CDN Domain Fronting Configuration for Censorship Evasion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Censors are blocking access to services hosted on content delivery networks (CDNs), which hinders freedom of speech, expression, and association, and existing domain fronting techniques are being curtailed by CDNs under pressure from autocratic governments.

Innovation Solution

A method that utilizes domain fronting and server-hopping techniques, where a client device connects to a CDN with a first domain name and an encrypted second domain name, and receives a configuration file listing multiple secondary servers to hop between for subsequent connections, ensuring continued access to services while evading censors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain fronting is used to circumvent censorship, then access to blocked services is maintained, but CDNs are pressured to curtail domain fronting leading to blocked access

Engineering Contradiction:
Improveaccess to servicesVSAvoidcensorship blocking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically updates configuration files containing multiple endpoint domains and IP addresses, allowing client devices to switch between different servers. This dynamic adaptation enables continuous access to services even when certain endpoints are blocked by censors, as the configuration can be updated to provide alternative access paths.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes network parameters by providing configuration files that contain multiple different endpoints (domains and IP addresses) for the same service. Client devices use these alternative parameters to connect to services when primary endpoints are blocked, effectively bypassing censorship through parameter substitution.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If configuration files are distributed to client devices, then security updates and patches can be delivered efficiently, but the distribution process itself may be blocked by censors

Engineering Contradiction:
Improvedistribution efficiencyVSAvoidcensorship blocking
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The configuration distribution system is segmented into multiple components: configuration files containing endpoint information, authentication mechanisms, and update protocols. This segmentation allows different parts of the system to be distributed through different channels, maintaining productivity even when certain distribution paths are blocked.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses configuration files as intermediaries to deliver security updates and endpoint information to client devices. These configuration files can be distributed through multiple channels including CDN integration, allowing efficient update delivery while bypassing censorship blocks on direct communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple secondary servers are provided in configuration files for server-hopping, then access availability is improved, but the complexity of managing multiple endpoints increases

Engineering Contradiction:
Improveaccess availabilityVSAvoidendpoint management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Client devices automatically manage multiple endpoints by reading configuration files and selecting appropriate servers without user intervention. The system self-services by handling endpoint selection, connection management, and failover automatically, reducing the perceived complexity for users while maintaining high availability through multiple servers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10992741B2System and method for providing a configuration file to client devices
Publication Date: 2021.04.27 WICKR INC
  • US10992741B2 patent drawing
  • US10992741B2 patent drawing
  • US10992741B2 patent drawing

AI summary

A solution for circumventing censorship is disclosed. A first device connects to a first server hosted in a content delivery network (CDN). The CDN routes the first device's connection request to the first server. The first server responds by providing the first device with a configuration file that contains a plurality of secondary servers for the first device to access. Accordingly, the first device disconnects from the first server and hops between one or more of the plurality of secondary servers contained in the configuration file. By distributing the configuration file from a first server hosted in a CDN, the first device is able to obfuscate the true endpoint of the connection. Thus, the first device is able to obtain the configuration file without drawing the ire of censors. By hopping from server-to-server, the first device is able to stay one-step ahead of censors. Accordingly, the present disclosure describes a multi-prong approach to staying a step ahead of eavesdroppers, sniffers, and censors.