Multi-factor Domain Name Resolution Service for Secure Address Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current domain name resolution systems lack the ability to effectively manage large sets of network addresses and prevent multi-address denial of service attacks, while also facilitating smooth transitions between software and hardware versions.
Innovation Solution
Implementing a multi-factor domain name resolution service (MDNRS) that uses a combination of destination-based and request-based name resolution rules, allowing clients to specify policies that consider request sequencing, destination resource health, and other characteristics to select network addresses, and store metadata in compliance with or extension of DNS standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional domain name resolution systems are used, then the system is simple to operate, but the system cannot effectively manage large sets of network addresses and prevent multi-address denial of service attacks
Solution Approach 1:
The patent segments the name resolution process into multiple independent components: policy specification module, address selection module, and resolution module. Each component handles specific aspects of the resolution process, allowing complex security policies to be managed through modular, independent units that can be configured and maintained separately.
Solution Approach 2:
The patent implements preliminary action by requiring clients to specify address selection policies in advance before actual name resolution occurs. These policies predefine the criteria for address selection based on request characteristics and destination properties, enabling the system to automatically make secure decisions without real-time complex analysis.
2Reliability
If multiple network addresses are assigned to a domain name, then the system can facilitate version transitions and improve robustness, but the system becomes vulnerable to multi-address denial of service attacks
Solution Approach 1:
The patent applies local quality by making address selection dynamic and context-specific. Instead of uniformly distributing requests across all addresses, the system evaluates each request's characteristics and destination properties to selectively choose addresses that meet security criteria, thereby protecting specific vulnerable addresses while maintaining overall system robustness.
Solution Approach 2:
The patent implements feedback mechanisms where the name resolution system continuously monitors request patterns, destination health status, and security threats. This feedback informs dynamic address selection policies, allowing the system to adapt to emerging threats and adjust address distribution in real-time to prevent exploitation while maintaining robustness.
3Adaptability or versatility
If clients can specify custom address selection policies, then the system enables finer-grained debugging and customization, but the system complexity and configuration difficulty increase
Solution Approach 1:
The patent achieves universality by designing a policy specification framework that handles multiple functions through a unified interface. The same policy mechanism supports debugging, load balancing, security filtering, and version transition management, allowing diverse operational requirements to be met through a single configurable system rather than separate specialized mechanisms.
Solution Approach 2:
The patent enables adaptability through parameter changes by allowing clients to configure address selection policies using adjustable parameters such as request type weights, destination property thresholds, and address priority levels. These parameters can be modified to optimize system behavior for different operational scenarios without changing the underlying system architecture.
Data Source
AI summary
A request for a network address corresponding to a domain name is received. From a plurality of network addresses associated with the domain name, a network address is identified based at least in part on a request-property-based address selection criterion. The network address is included in a response to the request.


