Cloud DNS-IP Mapping for Roaming Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network administrators face challenges in controlling network access to domain names, particularly during roaming, as cached DNS results can allow clients to access restricted domains without initiating new DNS transactions, making it difficult to enforce domain-based Access Control Lists (ACLs) and Policy-based Routing (PBR) across different access points.
Innovation Solution
A system that collects local DNS-IP mappings from individual access points within a virtual Local Area Network (VLAN) and generates a global DNS-IP mapping in a cloud computing system, which is then distributed to relevant access points, allowing them to control network traffic without requiring new DNS transactions upon roaming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If clients use cached DNS results during roaming, then access speed is improved, but network access control reliability deteriorates
Solution Approach 1:
The system performs preliminary action by collecting DNS-IP mappings from multiple access points before roaming occurs and storing them in a cloud-based database. When a client roams to a new access point, the pre-collected mapping data is already available, allowing the new access point to immediately enforce domain-based ACLs without waiting for new DNS transactions or cached results.
2Reliability
If domain-based ACLs are enforced at each access point, then network access control reliability is improved, but device complexity increases
Solution Approach 1:
The patent introduces a cloud-based intermediary system that collects DNS-IP mappings from multiple access points and stores them in a centralized database. This intermediary cloud system handles the complexity of maintaining and updating domain mappings, while individual access points simply query the cloud database for the required mapping data, significantly reducing the complexity burden on each access point device.
3Reliability
If new DNS transactions are initiated at each access point during roaming, then network access control reliability is improved, but loss of time increases
Solution Approach 1:
The system performs preliminary action by collecting and storing DNS-IP mappings in advance before roaming occurs. When a client roams to a new access point, the mapping data is already available in the cloud database, eliminating the need to wait for new DNS transactions and reducing time loss during the roaming process.
4Reliability
If all IP addresses of a domain are collected in ACL, then network access control reliability is improved, but difficulty of detecting and measuring increases
Solution Approach 1:
The patent introduces a cloud-based intermediary that automatically collects and maintains comprehensive domain IP address mappings from multiple access points. This intermediary system handles the complex task of tracking all domain IPs centrally, while individual access points simply query the cloud database for the complete mapping list, significantly reducing the difficulty of detecting and measuring all domain addresses without requiring complex local monitoring at each access point.
Data Source
AI summary
Some examples relate to controlling network traffic pertaining to a domain name based on a Domain Name System-Internet Protocol address (DNS-IP) mapping, An example includes receiving, in a cloud computing system, a local DNS-IP mapping for a domain name from respective Access Points (APs) in a virtual local area network (VLAN) along with geographical information of respective APs; generating a global DNS-IP mapping database comprising the local DNS-IP mapping for the domain name received from respective APs in the VLAN along with geographical information of respective APs, in the cloud computing system; and determining appropriate APs to distribute the global DNS-IP mapping, based on location information of respective APs.


