EP1979830B1

Systems and methods for remote access of network devices having private addresses

Abstract

This record has no abstract on file.

EP1979830B1, drawing sheet 1
Sheet 1 of 7

Term

0.3 yearsleft in the term

Expires 23 January 2027.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

37 claims: 4 independent, 33 dependent

  1. 1
    A proxy server (116), comprising a memory (182) configured to store and retrieve a client device identifier (134-2) and an associated client device public transport address (160-1); and a communication unit (184) configured to send and receive messages, the communication unit (184) being configured to receive an identification message according to a first protocol from a client device (102) through at least one intermediate network address translator, NAT, (154), the identification message including the client device identifier (134-2) and conveying the client device public transport address (160-1), wherein the communication unit (184) is configured to receive keep-alive messages according to the first protocol periodically sent by the client device (102) to maintain a NAT address binding, and to receive a request message from an admin device (114) including the client device identifier (134-1), wherein the memory (182) is updated with the conveyed client device public transport address (160-1) so that the conveyed client device public transport address (160-1) is associated in the memory (182) with the client device identifier (134-2); wherein the proxy server (116) is configured to:search the memory (182) for the client device identifier (134-2) that matches the client device identifier (134-1) included in the request message, select the updated public transport address (160-1) associated in memory with the client device identifier (134-1), retrieve the associated client device public transport address (160-1), and using the associated client device public transport address (160-1), instruct the client device (102) to open a connection with the proxy server (116) according to a second protocol that is different from the first protocol.
  2. 11
    A client device (102), comprising:a client device identifier (134);and a communication unit (138) configured to send and receive messages, the client device (102) being configured to send an identification message according to a first protocol, the identification message including the client device identifier (134) and conveying the client device public transport address (160) to establish a path through at least one intermediate network address translator, NAT, (154) to a proxy server (116), wherein the client device (102) is configured to periodically send keep-alive messages according to the first protocol to the proxy device (116) to maintain a NAT address binding and to receive a request message from the proxy server (116) according to the first protocol on the path established by the identification message, wherein the request message includes a request to establish a connection between the client device (102) and the proxy server (116) on the path according to a second protocol that is different from the first protocol.
  3. 22
    An admin device (114), comprising:a memory (172) configured to store and retrieve a client device identifier (134-1) that provides for identification of a client device (102) on a private network, the client device (102) having an associated client device public transport address (160) and maintaining a communication path with a proxy server (116) through at least one intermediate network address translator, NAT, (154), the client device (102) being configured to periodically send keep-alive messages according to the first protocol to the proxy device (116) to maintain a NAT address binding;and a communication unit (176) configured to send and receive messages, the admin device (114) being configured to send a first request message including the client device identifier (134-1) to the proxy server (116), the proxy server (116) being configured to update a memory (182) with the client device public transport address (160-1) so that the client device public transport address (160-1) is associated in the memory (182) with the client device identifier (134-2), receive the first request message, use the client device identifier (134-1) to search the memory (182) for the client device identifier (134-2) that matches the client device identifier (134-1) included in the first request message, select the updated public transport address (160-1) associated in memory (182) with the client device identifier (134-2), and retrieve the associated client device public transport address (160-1) for the client device (102), the proxy server (116) being configured to use the associated client device public transport address (160-1) to instruct the client device (102) to establish a connection with the proxy server (116) using a second protocol that is different from the first protocol, and to provide a relay of messages between the client device (102) and the admin device (114) using the connection.
  4. 26
    A method of providing access to a client device, the method comprising the operations of:establishing a communication path between a client device (102) and a proxy server (116) through at least one intermediate network address translator, NAT, (154), wherein the client device (102) provides a client device identifier (134) to the proxy server (116) and is configured to periodically send keep-alive messages according to the first protocol to the proxy device (116) to maintain a NAT address binding, wherein a client device public transport address (160) is conveyed to the proxy server (116);a memory (182) is updated with the conveyed client device public transport address (160-1) so that the conveyed client device public transport address (160-1) is associated in the memory (182) with the client device identifier (134-2);and establishing relay communications between an admin device (114) and the client device (102) through the proxy server (116) using a second protocol that is different from the first protocol, wherein the admin device (114) provides the client device identifier (134-1) to the proxy server (116), the proxy server (116) uses the client device identifier (134-1) to search the memory (182) for the client device identifier (134-2) that matches the client device identifier (134-1) provided to the proxy server (116) from the client device (102), select the updated public transport address (160-1) associated in memory (182) with the client device identifier (134-2), retrieve the associated client device public transport address (160-1), and using the associated client device public transport address (160-1), instruct the client device (102) to open a connection with the proxy server (116) according to the second protocol to access the communication path between the client device (102) and the proxy server (116).