DNS Proxy Host Detection for Cloud User Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for authenticating users to cloud security services face challenges such as managing a large number of Internal Gateways (IGWs), requiring customers to host internal DNS servers, and lacking a cloud-native solution, which increases deployment costs and administrative efforts.
Innovation Solution
An enhanced internal host detection protocol that utilizes a cloud security service's DNS proxy for user authentication, eliminating the need for customers to deploy their own DNS servers and IGWs, thereby providing a cloud-native solution with reduced costs and administrative burden.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud security services use traditional authentication methods requiring internal DNS servers and gateways, then user authentication can be performed, but deployment complexity and management costs increase
Solution Approach 1:
The patent introduces a DNS proxy as an intermediary component that mediates between the endpoint agent and the cloud security service. This DNS proxy handles the authentication process by intercepting and resolving authentication-related DNS queries, enabling secure authentication without requiring complex internal DNS server infrastructure. The intermediary absorbs the complexity of authentication management while presenting a simple interface to both clients and the cloud service.
Solution Approach 2:
The authentication mechanism enables endpoint agents to perform self-service authentication through DNS reverse lookup queries. The endpoint agent automatically queries the DNS proxy for authentication tokens or verification data without requiring manual intervention from administrators or complex gateway configurations. This self-service approach simplifies deployment while maintaining reliable authentication.
2Ease of manufacture
If cloud security services eliminate on-premises DNS servers and gateways, then deployment costs and administrative burden are reduced, but authentication security may be compromised
Solution Approach 1:
The DNS proxy serves as a secure intermediary that eliminates the need for on-premises DNS servers and gateways while maintaining authentication security. It handles sensitive authentication operations in a controlled environment, preventing exposure to external threats while avoiding the costs and complexities of maintaining internal infrastructure. The intermediary provides security functions that would otherwise require expensive on-premises hardware.
Solution Approach 2:
The patent replaces the mechanical/physical infrastructure of on-premises DNS servers and gateways with a software-based DNS proxy solution running in the cloud. This substitution eliminates the need for physical hardware deployment and maintenance while providing equivalent or enhanced security through software-based authentication mechanisms. The mechanical system of physical servers is replaced by a virtualized, cloud-based intermediary.
Data Source
AI summary
Techniques for an enhanced internal host detection protocol are disclosed. In some embodiments, a system, a process, and/or a computer program product for an enhanced internal host detection protocol includes sending a response to a get configuration query from a portal for a cloud security service to an endpoint agent; routing a DNS reverse lookup query to a predetermined IP address associated with a DNS proxy associated with the cloud security service; sending a response to the DNS reverse lookup query from the DNS proxy associated with the cloud security service; and verifying that the response to the DNS reverse lookup query is not spoofed based on a match with the response to the get configuration query.


