DNS and Proxy Mediation for Internet Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet device control technologies, such as device control software and subscriber firewalls, face challenges in scalability, security, and effectiveness in managing Internet usage across diverse devices and networks, as they are either complex to install, vulnerable to tampering, or require significant processing power.

Innovation Solution

A method and system that employs a Domain Name System (DNS) server and a proxy server to mediate Internet services by analyzing DNS queries and applying policies, selectively redirecting data requests, and applying proxy policies to manage and control Internet traffic, including actions like tracking behavior, limiting traffic rates, and blocking undesired content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device control software is distributed to each user device, then device control capability is provided, but installation and configuration complexity increases and devices become vulnerable to tampering

Engineering Contradiction:
Improvedevice control capabilityVSAvoidinstallation and configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between user devices and the ISP network. The gateway consolidates device control functionality, eliminating the need to install control software on each individual user device. This single point of control reduces installation complexity while maintaining reliable device control through the gateway's mediation of network traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a subscriber firewall is deployed to control traffic, then device control effectiveness is improved, but processing power requirements increase significantly

Engineering Contradiction:
Improvedevice control effectivenessVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The gateway serves as an intermediary that filters and controls traffic before it reaches the subscriber's network equipment. By placing the firewall functionality at the gateway level rather than requiring high-power firewalls at subscriber premises, the system achieves effective device control while distributing processing requirements more efficiently across the network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If control is implemented at the DNS server level, then processing overhead is reduced, but control granularity is limited

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidcontrol granularity
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements a multi-layer control architecture that segments device control functionality across different levels: DNS-level filtering for basic control efficiency, gateway-level filtering for enhanced granularity, and optional device-level software for fine-grained control when needed. This segmentation allows the system to optimize processing efficiency at higher levels while providing granular control capabilities at lower levels when required.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10263958B2Internet mediation
Publication Date: 2019.04.16 AKAMAI TECHNOLOGIES INC
  • US10263958B2 patent drawing
  • US10263958B2 patent drawing
  • US10263958B2 patent drawing

AI summary

A system for mediating Internet service includes a DNS server and a DNS policy engine associated with the DNS server. The DNS policy engine can be configured to apply one or more DNS policies selected by the DNS policy engine to DNS queries received by the DNS server from a client, analyze the DNS query based on predetermined criteria, and based on the analysis, and selectively redirect a data request associated with the client to a proxy server for further mediation. The system can further include a proxy server and a proxy policy engine associated with the proxy server. The proxy policy engine can be configured to apply one or more proxy policies selected by the proxy policy engine to at least one of data requests received by the proxy server from a client and data responses returned to the proxy server from an IP address.