DNS Intermediary for Dynamic Virtual Overlay Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional public computer networks with pre-defined connections are vulnerable to security breaches due to visibility and accessibility, necessitating a system that creates a dynamic, secured virtual overlay network after verifying credentials and rendering it inaccessible to unauthorized devices.
Innovation Solution
A computer-implemented system using a DNS server as an intermediary to establish a private communication link between source and destination computers through virtual private IP addresses, ensuring only authenticated devices can access the network, and the virtual overlay network is invisible to other devices on the public network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If pre-defined network connections are used in conventional public networks, then communication establishment time is reduced, but network security is compromised due to visibility and accessibility of connections
Solution Approach 1:
The patent applies dynamics by transitioning from static pre-defined network connections to dynamic virtual overlay connections. The virtual overlay network is created on-demand between source and destination computers only when communication is required, and is automatically destroyed after use. This dynamic creation and destruction of connections eliminates the security vulnerability of permanently visible routes while maintaining quick communication establishment.
Solution Approach 2:
The patent introduces a DNS server as an intermediary to manage and coordinate the creation of virtual overlay connections. The DNS server receives connection requests, verifies credentials, and facilitates the establishment of secure peer-to-peer connections between source and destination computers. This intermediary approach enables secure dynamic connection creation without requiring the source and destination to directly negotiate connection parameters.
2Reliability
If access control mechanisms are implemented to verify credentials, then network security is improved, but access complexity increases
Solution Approach 1:
The patent leverages the existing DNS server infrastructure to perform multiple functions: traditional domain name resolution, credential verification for virtual overlay connection establishment, and coordination of secure communication channels. By making the DNS server universal and multi-functional, the system adds security capabilities without requiring separate dedicated access control hardware or software at each endpoint.
Solution Approach 2:
The system implements self-service by having the source and destination computers automatically verify each other's credentials and establish secure connections without manual intervention. The DNS server handles credential verification automatically, and once verified, the virtual overlay connection is created and destroyed automatically based on communication needs, eliminating the need for manual access control management.
3Reliability
If virtual overlay networks are created dynamically with credential verification, then network security is enhanced, but system complexity increases
Solution Approach 1:
The patent implements nesting by creating a virtual overlay network that is nested within the existing public network infrastructure. The virtual overlay connections are established over the existing Internet Protocol network, using the DNS server that already operates within the network infrastructure. This nested approach allows secure private communication channels to be created without requiring a separate physical network infrastructure.
Solution Approach 2:
The patent changes the parameter of connection visibility from public and permanent to private and temporary. By modifying the connection parameters through credential verification and using encrypted communication channels within the virtual overlay network, the system transforms the nature of network connections from openly accessible to securely restricted, enhancing security without fundamentally changing the underlying network architecture.
Data Source
AI summary
The present disclosure envisages establishing a virtual overlay network between the source computer and the destination computer (in addition to a typical, unsecured, public computer network already connecting the source computer and the destination computer), and designating the source computer and destination computer to be identified on the virtual overlay network only by the corresponding source private IP address and destination private IP address. The present disclosure envisages an intermediary server for creating and subsequently managing the virtual overlay network. The intermediary server renders the virtual overlay network accessible only to the source computer and the destination computer to communicate with one another and to exchange data packets using the source private IP address and destination private address and the corresponding private ports, while ensuring that the virtual overlay network remains inaccessible to any other computer on the underlying public computer network.


