP Library Granted Patent US 9,628,291
Granted Patent B2
US 9,628,291 · App. 14/386,916 · Granted Apr 18, 2017

Method for automatic tunneling of IPV6 packets with topologically incorrect source addresses

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,628,291
App. No.
14/386,916
Granted
Apr 18, 2017
Kind
B2
Abstract

An apparatus and a method are provided, by which a gateway function between a first network and a second network is carried out, a packet is received from a network node located in the second network, wherein the packet comprises a source address which topologically does not belong to the second network, the received packet is encapsulated in a new packet, and the new packet is sent to the first network.

Claims (41)

1. An apparatus comprising:

a first interface unit configured to provide connection to a first network;

a second interface unit configured to provide connection to a network node located in a second network; and

at least one processor and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus to at least:

receive a packet from the network node via the second interface unit, wherein the packet comprises a source address which topologically does not belong to the second network,

encapsulate the received packet in a new packet,

create a destination address for the new packet by at least using a network prefix of the source address of the received packet and an interface identifier of a network control node of a network indicated by the network prefix, the interface identifier being at least one of fixed or cryptographically created by at least using a secret known to the apparatus and the network control node, and

send the new packet to the first network via the first interface unit.

2. The apparatus according to claim 1 , wherein the apparatus is further configured to at least use an interface address of the second interface unit as the source address of the new packet.

3. The apparatus according to claim 1 , wherein the apparatus is further configured to at least record a host route to the source address of the network node within the second network.

4. The apparatus according to claim 3 , wherein the apparatus is further configured to at least:

receive a packet from the first network destined to the network node via the first interface unit,

decapsulate the packet, and

route the decapsulated packet to the network node based on the recorded host route.

5. The apparatus according to claim 1 , wherein the apparatus is further configured to record the destination address of the received packet of the network node.

6. The apparatus according to claim 1 , wherein the apparatus is further configured to at least:

create the destination address of the new packet by using the destination address of the received packet as the destination address of the new packet.

7. The apparatus according to claim 1 , wherein the apparatus is further configured to at least perform encapsulating and sending when predefined rules regarding the network node are met.

8. The apparatus according to claim 1 , wherein the apparatus is further configured to at least detect whether the source address topologically does not belong to the second network by determining whether the network prefix of the source address differs from the network prefix of the second network.

9. An apparatus comprising:

a first interface unit configured to provide connection to a first network;

a second interface unit configured to provide connection to a second network; and

at least one processor and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus to at least:

receive an encapsulated packet from the first network via the first interface unit,

decapsulate the received packet, wherein the decapsulated packet comprises a destination address which topologically does not belong to the second network,

send, after decapsulating the received packet, a multicast message to the second network to request a response from a node at the destination address, and

send the decapsulated packet to the destination address to the second network via the second interface unit, when the response to the request is received by the apparatus.

10. The apparatus according to claim 9 , wherein the destination address is an address of a node located in the second network and the destination address is recorded by the processor.

11. The apparatus according to claim 9 , wherein the processor is configured to at least perform sending of the decapsulated packet only when predefined rules regarding the network node are met.

12. A method comprising:

receiving a packet from a network node located in the second network, wherein the packet comprises a source address which topologically does not belong to the second network;

encapsulating the received packet in a new packet; and

creating a destination address for the new packet by at least using a network prefix of the source address of the received packet and an interface identifier of a network control node of a network indicated by the network prefix, the interface identifier being at least one of fixed or cryptographically created by at least using a secret known to the apparatus and the network control node; and

sending the new packet to the first network.

13. The method according to claim 12 , further comprising:

using an interface address of a second interface unit configured to provide a connection of the apparatus carrying out the method to the second network as the source address of the new packet.

14. A method comprising:

receiving an encapsulated packet from the first network via the first interface unit;

decapsulating the received packet, wherein the decapsulated packet comprises a destination address which topologically does not belong to the second network;

sending, after decapsulating the received packet, a multicast message to the second network to request a response from a node at the destination address; and

sending the decapsulated packet to the destination address to the second network via the second interface unit, when the response to the request is received by the apparatus.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035232/0034 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2014
From: KORHONEN, JOUNI; SAVOLAINEN, TEEMU
To: NOKIA CORPORATION
Reel/Frame 034609/0061 →