One-Time DNS Remote Access for Overlapping Subnets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for remote access to devices on overlapping subnets, such as IPSec tunneling and web application proxies, require significant configuration, are not scalable and do not support fine-grained role-based access control, and often fail due to firewall blocks or the need for client-side software installation.

Innovation Solution

A remote access manager generates a universally unique identifier for each access request, assigning a one-time use DNS name that allows secure remote access through a web proxy without requiring client-side software or server modifications, enabling fine-grained access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IPSec tunneling or web application proxies are used for remote access to devices on overlapping subnets, then remote access capability is achieved, but configuration complexity increases and scalability is limited

Engineering Contradiction:
Improveremote access capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a remote access manager as an intermediary service that mediates between clients and devices on overlapping subnets. Instead of requiring complex IPSec configuration or web proxy setups, the remote access manager generates unique DNS names that resolve to the target devices, simplifying the remote access process while maintaining security through centralized management of device identifiers and access permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing remote access methods are deployed, then access control is achieved, but fine-grained role-based access control is not supported

Engineering Contradiction:
Improveaccess controlVSAvoidfine-grained access control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control by allowing the remote access manager to generate unique DNS names on-demand for each access request. These DNS names can be dynamically assigned and revoked, enabling fine-grained role-based access control that adapts to different user roles and device types without requiring static pre-configured access lists or complex authentication systems.

Inventive Principle:
Principle #15Dynamics

3Reliability

If client-side software installation is required for remote access, then access security is improved, but deployment complexity and user burden increase

Engineering Contradiction:
Improveaccess securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent enables self-service remote access by allowing clients to access devices through standard web browsers without requiring any additional software installation. The remote access manager provides unique DNS names that clients can directly resolve and connect to, eliminating the need for client-side agents while maintaining security through centralized authentication and authorization mechanisms.

Inventive Principle:
Principle #25Self-service

4Ease of manufacture

If overlapping subnets are used for device deployment, then device deployment is simplified, but remote access becomes challenging

Engineering Contradiction:
Improvedevice deployment simplicityVSAvoidremote access difficulty
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent resolves the subnet overlapping issue by introducing a new dimensional layer - unique DNS names - that operates independently of IP address configurations. Instead of trying to route through complex network configurations, the system uses DNS-based identification to reach devices regardless of their subnet assignments, allowing simplified IP deployment while enabling straightforward remote access through the DNS name resolution process.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250379863A1Secure remote access to devices on overlapping subnets
Publication Date: 2025.12.11 CISCO TECHNOLOGY INC
  • US20250379863A1 patent drawing
  • US20250379863A1 patent drawing
  • US20250379863A1 patent drawing

AI summary

In one embodiment, a remote access manager receives an access request from a client to remotely access a device on a local network. The remote access manager generates a universally unique identifier for the access request. The remote access manager sends a response to the client having a one-time use domain name system name that is based on the universally unique identifier. The remote access manager communicates with a web proxy to authorize the client to remotely access the device.