DNS Intermediary for Dynamic Virtual Overlay Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional public computer networks with pre-defined connections are vulnerable to security breaches due to visibility and accessibility, necessitating a system that creates a dynamic, secured virtual overlay network after verifying credentials and rendering it inaccessible to unauthorized devices.

Innovation Solution

A computer-implemented system using a DNS server as an intermediary to establish a private communication link between source and destination computers through virtual private IP addresses, ensuring only authenticated devices can access the network, and the virtual overlay network is invisible to other devices on the public network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If pre-defined network connections are used in conventional public networks, then communication establishment time is reduced, but network security is compromised due to visibility and accessibility of connections

Engineering Contradiction:
Improvecommunication establishment timeVSAvoidnetwork security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static pre-defined network connections to dynamic virtual overlay connections. The virtual overlay network is created on-demand between source and destination computers only when communication is required, and is automatically destroyed after use. This dynamic creation and destruction of connections eliminates the security vulnerability of permanently visible routes while maintaining quick communication establishment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a DNS server as an intermediary to manage and coordinate the creation of virtual overlay connections. The DNS server receives connection requests, verifies credentials, and facilitates the establishment of secure peer-to-peer connections between source and destination computers. This intermediary approach enables secure dynamic connection creation without requiring the source and destination to directly negotiate connection parameters.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are implemented to verify credentials, then network security is improved, but access complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing DNS server infrastructure to perform multiple functions: traditional domain name resolution, credential verification for virtual overlay connection establishment, and coordination of secure communication channels. By making the DNS server universal and multi-functional, the system adds security capabilities without requiring separate dedicated access control hardware or software at each endpoint.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service by having the source and destination computers automatically verify each other's credentials and establish secure connections without manual intervention. The DNS server handles credential verification automatically, and once verified, the virtual overlay connection is created and destroyed automatically based on communication needs, eliminating the need for manual access control management.

Inventive Principle:
Principle #25Self-service

3Reliability

If virtual overlay networks are created dynamically with credential verification, then network security is enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nesting by creating a virtual overlay network that is nested within the existing public network infrastructure. The virtual overlay connections are established over the existing Internet Protocol network, using the DNS server that already operates within the network infrastructure. This nested approach allows secure private communication channels to be created without requiring a separate physical network infrastructure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent changes the parameter of connection visibility from public and permanent to private and temporary. By modifying the connection parameters through credential verification and using encrypted communication channels within the virtual overlay network, the system transforms the nature of network connections from openly accessible to securely restricted, enhancing security without fundamentally changing the underlying network architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10630657B2System and method for enhancing the security of data packets exchanged across a computer network
Publication Date: 2020.04.21 COLORTOKENS INC
  • US10630657B2 patent drawing
  • US10630657B2 patent drawing
  • US10630657B2 patent drawing

AI summary

The present disclosure envisages establishing a virtual overlay network between the source computer and the destination computer (in addition to a typical, unsecured, public computer network already connecting the source computer and the destination computer), and designating the source computer and destination computer to be identified on the virtual overlay network only by the corresponding source private IP address and destination private IP address. The present disclosure envisages an intermediary server for creating and subsequently managing the virtual overlay network. The intermediary server renders the virtual overlay network accessible only to the source computer and the destination computer to communicate with one another and to exchange data packets using the source private IP address and destination private address and the corresponding private ports, while ensuring that the virtual overlay network remains inaccessible to any other computer on the underlying public computer network.