DNS Proxy Host Detection for Cloud User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for authenticating users to cloud security services face challenges such as managing a large number of Internal Gateways (IGWs), requiring customers to host internal DNS servers, and lacking a cloud-native solution, which increases deployment costs and administrative efforts.

Innovation Solution

An enhanced internal host detection protocol that utilizes a cloud security service's DNS proxy for user authentication, eliminating the need for customers to deploy their own DNS servers and IGWs, thereby providing a cloud-native solution with reduced costs and administrative burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud security services use traditional authentication methods requiring internal DNS servers and gateways, then user authentication can be performed, but deployment complexity and management costs increase

Engineering Contradiction:
Improveuser authenticationVSAvoiddeployment and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a DNS proxy as an intermediary component that mediates between the endpoint agent and the cloud security service. This DNS proxy handles the authentication process by intercepting and resolving authentication-related DNS queries, enabling secure authentication without requiring complex internal DNS server infrastructure. The intermediary absorbs the complexity of authentication management while presenting a simple interface to both clients and the cloud service.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication mechanism enables endpoint agents to perform self-service authentication through DNS reverse lookup queries. The endpoint agent automatically queries the DNS proxy for authentication tokens or verification data without requiring manual intervention from administrators or complex gateway configurations. This self-service approach simplifies deployment while maintaining reliable authentication.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If cloud security services eliminate on-premises DNS servers and gateways, then deployment costs and administrative burden are reduced, but authentication security may be compromised

Engineering Contradiction:
Improvedeployment costVSAvoidauthentication security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The DNS proxy serves as a secure intermediary that eliminates the need for on-premises DNS servers and gateways while maintaining authentication security. It handles sensitive authentication operations in a controlled environment, preventing exposure to external threats while avoiding the costs and complexities of maintaining internal infrastructure. The intermediary provides security functions that would otherwise require expensive on-premises hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical infrastructure of on-premises DNS servers and gateways with a software-based DNS proxy solution running in the cloud. This substitution eliminates the need for physical hardware deployment and maintenance while providing equivalent or enhanced security through software-based authentication mechanisms. The mechanical system of physical servers is replaced by a virtualized, cloud-based intermediary.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12621343B2Enhanced internal host detection protocol
Publication Date: 2026.05.05 PALO ALTO NETWORKS INC
  • US12621343B2 patent drawing
  • US12621343B2 patent drawing
  • US12621343B2 patent drawing

AI summary

Techniques for an enhanced internal host detection protocol are disclosed. In some embodiments, a system, a process, and/or a computer program product for an enhanced internal host detection protocol includes sending a response to a get configuration query from a portal for a cloud security service to an endpoint agent; routing a DNS reverse lookup query to a predetermined IP address associated with a DNS proxy associated with the cloud security service; sending a response to the DNS reverse lookup query from the DNS proxy associated with the cloud security service; and verifying that the response to the DNS reverse lookup query is not spoofed based on a match with the response to the get configuration query.