DNS Firewall Routing for Local Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face protection gaps from cyber threats when accessing local resources outside a protected internal network, as traditional DNS firewalls do not effectively extend protection to mobile devices or external networks, limiting access to internal services.

Innovation Solution

A system where a computing device sends DNS requests through a VPN server to identify with a customer's network block, allowing the DNS firewall to apply protections and direct requests to internal DNS servers for local resource access, ensuring both protection and functionality across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a DNS firewall is configured to forward global DNS traffic to provide cyber threat protection, then security protection is improved, but user devices outside the internal network lose protection and cannot access local resources

Engineering Contradiction:
Improvecyber threat protectionVSAvoidaccess to local resources outside internal network
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The DNS request handling is segmented into two distinct paths: one for global DNS requests (forwarded to DNS firewall for security filtering) and one for local DNS requests (handled by internal DNS server). The system determines which path to use based on the request type, allowing simultaneous protection and local resource access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computing device acts as an intermediary between the user device and the DNS infrastructure. It receives DNS requests, determines whether they are global or local, and routes them appropriately to either the DNS firewall or internal DNS server, enabling both security and local resource accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If DNS requests are forwarded to external DNS firewall server, then security filtering is improved, but access to internal network resources is lost

Engineering Contradiction:
Improvecyber threat filteringVSAvoidaccess to local services
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically adjusts DNS request routing based on the type of request. Local DNS requests are routed to the internal DNS server for easy access to local services, while global DNS requests are routed to the DNS firewall for security filtering. This dynamic routing ensures both security and ease of operation are maintained.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different quality of service is applied to different types of DNS requests. Local DNS requests receive direct handling by the internal DNS server for ease of access, while global DNS requests receive security filtering from the DNS firewall. This local quality approach ensures each request type gets the appropriate treatment.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If internal DNS server handles all DNS requests, then access to local resources is maintained, but cyber threat protection is lost

Engineering Contradiction:
Improveaccess to local resourcesVSAvoidexposure to cyber threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The DNS request handling is segmented into two distinct paths: one for global DNS requests (forwarded to DNS firewall for security filtering) and one for local DNS requests (handled by internal DNS server). The system determines which path to use based on the request type, allowing simultaneous protection and local resource access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computing device provides feedback by determining the origin and type of each DNS request, then routing it appropriately. This feedback mechanism ensures that local requests maintain access while global requests receive security filtering, preventing cyber threats from reaching the internal network.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10230691B2Systems, devices, and methods for improved domain name system firewall protection
Publication Date: 2019.03.12 VERISIGN INC
  • US10230691B2 patent drawing
  • US10230691B2 patent drawing
  • US10230691B2 patent drawing

AI summary

Embodiments relate to systems, devices, and computing-implemented methods for resolving DNS requests by sending, from a device, a first DNS request for a domain name associated with a local service device to a DNS firewall server. The DNS firewall server can send a response that includes a status indicating a server failure in response to determining that the first DNS request is associated with a customer of a DNS firewall service and determining that a record associated with the domain name cannot be found. The device can receive the response and send a second DNS request to an internal DNS server in response to the status indicating the server failure.