Dynamic DNS Hostname Firewall Policy Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls are incompatible with dynamic IP addressing, making it difficult and expensive for residential homes and small businesses to implement effective security measures, as they require static IP addresses and proprietary solutions.

Innovation Solution

A method to associate a firewall policy with a dynamic DNS hostname, allowing for the translation of hostnames to network addresses and updating firewall configurations accordingly, enabling firewall policies to be applied dynamically without the need for static IP addresses or proprietary software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static IP addresses are used for firewall protection, then security effectiveness is improved, but cost increases significantly

Engineering Contradiction:
Improvefirewall protection effectivenessVSAvoidcost of IP addresses
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces a dynamic DNS hostname as an intermediary between the firewall and the dynamic IP address. The hostname serves as a stable identifier that resolves to whatever current IP address is assigned by the ISP, allowing the firewall to track and protect the user's device without requiring static IP addresses or expensive custom firewall solutions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If dynamic IP addressing is used, then cost is reduced, but firewall compatibility is lost

Engineering Contradiction:
Improvecost of IP addressingVSAvoidfirewall compatibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The system implements feedback by continuously monitoring changes in the IP address associated with the dynamic DNS hostname. When the IP address changes (detected through periodic DNS lookups), the firewall automatically updates its configuration to associate the new IP address with the existing hostname-based security profile, maintaining continuous protection without manual intervention.

Inventive Principle:
Principle #23Feedback

3Reliability

If custom firewall solutions are used for dynamic IP addressing, then firewall functionality is achieved, but device complexity and expertise requirements increase

Engineering Contradiction:
Improvefirewall protection capabilityVSAvoidrouter and software complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the standard firewall capability universal by enabling it to work with both static and dynamic IP addressing through the dynamic DNS hostname mechanism. Instead of requiring proprietary firewall software or specialized router configurations, the solution uses standard DNS resolution and firewall hostname matching features that are commonly available in consumer-grade equipment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10749901B2Associating a policy-based firewall with a dynamic DNS hostname
Publication Date: 2020.08.18 VERISIGN INC
  • US10749901B2 patent drawing
  • US10749901B2 patent drawing
  • US10749901B2 patent drawing

AI summary

Various embodiments of the invention disclosed herein provide techniques for associating a firewall policy with a dynamic domain name system (DNS) hostname. A policy configuration portal transmits a first request to a names server to translate a first hostname into a corresponding network address. The policy configuration portal receives a first network address from the names server in response to the first request. The policy configuration portal determines that the first network address is different than a second network address that is currently associated with the first hostname. The policy configuration portal associates the first network address with the first hostname. The policy configuration portal modifies a firewall policy configuration associated with the first hostname to include the first network address. At least one advantage of the disclosed techniques is that a firewall policy can be implemented for a residential home or small business that employs dynamic IP addressing.