Need-to-Know DNS for Private Domain Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Global DNS systems often publish detailed information about domains, which can be exploited by attackers to infiltrate and attack publicly listed domains, leading to vulnerabilities.
Innovation Solution
Implementing a need-to-know domain name system (DNS) that uses a local DNS with private domain names unpublished in the global DNS, where network traffic is intercepted, wrapped with a one-time password, and pushed to a cloud server, with security context data monitored for access control and potential termination of access if compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a global DNS system publishes detailed domain information for public access, then domain accessibility and information availability are improved, but security vulnerabilities increase as attackers can exploit this public information to infiltrate domains
Solution Approach 1:
The patent segments the DNS system into multiple hierarchical levels: global DNS for public resolution and local private DNS instances for organization-specific security zones. This segmentation allows public domain information to be published while isolating internal computing resources from direct exposure, thereby maintaining information availability while reducing security vulnerabilities.
Solution Approach 2:
The patent introduces an intermediary layer (local private DNS and cloud server infrastructure) between the global public DNS and internal computing resources. This intermediary controls and filters access requests, allowing legitimate traffic while blocking malicious attacks, thus resolving the contradiction between public information access and security protection.
2Object-affected harmful factors
If a local private DNS system is implemented to limit access to protected resources, then security is improved by reducing attack surfaces, but system complexity increases due to multiple DNS layers and authentication mechanisms
Solution Approach 1:
The patent implements a universal cloud server infrastructure that can function as both a public DNS resolver and a private DNS authority for multiple organizations. This multi-functional approach reduces overall system complexity by consolidating DNS management capabilities rather than requiring separate specialized systems for each function.
Solution Approach 2:
The patent employs dynamic DNS configurations where local private DNS instances can be created, modified, or removed based on organizational needs and security requirements. This dynamic approach allows the system to adapt to changing security contexts without requiring complete system redesign, thereby managing complexity while maintaining security.
3Reliability
If one-time passwords and security context monitoring are implemented for access control, then access security is improved, but processing overhead and system complexity increase
Solution Approach 1:
The patent implements self-service authentication mechanisms where clients automatically obtain one-time passwords and security context information without manual intervention. The system autonomously manages authentication tokens and security policies, reducing the operational complexity burden on administrators while maintaining high security standards.
Solution Approach 2:
The patent utilizes parameter changes in authentication mechanisms, specifically implementing one-time passwords that change with each authentication event rather than static credentials. This dynamic parameter approach enhances security while the automated management of these changing parameters reduces the perceived complexity for users.
Data Source
AI summary
The disclosed computer-implemented method for managing a need-to-know domain name system may include (i) intercepting, by an agent of the computing device, network traffic received on the computing device, (ii) generating, by the agent, a one-time password based on a unique identifier of the agent of the computing device, (iii) wrapping, by the agent, the network traffic with the one-time password, and (iv) pushing, by the agent, the wrapped network traffic to a cloud server using a local domain name system (DNS) of the agent of the computing device, wherein the local DNS comprises a private domain name unpublished in a global DNS. Various other methods, systems, and computer-readable media are also disclosed.


