Anycast DNS Server for Zero Footprint Intranet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems require complex domain names and agents like VPNs to access internal applications from outside an intranet, making it difficult to provide access without additional technology or user-friendly domain names.

Innovation Solution

A method using a DNS server configured for the intranet to pre-establish a connection by resolving a fully qualified domain name (FQDN) of a web application, allowing access without a VPN, by directing the client to send a handshake message to an access service for conditional access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN tunnel or agent is used to access internal applications from outside the intranet, then secure access is provided, but device complexity and ease of operation deteriorate due to requiring additional technology and complicated domain names

Engineering Contradiction:
Improvesecure accessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the DNS resolution function from the traditional VPN/agent architecture and places it at the network infrastructure level. The anycast DNS servers resolve FQDNs to appropriate intranet addresses without requiring client-side VPN agents, thereby removing the complexity burden from end devices while maintaining secure access through network-level controls.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces anycast DNS servers as intermediaries between external clients and internal applications. These DNS servers act as mediators that translate user-friendly FQDNs into intranet addresses, enabling access without direct VPN connections or complex client configurations, thus reducing device complexity while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a VPN tunnel or agent is used to access internal applications from outside the intranet, then secure access is provided, but ease of operation worsens due to requiring client agents and complicated domain names

Engineering Contradiction:
Improvesecure accessVSAvoidaccess simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent removes the requirement for client-side VPN agents by extracting the secure access functionality to the network infrastructure level. External users simply use standard DNS resolution with anycast servers, eliminating the need for complex agent installations and configurations while maintaining secure access controls.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The anycast DNS system provides self-service functionality by automatically resolving FQDNs to appropriate intranet addresses without requiring user configuration or agent installation. The system handles security, routing, and address resolution automatically, making the access process as simple as typing a standard domain name.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional DNS resolution is used for external access to intranet applications, then domain name resolution is provided, but productivity worsens due to inability to resolve internal FQDNs from outside the intranet

Engineering Contradiction:
Improvedomain name resolutionVSAvoidaccess speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-positioning anycast DNS servers in multiple network locations before external access requests arrive. These servers are预先 configured with knowledge of intranet address mappings, enabling immediate resolution of FQDNs without requiring real-time VPN tunnel establishment or complex lookup procedures, thus improving access speed while maintaining ease of operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230012224A1Zero footprint VPN-less access to internal applications using per-tenant domain name system and keyless secure sockets layer techniques
Publication Date: 2023.01.12 CITRIX SYSTEMS INC
  • US20230012224A1 patent drawing
  • US20230012224A1 patent drawing
  • US20230012224A1 patent drawing

AI summary

Described embodiments provide systems and methods for accessing a web application hosted in an intranet from outside said intranet. A server hosting a domain name service configured for the intranet can receive a request from a client that is outside the intranet to access the web application. The request may include a fully qualified domain name (FQDN) of the web application in the intranet. Responsive to the FQDN of the web application in the intranet, the server may send a notification to an access service, to cause the access service to pre-establish a connection to the intranet. Responsive to the FQDN of the web application in the intranet, the server may direct the client to send a handshake message to the access service to request access to the web application.