Private Network Identifier Resolution via Edge Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional remote access technologies, such as VPN and link translation, do not provide the desired level of access control and accuracy, allowing unauthorized access to private network resources and causing user experience issues by making permanent edits to documents.
Innovation Solution
Implementing a system where private network identifiers are made resolvable on outside networks using DNS, allowing communication through an edge resource that secures and routes communications to the intended private network resource, while maintaining security limitations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN is used to provide remote access to private network, then access to private network resources is enabled, but access control precision is lost and unauthorized access cannot be prevented
Solution Approach 1:
The patent segments the network access by creating separate virtual network interfaces for different private networks. Each virtual interface is associated with specific network resources, allowing precise control over which resources are accessible through which network connections. This segmentation enables the system to maintain security boundaries while providing convenient remote access to authorized resources.
Solution Approach 2:
The patent introduces a gateway device as an intermediary between outside networks and private networks. The gateway translates external network identifiers to internal private network identifiers and enforces access control policies. This intermediary layer allows the system to provide remote access capability while maintaining security through controlled translation and authorization.
2Measurement precision
If link translation is used to translate private network identifiers, then access to specific resources is enabled, but document edits are made permanently and user experience deteriorates
Solution Approach 1:
The patent implements dynamic identifier translation where the translation occurs at the network layer rather than modifying documents. The system dynamically resolves private network identifiers to external identifiers based on the current network connection state. This dynamic approach maintains access accuracy while avoiding permanent document edits, as the translation happens transparently at the network level rather than modifying the content of documents or links.
Solution Approach 2:
The patent replaces the mechanical document-editing approach of traditional link translation with a network-layer identifier resolution mechanism. Instead of modifying documents mechanically, the system uses DNS-like resolution to translate identifiers dynamically at the network level, substituting a softer, more flexible mechanism that preserves document integrity while achieving accurate resource access.
3Measurement precision
If private network identifiers are made resolvable outside the network, then access precision is improved, but security settings may be bypassed
Solution Approach 1:
The patent implements feedback mechanisms where the gateway device monitors and controls identifier resolution. When an outside network attempts to resolve a private network identifier, the gateway validates the resolution against access control policies. This feedback loop ensures that identifier resolution provides precise access to intended resources while preventing security bypasses through continuous validation and control.
Data Source
AI summary
In some embodiments of the invention, techniques may make private identifiers for private network resources usable to establish connections to those private network resources from computing devices connected to an outside network. For example, when a computing device is connected to an outside network and attempting to contact a private network resource, DNS may be used to resolve a domain name for the private network resource to an IP address for an edge resource of the private network. Communications may be passed between the computing device and the edge resource according to protocols which embed the identifier originally used to identify the private network resource. The edge resource of the private network may analyze communications over the connection to determine this identifier, and use it to pass the communication to the desired private network resource.


