H04L61/5076

Methods and systems for secure DNS routing

Various arrangements for performing secure domain name system (DNS) routing are presented. A secure signature may be generated using an internet protocol (IP) address of an authorized device. An encoded character string may be generated that comprises the IP address. The domain name server may receive a request for an IP address mapped to the hostname. The hostname may be validated using the secure signature. The IP address of the authorized device may be decoded from the encoded character string at least partially in response to the hostname being validated by the domain name server. The IP address decoded from the encoded character string may be transmitted at least partially based on the hostname being validated and the request for the IP address.

Methods and systems for secure DNS routing

Various arrangements for performing secure domain name system (DNS) routing are presented. A secure signature may be generated using an internet protocol (IP) address of an authorized device. An encoded character string may be generated that comprises the IP address. The domain name server may receive a request for an IP address mapped to the hostname. The hostname may be validated using the secure signature. The IP address of the authorized device may be decoded from the encoded character string at least partially in response to the hostname being validated by the domain name server. The IP address decoded from the encoded character string may be transmitted at least partially based on the hostname being validated and the request for the IP address.

Adjusting DNS resolution based on predicted application experience metrics

In one embodiment, a device obtains application experience metrics for an online application. The device predicts, based on the application experience metrics, future application experience metrics for each of a set of provider endpoints for the online application. The device selects, based on the future application experience metrics, a particular provider endpoint from among the set of provider endpoints. The device provides, to a Domain Name System (DNS) resolver, resolution information for one or more of the set of provider endpoints that causes a query for one of those provider endpoints to resolve to an address of the particular provider endpoint.

Deploying Applications On Home-Network Router
20220417053 · 2022-12-29 ·

Various embodiments describe methods, systems, and devices for deploying an application associated with a user-selected container on a home-network router. Exemplary implementations may include receiving, at the home-network router from a remote server, container acquisition data including configuration information and rules for downloading the user-selected container. Also, initiating, by the home-network router, operation of application logic of the user-selected container in response to downloading the user-selected container from a remote container registry. Further, updating, by the home-network router, a reverse proxy maintained in the home-network router through application logic, wherein the reverse proxy is configured to forward requests from operation of the user-selected container to one or more remote servers; transmitting, from the home-network router to a remote computing device, a notification that the application associated with the user-selected container is deployed.

FEDERATED DNS CACHING
20220400099 · 2022-12-15 · ·

Systems and methods are provided for distributing a domain name service (DNS) response cache in a DNS resolving system on a network. The systems and methods described herein may improve response times for client queries and also protect the DNS resolving system from DNS related cyber attacks

FEDERATED DNS CACHING
20220400099 · 2022-12-15 · ·

Systems and methods are provided for distributing a domain name service (DNS) response cache in a DNS resolving system on a network. The systems and methods described herein may improve response times for client queries and also protect the DNS resolving system from DNS related cyber attacks

EDGE SWITCHING SYSTEM, EDGE SWITCHING DEVICE, EDGE SWITCHING METHOD, AND PROGRAM
20220394011 · 2022-12-08 ·

An edge switching device (10) of an edge switching system (1000) includes: a remaining lease time information obtainment unit (122) that obtains remaining lease time information for each of user terminals (4) from a DHCP server (30); a submission order determination unit (123) that determines a submission order for user configuration information in order from a shortest remaining lease time; a user configuration information submission unit (124) that submits, to a backup system edge router (2B), user configuration information of each of the user terminals (4), according to the determined submission order; and a reconnection inducement instruction unit (125) that sends, to the DHCP server, an instruction to send reconnection inducement information to the user terminals for which the user configuration information has been submitted.

EDGE SWITCHING SYSTEM, EDGE SWITCHING DEVICE, EDGE SWITCHING METHOD, AND PROGRAM
20220394011 · 2022-12-08 ·

An edge switching device (10) of an edge switching system (1000) includes: a remaining lease time information obtainment unit (122) that obtains remaining lease time information for each of user terminals (4) from a DHCP server (30); a submission order determination unit (123) that determines a submission order for user configuration information in order from a shortest remaining lease time; a user configuration information submission unit (124) that submits, to a backup system edge router (2B), user configuration information of each of the user terminals (4), according to the determined submission order; and a reconnection inducement instruction unit (125) that sends, to the DHCP server, an instruction to send reconnection inducement information to the user terminals for which the user configuration information has been submitted.

System and method of acquiring network-centric information for customer premises equipment (CPE) management

A method, device, and computer-readable medium are provided for sending, by a customer-premises equipment (CPE) device to a wireless access device via a CPE network interface, an Internet protocol (IP) address lease request, wherein the wireless access device terminates a wireless backhaul connection to a service provider network; receiving, responsive to the IP address lease request, an acknowledge message that includes a requested IP address and a protocol configuration option (PCO) providing identification information for the wireless access device; connecting, via the wireless access device and using the requested IP address, to a bootstrap server device associated with the service provider network; receiving, via the wireless access device, attachment information associated with a network management server and the service provider network; and sending, via the wireless access device, the identification information to the network management server in an attachment procedure using the attachment information.

System and method of acquiring network-centric information for customer premises equipment (CPE) management

A method, device, and computer-readable medium are provided for sending, by a customer-premises equipment (CPE) device to a wireless access device via a CPE network interface, an Internet protocol (IP) address lease request, wherein the wireless access device terminates a wireless backhaul connection to a service provider network; receiving, responsive to the IP address lease request, an acknowledge message that includes a requested IP address and a protocol configuration option (PCO) providing identification information for the wireless access device; connecting, via the wireless access device and using the requested IP address, to a bootstrap server device associated with the service provider network; receiving, via the wireless access device, attachment information associated with a network management server and the service provider network; and sending, via the wireless access device, the identification information to the network management server in an attachment procedure using the attachment information.