DNS Message Data Embedding for Credential-Free Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication techniques for devices connected to networks require authentication codes, which can be insecure and resource-intensive, especially for devices with limited battery life or size constraints, making it difficult for them to connect and communicate over secured networks without significant overhead.
Innovation Solution
The technology leverages the Domain Name System (DNS) to enable communication by embedding data in DNS messages, allowing devices to transmit information without traditional authentication codes by using open DNS networks and encoding messages within DNS requests, which can be routed through DNS servers for processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication codes are used for network communication, then security is improved, but device complexity and resource consumption increase
Solution Approach 1:
The patent extracts the authentication function from traditional network protocols and relocates it to the DNS resolution process. By embedding authentication information in DNS queries and responses, the system eliminates the need for separate authentication codes on devices while maintaining security. This extraction resolves the contradiction by removing complex authentication mechanisms from device-level operations.
Solution Approach 2:
The patent introduces DNS servers as intermediaries that handle authentication and communication routing. Instead of devices directly managing authentication codes, the DNS server acts as a mediator that receives encoded messages, resolves domain names, and facilitates communication. This intermediary approach reduces device complexity while maintaining security through centralized authentication management.
2Reliability
If authentication codes and network security protocols are implemented, then security is improved, but energy consumption increases
Solution Approach 1:
The patent extracts authentication operations from device-level network stacks and relocates them to DNS server processing. By moving authentication code execution from resource-constrained devices to more powerful DNS servers, the system reduces energy consumption on battery-powered devices while maintaining security through server-based authentication validation.
3Reliability
If standard network communication protocols are used, then communication reliability is improved, but overhead and setup complexity increase
Solution Approach 1:
The patent makes DNS serve multiple functions: domain name resolution, authentication verification, and communication routing. By consolidating these functions into a single universal protocol layer, the system eliminates the need for separate setup procedures for each function, reducing overall setup complexity while maintaining communication reliability through standardized DNS-based operations.
4Reliability
If devices connect to secured networks, then communication security is improved, but authentication overhead increases
Solution Approach 1:
The patent performs authentication actions preliminarily during the DNS resolution process itself. By embedding authentication verification in the DNS query-response cycle, the system completes authentication before actual data transmission begins. This preliminary authentication action eliminates subsequent authentication overhead and reduces the time required for secure connection establishment.
Data Source
AI summary
Technology for communicating by embedding messages in DNS requests/responses is disclosed. In many cases it is desirable for a device to communicate without that device having to supply network credentials. In some network environments, credentials are not required to send or receive DNS messages. The question section of a DNS request message may include a message for a destination DNS server and a query domain which, when using standard DNS routing, will result in the DNS request being directed to the intended destination DNS server. The message may be encoded in such a way that an algorithm run by the destination DNS server is able to parse the message from the DNS request.


