Proxy DNS IP Address Rewriting for Transparent Subscriber Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional DNS systems face challenges in efficiently routing network traffic and authenticating subscribers across computer networks, particularly when proxy servers cannot determine the original destination IP address, leading to dropped network traffic and inefficient resource requests.
Innovation Solution
A system that facilitates communication between a proxy service and a DNS nameserver to determine a subscriber identifier, selecting a unique IP address from a pool and associating it with the subscriber and target domain name, allowing transparent authentication and efficient routing of network traffic without user intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DNS systems are used for routing network traffic, then domain name resolution is provided, but proxy servers cannot determine the original destination IP address, leading to dropped network traffic
Solution Approach 1:
The patent introduces an intermediary mechanism between the proxy server and DNS system that preserves destination information through IP address rewriting. The proxy server rewrites the destination IP address in DNS requests to a special addresses, and maintains a mapping between the rewritten address and the original destination, allowing the proxy to later retrieve the original destination without losing information in the process
2Reliability
If proxy servers drop network traffic when destination cannot be determined, then network security is maintained, but efficient resource requests cannot be processed
Solution Approach 1:
The patent uses IP address rewriting as an intermediary technique that allows the proxy server to maintain security controls while enabling resource request processing. By rewriting the destination IP address to a special address and maintaining a mapping, the proxy can process requests efficiently while still having the ability to determine the original destination when needed for security decisions
3Extent of automation
If unique IP addresses are assigned to each subscriber-destination combination, then transparent authentication is enabled, but IP address pool management complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-assigning IP addresses from a pool to subscriber-destination combinations before actual communication occurs. The system maintains a mapping table that pre-establishes which IP address corresponds to which subscriber and destination pair, so that when communication needs to occur, the authentication and routing information is already in place, enabling transparent authentication without real-time computation
Solution Approach 2:
The patent uses copying by creating a mapping relationship between rewritten IP addresses and original destination addresses. Instead of directly managing complex subscriber-destination mappings, the system creates a copy or representation of the destination address in the form of a rewritten IP address that points to the proxy, while maintaining a separate mapping table that copies the essential routing information needed for authentication and forwarding
Data Source
AI summary
Internet protocol addressing to uniquely identify clients and destinations across computer networks is provided. Communication between a proxy service and a DNS nameserver is facilitated to permit the DNS nameserver to send a subscriber identifier to the proxy service in response to a DNS request for a flagged domain name. The proxy service selects a unique IP address from a pool of IP addresses assigned to the proxy service. The proxy service associates the selected IP address with the subscriber identifier and optionally, the target domain name of the DNS request. The proxy service provides the unique IP address to the DNS nameserver which returns the unique IP address to the client device for the target domain name. The subscriber can then be authenticated at the proxy service transparently without input from the subscriber or client device based on the unique IP address provided by the client device to the proxy service.


