One-Time DNS Remote Access for Overlapping Subnets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for remote access to devices on overlapping subnets, such as IPSec tunneling and web application proxies, require significant configuration, are not scalable and do not support fine-grained role-based access control, and often fail due to firewall blocks or the need for client-side software installation.
Innovation Solution
A remote access manager generates a universally unique identifier for each access request, assigning a one-time use DNS name that allows secure remote access through a web proxy without requiring client-side software or server modifications, enabling fine-grained access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IPSec tunneling or web application proxies are used for remote access to devices on overlapping subnets, then remote access capability is achieved, but configuration complexity increases and scalability is limited
Solution Approach 1:
The patent introduces a remote access manager as an intermediary service that mediates between clients and devices on overlapping subnets. Instead of requiring complex IPSec configuration or web proxy setups, the remote access manager generates unique DNS names that resolve to the target devices, simplifying the remote access process while maintaining security through centralized management of device identifiers and access permissions.
2Reliability
If existing remote access methods are deployed, then access control is achieved, but fine-grained role-based access control is not supported
Solution Approach 1:
The patent implements dynamic access control by allowing the remote access manager to generate unique DNS names on-demand for each access request. These DNS names can be dynamically assigned and revoked, enabling fine-grained role-based access control that adapts to different user roles and device types without requiring static pre-configured access lists or complex authentication systems.
3Reliability
If client-side software installation is required for remote access, then access security is improved, but deployment complexity and user burden increase
Solution Approach 1:
The patent enables self-service remote access by allowing clients to access devices through standard web browsers without requiring any additional software installation. The remote access manager provides unique DNS names that clients can directly resolve and connect to, eliminating the need for client-side agents while maintaining security through centralized authentication and authorization mechanisms.
4Ease of manufacture
If overlapping subnets are used for device deployment, then device deployment is simplified, but remote access becomes challenging
Solution Approach 1:
The patent resolves the subnet overlapping issue by introducing a new dimensional layer - unique DNS names - that operates independently of IP address configurations. Instead of trying to route through complex network configurations, the system uses DNS-based identification to reach devices regardless of their subnet assignments, allowing simplified IP deployment while enabling straightforward remote access through the DNS name resolution process.
Data Source
AI summary
In one embodiment, a remote access manager receives an access request from a client to remotely access a device on a local network. The remote access manager generates a universally unique identifier for the access request. The remote access manager sends a response to the client having a one-time use domain name system name that is based on the universally unique identifier. The remote access manager communicates with a web proxy to authorize the client to remotely access the device.


