DNS-Triggered Pinhole Creation for NAT Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network address translation (NAT) devices restrict communication by only allowing traffic from the masqueraded network to pass through, limiting access to protected devices behind firewalls or NATs, and lack dynamic addressing support for mobile devices, which complicates secure access management.

Innovation Solution

A method and apparatus that initiate a 'pinhole' through a network address translator or firewall in response to a DNS query, allowing traffic from external devices to reach protected devices by creating a temporary communication path with authentication, using a transport address and port number, enabling secure and dynamic access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If NAT devices restrict communication to only allow traffic from the masqueraded network, then network security is improved, but access to protected devices from external networks is blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess to protected devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by establishing translation table entries in advance that allow external devices to initiate connections to protected devices. The DNS server pre-configures the NAT device with translation rules mapping external addresses to internal protected device addresses, enabling incoming traffic before it is needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a DNS server as an intermediary that mediates between external devices and protected devices behind NAT. The DNS server receives connection requests, determines the appropriate protected device, and facilitates the creation of translation table entries, acting as a trusted mediator that enables secure access without compromising NAT protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If static NAT entries are configured for permanent use, then access to designated hosts is enabled, but device complexity and configuration management increase

Engineering Contradiction:
Improveaccess to designated hostsVSAvoidconfiguration management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing the NAT device to automatically create and manage translation table entries based on DNS server instructions. Instead of requiring manual configuration of static NAT entries, the NAT device receives dynamic instructions from the DNS server and automatically updates its translation tables, reducing configuration complexity while maintaining access capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the static NAT configuration into a dynamic system where translation table entries are created, modified, and removed based on real-time needs. The NAT device dynamically adjusts its translation tables according to instructions from the DNS server, allowing flexible access management without permanent configurations, thereby reducing complexity for mobile and temporary access scenarios.

Inventive Principle:
Principle #15Dynamics

3Reliability

If translation table state is flushed after a short period without traffic, then security is maintained, but mobile devices with changing addresses cannot maintain connections

Engineering Contradiction:
ImprovesecurityVSAvoidmobile device support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements feedback mechanisms where the DNS server monitors connection status and traffic patterns, then provides instructions to the NAT device to refresh or extend translation table entries. This feedback loop allows the NAT device to maintain connections for mobile devices by receiving periodic refresh instructions from the DNS server, balancing security (automatic flushing) with mobile device support (controlled extension).

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs periodic action by having the DNS server send periodic refresh instructions to the NAT device to maintain translation table entries for active connections. Instead of relying on continuous traffic to refresh state, the system uses periodic DNS-mediated refresh commands to extend connection validity, enabling mobile devices to maintain connections during temporary inactivity while still allowing automatic security flushing after extended periods.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8612592B2Protected device initiated pinhole creation to allow access to the protected device in response to a domain name system (DNS) query
Publication Date: 2013.12.17 CISCO TECHNOLOGY INC
  • US8612592B2 patent drawing
  • US8612592B2 patent drawing
  • US8612592B2 patent drawing

AI summary

Disclosed are, inter alia, methods, apparatus, computer-storage media, mechanisms, and means associated with a protected device initiating a pinhole through a network address translator and/or firewall to allow access to the protected device in response to a Domain Name System (DNS) query. In response to a received DNS query from a domain name system (DNS) server, an apparatus requests a traffic pinhole be created in a firewall or network address translator for allowing traffic initiated from a device, on another side of the firewall or said network address translator from the apparatus, to reach the apparatus.