DNS-Based Device Control via Gateway Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device control technologies are cumbersome, limited in functionality, and can be evaded by users, as they require separate software installations on each device, lack distinction among individual devices, and are constrained by the memory and computing power of gateway devices.
Innovation Solution
A DNS-based device control system that attaches unique identifiers to DNS messages from individual devices via the gateway, allowing a central software module to enforce policies and control access, distinguish among devices, and operate independently of device capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device control software is installed on each individual device, then device control functionality is achieved, but installation and configuration complexity increases
Solution Approach 1:
The patent extracts the control functionality from individual devices and relocates it to the gateway device. The gateway runs a control software module that intercepts and filters DNS queries, eliminating the need to install control software on each individual device while maintaining centralized control capabilities
Solution Approach 2:
The patent combines multiple device control functions into a single gateway-based software module. This module handles DNS query interception, device identification, policy enforcement, and content filtering all in one centralized location, simplifying installation and configuration
2Device complexity
If gateway software is used for device control, then installation simplicity is improved, but control functionality is limited by gateway resources
Solution Approach 1:
The patent uses DNS queries as an intermediary mechanism between individual devices and the gateway control module. The DNS interception capability allows the gateway to monitor and control all device communications without requiring direct software installation on individual devices, while maintaining comprehensive control functionality
Solution Approach 2:
The gateway-based software module is designed to handle multiple device types and control scenarios universally. It can identify different devices through DNS query analysis, apply different policies to different devices, and provide parental control, security filtering, and content management all through a single multi-functional system
3Ease of operation
If server-based control software is used, then centralized control is achieved, but ability to distinguish among individual devices is lost
Solution Approach 1:
The patent applies local quality by making the gateway control module aware of individual device characteristics through DNS query analysis. Each device's DNS queries are examined for unique identifiers, allowing the system to apply device-specific policies while maintaining centralized control architecture
Solution Approach 2:
The patent changes the parameter of device identification by using DNS query characteristics (such as query patterns, timestamps, and embedded device identifiers) instead of requiring direct device communication. This allows the centralized system to distinguish among devices through indirect observation of their DNS traffic
Data Source
AI summary
A device control system is associated with individual devices connected through a network control point to a gateway and thereby to the Internet. The gateway inserts an EDNS0 pseudo resource record into an additional data section in each DNS query initiated by an individual device, the EDNS0 pseudo resource record identifying the initiating device. A dynamic policy enforcement engine in front of the DNS engine intercepts the DNS query, identifies the initiating device, and selects a policy that applies to the device. The dynamic policy enforcement engine may provide parental control and security service to the individual device by blocking the DNS query or passing it to the DNS engine according to the policy. A component that intercepts DNS queries may provide several additional types of services to the individual devices, including advertising, messaging, mobile device tracking, individual device application control, and delivery of individualized content.


