Multi-factor Domain Name Resolution Service for Secure Address Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current domain name resolution systems lack the ability to effectively manage large sets of network addresses and prevent multi-address denial of service attacks, while also facilitating smooth transitions between software and hardware versions.

Innovation Solution

Implementing a multi-factor domain name resolution service (MDNRS) that uses a combination of destination-based and request-based name resolution rules, allowing clients to specify policies that consider request sequencing, destination resource health, and other characteristics to select network addresses, and store metadata in compliance with or extension of DNS standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional domain name resolution systems are used, then the system is simple to operate, but the system cannot effectively manage large sets of network addresses and prevent multi-address denial of service attacks

Engineering Contradiction:
Improvesecurity against denial of service attacksVSAvoidname resolution system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the name resolution process into multiple independent components: policy specification module, address selection module, and resolution module. Each component handles specific aspects of the resolution process, allowing complex security policies to be managed through modular, independent units that can be configured and maintained separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by requiring clients to specify address selection policies in advance before actual name resolution occurs. These policies predefine the criteria for address selection based on request characteristics and destination properties, enabling the system to automatically make secure decisions without real-time complex analysis.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple network addresses are assigned to a domain name, then the system can facilitate version transitions and improve robustness, but the system becomes vulnerable to multi-address denial of service attacks

Engineering Contradiction:
Improvesystem robustnessVSAvoiddenial of service attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making address selection dynamic and context-specific. Instead of uniformly distributing requests across all addresses, the system evaluates each request's characteristics and destination properties to selectively choose addresses that meet security criteria, thereby protecting specific vulnerable addresses while maintaining overall system robustness.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms where the name resolution system continuously monitors request patterns, destination health status, and security threats. This feedback informs dynamic address selection policies, allowing the system to adapt to emerging threats and adjust address distribution in real-time to prevent exploitation while maintaining robustness.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If clients can specify custom address selection policies, then the system enables finer-grained debugging and customization, but the system complexity and configuration difficulty increase

Engineering Contradiction:
Improveaddress selection customizationVSAvoidpolicy configuration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent achieves universality by designing a policy specification framework that handles multiple functions through a unified interface. The same policy mechanism supports debugging, load balancing, security filtering, and version transition management, allowing diverse operational requirements to be met through a single configurable system rather than separate specialized mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables adaptability through parameter changes by allowing clients to configure address selection policies using adjustable parameters such as request type weights, destination property thresholds, and address priority levels. These parameters can be modified to optimize system behavior for different operational scenarios without changing the underlying system architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10944714B1Multi-factor domain name resolution
Publication Date: 2021.03.09 AMAZON TECH INC
  • US10944714B1 patent drawing
  • US10944714B1 patent drawing
  • US10944714B1 patent drawing

AI summary

A request for a network address corresponding to a domain name is received. From a plurality of network addresses associated with the domain name, a network address is identified based at least in part on a request-property-based address selection criterion. The network address is included in a response to the request.