Fabric DNS for Cloud Application Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing a unified security policy and managing access to applications hosted on multiple cloud computing platforms is complex due to the diverse nature of cloud environments and user locations, making it difficult to authenticate users coherently.
Innovation Solution
The system employs edge clusters and a dashboard to manage access through domain name resolution, routing, and authentication, using identity providers and intelligent routing modules to ensure secure and efficient access across multiple cloud platforms, while optimizing latency and cost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users access applications from diverse global locations, then application accessibility and global operation are improved, but authentication complexity and security management difficulty increase
Solution Approach 1:
The patent introduces a fabric DNS system as an intermediary between users and cloud-hosted applications. The fabric DNS receives authentication credentials from identity providers, performs authentication, and then resolves domain names to route authenticated users to appropriate application instances. This intermediary approach centralizes authentication management while maintaining global accessibility, solving the contradiction by adding a mediating layer rather than directly managing complex authentication across all access points.
Solution Approach 2:
The fabric DNS is designed to perform multiple functions: authentication verification, domain name resolution, and intelligent routing. By consolidating these functions into a single universal system, the patent reduces overall system complexity while maintaining the ability to handle diverse global access scenarios. The fabric DNS acts as a multi-functional gateway that simplifies the authentication process for users worldwide.
2Reliability
If applications are hosted on multiple cloud computing platforms, then service availability and scalability are improved, but security policy management complexity increases
Solution Approach 1:
The patent merges security policy management and authentication functions into a centralized fabric DNS system that operates across multiple cloud platforms. Instead of managing separate security policies for each cloud platform, the fabric DNS provides a unified authentication mechanism that works consistently across AWS, Azure, Google Cloud, and other platforms. This consolidation simplifies security policy management while maintaining service availability across diverse cloud infrastructures.
Solution Approach 2:
The patent segments the system into distinct functional components: identity providers that issue credentials, fabric DNS that performs authentication and resolution, and cloud platform-specific application instances. This segmentation allows each component to be optimized independently while maintaining coherent security policies across the entire distributed system. The fabric DNS acts as a segmentation boundary that isolates authentication logic from cloud platform-specific implementations.
3Adaptability or versatility
If traffic is routed through multiple cloud platforms, then application accessibility is improved, but latency and cost increase
Solution Approach 1:
The patent implements dynamic routing through the fabric DNS, which can adaptively resolve domain names based on current system state, user location, and cloud platform performance. The routing logic dynamically selects optimal cloud platform instances for each user request, considering factors like geographic proximity, current load, and network conditions. This dynamic approach reduces latency while maintaining global accessibility, as users are routed to the most appropriate instance rather than following fixed routing paths.
Data Source
AI summary
Edge clusters execute in a plurality of regional clouds of a cloud computing platforms, which may include cloud POPs. Edge clusters may be programmed to control access to applications executing in the cloud computing platform. Edge clusters and an intelligent routing module route traffic to applications executing in the cloud computing platform. Cost and latency may be managed by the intelligent routing module by routing requests over the Internet or a cloud backbone network and using or bypassing cloud POPs. The placement of edge clusters may be selected according to measured or estimated latency. Latency may be estimated using speed test servers and the locations of speed test servers may be verified.


