Fabric DNS for Cloud Application Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing a unified security policy and managing access to applications hosted on multiple cloud computing platforms is complex due to the diverse nature of cloud environments and user locations, making it difficult to authenticate users coherently.

Innovation Solution

The system employs edge clusters and a dashboard to manage access through domain name resolution, routing, and authentication, using identity providers and intelligent routing modules to ensure secure and efficient access across multiple cloud platforms, while optimizing latency and cost.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users access applications from diverse global locations, then application accessibility and global operation are improved, but authentication complexity and security management difficulty increase

Engineering Contradiction:
Improveapplication accessibilityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a fabric DNS system as an intermediary between users and cloud-hosted applications. The fabric DNS receives authentication credentials from identity providers, performs authentication, and then resolves domain names to route authenticated users to appropriate application instances. This intermediary approach centralizes authentication management while maintaining global accessibility, solving the contradiction by adding a mediating layer rather than directly managing complex authentication across all access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The fabric DNS is designed to perform multiple functions: authentication verification, domain name resolution, and intelligent routing. By consolidating these functions into a single universal system, the patent reduces overall system complexity while maintaining the ability to handle diverse global access scenarios. The fabric DNS acts as a multi-functional gateway that simplifies the authentication process for users worldwide.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If applications are hosted on multiple cloud computing platforms, then service availability and scalability are improved, but security policy management complexity increases

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity policy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security policy management and authentication functions into a centralized fabric DNS system that operates across multiple cloud platforms. Instead of managing separate security policies for each cloud platform, the fabric DNS provides a unified authentication mechanism that works consistently across AWS, Azure, Google Cloud, and other platforms. This consolidation simplifies security policy management while maintaining service availability across diverse cloud infrastructures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the system into distinct functional components: identity providers that issue credentials, fabric DNS that performs authentication and resolution, and cloud platform-specific application instances. This segmentation allows each component to be optimized independently while maintaining coherent security policies across the entire distributed system. The fabric DNS acts as a segmentation boundary that isolates authentication logic from cloud platform-specific implementations.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If traffic is routed through multiple cloud platforms, then application accessibility is improved, but latency and cost increase

Engineering Contradiction:
Improveapplication accessibilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements dynamic routing through the fabric DNS, which can adaptively resolve domain names based on current system state, user location, and cloud platform performance. The routing logic dynamically selects optimal cloud platform instances for each user request, considering factors like geographic proximity, current load, and network conditions. This dynamic approach reduces latency while maintaining global accessibility, as users are routed to the most appropriate instance rather than following fixed routing paths.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20220200954A1Managing Access To Cloud-Hosted Applications Using Domain Name Resolution
Publication Date: 2022.06.23 PALO ALTO NETWORKS INC
  • US20220200954A1 patent drawing
  • US20220200954A1 patent drawing
  • US20220200954A1 patent drawing

AI summary

Edge clusters execute in a plurality of regional clouds of a cloud computing platforms, which may include cloud POPs. Edge clusters may be programmed to control access to applications executing in the cloud computing platform. Edge clusters and an intelligent routing module route traffic to applications executing in the cloud computing platform. Cost and latency may be managed by the intelligent routing module by routing requests over the Internet or a cloud backbone network and using or bypassing cloud POPs. The placement of edge clusters may be selected according to measured or estimated latency. Latency may be estimated using speed test servers and the locations of speed test servers may be verified.