DNSSEC Load Balance Switch Address Reordering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional global server load balancing systems do not effectively detect unavailable servers, consider geographical location for response time optimization, and allow invalid IP addresses to persist until TTL expiration, leading to suboptimal performance and security vulnerabilities in DNS responses.
Innovation Solution
A load balance switch reorders network addresses in DNSSEC replies while preserving the original signature, modifying TTL values and supporting DNSSEC without recalculating signatures, to ensure data integrity and authenticity, and optimize server selection based on performance metrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a load balance switch reorders network addresses in DNSSEC replies to optimize server selection, then load balancing performance is improved, but data integrity is compromised because the original signature becomes invalid
Solution Approach 1:
The patent separates the signature validation function from the address ordering function. The load balance switch performs address reordering based on performance metrics while the DNSSEC validation is performed separately on the reordered addresses, allowing both optimization and integrity verification to coexist
Solution Approach 2:
The patent changes the parameter being optimized from canonical address order to performance-based address order. By using performance metrics (response time, availability, load) as the sorting parameter instead of canonical ordering, the system achieves optimal load balancing while maintaining DNSSEC security through proper validation of reordered addresses
2Loss of time
If the load balance switch modifies TTL values in DNS responses, then response time optimization is improved, but signature validity is compromised requiring recalculations
Solution Approach 1:
The patent performs preliminary performance assessment and address selection before TTL modification. By pre-evaluating server performance metrics and selecting optimal addresses, the system can modify TTL values without requiring signature recalculations, as the selection is already optimized
Solution Approach 2:
The patent introduces performance metrics as an intermediary between the DNS response and the client. These metrics guide address selection and TTL modification decisions, allowing the load balance switch to optimize response times without compromising signature validity through proper metric-based filtering
3Device complexity
If conventional load balancing systems allow invalid IP addresses to persist until TTL expiration, then system simplicity is maintained, but service availability deteriorates
Solution Approach 1:
The patent implements feedback mechanisms where the load balance switch continuously monitors server performance metrics and availability. This feedback loop enables real-time detection of invalid IP addresses and dynamic updates to DNS responses, eliminating stale addresses before TTL expiration while maintaining system simplicity through automated monitoring
Solution Approach 2:
The patent employs periodic performance checks and DNS response updates. By periodically reassessing server availability and performance metrics, the system proactively identifies and removes invalid IP addresses from DNS responses before their TTL expires, ensuring continuous service availability without complex manual intervention
Data Source
AI summary
Techniques are provided to enable a network device, such as a switch, to perform global server load balancing (GSLB) while operating as a proxy to a domain name system security extensions (DNSSEC)-capable authoritative DNS server. The network device preserves an original signature generated by the DNSSEC-capable authoritative DNS server for a resource record set contained in a DNSSEC reply.


