IP Library Granted Patent US 9,648,121
Granted Patent B2
US 9,648,121 · App. 14/722,441 · Granted May 9, 2017

Source-destination network address translation (SDNAT) proxy and method thereof

Inventors: Boris Figovsky (Hadera, IL); Alexander Fishman (Raanana, IL)
Assignee: Ravello Systems Ltd.
H04L67/28G06F9/45558H04L61/2528G06F2009/45595H04L61/6068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,648,121
App. No.
14/722,441
Granted
May 9, 2017
Kind
B2
Abstract

A proxy and method for performing source destination network address translation are presented. The method includes receiving a first message from a node communicatively connected to a first network to access a resource communicatively connected to a second network, wherein the first message contains at least a source address and a destination address used within the first network; translating the destination address designated in the first message to an address of the resource; generating a unique address for the destination address designated in the first message, wherein the unique address is an address not in use on the second network; providing a translated message including the translated destination address and the unique address; and forwarding the translated message to the resource communicatively connected to the second network.

Claims (45)

1. A source-destination network address translation (SDNAT) proxy comprising:

a processing system;

a memory, the memory containing instructions that, when executed by the processing system, configure the SDNAT proxy to:

receive a first message from a node communicatively connected to a first network to access a resource communicatively connected to a second network, wherein the first message contains at least a source address and a destination address used within the first network;

translate the destination address designated in the first message to an address of the resource;

generate a unique address for the source address designated in the first message, wherein the unique address is an address not in use on the second network;

provide a translated message including the translated destination address and the unique address; and

forward the translated message to the resource communicatively connected to the second network.

2. The SDNAT proxy of claim 1 , wherein the memory contains a map for translation of the destination address.

3. The SDNAT proxy of claim 1 , further configured to:

identify whether the resource is capable of communicating with the node over the first network; and

upon determination that the resource is not configured for communication over the first network, generate the unique address.

4. The SDNAT proxy of claim 1 , further configured to:

save in the memory a mapping between the source address and the unique address.

5. The SDNAT proxy of claim 1 , wherein the second network is a virtual network and the resource is a virtual machine (VM) component, wherein the VM component and the virtual network are part of a VM environment.

6. The SDNAT proxy of claim 5 , wherein the SDNAT proxy is connected in the VM environment.

7. The SDNAT proxy of claim 5 , wherein the first network is external to the VM environment.

8. The SDNAT proxy of claim 1 , further configured to:

receive a response message from the resource on the second network, wherein the response message includes a resource source address of the resource on the second network and the unique address.

9. The SDNAT proxy of claim 8 , further configured to:

translate the unique address, from the response message, to a node destination address of the node on the first network;

translate the source address of the resource on the second network to (a) the destination address included in the first message;

generating a translated response message including (a) the node destination address of the node on the first network as a destination address for the translated response message and (b) the destination address in the first message as a source address for the translated response message;

send the translated response message to the node on the first network.

10. A method for performing source destination network address translation, comprising:

receiving a first message from a node communicatively connected to a first network to access a resource communicatively connected to a second network, wherein the first message contains at least a source address and a destination address used within the first network;

translating the destination address designated in the first message to an address of the resource;

generating a unique address for the source address designated in the first message, wherein the unique address is an address not in use on the second network;

providing a translated message including the translated destination address and the unique address; and

forwarding the translated message to the resource communicatively connected to the second network.

11. The method of claim 10 , further comprising:

identifying whether the resource is capable of communicating with the node over the first network; and

upon determination that the resource is not configured for communication over the first network, generating the unique address.

12. The method of claim 10 , further comprising:

saving in a memory a mapping between the source address and the unique address, wherein the memory contains a map for translation of the destination address.

13. The method of claim 10 , wherein the second network is a virtual network and the resource is a virtual machine (VM) component, wherein the VM component and the virtual network are part of a VM environment.

14. The method of claim 13 , wherein the method is performed by a SDNAT proxy connected in the VM environment.

15. The method of claim 13 , wherein the first network is external to the VM environment.

16. The method of claim 10 , further comprising:

receiving a response message from the resource on the second network, wherein the response message includes a resource source address of the resource on the second network and the unique address.

17. The method of claim 16 , further comprising:

translating the unique address, from the response message, to a node destination address of the node on the first network;

translating the source address of the resource on the second network to (a) the destination address included in the first message;

generating a translated response message including (a) the node destination address of the node on the first network as a destination address for the translated response message and (b) the destination address in the first message as a source address for the translated response message;

sending the translated response message to the node on the first network.

Assignments (3)
CHANGE OF NAME Recorded Mar 4, 2021
From: RAVELLO SYSTEMS LTD.
To: ORACLE RAVELLO SYSTEMS LTD.
Reel/Frame 055489/0754 →
CHANGE OF NAME Recorded Mar 4, 2021
From: RAVELLO SYSTEMS LTD
To: ORACLE RAVELLO SYSTEMS LTD
Reel/Frame 055492/0005 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2015
From: FIGOVSKY, BORIS; FISHMAN, ALEXANDER
To: RAVELLO SYSTEMS LTD.
Reel/Frame 035720/0670 →
Continuity (2)
Provisional Application 62003032 · May 27, 2014
Related Publication 20150350157A1 · Dec 3, 2015