Method for processing a request for resolution of at least one naming identifier, corresponding device and computer program

The method redirects naming identifier requests through a proxy server to selected resolvers based on equipment and identifier parameters, addressing inefficiencies in existing systems by reducing costs and enhancing performance and security in naming identifier resolution.

FR3141023B1Active Publication Date: 2025-10-24ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022010753
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-18
Publication Date
2025-10-24
Estimated Expiration
2042-10-18

AI Technical Summary

Technical Problem

Existing naming identifier resolution systems, such as DNS over HTTPS (DoH) and DNS over TLS (DoT), lack flexibility and security, leading to suboptimal resource management and intervention capabilities for internet service providers (ISPs) due to direct communication with default resolvers, which can result in inefficient resource utilization and lack of control over resolution processes.

Method used

A method involving a proxy server that intercepts naming identifier requests, redirects them to selected resolvers based on equipment and identifier parameters, and provides authorization using digital fingerprints, allowing ISPs to manage resources effectively and enhance security.

Benefits of technology

This approach reduces connection costs and energy consumption by delegating resolution functions to proxy servers, enhances performance through reduced connections, and ensures reliable and secure naming identifier resolution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000022_0000
    Figure 00000022_0000
  • Figure 00000022_0001
    Figure 00000022_0001
  • Figure 00000022_0002
    Figure 00000022_0002
Patent Text Reader

Abstract

Method for processing a request for resolution of at least one naming identifier, corresponding device and computer program In certain existing naming identifier resolution solutions, the resolver intended to resolve a naming identifier is selected by default by the equipment requesting the resolution of this naming identifier. This is detrimental because the requests for resolution of naming identifiers are transmitted by the equipment to naming identifier resolvers without consultation with the internet service provider (ISP) with which a user of the equipment has subscribed to a service offer and without the latter having access to these requests for resolution of naming identifiers since the latter are transmitted through a tunnel established between the equipment and a proxy server operated by a third-party company.The invention makes it possible to force the transmission of the request for resolution of a naming identifier to another naming identifier resolver selected by the internet service provider with which a user of the equipment has subscribed to a service offer. FIGURE 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for processing a request for resolution of at least one naming identifier, corresponding device and computer program Field of invention

[0001] The field of the invention is that of the resolution of naming identifiers such as domain names. More specifically, the invention relates to the identification and selection of an entity embedding a naming identifier resolution function, normally executed by default naming identifier resolvers. Prior art and its drawbacks

[0002] The recent development of secure transport protocols for naming resolutions (DNS) such as the DoH protocols (DoH meaning DNS over HTTPS) specified in the document RFC8484 (Request for Comment) published by the IETF (Internet Engineering Task Force) or DoT (DNS over TLS), specified in the document RFC7858 also published by the IETF has been accompanied by the dynamic selection of the naming identifier resolver, or DNS resolver, by the equipment requesting the resolution of a naming identifier. In order to allow an equipment to select the appropriate naming identifier resolver, the latter is equipped with a naming identifier resolution routing table or DNS routing table, listing the naming identifier resolver(s) to which it can transmit a request for naming identifier resolution as well as a set of rules for selecting the appropriate naming identifier resolver.

[0003] In a first mode, called “default”, the equipment establishes a secure connection with the selected resolver and transmits to it a request for resolution of naming identifiers.

[0004] In order to further increase the level of security, it is proposed that the devices 10 communicate with a proxy server in order to hide their network address from naming identifier resolvers.

[0005] [Fig.1A] shows an example of the naming identifier resolution scenario involving a proxy server, in which a device 10, such as a user terminal, comprises a DNS routing table TRDNS comprising the identifiers such as a network address, a domain name, etc. of three naming identifier resolvers 12, 13 and 14 as well as the rules for selecting the naming identifier resolver to be contacted. Such a DNS routing table indicates that a naming identifier in ".com" is resolved by the resolver of naming identifiers 12, that a naming identifier in “.fr” is resolved by the naming identifier resolver 13 and that the naming identifier resolver 14 is the default naming identifier resolver. The naming identifier resolver 16 is not listed in the DNS routing table TRDNS. The device 17 is an authoritative server associated with at least one naming identifier to be resolved.

[0006] The equipment 10 establishes a connection with a proxy server 11 operated by a third-party company. In other words, the data exchanged between the equipment 10 and the proxy server 11 are encapsulated in accordance with the HTTPS protocol (for Hypertext Transfer Protocol Secure in English) transported by the secure transport protocols TLS (for Transport Location Security in English) or QUIC (for Quick UDP Internet Connection in English). This encapsulation of the exchanged data is represented in the form of a Tun tunnel established between the equipment 10 and the proxy server 11.Such encapsulation can be achieved by exchanging messages conforming to the DATAGRAM extension of the QUIC protocol as defined in RFC 9221 published by the IETF, to the "capsule" extension defined in RFC 9297 published by the IETF or to the "draft-ietf-masque-connect-ip" and "connect-udp" extensions defined in RFC 9298 also published by the IETF.

[0007] The equipment 10 sends a request for resolution of naming identifiers to the appropriate naming identifier resolver, for example the resolver 12 because the naming identifier to be resolved is “example.com” through the Tun tunnel.

[0008] The proxy server 11 then relays a message sent by the resolver 12, intended for the equipment 10, comprising at least one naming identifier, such as for example an IP (Internet Protocol) address of the IPv4 or IPv6 type or redirection data such as a canonical domain name or DNS CNAME associated with servers 15 associated with the naming identifier to be resolved, these servers 15 storing data relating to the implementation of a service required by the equipment 10 such as data relating to a web page or data relating to downloadable content, etc. Such a message is transmitted by the proxy server 11 to the equipment 10 through the tunnel Tun.

[0009] The equipment 10 can then establish a connection with the corresponding server 15 and can access the data relating to the implementation of the required service.

[0010] [Fig.lB] represents an example of the so-called “default” naming identifier resolution scenario, in which the equipment 10 always comprises a DNS routing table TRDNS comprising the identifiers such as a network address, a domain name, etc. of three naming identifier resolvers 12, 13 and 14 as well as the rules for selecting the naming identifier resolver to be used. contact. Such a DNS routing table indicates that a naming identifier in ".com" is resolved by the naming identifier resolver 12, that a naming identifier in ".fr" is resolved by the naming identifier resolver 13 and that the naming identifier resolver 14 is the default naming identifier resolver. The naming identifier resolver 16 is not listed in the DNS routing table TRDNS. The device 17 is an authoritative server associated with at least one naming identifier to be resolved.

[0011] The equipment 10 establishes a connection with a proxy server 11 operated by a third-party company and embedded in the resolver 12. In other words, the data exchanged between the equipment 10 and the authoritative server 12 are encapsulated in accordance with the HTTPS protocol transported by the secure transport protocols TLS or QUIC. This encapsulation of the exchanged data is represented by the tunnel Tun established between the equipment 10 and the resolver 12. Such encapsulation can be obtained by exchanging messages conforming to the DATAGRAM extension of the QUIC protocol, to the “capsule” extension or even the “draft-ietf-masque-connect-ip” and “connect-udp” extensions.

[0012] The equipment 10 sends a request for resolution of naming identifiers to the resolver 12 because the naming identifier to be resolved is “example.com” through the Tun tunnel.

[0013] The resolver 12 then transmits a message through the tunnel Tun to the equipment 10, comprising at least one naming identifier, such as for example an IP (Internet Protocol) address of the IPv4 or IPv6 type or redirection data such as a canonical domain name or DNS CNAME associated with servers 15 associated with the naming identifier to be resolved, these servers 15 storing data relating to the implementation of a service required by the equipment 10 such as data relating to a web page or data relating to downloadable content, etc.

[0014] The equipment 10 can then establish a connection with the corresponding server 15 and can access the data relating to the implementation of the required service.

[0015] In this scenario, the requests for resolution of naming identifiers are transmitted to naming identifier resolvers without consultation with the internet service provider ISP from which a user of the equipment 10 has subscribed to a service offer, in particular a connectivity service offer that may contain differentiated qualities of service depending on the offers / needs of the partners of the service provider ISP, and without the latter having access to these requests for resolution of naming identifiers since the latter are transmitted through the tunnel Tun.

[0016] This impacts the management of resources of the different communication equipment, managed by the internet service provider ISP from which a user of the equipment 10 has subscribed to a service offer and involved in the resolution of naming identifiers which may not be used optimally. The service provider, moreover, cannot intervene for example on the resolution request and the response to this request, in particular to adapt the response to the architecture of the service provider or partners to the service provider. The intervention may in fact consist of enriching the request with information which can be used to adapt the response according to this enrichment or else to balance for example the load between several servers operated on behalf of one or more partners of the service provider ISP storing the data relating to the implementation of the service.There is therefore a need for a technique for resolving naming identifiers that does not have all or part of the aforementioned drawbacks. Statement of the invention

[0017] The invention meets this need by proposing a method for processing a request for resolution of at least one naming identifier sent by a device through a path established between said device and a proxy server, said method being implemented by said proxy server and comprising the following steps: - interception of said request comprising an identifier of at least one first entity implementing a resolution function of at least one naming identifier, called the default entity, to which it was sent, - transmission of said request to at least one second entity implementing a function for resolving at least one naming identifier, said second entity being selected as a function of at least one parameter relating to said equipment and / or at least one parameter relating to the naming identifier to be resolved, - transmission to said equipment of an identifier of at least one server associated with the naming identifier to be resolved transmitted by said second entity.

[0018] By proxy server we mean any intermediate equipment known to the equipment or discovered during the protocol exchanges implemented when establishing the tunnel.

[0019] Such a solution makes it possible to force the transmission of the request for resolution of a naming identifier sent by the equipment to a default naming identifier resolver to another naming identifier resolver.

[0020] The identity of this second naming identifier resolver may, for example, result from an agreement between the internet service provider with which a user of the equipment has subscribed to a service offer and a third-party company operating the authoritative servers associated with the naming identifiers to be resolved.

[0021] To do this, the proxy server has in its possession information allowing it, for a naming identifier to be resolved, to identify at least one naming identifier resolver to which to transmit the request for naming identifier resolution.

[0022] Thus, based on information relating to the equipment that requested resolution of a naming identifier, the proxy server is capable of determining to which naming identifier resolver it must entrust the processing of the request for resolution of naming identifiers sent by the equipment.

[0023] Such a request for resolution of naming identifiers being transmitted to a naming identifier resolver chosen by the internet service provider from which a user of the equipment has subscribed to a service offer, the latter again has the capacity to manage the resources of the different communication equipment that it operates.

[0024] According to another characteristic of the method which is the subject of the invention, the latter comprises, prior to the interception of said request, a step of receiving at least one message comprising said at least one parameter relating to said equipment and said at least one parameter relating to the naming identifier to be resolved, said message being sent by an authoritative server associated with the at least one naming identifier to be resolved.

[0025] According to another characteristic of the method which is the subject of the present invention, said received message is further signed with a certificate from said authoritative server indicating the ownership of the at least one naming identifier to be resolved.

[0026] Such an ownership certificate may be issued to the authoritative server associated with the naming identifier to be resolved by a trusted authority. Thus, the proxy server knows that the information provided by the authoritative server is reliable.

[0027] In an implementation of the method which is the subject of the present invention, said at least one parameter relating to the at least one naming identifier to be resolved comprises at least one network address of a naming identifier resolver embedding said second entity and / or information for redirecting said request to said naming identifier resolver.

[0028] In such an implementation, the proxy server redirects the request for resolution of naming identifiers sent by the equipment to a naming identifier resolver whose network address has been provided to it by the authoritative server associated with the naming identifier to be resolved.

[0029] In another implementation of the method which is the subject of the present invention, said second entity being embedded in said proxy server, said at least one parameter relating to the at least one naming identifier to be resolved comprises at least one authorization for execution by said proxy server of a function for resolving at least one naming identifier.

[0030] Such a solution makes it possible to delegate the resolution of naming identifiers carried out by default by naming identifier resolvers to the proxy server.

[0031] Delegating the resolution of naming identifiers to the proxy server makes it possible to reduce the costs associated with the execution of this naming identifier resolution function. Indeed, by delegating the resolution of naming identifiers to the proxy server, it is possible to reduce the number of connections between communication equipment in order to resolve a naming identifier, in particular by reusing existing connections between the user equipment and the proxy servers. Such a reduction in the number of connections between communication equipment leads to a reduction in the energy consumption of this communication equipment.

[0032] In addition, such a solution for delegating the resolution of naming identifiers also has increased performance. This is due to the fact that the number of connections established between communication equipment in order to resolve a naming identifier is reduced.

[0033] Furthermore, the proposed solution for delegating the resolution of naming identifiers is reliable. Indeed, in the context of the present solution, a proxy server implementing a resolution of naming identifiers instead of a naming identifier resolver is provided with an authorization to execute this function of resolving at least one naming identifier which can be verified if necessary.

[0034] According to a characteristic of the method which is the subject of the present invention, the execution authorization is a digital fingerprint of the at least one naming identifier associated with said proxy server signed by a cryptographic key associated with said authoritative server associated with said at least one naming identifier to be resolved.

[0035] The execution authorization is generated by the authoritative server associated with the naming identifier to be resolved and is specific to each proxy server to which a naming identifier resolution function is delegated. Thus, only a proxy server authorized by an authoritative server associated with a naming identifier is delegated naming identifier resolution.

[0036] According to a characteristic of the method which is the subject of the present invention, the parameter relating to the equipment is a location parameter of the equipment.

[0037] Depending on the location of the equipment, one naming identifier resolver may be preferred to another.

[0038] The invention also relates to a method for generating an authorization for execution, by a proxy server, of a function for resolving at least one naming identifier, said proxy server intercepting a request for resolving at least one naming identifier sent by a device through a path established between said device and a proxy server, said request comprising an identifier of at least one first entity implementing a function for resolving at least one naming identifier, called the default entity, to which it was sent, said method being implemented by an authoritative server associated with said naming identifier to be resolved and comprising the following steps: - determination of a digital fingerprint of said at least one naming identifier to be resolved associated with an identifier of said proxy server, - transmission, to the proxy server, of said execution authorization including said digital fingerprint.

[0039] According to a characteristic of the method for generating an execution authorization which is the subject of the present invention, said digital fingerprint is further signed by a cryptographic key associated with the authoritative server.

[0040] Thus, the authenticity and integrity of the digital fingerprint are ensured and can be, if necessary, verified by the proxy server.

[0041] The invention also relates to a proxy server capable of processing a request for resolution of at least one naming identifier sent by a device through a path established between said device and said proxy server, said proxy server comprising at least one processor configured to: - intercept said request comprising an identifier of at least one first entity implementing a resolution function of at least one naming identifier, called the default entity, to which it was sent, - transmitting said request to at least one second entity implementing a function for resolving at least one naming identifier, said second entity being selected as a function of at least one parameter relating to said equipment and / or at least one parameter relating to the naming identifier to be resolved, - transmit to said equipment an identifier of at least one server associated with the naming identifier to be resolved transmitted by said second entity.

[0042] Another object of the invention is an authoritative server associated with at least one naming identifier, said server being capable of generating an authorization for execution, by a proxy server, of a function for resolving said at least one naming identifier, said proxy server intercepting a request for resolving at least one naming identifier sent by a device through an established path. between said equipment and a proxy server, said request comprising an identifier of at least one first entity implementing a resolution function of at least one naming identifier, called the default entity, to which it was sent, said authoritative server comprising at least one processor configured to: - determine a digital fingerprint of said at least one naming identifier to be resolved associated with an identifier of said proxy server, - transmit, to the proxy server, said execution authorization including said digital fingerprint.

[0043] The invention finally relates to computer program products comprising program code instructions for implementing the methods as described above, when they are executed by a processor.

[0044] The invention also relates to a computer-readable recording medium on which computer programs are recorded comprising program code instructions for executing the steps of the methods according to the invention as described above.

[0045] Such a recording medium may be any entity or device capable of storing the programs. For example, the medium may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a USB key or a hard disk.

[0046] On the other hand, such a recording medium may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means, so that the computer programs it contains are remotely executable. The programs according to the invention may in particular be downloaded over a network, for example the Internet.

[0047] Alternatively, the recording medium may be an integrated circuit in which the programs are incorporated, the circuit being adapted to execute or to be used in the execution of the methods which are the subject of the invention mentioned above. List of figures

[0048] Other aims, characteristics and advantages of the invention will appear more clearly on reading the following description, given as a simple illustrative, and non-limiting, example, in relation to the figures, among which:

[0049] [Fig. 1 A]: this figure represents a first example of a resolution scenario naming identifiers,

[0050] [Fig.lB]: this figure represents a second example of a scenario for resolving naming identifiers,

[0051] [Fig.2]: this figure represents a diagram of exchanges between different communication equipment involved in a first mode of implementation of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server, of a function for resolution of at least one naming identifier,

[0052] [Fig.3]: this figure represents a diagram of exchanges between different communication equipment involved in a second mode of implementation of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server, of a function for resolution of at least one naming identifier,

[0053] [Fig.4]: this figure represents a diagram of exchanges between different communication equipment involved in a third mode of implementation of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server, of a function for resolution of at least one naming identifier,

[0054] [Fig.5]: this figure represents a proxy server capable of implementing the different embodiments of the method for processing a request for resolution of at least one naming identifier according to the invention,

[0055] [Fig.6]: this figure represents an authoritative server capable of implementing the different embodiments of the method for generating an authorization for execution, by a proxy server, of a function for resolving at least one naming identifier according to the invention.

[0056] Detailed description of embodiments of the invention

[0057] The general principle of the invention is based on the transmission of a request for resolution of a naming identifier intended to be processed by a naming identifier resolver defined by default to another naming identifier resolver chosen for example following an agreement between an internet service provider from which a user has subscribed to a service offer and a third-party company operating authoritative servers associated with the naming identifiers to be resolved.

[0058] This allows in particular the internet service provider with whom a user of the equipment has subscribed to a service offer to once again have the capacity to manage the resources of the different communication equipment that it operates.

[0059] We now present, in relation to [Fig.2], a diagram of exchanges between different communication equipment involved in a first mode of implementation of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server, of a function for resolution of at least one naming identifier.

[0060] During a step E0, an authoritative server 17 associated with an identifier of naming identifier, such as example.com, transmits a Record message comprising at least one parameter relating to said equipment 10, or a parameter relating to the naming identifier to be resolved to the proxy server 11 and a certificate indicating that the operator of the authoritative server 17 is the owner of the naming identifier in question. Such an ownership certificate may be issued to the authoritative server 17 associated with the naming identifier to be resolved by a trusted authority. Thus, the proxy server 11 knows that the information provided by the authoritative server 17 is reliable. The parameter relating to the equipment 10 is for example an IP address mask, an IP address or more generally an identifier of the equipment 10. Thus, the proxy server 11 can identify the equipment 10 for which a particular processing of requests for resolution of naming identifiers must be applied.

[0061] During a step E1, a device 10, such as a user terminal, sends a message requesting the establishment of a communication session of the Mask type to the proxy server 11. Such a message for establishing a communication session is for example an http message of the CONNECT "connect-udp" type defined in the document RFC 9298 published by the IETF.

[0062] HEADERS

[0063] :method = CONNECT

[0064] :protocol = connect-udp

[0065] :scheme = https

[0066] :path = / .well-known / masque / udp / 192.0.2.6 / 443 /

[0067] :authority = agent.org

[0068] capsule-protocol = ?1

[0069] in which 192.0.2.6 is the network address of resolver 12.

[0070] The data exchanged between the equipment 10 and the proxy server 11 during this session are therefore, for example, encapsulated in DATAGRAM type messages of the QUIC protocol, or “capsule” extensions (in the case of CONNECT type http messages “connect-ip”). This encapsulation of the exchanged data is represented in the form of the Tun tunnel established between the equipment 10 and the proxy server 11.

[0071] Once the communication session has been established between the equipment 10 and the proxy server 11, the equipment 10 sends, in a step E2, a request for resolution of an RDN naming identifier to the proxy server 11 for the naming identifier example.com. This request for resolution of an RDN naming identifier is for example a message of the DNS over QUIC type example.com. In accordance with what is indicated in the DNS routing table TRDNS of the equipment 10, the default naming identifier resolver identified for resolving naming identifiers with a “.com” extension is the resolver 12. Thus, the request for resolving the RDN naming identifier is sent by the equipment 10 to the resolver 12.

[0072] In a step E3, the proxy server 11 intercepts the request for resolution of an RDN naming identifier. The proxy server 11 determines, for example by means of the mask of IP addresses received during the step E0, whether or not the request for resolution of an RDN naming identifier must be subject to particular processing. If this is the case, the proxy server 11 implements the step E4.

[0073] In this first embodiment, the Record message sent by the authoritative server 17 during step E0 comprises, in addition to the parameter relating to said equipment 10, the parameter relating to the naming identifier to be resolved and the certificate of ownership of the authoritative server 17, a parameter for redirecting the request for resolution of naming identifiers. Such a redirection parameter is, for example, an identifier such as an IP address of the naming identifier resolver 16, which is, for example, operated by the internet service provider with which a user of the equipment 10 has subscribed to a service offer.

[0074] The proxy server 11 then sends the request for resolution of an RDN naming identifier to the resolver 16, during step E4, instead of transferring it to the resolver 12 as requested by the equipment 10.

[0075] In a step E5, the resolver 16 resolves the naming identifier included in the RDN naming identifier resolution request and sends in a step E6 an MSG message comprising an IP address or an identifier associated with at least one server 15 associated with the naming identifier to be resolved. Such an MSG message is a message conforming to the DNS protocol.

[0076] Such a server 15 may be located in a remote network or be close to the equipment 10 when the IP address of the server 15 transmitted by the resolver 16 corresponds to a particular subnetwork in which the equipment 10 is located, for example. The choice of favoring a server 15 located in a remote network or in a subnetwork close to that in which the equipment 10 is located is subject to the agreement established between the internet service provider from which a user has subscribed to a service offer and the third-party company operating the authoritative servers 17 associated with the naming identifiers to be resolved.

[0077] In a step E7, the proxy server 11 intercepts the MSG message and transmits it, in a step E8 to the equipment 10:

[0078] Finally, in a step E9, the equipment 10 establishes a communication session with the server 15 whose identifier, for example the IP address, was included in the MSG message in order to obtain, for example, the content associated with the request for resolution of the naming identifier that it sent.

[0079] We now present, in relation to [Fig. 3], a diagram of exchanges between different communication equipment involved in a second mode of implementation of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server embedded in an authoritative server, of a function for resolution of at least one naming identifier.

[0080] During a step F0, an authoritative server 17 associated with a naming identifier, such as example.com, transmits a Record message comprising at least one parameter relating to said equipment 10, or a parameter relating to the naming identifier to be resolved to the proxy server 11 embedded in the resolver 12 and a certificate indicating that the operator of the authoritative server 17 is the owner of the naming identifier in question. Such an ownership certificate may be delivered to the authoritative server 17 associated with the naming identifier to be resolved by a trusted authority. Thus, the proxy server 11 knows that the information provided by the authoritative server 17 is reliable. The parameter relating to the equipment 10 is for example an IP address mask, an IP address or more generally an identifier of the equipment 10.Thus, the proxy server 11 can identify the devices 10 for which a particular processing of requests for resolution of naming identifiers must be applied.

[0081] During a step F1, the equipment 10 sends a message requesting the establishment of a communication session of the Mask type to the proxy server 11 embedded in the resolver 12. Such a message for establishing a communication session is for example an http message of the CONNECT "connect-udp" type.

[0082] HEADERS

[0083] :method = CONNECT

[0084] :protocol = connect-udp

[0085] :scheme = https

[0086] :path = / .well-known / masque / udp / 192.0.2.6 / 443 /

[0087] :authority = agent.org

[0088] capsule-protocol = ?1

[0089] in which 192.0.2.6 is the network address of resolver 12.

[0090] The data exchanged between the equipment 10 and the proxy server 11 during this session are therefore, for example, encapsulated in DATAGRAM type messages of the QUIC protocol, or “capsule” extensions (in the case of http messages of CONNECT type “connect-ip”. This encapsulation of the exchanged data is represented in the form of the Tun tunnel established between the equipment 10 and the resolver 12.

[0091] Once the communication session has been established between the equipment 10 and the proxy server 11, the equipment 10 sends, in a step F2, a request for resolution of an RDN naming identifier to the proxy server 11 embedded in the resolver 12 since, in accordance with what is indicated in the DNS routing table TRDNS of the equipment 10, the default naming identifier resolver identified for resolving naming identifiers having a “.com” extension is the resolver 12. This request for resolution of an RDN naming identifier is for example a message of the DNS over QUIC example.com type.

[0092] In a step F3, the proxy server 11 receives the request for resolution of an RDN naming identifier. The proxy server 11 determines, for example by means of the mask of IP addresses received during the step E0, whether or not the request for resolution of an RDN naming identifier must be subject to particular processing. If this is the case, the proxy server 11 implements step F4.

[0093] In this first embodiment, the Record message sent by the authoritative server 17 during step F0 comprises, in addition to the parameter relating to said equipment 10, the parameter relating to the naming identifier to be resolved and the certificate of ownership of the authoritative server 17, a parameter for redirecting the request for resolution of naming identifiers. Such a redirection parameter is, for example, an identifier such as an IP address of the naming identifier resolver 16 which is, for example, operated by the internet service provider with which a user of the equipment 10 has subscribed to a service offer.

[0094] The resolver 12 then transmits the request for resolution of an RDN naming identifier to the resolver 16, during step F4, instead of processing it itself as requested by the equipment 10.

[0095] In a step F5, the resolver 16 resolves the naming identifier included in the request for resolution of the RDN naming identifier and sends in a step F6 an MSG message comprising an IP address or an identifier associated with at least one server 15 associated with the naming identifier to be resolved to the proxy server 11. Such an MSG message is a message conforming to the DNS protocol.

[0096] Such a server 15 may be located in a remote network or be close to the equipment 10 when the IP address of the server 15 transmitted by the resolver 16 corresponds to a particular subnetwork in which the equipment 10 is located, for example. The choice of favoring a server 15 located in a remote network or in a subnetwork close to that in which the equipment 10 is located is subject to the agreement established between the internet service provider from which a user has subscribed to a service offer and the third-party company operating the authoritative servers 17 associated with the naming identifiers to be resolved.

[0097] In a step F7, the proxy server 11 intercepts the MSG message and transmits, in a step F8 to the equipment via the addition of http header fields specific to the present method such as a header field DNS_ID = 'example.com', a header field DNS_TYPE='A' or a header field DNS_VALUE=' 103.168.1.1' indicating to the equipment 10 that it must request the content identified by the domain identifier "example.com" from the server 15 whose network address is 193.168.1.1.

[0098] The proxy server 11 embedded in the resolver can further indicate in the MSG message a modification of the resolver for this domain identifier.

[0099] For this, header fields specific to the present method are added to the MSG message such as a DNS_ROUTE_DOMAIN header field and a DNS_ROUTE_RESOLVER header field indicating to the equipment 10 that the resolver 16 is now the default resolver for the domain identifier example.com. Such a procedure is defined by the IETF in the following document: https: / / httpwg.org / http-extensions / draft-ietf-httpbis-message-signatures.html.

[0100] Upon receipt of the MSG message, the equipment 10 updates the TRFNS routing table with this information.

[0101] Finally, in a step F9, the equipment 10 establishes a communication session with the server 15 whose identifier, for example the IP address, was included in the MSG message in order to obtain, for example, the content associated with the http request that it makes.

[0102] We now present, in relation to [Fig.4], a diagram of exchanges between different communication equipment involved in a third mode of implementation of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server, of a function for resolution of at least one naming identifier.

[0103] During step G0, the authoritative server 17 associated with the naming identifier example.com generates an AD execution authorization associated with the proxy server 11 for the naming identifier example.com.

[0104] Thus, the authoritative server 17 encrypts with a private cryptographic key associated with a public cryptographic key each naming identifier associated with a proxy server 11 to which it gives authorization to execute a function for resolving at least one naming identifier. The authoritative server 17 then calculates a digital fingerprint of the naming identifier associated with an identifier of the proxy server 11 signed by means of the cryptographic key associated with the authoritative server 17. Such a digital fingerprint is for example a hash of the public key of the authoritative server 17, of the naming identifier, example.com, and of the identifier of the proxy server 11. The authoritative server 17 thus determines AD execution permission for proxy server 11 for naming identifier example.com.

[0105] In a step G1, the authoritative server 17 transmits a Record message comprising at least one parameter relating to said equipment 10, a certificate of ownership of the authoritative server 17 and an execution authorization AD. Such a certificate of ownership can be delivered to the authoritative server 17 associated with the naming identifier to be resolved by a trusted authority. Thus, the proxy server 11 knows that the information provided by the authoritative server 17 is reliable. The parameter relating to the equipment 10 is for example an IP address mask. Thus, the proxy server 11 can identify the equipment 10 for which a particular processing of the requests for resolution of naming identifiers must be applied.

[0106] In a step G2, the naming identifier resolver 12 stores IP addresses of servers 15 associated with the naming identifiers for which it has AD execution authorization in a correspondence table intended to be used when resolving the naming identifiers.

[0107] These steps G0, G1 and G2 do not directly trigger steps G3 and following, they can be prior to them or be subsequent to step G3 in order to ensure the correct execution of the methods for processing a request for resolution of at least one naming identifier and for generating an authorization for execution, by a proxy server, of a function for resolution of at least one naming identifier.

[0108] During a step G3, the equipment 10 sends a message requesting the establishment of an HS communication session to the proxy server 11. Such a message for establishing a communication session is for example an http message of the CONNECT "connect-udp" type:

[0109] HEADERS

[0110] :method = CONNECT [YES] :protocol = connect-udp

[0112] :scheme = http s

[0113] :path = / .well-known / masque / udp / 192.0.2.6 / 443 /

[0114] :authority = agent.org

[0115] capsule-protocol = ?1

[0116] where 192.0.2.6 is the network address of resolver 12.

[0117] The data exchanged between the equipment 10 and the proxy server 11 during this session are therefore encapsulated in UDP packets. This encapsulation of the exchanged data is represented in the form of the tunnel Tun established between the equipment 10 and the proxy server 11.

[0118] Once the communication session has been established between the equipment 10 and the server proxy 11, the equipment 10 sends, in a step G4, a request for resolution of an RDN naming identifier to the proxy server 11 for the naming identifier example.com. This request for resolution of an RDN naming identifier is for example a message of the DNS over QUIC type example.com. In accordance with what is indicated in the DNS routing table TRDNS of the equipment 10, the default naming identifier resolver identified for resolving naming identifiers having a “.com” extension, or a specific naming identifier such as “example.com”, is the resolver 12. Thus, the request for resolution of an RDN naming identifier is sent by the equipment 10 to the resolver 12.

[0119] In a step G5, the proxy server 11 intercepts the request for resolution of an RDN naming identifier. The proxy server 11 determines, by means of the IP address mask received during step G2, whether or not the request for resolution of an RDN naming identifier must be subject to special processing. If this is the case, the proxy server 11 implements step G6.

[0120] During step G6, the proxy server 11, having determined that it has an AD execution authorization associated with the naming identifier to be resolved, does not proceed with the transmission of the intercepted naming identifier resolution request. Instead, it proceeds with the resolution of the naming identifier included in the naming identifier resolution request by means of the correspondence table obtained in step G3.

[0121] Once the naming identifier has been resolved, the proxy server 11 sends, in a step G7, a message MSG1 comprising an identifier such as for example an IP address, a domain name, etc. associated with at least one server 15 associated with the resolved naming identifier to the equipment 10.

[0122] Such a server 15 may be located in a remote network or be close to the equipment 10 when the IP address of the server 15 transmitted by the resolver 16 corresponds to a particular subnetwork in which the equipment 10 is located, for example. The choice of favoring a server 15 located in a remote network or in a subnetwork close to that in which the equipment 10 is located is subject to the agreement established between the internet service provider from which a user has subscribed to a service offer and an entity operating the authoritative servers 17 associated with the naming identifiers to be resolved.

[0123] Finally, in a step G8, the equipment 10 establishes a communication session with the server 15 whose IP address was included in the MSG message.

[0124] [Fig.5] represents a proxy server 11 capable of implementing the different embodiments of the method for processing a request for resolution of at least one naming identifier according to FIGS. 2 to 4.

[0125] A proxy server 11 may comprise at least one hardware processor 51, a storage unit 52, and at least one network interface 53 which are connected to each other through a bus 54. Of course, the constituent elements of the proxy server 11 may be connected by means of a connection other than a bus.

[0126] The processor 51 controls the operations of the proxy server 11. The storage unit 52 stores at least one program for implementing the method according to an embodiment to be executed by the processor 51, and various data, such as parameters used for calculations performed by the processor 51, intermediate data of calculations performed by the processor 51, etc. The processor 51 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 51 may be formed by dedicated hardware such as a processing circuit, or by a programmable processing unit such as a central processing unit (Central Processing Unit) which executes a program stored in a memory thereof.

[0127] The storage unit 52 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of the storage unit 52 include non-transitory computer-readable storage media such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.

[0128] At least one network interface 53 provides a connection between the proxy server 11, the resolvers 12-16, the equipment 10 and the authoritative server 17.

[0129] [Fig.6] represents an authoritative server 17 capable of implementing the different embodiments of the method for generating an authorization for execution, by a proxy server, of a function for resolving at least one naming identifier according to FIGS. 2 to 4.

[0130] An authoritative server 17 may comprise at least one hardware processor 61, a storage unit 62, and at least one network interface 63 which are connected to each other through a bus 64. Of course, the constituent elements of the server hosting resources 14 may be connected by means of a connection other than a bus.

[0131] The processor 61 controls the operations of the authoritative server 17. The storage unit 62 stores at least one program for implementing the method according to an embodiment to be executed by the processor 61, and various data, such as parameters used for calculations performed by the processor 61, intermediate data of calculations performed by the processor 61, etc. The processor 61 may be formed by any known and suitable hardware or software, or by a combination of hardware and software. For example, the processor 61 may be formed by hardware dedicated such as a processing circuit, or by a programmable processing unit such as a central processing unit (CPU) which executes a program stored in a memory thereof.

[0132] The storage unit 62 may be formed by any suitable means capable of storing the program(s) and data in a computer-readable manner. Examples of the storage unit 62 include non-transitory computer-readable storage media such as semiconductor memory devices, and magnetic, optical, or magneto-optical recording media loaded into a read-write unit.

[0133] At least one network interface 63 provides a connection between the authoritative server 17 and the proxy server 11.

Claims

Claims

1. Method for processing a request for resolution of at least one naming identifier sent by a device through a path established between said device and a proxy server, said method being implemented by said proxy server and comprising the following steps: - interception of said request comprising an identifier of at least one first entity implementing a function for resolving at least one naming identifier, called the default entity, to which said request was sent, - transmission of said request to at least one second entity implementing a function for resolving the at least one naming identifier, said second entity being selected as a function of at least one parameter relating to said device and / or at least one parameter relating to the at least one naming identifier to be resolved,- transmission to said equipment of an identifier of at least one server associated with the at least one naming identifier to be resolved transmitted by said second entity.,

2. Method for processing a request for resolution of at least one naming identifier according to claim 1 comprising, prior to the interception of said request, a step of receiving at least one message comprising said at least one parameter relating to said equipment and said at least one parameter relating to the naming identifier to be resolved, said message being sent by an authoritative server associated with the at least one naming identifier to be resolved.

3. Method for processing a request for resolution of at least one naming identifier according to claim 2 wherein said received message is further signed with a certificate from said authoritative server indicating ownership of the at least one naming identifier to be resolved.

4. Method for processing a request for resolution of at least one naming identifier according to any one of claims 1 to 3 wherein said at least one parameter relating to the at least one naming identifier to be resolved comprises at least one network address of a naming identifier resolver embedding said second entity and / or information for redirecting said request to destination of said naming identifier resolver.

5. Method for processing a request for resolution of at least one naming identifier according to claims 2 to 3 wherein, said second entity being embedded in said proxy server, said at least one parameter relating to the at least one naming identifier to be resolved comprises at least one authorization for execution by said proxy server of a function for resolution of at least one naming identifier.

6. Method for processing a request for resolution of at least one naming identifier according to claim 5 in which the execution authorization is a digital fingerprint of the at least one naming identifier associated with said proxy server signed by a cryptographic key associated with said authoritative server associated with said at least one naming identifier to be resolved.

7. Method for processing a request for resolution of at least one naming identifier according to any one of the preceding claims in which the at least one parameter relating to the equipment is a location parameter of the equipment.

8. Method for generating an authorization for execution, by a proxy server, of a function for resolving at least one naming identifier, said proxy server intercepting a request for resolving at least one naming identifier sent by a device through a path established between said device and a proxy server, said request comprising an identifier of at least one first entity implementing a function for resolving at least one naming identifier, called the default entity, to which it was sent, said method being implemented by an authoritative server associated with said naming identifier to be resolved and comprising the following steps: - determining a digital fingerprint of said at least one naming identifier to be resolved associated with an identifier of said proxy server, - transmitting, to the proxy server,of said execution authorization including said digital fingerprint.,

9. A method of generating an execution authorization according to claim 8 wherein said digital fingerprint is further signed by a cryptographic key associated with the authoritative server.

10. Proxy server capable of processing a request for resolution of at least at least one naming identifier issued by a device through a path established between said device and said proxy server, said proxy server comprising at least one processor configured to: - intercept said request comprising an identifier of at least one first entity implementing a function for resolving at least one naming identifier, called the default entity, to which it was issued, - transmit said request to at least one second entity implementing a function for resolving at least one naming identifier, said second entity being selected according to at least one parameter relating to said device and / or at least one parameter relating to the naming identifier to be resolved, - transmit to said device an identifier of at least one server associated with the naming identifier to be resolved transmitted by said second entity.

11. Authoritative server associated with at least one naming identifier, said server being capable of generating an authorization for execution, by a proxy server, of a function for resolving said at least one naming identifier, said proxy server intercepting a request for resolving at least one naming identifier sent by a device through a path established between said device and a proxy server, said request comprising an identifier of at least one first entity implementing a function for resolving at least one naming identifier, called the default entity, to which it was sent, said authoritative server comprising at least one processor configured to: - determine a digital fingerprint of said at least one naming identifier to be resolved associated with an identifier of said proxy server, - transmit, to the proxy server,said execution authorization including said digital fingerprint.,

12. A computer program product comprising program code instructions for implementing a method according to claims 1 to 7, when executed by a processor.

13. A computer program product comprising program code instructions for implementing a method according to claims 8 to 9, when executed by a processor.