Secure Communication Link Authentication via DNS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for establishing secure communication links between electronic devices often fail to prevent unauthorized access, even when information is encrypted, as they do not adequately authenticate users on both ends of the communication link.
Innovation Solution
The implementation of a system and method that authenticates users by accessing their identification information, generating and comparing hash values using random vectors and keys, and transmitting secure network addresses only after successful authentication, ensuring that both clients are verified before establishing a secure communication link.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to protect information during transit, then information security is improved, but unauthorized access by rogue users with access to user devices cannot be prevented
Solution Approach 1:
The patent implements preliminary authentication actions before establishing secure communication links. User identification information is obtained and authenticated in advance, and secure communication links are only established after successful authentication. This preliminary verification prevents unauthorized access before encryption can be compromised.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that mediates between users and the communication channel. A secure name service authenticates users using their identification information before allowing them to establish encrypted communication links, adding a layer of verification that prevents rogue users from accessing even encrypted information.
2Object-affected harmful factors
If user authentication is implemented before establishing secure communication links, then unauthorized access is prevented, but system complexity increases
Solution Approach 1:
The patent makes the secure name service perform multiple functions: it serves as both a domain name resolution service and an authentication service. By combining these functions, the system avoids adding separate authentication infrastructure, thereby limiting the increase in system complexity while still implementing comprehensive user verification.
Data Source
AI summary
Systems and methods are provided for establishing a secure communication link between a first client and a second client. One exemplary computer-implemented method for establishing a secure communication link between a first diem and a second client includes accessing, from a storage, identification information of a user of the first client. The method further includes receiving a Domain Name Service (DNS) request from the first client requesting a secure network address corresponding to a secure domain name associated with the second client. The method further includes authenticating the user based on the user identification information. The method also includes transmitting the secure computer network address in response to the DNS request based on a determination that the user has been authenticated. A secure communication link between the first diem and the second client is established based on the secure computer network address.


