Router DNS Resolution for Domain-Based Network Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network devices, such as routers and proxy servers, lack flexibility in enforcing network policies using domain names, requiring manual IP address resolution and increasing complexity and resource usage when trying to implement domain name-based policies.

Innovation Solution

A method and system that allow network devices to create and enforce Internet Protocol address-based network policies using domain name-based policies, where domain names are translated into IP addresses for policy enforcement, reducing the need for manual IP address resolution and improving flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a router uses an overriding routing table to enforce network policies, then the simplicity of enforcing network policies is improved, but the flexibility to use domain name to enforce network policies deteriorates

Engineering Contradiction:
Improvesimplicity of enforcing network policiesVSAvoidflexibility to use domain name
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces a domain name resolution mechanism as an intermediary between the router and the routing table. When a packet with a domain name destination arrives, the router resolves the domain name to an IP address through DNS lookup, then applies the routing policy based on the resolved IP address. This intermediary process enables domain name-based policy enforcement while maintaining the simplicity of IP-address-based routing tables.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a proxy server examines contents to enforce routing policies, then the flexibility to use domain name to create network traffic routing policies is improved, but the network traffic throughput deteriorates

Engineering Contradiction:
Improveflexibility to use domain nameVSAvoidnetwork traffic throughput
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the domain name resolution function from the proxy server and implements it directly in the router. By taking out the DNS resolution capability from the content-examining proxy server and placing it in the router, the system maintains domain name-based policy flexibility while avoiding the throughput bottleneck caused by proxy server content examination.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If a proxy server is used to enforce network policies, then the flexibility to use domain name is improved, but the computational resource requirements deteriorate

Engineering Contradiction:
Improveflexibility to use domain nameVSAvoidcomputational resource requirements
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent makes the router multi-functional by enabling it to perform both traditional IP-address-based routing and domain name-based policy enforcement. The router now serves as both a simple routing device and a domain name resolution device, eliminating the need for a separate proxy server and reducing overall computational resource requirements in the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9369345B2Method and system for allowing the use of domain names in enforcing network policy
Publication Date: 2016.06.14 PISMO LABS TECH
  • US9369345B2 patent drawing
  • US9369345B2 patent drawing
  • US9369345B2 patent drawing

AI summary

A method and a system for creating Internet Protocol address based network policy by using domain name based network policies is disclosed. The domain name based network policies are stored. When a network device receives an record Domain Name System look-up reply, the network device identifies one or more Interact Protocol addresses of one or more host names specified in the address record Domain Name System look-up reply, then determine whether the one or more host names contain a domain name used in one or more domain name based network policies and create one or more Internet Protocol address based network policies.