Multi-Tenant DNS Resolver for Secure Cloud Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional private access options in multi-tenancy environments face challenges in identifying and utilizing specific private communications components, leading to difficulties in coordinating communications between cloud provider and customer virtual cloud environments due to limitations on the number of private communications components that can be associated with a shared instance.
Innovation Solution
Implementing a multi-tenant DNS resolver that uses forwarding rules to resolve and direct communications traffic to the appropriate Reverse Connection (RCE) DNS proxy, allowing for secure and efficient communication by appending a unique suffix to Fully Qualified Domain Names (FQDNs) to identify specific RCE proxies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple tenants share the same instance in a multi-tenancy environment, then resource sharing and cost efficiency are improved, but the ability to properly identify and coordinate communications for each specific tenant deteriorates due to limits on the number of private communications components that can be associated with the shared instance
Solution Approach 1:
The patent segments the communication identification problem by introducing DNS name suffixes that append tenant-specific identifiers to domain names. This allows multiple tenants sharing the same instance to be distinguished through DNS resolution, enabling proper communication coordination without increasing the number of physical communications components associated with the shared instance.
Solution Approach 2:
The patent uses DNS resolution as an intermediary mechanism between the shared instance and individual tenants. The DNS system acts as a mediator that translates generic instance references into tenant-specific communication paths through suffix-based domain name resolution, enabling reliable tenant identification without direct association of multiple private communications components with the shared instance.
2Device complexity
If a limit is imposed on the number of private communications components associated with a sharedinstance, then system complexity and resource management are simplified, but the capacity to support multiple tenants with unique communication paths deteriorates
Solution Approach 1:
The patent resolves the contradiction by adding a dimensional layer through DNS name suffixes. Instead of increasing the number of associated communications components (horizontal expansion), the system uses DNS resolution as an additional identification dimension, allowing unlimited tenants to be supported through suffix-based domain name differentiation while maintaining simple component association.
Solution Approach 2:
The patent makes the DNS resolution system universal by enabling it to handle multiple tenant identification scenarios through a single mechanism. The same DNS resolution process with suffix appending serves all tenants sharing the instance, providing multi-functional tenant differentiation without requiring separate private communications components for each tenant.
3Ease of manufacture
If conventional private access options are used in multi-tenancy environments, then implementation simplicity is maintained, but the ability to properly identify and direct traffic to specific tenants deteriorates
Solution Approach 1:
The patent applies local quality by making the DNS suffixes tenant-specific and locally meaningful. Each tenant gets unique suffixes that are locally resolved to their specific communication paths, enabling proper tenant identification while maintaining the simplicity of using standard DNS infrastructure. The suffixes provide tenant-specific differentiation without requiring complex custom configuration.
Data Source
AI summary
Disclosed is an approach to implement a multi-tenant DNS resolver for secure communications for a virtual cloud environment. The approach can perform split-horizon DNS forwarding via an intermediate customized DNS server.


