Cloud DNS-IP Mapping for Roaming Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network administrators face challenges in controlling network access to domain names, particularly during roaming, as cached DNS results can allow clients to access restricted domains without initiating new DNS transactions, making it difficult to enforce domain-based Access Control Lists (ACLs) and Policy-based Routing (PBR) across different access points.

Innovation Solution

A system that collects local DNS-IP mappings from individual access points within a virtual Local Area Network (VLAN) and generates a global DNS-IP mapping in a cloud computing system, which is then distributed to relevant access points, allowing them to control network traffic without requiring new DNS transactions upon roaming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If clients use cached DNS results during roaming, then access speed is improved, but network access control reliability deteriorates

Engineering Contradiction:
Improveaccess speedVSAvoidnetwork access control reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary action by collecting DNS-IP mappings from multiple access points before roaming occurs and storing them in a cloud-based database. When a client roams to a new access point, the pre-collected mapping data is already available, allowing the new access point to immediately enforce domain-based ACLs without waiting for new DNS transactions or cached results.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If domain-based ACLs are enforced at each access point, then network access control reliability is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork access control reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based intermediary system that collects DNS-IP mappings from multiple access points and stores them in a centralized database. This intermediary cloud system handles the complexity of maintaining and updating domain mappings, while individual access points simply query the cloud database for the required mapping data, significantly reducing the complexity burden on each access point device.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If new DNS transactions are initiated at each access point during roaming, then network access control reliability is improved, but loss of time increases

Engineering Contradiction:
Improvenetwork access control reliabilityVSAvoidtime loss
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by collecting and storing DNS-IP mappings in advance before roaming occurs. When a client roams to a new access point, the mapping data is already available in the cloud database, eliminating the need to wait for new DNS transactions and reducing time loss during the roaming process.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If all IP addresses of a domain are collected in ACL, then network access control reliability is improved, but difficulty of detecting and measuring increases

Engineering Contradiction:
Improvenetwork access control reliabilityVSAvoiddifficulty of detecting and measuring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a cloud-based intermediary that automatically collects and maintains comprehensive domain IP address mappings from multiple access points. This intermediary system handles the complex task of tracking all domain IPs centrally, while individual access points simply query the cloud database for the complete mapping list, significantly reducing the difficulty of detecting and measuring all domain addresses without requiring complex local monitoring at each access point.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11588781B2Controlling network traffic pertaining to a domain name based on a DNS-IP mapping
Publication Date: 2023.02.21 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11588781B2 patent drawing
  • US11588781B2 patent drawing
  • US11588781B2 patent drawing

AI summary

Some examples relate to controlling network traffic pertaining to a domain name based on a Domain Name System-Internet Protocol address (DNS-IP) mapping, An example includes receiving, in a cloud computing system, a local DNS-IP mapping for a domain name from respective Access Points (APs) in a virtual local area network (VLAN) along with geographical information of respective APs; generating a global DNS-IP mapping database comprising the local DNS-IP mapping for the domain name received from respective APs in the VLAN along with geographical information of respective APs, in the cloud computing system; and determining appropriate APs to distribute the global DNS-IP mapping, based on location information of respective APs.