CDN Domain Fronting Configuration for Censorship Evasion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Censors are blocking access to services that utilize content delivery networks (CDNs) for domain fronting, which hinders freedom of speech, expression, and association, and existing solutions are not effective in circumventing these restrictions.
Innovation Solution
A method that uses domain fronting and server-hopping techniques, where a client device connects to a CDN with a first domain name and an encrypted second domain name, and receives a configuration file listing multiple back-end servers, allowing it to randomly select a different server for each connection, thereby evading censors and maintaining access to services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If domain fronting is used to circumvent censorship, then access to blocked services is maintained, but censors block the CDN itself causing collateral damage to unblocked services
Solution Approach 1:
The system segments the service access by providing multiple independent backend servers (second servers) in the configuration file. Instead of relying on a single CDN endpoint, the client device is given a list of alternative servers it can connect to directly, dividing the access path into multiple independent routes that can be selected based on censorship conditions.
Solution Approach 2:
The CDN acts as an intermediary that enables domain fronting to hide the true endpoint, but the patent introduces a second intermediary layer: the configuration file containing multiple backend server addresses. This allows the client to bypass the CDN for actual service access while using the CDN only for initial configuration retrieval, thus eliminating collateral damage to other CDN-hosted services.
2Stability of the object's composition
If a single backend server is used for service access, then connection stability is maintained, but censors can easily block the service by targeting that single endpoint
Solution Approach 1:
The system dynamically adapts to censorship conditions by providing a list of multiple backend servers in the configuration file. The client device can select from these servers based on which ones are currently accessible, transforming the static single-server connection into a dynamic multi-server selection process that adapts to changing censorship conditions.
Solution Approach 2:
The patent changes the parameter of server selection from fixed (single backend server) to variable (multiple backend servers with selection capability). The configuration file contains a plurality of second servers, and the client can change which server it connects to based on accessibility, thus adapting to censorship without losing connection stability.
3Productivity
If configuration files are distributed through the same CDN used for domain fronting, then update efficiency is improved, but security risks increase due to potential interception
Solution Approach 1:
The system performs preliminary action by distributing the configuration file containing multiple backend server addresses through the CDN in a controlled manner. Once the client receives this configuration file, it has the necessary information to connect directly to backend servers without further CDN involvement, thus securing subsequent communications while maintaining efficient initial configuration distribution.
Data Source
AI summary
A solution for circumventing censorship is disclosed. A first device connects to a first server hosted in a content delivery network (CDN). The CDN routes the first device's connection request to the first server. The first server responds by providing the first device with a configuration file that contains a plurality of second servers for the first device to access. The first device disconnects from the first server and hops between one or more of the plurality of second servers contained in the configuration file. By distributing the configuration file from a first server hosted in a CDN, the first device obfuscates the true endpoint of the connection. Thus, the first device obtains the configuration file without drawing the ire of censors. By hopping from server-to-server, the first device stays one step ahead of censors. Accordingly, a multi-prong approach to staying a step ahead of eavesdroppers, sniffers, and censors is described.


