DNS-Triggered Pinhole Creation for NAT Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network address translation (NAT) devices restrict communication by only allowing traffic from the masqueraded network to pass through, limiting access to protected devices behind firewalls or NATs, and lack dynamic addressing support for mobile devices, which complicates secure access management.
Innovation Solution
A method and apparatus that initiate a 'pinhole' through a network address translator or firewall in response to a DNS query, allowing traffic from external devices to reach protected devices by creating a temporary communication path with authentication, using a transport address and port number, enabling secure and dynamic access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NAT devices restrict communication to only allow traffic from the masqueraded network, then network security is improved, but access to protected devices from external networks is blocked
Solution Approach 1:
The system performs preliminary actions by establishing translation table entries in advance that allow external devices to initiate connections to protected devices. The DNS server pre-configures the NAT device with translation rules mapping external addresses to internal protected device addresses, enabling incoming traffic before it is needed.
Solution Approach 2:
The patent introduces a DNS server as an intermediary that mediates between external devices and protected devices behind NAT. The DNS server receives connection requests, determines the appropriate protected device, and facilitates the creation of translation table entries, acting as a trusted mediator that enables secure access without compromising NAT protection.
2Adaptability or versatility
If static NAT entries are configured for permanent use, then access to designated hosts is enabled, but device complexity and configuration management increase
Solution Approach 1:
The system enables self-service by allowing the NAT device to automatically create and manage translation table entries based on DNS server instructions. Instead of requiring manual configuration of static NAT entries, the NAT device receives dynamic instructions from the DNS server and automatically updates its translation tables, reducing configuration complexity while maintaining access capability.
Solution Approach 2:
The patent transforms the static NAT configuration into a dynamic system where translation table entries are created, modified, and removed based on real-time needs. The NAT device dynamically adjusts its translation tables according to instructions from the DNS server, allowing flexible access management without permanent configurations, thereby reducing complexity for mobile and temporary access scenarios.
3Reliability
If translation table state is flushed after a short period without traffic, then security is maintained, but mobile devices with changing addresses cannot maintain connections
Solution Approach 1:
The system implements feedback mechanisms where the DNS server monitors connection status and traffic patterns, then provides instructions to the NAT device to refresh or extend translation table entries. This feedback loop allows the NAT device to maintain connections for mobile devices by receiving periodic refresh instructions from the DNS server, balancing security (automatic flushing) with mobile device support (controlled extension).
Solution Approach 2:
The patent employs periodic action by having the DNS server send periodic refresh instructions to the NAT device to maintain translation table entries for active connections. Instead of relying on continuous traffic to refresh state, the system uses periodic DNS-mediated refresh commands to extend connection validity, enabling mobile devices to maintain connections during temporary inactivity while still allowing automatic security flushing after extended periods.
Data Source
AI summary
Disclosed are, inter alia, methods, apparatus, computer-storage media, mechanisms, and means associated with a protected device initiating a pinhole through a network address translator and/or firewall to allow access to the protected device in response to a Domain Name System (DNS) query. In response to a received DNS query from a domain name system (DNS) server, an apparatus requests a traffic pinhole be created in a firewall or network address translator for allowing traffic initiated from a device, on another side of the firewall or said network address translator from the apparatus, to reach the apparatus.


