CDN Domain Fronting Configuration for Censorship Evasion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Censors are blocking access to services that utilize content delivery networks (CDNs) for domain fronting, which hinders freedom of speech, expression, and association, and existing solutions are not effective in circumventing these restrictions.

Innovation Solution

A method that uses domain fronting and server-hopping techniques, where a client device connects to a CDN with a first domain name and an encrypted second domain name, and receives a configuration file listing multiple back-end servers, allowing it to randomly select a different server for each connection, thereby evading censors and maintaining access to services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain fronting is used to circumvent censorship, then access to blocked services is maintained, but censors block the CDN itself causing collateral damage to unblocked services

Engineering Contradiction:
Improveaccess to blocked servicesVSAvoidcollateral blocking of unblocked services
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the service access by providing multiple independent backend servers (second servers) in the configuration file. Instead of relying on a single CDN endpoint, the client device is given a list of alternative servers it can connect to directly, dividing the access path into multiple independent routes that can be selected based on censorship conditions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CDN acts as an intermediary that enables domain fronting to hide the true endpoint, but the patent introduces a second intermediary layer: the configuration file containing multiple backend server addresses. This allows the client to bypass the CDN for actual service access while using the CDN only for initial configuration retrieval, thus eliminating collateral damage to other CDN-hosted services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If a single backend server is used for service access, then connection stability is maintained, but censors can easily block the service by targeting that single endpoint

Engineering Contradiction:
Improveconnection stabilityVSAvoidresistance to censorship
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to censorship conditions by providing a list of multiple backend servers in the configuration file. The client device can select from these servers based on which ones are currently accessible, transforming the static single-server connection into a dynamic multi-server selection process that adapts to changing censorship conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of server selection from fixed (single backend server) to variable (multiple backend servers with selection capability). The configuration file contains a plurality of second servers, and the client can change which server it connects to based on accessibility, thus adapting to censorship without losing connection stability.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If configuration files are distributed through the same CDN used for domain fronting, then update efficiency is improved, but security risks increase due to potential interception

Engineering Contradiction:
Improveconfiguration update efficiencyVSAvoidsecurity of configuration distribution
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary action by distributing the configuration file containing multiple backend server addresses through the CDN in a controlled manner. Once the client receives this configuration file, it has the necessary information to connect directly to backend servers without further CDN involvement, thus securing subsequent communications while maintaining efficient initial configuration distribution.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11425122B2System and method for providing a configuration file to client devices
Publication Date: 2022.08.23 WICKR INC
  • US11425122B2 patent drawing
  • US11425122B2 patent drawing
  • US11425122B2 patent drawing

AI summary

A solution for circumventing censorship is disclosed. A first device connects to a first server hosted in a content delivery network (CDN). The CDN routes the first device's connection request to the first server. The first server responds by providing the first device with a configuration file that contains a plurality of second servers for the first device to access. The first device disconnects from the first server and hops between one or more of the plurality of second servers contained in the configuration file. By distributing the configuration file from a first server hosted in a CDN, the first device obfuscates the true endpoint of the connection. Thus, the first device obtains the configuration file without drawing the ire of censors. By hopping from server-to-server, the first device stays one step ahead of censors. Accordingly, a multi-prong approach to staying a step ahead of eavesdroppers, sniffers, and censors is described.