Secure Hostname-to-IP Mapping for DNS Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Domain Name System (DNS) has limitations such as time-consuming lookups, susceptibility to failures, and security vulnerabilities, making it inefficient for mapping hostnames to IP addresses in secure communication protocols.

Innovation Solution

A computer-implemented method and system that bypasses DNS by transmitting mappings between hostnames and IP addresses directly to client applications via secure communication channels, allowing clients to connect to servers without relying on DNS lookups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If DNS lookup is used to map hostname to IP address, then hostname resolution is achieved, but time consumption increases

Engineering Contradiction:
ImproveDNS lookup timeVSAvoidhostname resolution reliability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent pre-establishes multiple secure communication channels between client applications and servers before actual communication is needed. By preparing these channels in advance with embedded hostname-to-IP mappings, the system eliminates the need for time-consuming DNS lookups at the moment of connection, while ensuring reliable hostname resolution through pre-validated mappings.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces secure communication channels as an intermediary mechanism that carries hostname-to-IP address mappings directly to client applications. This intermediary approach bypasses the traditional DNS system, providing both time savings and enhanced security through encrypted transmission of mapping information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DNS is used for hostname resolution, then mapping service is provided, but security vulnerabilities increase

Engineering Contradiction:
Improvehostname resolution securityVSAvoidcommunication channel setup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces secure communication channels as an intermediary mechanism that carries hostname-to-IP address mappings directly to client applications. This intermediary approach bypasses the traditional DNS system, providing both time savings and enhanced security through encrypted transmission of mapping information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Client applications autonomously establish secure communication channels and obtain hostname-to-IP mappings directly from servers without relying on external DNS infrastructure. This self-service approach enhances security by eliminating vulnerable intermediate DNS servers while distributing the resolution capability across multiple direct communication channels.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional DNS lookup process is used, then hostname to IP address mapping is obtained, but susceptibility to server failures increases

Engineering Contradiction:
Improvehostname resolution availabilityVSAvoidresolution time variability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-establishes multiple secure communication channels between client applications and servers before actual communication is needed. By preparing these channels in advance with embedded hostname-to-IP mappings, the system eliminates the need for time-consuming DNS lookups at the moment of connection, while ensuring reliable hostname resolution through pre-validated mappings.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the fundamental parameter of how hostname-to-IP mappings are transmitted by switching from traditional UDP-based DNS queries to reliable TCP-based secure communication channels. This parameter change ensures that mappings are delivered through a more reliable and controllable transmission mechanism, reducing variability in resolution time and improving availability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12348802B2Techniques for bypassing the domain name system
Publication Date: 2025.07.01 NETFLIX INC
  • US12348802B2 patent drawing
  • US12348802B2 patent drawing
  • US12348802B2 patent drawing

AI summary

In various embodiments, a client application requests information relating to content servers from which particular content can be accessed, or a manifest server that maintains such information and is distinct from the Domain Name System (DNS) automatically determines that the client application is likely to request the content server information. The manifest server then transmits, to the client application, information specifying (1) hostnames associated with the content servers from which the particular content can be accessed, and (2) Internet Protocol (IP) addresses corresponding to the hostnames. Thereafter, the client application can use the IP addresses to connect to the content servers and validate certificates provided by the content servers, in order to establish secure communication channels with the content servers.