Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Fully qualified domain name" patented technology

A fully qualified domain name (FQDN), sometimes also referred to as an absolute domain name, is a domain name that specifies its exact location in the tree hierarchy of the Domain Name System (DNS). It specifies all domain levels, including the top-level domain and the root zone. A fully qualified domain name is distinguished by its lack of ambiguity: it can be interpreted only in one way.

Systems and methods for counter-reconnaissance in cloud infrastructure to disrupt adversarial targeting

The present invention relates to a cybersecurity system for preventing adversarial reconnaissance in cloud, hybrid, and multi-cloud environments by dynamically modifying user authentication identifiers, hostnames and fully qualified domain names. The system updates login usernames in real time using randomized, non-repeating values generated from a configurable dictionary. Updates occur at scheduled, random, coordinated, or event-triggered intervals to disrupt profiling and targeting attempts. When identifiers are changed, associated sessions and tokens are invalidated to prevent reuse. The system monitors expired credential usage to detect potential reconnaissance, generating alerts with intelligence such as IP addresses, timestamps, and affected resources. By eliminating predictable identity patterns, the system defends against reconnaissance-based attacks, unauthorized access attempts, and other credential-driven threats, thereby improving organizational security across cloud platforms.
Owner:FRENETIK LLC

Wildcard based private application access

ActiveUS12470520B2Networks interconnectionSecuring communicationDomain nameFully qualified domain name
Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and / or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
Owner:PALO ALTO NETWORKS INC

Intelligent DNS load balancing using combination of dynamic DNAT pool and application probing in connector based solution for private application access

PendingUS20260032115A1Securing communicationDomain nameFully qualified domain name
The present application discloses a method, system, and computer system for providing intelligent DNS load balancing using a combination of a dynamic DNAT pool and application providing in a connector-based solution for private application access. The method includes: (a) performing a DNS re-resolution for resolving an application Fully Qualified Domain Name (FQDN) to obtain a plurality of IP addresses for a plurality of application servers, (b) performing periodic application server probing, and (c) dynamically updating a destination network address translation (DNAT) to provide DNS load balancing for application traffic. The DNAT is updated based at least in part on one or more of the DNS re-resolution and the application server probing.
Owner:PALO ALTO NETWORKS INC

Detecting visual similarity between DNS fully qualified domain names

ActiveUS12513185B2Computer security arrangementsSecuring communicationDomain nameFully qualified domain name
Various techniques for detecting visual similarity between DNS fully qualified domain names (FQDNs) are disclosed. In some embodiments, a system, process, and / or computer program product for detecting visual similarity between DNS FQDNs includes receiving a DNS data stream, wherein the DNS data stream includes a DNS query and a DNS response for resolution of the DNS query; performing extended sequence alignment for each of the set of FQDNs to identify potential malware FQDNs for one or more target FQDNs based on a visual similarity for each domain in the DNS data stream; and classifying the set of domains as malware FQDNs or benign FQDNs based on results of the extended sequence alignment.
Owner:INFOBLOX INC

Nwdaf-assisted application detection based on domain name service (DNS)

PendingUS20260075030A1TransmissionDomain nameFully qualified domain name
Embodiments include methods for a network data analytics function (NWDAF) configured to assist with application detection in a communication network. Such methods include receiving, from a consumer network function (cNF) of the communication network, an analytic request related to assisted application detection and based on the analytic request, sending to a first DNS resolver associated with the communication network an exposure request for events related to fully qualified domain name (FQDN)-to-address mapping for application servers associated with applications. Such methods also include receiving from the first DNS resolver a first FQDN associated with a first application, in accordance with the exposure request, and based on the first FQDN, determining one or more packet flow descriptions (PFDs) associated with the first application. Such methods also include sending to the cNF an analytic result comprising the one or more PFDs, in accordance with the analytic request.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

A method and apparatus for updating credential information in a wireless communication system

PendingUS20260255161A1Domain nameFully qualified domain name
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method and apparatus for updating credential information in a wireless communication system is provided. According to an embodiment of the disclosure, a method of a user equipment (UE) in wireless communication system includes: transmitting, to an access and mobility function (AMF) entity, a registration request message based on a credential of a credentials holder via 3rd generation partnership project (3GPP) interworking function (N3IWF) entity for an untrusted non-3GPP access, and receiving, from the AMF entity, a registration accept message including updated credential information or a credential information update indication. The updated credential information included in the registration message includes at least one of: credentials holder controlled prioritized list of preferred standalone non-public networks (SNPNs) with N3IWF fully qualified domain names (FQDNs) of the preferred SNPNs, credentials holder controlled prioritized list of group identifier (ID) for network selections (GINs) with N3IWF FQDNs of SNPNs which broadcast the GINs, or credentials holder controlled prioritized list of N3IWFs.
Owner:SAMSUNG ELECTRONICS CO LTD

A wireless communication method, platform, device and storage medium

The application discloses a wireless communication method, a wireless communication platform, an electronic device and a computer readable storage medium, receiving first DNS configuration information associated with a first application network element sent by an edge computing server; the first DNS configuration information comprises at least one of a data network address, an application network element service identifier, a data network access identifier, a fully qualified domain name, a service filtering identifier and domain name system information; configuring the first DNS configuration information for a to-be-configured network element associated with the first application network element in a core network device, and sending DNS feedback information to the edge computing server; the DNS feedback information is used for indicating that the to-be-configured network element is successfully configured, or indicating that the to-be-configured network element fails to be configured. In this way, it is ensured that a terminal device can access services carried on the edge computing server through local DNS services.
Owner:CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1

Methods and apparatus for a sixth generation (6G) roaming solution using protocol for n32 interconnect security (PRINS) with roaming intermediaries

Session management for a Fifth Generation (5G) roaming solution using PRotocol for N32 INterconnect Security (PRINS) with roaming intermediaries is described herein. A first network node establishes a transport layer security (TLS) connection with a second network node, wherein the TLS connection is established using hypertext transfer protocol secure (HTTPS) as a uniform resource identifier (URI). The first network node creates a security negotiation request message, including a fully qualified domain name (FQDN) of the second network node. The first network node protects information elements (IEs) in the security negotiation request message with a Javascript Object Notation (JSON) Web Signature (JWS) token, wherein the JWS token uses a digital signature and includes a public key certificate of the first network node. The first network node sends over TLS, to the second network node, an HTTPS request, including the security negotiation request message and the JWS token.
Owner:CABLE TELEVISION LAB INC

Registration and authentication using multiple certificates

PCT designated stageWO2026051381A1Security arrangementSecuring communicationDomain nameFully qualified domain name
Various aspects of the present disclosure relate to registration and authentication using multiple certificates. A network equipment (NE) may transmit a request for a vendor-signed certificate to a server device associated with a vendor of the NE and based on a security key and a fully qualified domain name (FQDN). The NE may receive the vendor-signed certificate from the server device associated with the vendor of the NE. The NE may transmit a request for an operator-signed certificate to a server device associated with an operator of the NE and based on the vendor-signed certificate. The NE may receive the operator-signed certificate from the server device associated with the operator of the NE. The NE may establish a secure connection between the NE and a core network (CN) based on the vendor-signed certificate and the operator-signed certificate.
Owner:LENOVO (BEIJING) LTD

Methods and systems for accessing content

An identifier, for example, an identifier of a domain and / or a host of the domain (e.g., a fully qualified domain name (FQDN), etc.), such as a service management device (e.g., a server, a web server, a computing device, a web host device, a webpage, etc.), may be modified (e.g., hashed, encrypted, etc.) by a network device (e.g., a server, a domain name system (DNS) server, a DNS over hypertext transfer protocol secure (HTTPS) server / gateway (DoH server), DNS over Transport Layer Security (TLS) server / gateway (DoT server), a network management device, a computing device, etc.), sent to a user device (e.g., a client device, a smart device, a mobile device, a content output device, a computing device, a web browser, a search engine, etc.), and reused by the user device to request a service (e.g., a web service, a webpage, a file, content, a content item, etc.).
Owner:COMCAST CABLE COMM LLC

Network security

ActiveUS12452063B2User identity/authority verificationSecurity arrangementDomain nameFully qualified domain name
According to an example aspect of the present invention, there is provided an apparatus configured to function as a network function repository, and transmit to a network function consumer an access token authorizing access to a service provided by a network function producer, the access token comprising an at least one of: indication of a fully qualified domain name of the network function consumer, an indication of a domain from which access to the network function producer is allowed and an indication of a stand-alone non-public network from which access to the network function producer is allowed.
Owner:NOKIA TECHNOLOGIES OY

DNS query ddos flooding mitigation using legitimate FQDN matching

ActiveUS20260089186A1Securing communicationDomain nameFully qualified domain name
Responsive to domain name server (DNS) flood conditions being detected, a fully qualified domain name (FQDN) of each DNS query is checked against a table of legitimate FQDNs, and DNS queries having FQDNs that are verified as legitimate queries to pass to the DNS server are allowed, and DNS queries having FQDNs not verified as legitimate queries from passing to the DNS server are blocked.
Owner:FORTINET INC

Communication method and apparatus, electronic device, and storage medium

PendingCN122269264ASolve data inefficiencyNetwork data managementDomain nameFully qualified domain name
The present disclosure provides a communication method, device, electronic equipment and storage medium, and relates to the technical field of wireless communication. The method comprises: a policy control function (PCF) network element receiving a target message sent by a target network element (NF), wherein the target message comprises any one or more of the following: a target Internet Protocol (IP) address; a target fully qualified domain name (FQDN); a data network name (DNN) of a target protocol data unit (PDU) session; and single network slice selection assistance information (S-NSSAI) of the target PDU session. The present disclosure transmits data through a user plane, collects data from a user equipment by a core network element through the user plane, and establishes a channel between the user equipment and the core network element to collect user data, thereby solving the problem of low data transmission efficiency through a control plane.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Dns query method, apparatus, device, and medium

ActiveCN115706721BTransmissionWireless communicationDomain nameFully qualified domain name
The application discloses a DNS query method, device, equipment and medium, and belongs to the communication technical field. The DNS query method comprises the following steps: a first communication device receives a DNS query and obtains a fully qualified domain name (FQDN); the first communication device sends first information to a second communication device; the first information comprises the FQDN or N server IP addresses corresponding to the FQDN; N is a positive integer; the first communication device obtains server experience information corresponding to the N server IP addresses from the second communication device; the server experience information is used for indicating the service experience of a server corresponding to each server IP address; and the first communication device sends a DNS response to a terminal based on the server experience information.
Owner:VIVO MOBILE COMM CO LTD

Enhanced internet protocol security management for virtual private network concentrators

ActiveUS12537798B2Securing communicationDomain nameFully qualified domain name
This disclosure describes systems, methods, and devices related to managing Internet Protocol Security (IPsec) for virtual private network (VPN) concentrators. A method may include: identifying, by an edge gateway backend system, a first IPsec tunnel, a second IPsec tunnel, and a third IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; determining, by the edge gateway backend system, that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; determining, by the edge gateway backend system, that the highest priority tunnel between the VPN client and the VPN concentrator is active; and deactivating, by the edge gateway backend system, fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Home network function selection for mobile network home-routed roaming

A mobility management function residing in a visited Public Land Mobile Network (vPLMN) receives, from a Network Repository Function (NRF) residing in a home Public Land Mobile Network (hPLMN), a network address and / or a fully qualified domain name (FQDN) of a home network function (hNF) residing in the hPLMN. The mobility management function creates a network service request, associated with a User Equipment device (UE) that is roaming in the vPLMN, where the network service request comprises the network address and / or the FQDN. The mobility management function sends the network service request to a visited network function (vNF) residing in the vPLMN, and receives, via the vNF, results of execution of a network service by the hNF, and uses the results for handling the roaming UE’s traffic in the vPLMN.
Owner:VERIZON PATENT & LICENSING INC

Wildcard based private application access

PendingUS20260100933A1Networks interconnectionSecuring communicationDomain nameFully qualified domain name
Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and / or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
Owner:PALO ALTO NETWORKS INC

Methods and systems for accessing content

An identifier, for example, an identifier of a domain and / or a host of the domain (e.g., a fully qualified domain name (FQDN), etc.), such as a service management device (e.g., a server, a web server, a computing device, a web host device, a webpage, etc.), may be modified (e.g., hashed, encrypted, etc.) by a network device (e.g., a server, a domain name system (DNS) server, a DNS over hypertext transfer protocol secure (HTTPS) server / gateway (DoH server), DNS over Transport Layer Security (TLS) server / gateway (DoT server), a network management device, a computing device, etc.), sent to a user device (e.g., a client device, a smart device, a mobile device, a content output device, a computing device, a web browser, a search engine, etc.), and reused by the user device to request a service (e.g., a web service, a webpage, a file, content, a content item, etc.).
Owner:COMCAST CABLE COMM LLC

Fast QoS rule changes for high priority MO data

Methods and apparatuses are described herein for providing fine-grained QoS rules within UE Policies. A network entity may receive triggers to update the policies of a user equipment (UE) with parameters based on input such as input from a third party. The network entity may derive fine-grained quality of service (QoS) rules and corresponding QoS Profiles and delivers them to the UE using a UE Policy container via the Non-Access Stratum (NAS). The fine-grained rules may comprise: a destination fully qualified domain name (FQDN) or uniform resource locator (URL), an Application ID, a User Route Selection Policy precedence value, etc. The fine-grained rules also provide mechanisms for time gating or volume gating. The UE may request new QoS treatment resulting in UE Policy update and may use the information in the fine-grained QoS rules when establishing or modifying PDU Session to apply QoS Flow Identifier (QFI) marking.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Network switching method, device and equipment of user terminal, and storage medium

The application relates to a network switching method and device of a user terminal, equipment and a storage medium, and relates to the technical field of mobile communication. The method comprises the following steps: a first access and mobility management function (AMF) determines a target network slice according to a data network name (DNN) to be accessed and a user terminal identifier, and determines a target AMF according to the target network slice. In the case that the first AMF is the target AMF, the first AMF determines a target session management function (SMF) according to a packet data network gateway (PGW) fully qualified domain name (FQDN), a target base station area identifier and the target network slice, and performs network switching on the user terminal according to the target network slice and the target SMF. In the case that the first AMF is not the target AMF, the first AMF sends a relocation request message to the target AMF, so that the target AMF performs network switching on the user terminal. The application is used for realizing network switching of a user terminal and improving the network experience of users.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Methods and systems for implementing very large DNS zones

PendingUS20250379847A1TransmissionDomain nameFully qualified domain name
Systems, methods and devices are provided for registering DNS hostnames of Internet host devices for very large domain zones (VLZ) stored on a DNS server on a network, including setting a pseudo-zone as the VLZ, intercepting DNS updates to the pseudo-zone, mapping the entries in the pseudo-zone into a hierarchy of real parent zones and sub-zones using a mapping formula, and translating DNS updates to the pseudo-zone from an original fully qualified domain name (FQDN) into a at least one new FQDNs and adding the at least one new FQDNs to an authoritative DNS Server.
Owner:BLUECAT NETWORKS USA

Enhanced internet protocol security management for virtual private network concentrators

PendingUS20260149697A1Securing communicationDomain nameFully qualified domain name
This disclosure describes systems, methods, and devices related to managing Internet Protocol Security (IPsec) for virtual private network (VPN) concentrators. A method may include: identifying, by an edge gateway backend system, a first IPsec tunnel, a second IPsec tunnel, and a third IPsec tunnel between a VPN client and a VPN concentrator of the edge gateway backend system; determining, by the edge gateway backend system, that the first IPsec tunnel is a highest priority tunnel between the VPN client and the VPN concentrator; determining, by the edge gateway backend system, that the highest priority tunnel between the VPN client and the VPN concentrator is active; and deactivating, by the edge gateway backend system, fully qualified domain names of the second IPsec tunnel and the third IPsec tunnel from the VPN concentrator based on the determination that the highest priority tunnel between the VPN client and the VPN concentrator is active.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Intelligent domain name service (DNS) pre-cache

ActiveUS12621259B2TransmissionElectric digital data processingDomain nameFully qualified domain name
A gateway router is provisioned with network access by a service provider computing system associated with a service provider. The service provider computing system generates a domain name service (DNS) profile for a user of the gateway router based on customer profile data associated with the user. The DNS profile includes a predicted fully qualified domain name (FQDN). During an initialization process, the gateway router receives the DNS profile from the service provider computing system and stores the DNS profile in a DNS cache. Subsequently, the gateway router obtains an internet protocol (IP) address corresponding to the predicted FQDN in the DNS profile and stores the IP address in the DNS cache. Subsequently, the gateway router implements a local area network (LAN) and establishes connection to one or more client computing devices.
Owner:CHARTER COMM OPERATING LLC