Secure Hostname-to-IP Mapping for DNS Bypass
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Domain Name System (DNS) has limitations such as time-consuming lookups, susceptibility to failures, and security vulnerabilities, making it inefficient for mapping hostnames to IP addresses in secure communication protocols.
Innovation Solution
A computer-implemented method and system that bypasses DNS by transmitting mappings between hostnames and IP addresses directly to client applications via secure communication channels, allowing clients to connect to servers without relying on DNS lookups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If DNS lookup is used to map hostname to IP address, then hostname resolution is achieved, but time consumption increases
Solution Approach 1:
The patent pre-establishes multiple secure communication channels between client applications and servers before actual communication is needed. By preparing these channels in advance with embedded hostname-to-IP mappings, the system eliminates the need for time-consuming DNS lookups at the moment of connection, while ensuring reliable hostname resolution through pre-validated mappings.
Solution Approach 2:
The patent introduces secure communication channels as an intermediary mechanism that carries hostname-to-IP address mappings directly to client applications. This intermediary approach bypasses the traditional DNS system, providing both time savings and enhanced security through encrypted transmission of mapping information.
2Reliability
If DNS is used for hostname resolution, then mapping service is provided, but security vulnerabilities increase
Solution Approach 1:
The patent introduces secure communication channels as an intermediary mechanism that carries hostname-to-IP address mappings directly to client applications. This intermediary approach bypasses the traditional DNS system, providing both time savings and enhanced security through encrypted transmission of mapping information.
Solution Approach 2:
Client applications autonomously establish secure communication channels and obtain hostname-to-IP mappings directly from servers without relying on external DNS infrastructure. This self-service approach enhances security by eliminating vulnerable intermediate DNS servers while distributing the resolution capability across multiple direct communication channels.
3Reliability
If traditional DNS lookup process is used, then hostname to IP address mapping is obtained, but susceptibility to server failures increases
Solution Approach 1:
The patent pre-establishes multiple secure communication channels between client applications and servers before actual communication is needed. By preparing these channels in advance with embedded hostname-to-IP mappings, the system eliminates the need for time-consuming DNS lookups at the moment of connection, while ensuring reliable hostname resolution through pre-validated mappings.
Solution Approach 2:
The patent changes the fundamental parameter of how hostname-to-IP mappings are transmitted by switching from traditional UDP-based DNS queries to reliable TCP-based secure communication channels. This parameter change ensures that mappings are delivered through a more reliable and controllable transmission mechanism, reducing variability in resolution time and improving availability.
Data Source
AI summary
In various embodiments, a client application requests information relating to content servers from which particular content can be accessed, or a manifest server that maintains such information and is distinct from the Domain Name System (DNS) automatically determines that the client application is likely to request the content server information. The manifest server then transmits, to the client application, information specifying (1) hostnames associated with the content servers from which the particular content can be accessed, and (2) Internet Protocol (IP) addresses corresponding to the hostnames. Thereafter, the client application can use the IP addresses to connect to the content servers and validate certificates provided by the content servers, in order to establish secure communication channels with the content servers.


