Dynamic Split Tunneling via DNS Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Virtual Private Network (VPN) split tunneling methods are cumbersome and require large, complex rules for routing traffic to specific data centers, making them inefficient for modern cloud-based services that need to route traffic based on application services rather than traditional routes.

Innovation Solution

Implementing dynamic split tunneling logic that uses Fully Qualified Domain Names (FQDNs) to route traffic securely to multiple data centers, with a VPN client intercepting and modifying DNS requests and responses to use dummy IP addresses for sub-domains, allowing traffic to be routed through the appropriate tunnels without user-driven authentication, enabling efficient and secure access to application services across multiple networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional split tunneling methods are used to route traffic to specific data centers, then traffic routing capability is provided, but the system becomes cumbersome with very large split include/exclude VPN rules

Engineering Contradiction:
Improvetraffic routing capabilityVSAvoidVPN rules complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent changes the routing parameter from traditional IP-based include/exclude rules to application service-based routing. Instead of managing large lists of IP addresses and subnets, the system routes traffic based on application services identified through DNS interception and FQDN matching, dramatically reducing rule complexity while maintaining routing capability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary mechanism between DNS resolution and traffic routing. The VPN client intercepts DNS requests, modifies them to include FQDN information, and uses this intermediate layer to determine routing decisions, eliminating the need for complex traditional split tunneling rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional VPN tunnels all traffic, then secure access is provided, but efficiency is reduced due to unnecessary encryption and routing of non-service traffic

Engineering Contradiction:
Improvesecure accessVSAvoidtraffic routing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments traffic routing by application service rather than applying a blanket tunnel to all traffic. Each application service can be routed through appropriate VPN tunnels based on its specific requirements, providing security where needed while allowing efficient direct routing for services that don't require tunneling.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic routing decisions based on real-time DNS interception and FQDN matching. The system dynamically determines which traffic should be tunneled and which should use direct routes, adapting to application service requirements rather than using static all-or-nothing tunneling.

Inventive Principle:
Principle #15Dynamics

3Productivity

If split tunneling is implemented to allow access to certain network segments, then routing efficiency is improved, but user-driven authentication becomes cumbersome

Engineering Contradiction:
Improverouting efficiencyVSAvoidauthentication process
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication through automatic FQDN-based routing. The VPN client automatically intercepts DNS requests, determines the appropriate tunnel based on FQDN matching, and routes traffic without requiring user intervention or manual authentication decisions, making the process transparent to the user.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary DNS interception and FQDN matching before traffic routing decisions are made. By resolving service names and matching FQDNs in advance, the system prepares routing information beforehand, enabling efficient automatic authentication and routing without user-driven processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9455909B2Application services based on dynamic split tunneling
Publication Date: 2016.09.27 CISCO TECHNOLOGY INC
  • US9455909B2 patent drawing
  • US9455909B2 patent drawing
  • US9455909B2 patent drawing

AI summary

One embodiment provides selectively routing Domain Name System (DNS) request for sub-domains associated with a first network through a tunnel associated with the first network via the interface. DNS requests for sub-domains associated with a second network are selectively routed through a tunnel associated with the second network via the interface. Embodiments include replacing the destination address for DNS requests for sub-domains associated with the second network to match an address of a DNS server associated with the second network. Data representative of DNS requests for sub-domains associated with the second network is stored. Embodiments forward the DNS requests for sub-domains associated with the second network with the address of the DNS server associated with the second network.