Local Server Secure Connectivity via Unique Domain Name Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RTC and HTTPS applications on devices cannot communicate with local servers lacking a domain-validated certificate, as they require a unique domain name registered with a certificate authority, which is burdensome and costly for clients.

Innovation Solution

A method and system that provide a unique domain name for a local server by forming a unique domain name comprising a unique part and a general part, associating it with the server's IP address on a domain name server, and storing this association to enable communication between devices without requiring CA registration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a local server uses a static or dynamic IP address without domain registration, then device communication setup is simplified, but secure HTTPS/RTC communication cannot be established due to lack of domain-validated certificate

Engineering Contradiction:
Improveease of server deploymentVSAvoidsecure communication capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a domain name server as an intermediary that maps IP addresses to domain names. This mediator enables secure HTTPS/RTC communication by providing the domain name structure required for certificate validation, while the actual server deployment remains simple with just an IP address. The domain name server bridges the gap between simple IP-based deployment and certificate-based security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If clients register with a certificate authority to obtain domain-validated certificates, then secure HTTPS/RTC communication is enabled, but costs and administrative burdens increase

Engineering Contradiction:
Improvesecure communication capabilityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service secure communication by allowing local servers to obtain domain names automatically through the domain name server without requiring client registration with certificate authorities. The server can generate or obtain certificates using the domain name resolved from its IP address, eliminating the need for manual CA registration and reducing administrative burden while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If a unique domain name is registered with a certificate authority for each local server, then certificate-based security is achieved, but complexity and cost increase

Engineering Contradiction:
Improvecertificate validationVSAvoiddomain registration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The domain name server provides a universal solution that serves multiple local servers with different IP addresses through a common domain name mapping mechanism. Instead of requiring separate CA registration processes for each server, the system uses a single domain name server that handles multiple servers, reducing overall system complexity while maintaining individual certificate validation for each server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11425114B2Systems and methods for supporting a secure connectivity
Publication Date: 2022.08.23 RINGCENTRAL INC
  • US11425114B2 patent drawing
  • US11425114B2 patent drawing
  • US11425114B2 patent drawing

AI summary

A method for establishing communication includes receiving a request to establish communication with a server, the request including an internet protocol address of the server, forming a unique domain name comprising a unique part and a general part, and associating the unique domain name with the internet protocol address. The method further includes storing the unique domain name in association with the internet protocol address on a domain name server, and establishing a communication between a user device and the server by resolving the unique domain name.