CPE Encrypted DNS Caching via TLS Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Encrypted DNS poses challenges in satellite systems by degrading user quality of experience (QoE) and inefficient use of satellite resources, as it prevents DNS caching and security measures like filtering and content blocking, due to the inability to identify encrypted DNS information.
Innovation Solution
Implementing a customer premise equipment (CPE) terminal with a processor that receives a CA-signed TLS certificate from a certificate server, allowing for encrypted DNS services and secure web services using private IP addresses, enabling local DNS caching and secure value-added services without modifying off-the-shelf browsers or applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted DNS is used, then security and privacy are improved, but DNS caching becomes impossible and user quality of experience degrades
Solution Approach 1:
The patent segments the DNS resolution process into two parts: encrypted transmission of DNS queries and responses over the satellite link, and local caching of DNS records at the CPE. This allows the security benefits of encryption to be maintained while restoring caching capability by separating the encryption function from the caching function.
Solution Approach 2:
The CPE acts as an intermediary between the client device and the encrypted DNS service. It receives encrypted DNS queries, decrypts them locally, performs DNS resolution, caches the results, and then forwards encrypted responses to clients. This intermediary role enables both encryption and caching to coexist.
2Reliability
If encrypted DNS is used, then privacy is improved, but satellite radio resources are used inefficiently
Solution Approach 1:
The patent implements preliminary action by preloading and caching DNS records at the CPE before they are needed. When DNS queries arrive at the CPE, cached records can be served locally without transmitting over the satellite link, thus saving valuable radio resources while maintaining privacy through encrypted DNS transmission.
3Reliability
If encrypted DNS is used, then security is improved, but security measures like filtering and content blocking can no longer function
Solution Approach 1:
The patent applies local quality by implementing different security measures at different locations in the network. At the CPE level, encrypted DNS provides privacy protection. At the gateway level, unencrypted DNS queries can still be filtered and monitored for security policies. This layered approach maintains both encryption benefits and security measure functionality.
Data Source
AI summary
A satellite communication system which supports encrypted DNS at the customer premise equipment terminal to provide the benefits of local DNS caching. Some implementations use Certificate Authority (CA)-signed Transport Layer Security (TLS) certificates. Implementations may provide encrypted DNS service at the CPE, where the system installs CA-signed TLS certificate at the customer premise equipment (CPE) terminal. The same certificate can be used at multiple terminals using a wild-card certificate distributed by the satellite to provide value added services at a CPE as secure web services to off-the-shelf web clients and applications.


