DNS Everywhere Geolocation-Aware Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In hybrid enterprise networks, globally distributed Software as a Service (SaaS) environments experience performance issues due to incorrect geolocation mapping, where DNS requests are backhauled through data centers, leading to suboptimal routing and increased latency.
Innovation Solution
The DNS Everywhere system directs DNS requests from end users to a global network of Recursive DNS Servers, using Akamai's CDN to perform geolocation-aware lookups closer to the user, and establishes secure tunnels for internal resolutions, ensuring that users connect to the nearest SaaS servers without compromising security or privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNS requests are backhauled through data centers in hybrid networks, then internal resource access is secured, but SaaS performance deteriorates due to incorrect geolocation mapping and increased latency
Solution Approach 1:
The system segments DNS resolution into two distinct paths: one for internal resources through the data center for security, and another for external SaaS resources through direct Internet access via CDN nodes. This segmentation allows each traffic type to follow the optimal path without interference, resolving the contradiction between security and speed.
Solution Approach 2:
The patent implements local quality by deploying CDN nodes with DNS resolution capabilities at locations close to end users. These local nodes perform geolocation-aware DNS resolution for SaaS resources, providing fast local access while the centralized data center maintains security control for internal resources. The system makes different parts of the DNS infrastructure have different functions based on their location and purpose.
2Reliability
If all DNS requests are routed through centralized data centers, then security and control are maintained, but latency increases and geolocation accuracy is lost
Solution Approach 1:
The patent introduces a new dimensional approach by deploying DNS resolution capability across multiple geographic locations through CDN nodes, rather than concentrating it in a single centralized data center. This spatial distribution allows DNS requests to be resolved locally at the edge network, significantly reducing latency while the system maintains security through centralized policy control and authentication mechanisms.
3Productivity
If direct Internet access is implemented at branch offices, then deployment speed and cost are improved, but DNS resolution for internal resources becomes complex
Solution Approach 1:
The CDN nodes deployed at branch offices perform multiple functions: they provide fast local DNS resolution for SaaS resources, enable secure access to internal resources through the data center, and maintain geolocation-aware routing. This multi-functionality simplifies the overall network architecture by consolidating DNS resolution capabilities at the edge while maintaining security and performance requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In the system, the end user client is configured to direct a DNS request, the DNS request being a request to resolve a hostname, directly onto the public Internet to a DNS service platform operated by a service provider on behalf of the enterprise, the DNS service platform comprising a plurality of platform DNS servers distributed around the Internet. One unique feature of this solution is that the end users in the company branch offices always utilize the nearest DNS Everywhere resolvers to do lookups on their behalf, thus ensuring any service that does geolocation maps their requests to nearby machines. Further, the enterprise DNS server is configured to receive the end user client-s DNS requests, which is for internal hostname, and generate a DNS answer, which is returned to the end user client via the secure tunnel.