Trusted Network Interface Controllers for Secure DNS Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack the capability to restrict unauthorized access to device and network data, as they do not have adequate security mechanisms to authenticate incoming DNS requests, leading to potential data breaches.

Innovation Solution

A system that establishes a secure session for DNS requests using dynamically configurable trusted network interface controllers, which involves encrypting data, initiating a handshaking protocol, verifying active sessions, and dynamically changing authentication protocols and keys to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional systems are used without authentication mechanisms, then device and network data are accessible to all users, but security against unauthorized access is compromised

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary enrollment of devices and establishment of handshaking sessions before actual DNS operations. Authentication credentials and session keys are pre-configured during enrollment, so that when DNS requests occur, the authentication mechanism is already in place and operational, providing security without adding complexity to the core DNS functionality

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication layer between DNS clients and DNS servers. This intermediary system handles the complex authentication logic, session management, and credential verification, allowing the core DNS system to remain simple while security requirements are met through the intermediary authentication mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If handshaking protocols and encrypted data are implemented for DNS requests, then authentication security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improverequest authenticationVSAvoidDNS request processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Handshaking sessions and encrypted credentials are established during the enrollment phase before actual DNS operations. This preliminary setup allows subsequent DNS requests to use pre-configured session keys and authentication mechanisms, reducing the time overhead during actual DNS resolution operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically manages session states, transitioning between enrolled, authenticated, and active states. Session keys and authentication parameters are dynamically generated and updated during handshaking, allowing the system to optimize processing time by reusing established sessions while maintaining security through dynamic credential updates

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If dynamic configuration of trusted network interface controllers is implemented, then adaptability to different devices is improved, but system complexity and configuration overhead increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidconfiguration management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal enrollment mechanism that works across different device types and network interface controllers. The enrollment process and authentication framework are designed to be device-agnostic, allowing the same system to handle diverse devices through a common interface and protocol, thereby achieving adaptability without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service enrollment where devices can automatically register themselves with the authentication system. During enrollment, devices automatically generate credentials, establish handshaking sessions, and configure their network interface controllers without requiring manual configuration, thereby achieving device compatibility while minimizing configuration overhead through automated self-registration

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12095754B2System and method for establishing a secure session to authenticate DNS requests via dynamically configurable trusted network interface controllers
Publication Date: 2024.09.17 BANK OF AMERICA CORP
  • US12095754B2 patent drawing
  • US12095754B2 patent drawing
  • US12095754B2 patent drawing

AI summary

Embodiments of the present invention provide a system for establishing a secure session to authenticate DNS requests via dynamically configurable trusted network interface controllers. The system is configured for receiving a DNS request from a first device, wherein the DNS request comprises a unique authentication package, wherein the unique authentication package comprises encrypted data, in response to receiving the DNS request, initiating a handshaking protocol with the first device, establishing a handshaking session with the first device based on the encrypted data using the handshaking protocol, receiving a query associated with the DNS request, wherein the query is generated using a handshaking algorithm associated with the handshaking protocol, and performing at least one action in response to receiving the query.