DNSSEC Load Balance Switch Address Reordering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional global server load balancing systems do not effectively detect unavailable servers, consider geographical location for response time optimization, and allow invalid IP addresses to persist until TTL expiration, leading to suboptimal performance and security vulnerabilities in DNS responses.

Innovation Solution

A load balance switch reorders network addresses in DNSSEC replies while preserving the original signature, modifying TTL values and supporting DNSSEC without recalculating signatures, to ensure data integrity and authenticity, and optimize server selection based on performance metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a load balance switch reorders network addresses in DNSSEC replies to optimize server selection, then load balancing performance is improved, but data integrity is compromised because the original signature becomes invalid

Engineering Contradiction:
Improveload balancing performanceVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent separates the signature validation function from the address ordering function. The load balance switch performs address reordering based on performance metrics while the DNSSEC validation is performed separately on the reordered addresses, allowing both optimization and integrity verification to coexist

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter being optimized from canonical address order to performance-based address order. By using performance metrics (response time, availability, load) as the sorting parameter instead of canonical ordering, the system achieves optimal load balancing while maintaining DNSSEC security through proper validation of reordered addresses

Inventive Principle:
Principle #35Parameter changes

2Loss of time

If the load balance switch modifies TTL values in DNS responses, then response time optimization is improved, but signature validity is compromised requiring recalculations

Engineering Contradiction:
Improveresponse timeVSAvoidsignature recalculation complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent performs preliminary performance assessment and address selection before TTL modification. By pre-evaluating server performance metrics and selecting optimal addresses, the system can modify TTL values without requiring signature recalculations, as the selection is already optimized

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces performance metrics as an intermediary between the DNS response and the client. These metrics guide address selection and TTL modification decisions, allowing the load balance switch to optimize response times without compromising signature validity through proper metric-based filtering

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If conventional load balancing systems allow invalid IP addresses to persist until TTL expiration, then system simplicity is maintained, but service availability deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidservice availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the load balance switch continuously monitors server performance metrics and availability. This feedback loop enables real-time detection of invalid IP addresses and dynamic updates to DNS responses, eliminating stale addresses before TTL expiration while maintaining system simplicity through automated monitoring

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs periodic performance checks and DNS response updates. By periodically reassessing server availability and performance metrics, the system proactively identifies and removes invalid IP addresses from DNS responses before their TTL expires, ensuring continuous service availability without complex manual intervention

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9338182B2Domain name system security extensions (DNSSEC) for global server load balancing
Publication Date: 2016.05.10 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9338182B2 patent drawing
  • US9338182B2 patent drawing
  • US9338182B2 patent drawing

AI summary

Techniques are provided to enable a network device, such as a switch, to perform global server load balancing (GSLB) while operating as a proxy to a domain name system security extensions (DNSSEC)-capable authoritative DNS server. The network device preserves an original signature generated by the DNSSEC-capable authoritative DNS server for a resource record set contained in a DNSSEC reply.