Private Network Identifier Resolution via Edge Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote access technologies, such as VPN and link translation, do not provide the desired level of access control and accuracy, allowing unauthorized access to private network resources and causing user experience issues by making permanent edits to documents.

Innovation Solution

Implementing a system where private network identifiers are made resolvable on outside networks using DNS, allowing communication through an edge resource that secures and routes communications to the intended private network resource, while maintaining security limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN is used to provide remote access to private network, then access to private network resources is enabled, but access control precision is lost and unauthorized access cannot be prevented

Engineering Contradiction:
Improveremote access capabilityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network access by creating separate virtual network interfaces for different private networks. Each virtual interface is associated with specific network resources, allowing precise control over which resources are accessible through which network connections. This segmentation enables the system to maintain security boundaries while providing convenient remote access to authorized resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a gateway device as an intermediary between outside networks and private networks. The gateway translates external network identifiers to internal private network identifiers and enforces access control policies. This intermediary layer allows the system to provide remote access capability while maintaining security through controlled translation and authorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If link translation is used to translate private network identifiers, then access to specific resources is enabled, but document edits are made permanently and user experience deteriorates

Engineering Contradiction:
Improveresource access accuracyVSAvoiduser experience
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements dynamic identifier translation where the translation occurs at the network layer rather than modifying documents. The system dynamically resolves private network identifiers to external identifiers based on the current network connection state. This dynamic approach maintains access accuracy while avoiding permanent document edits, as the translation happens transparently at the network level rather than modifying the content of documents or links.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces the mechanical document-editing approach of traditional link translation with a network-layer identifier resolution mechanism. Instead of modifying documents mechanically, the system uses DNS-like resolution to translate identifiers dynamically at the network level, substituting a softer, more flexible mechanism that preserves document integrity while achieving accurate resource access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If private network identifiers are made resolvable outside the network, then access precision is improved, but security settings may be bypassed

Engineering Contradiction:
Improveidentifier resolution accuracyVSAvoidsecurity bypass risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the gateway device monitors and controls identifier resolution. When an outside network attempts to resolve a private network identifier, the gateway validates the resolution against access control policies. This feedback loop ensures that identifier resolution provides precise access to intended resources while preventing security bypasses through continuous validation and control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8910270B2Remote access to private network resources from outside the network
Publication Date: 2014.12.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8910270B2 patent drawing
  • US8910270B2 patent drawing
  • US8910270B2 patent drawing

AI summary

In some embodiments of the invention, techniques may make private identifiers for private network resources usable to establish connections to those private network resources from computing devices connected to an outside network. For example, when a computing device is connected to an outside network and attempting to contact a private network resource, DNS may be used to resolve a domain name for the private network resource to an IP address for an edge resource of the private network. Communications may be passed between the computing device and the edge resource according to protocols which embed the identifier originally used to identify the private network resource. The edge resource of the private network may analyze communications over the connection to determine this identifier, and use it to pass the communication to the desired private network resource.