CPE Encrypted DNS Caching via TLS Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Encrypted DNS poses challenges in satellite systems by degrading user quality of experience (QoE) and inefficient use of satellite resources, as it prevents DNS caching and security measures like filtering and content blocking, due to the inability to identify encrypted DNS information.

Innovation Solution

Implementing a customer premise equipment (CPE) terminal with a processor that receives a CA-signed TLS certificate from a certificate server, allowing for encrypted DNS services and secure web services using private IP addresses, enabling local DNS caching and secure value-added services without modifying off-the-shelf browsers or applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted DNS is used, then security and privacy are improved, but DNS caching becomes impossible and user quality of experience degrades

Engineering Contradiction:
Improvesecurity and privacyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the DNS resolution process into two parts: encrypted transmission of DNS queries and responses over the satellite link, and local caching of DNS records at the CPE. This allows the security benefits of encryption to be maintained while restoring caching capability by separating the encryption function from the caching function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CPE acts as an intermediary between the client device and the encrypted DNS service. It receives encrypted DNS queries, decrypts them locally, performs DNS resolution, caches the results, and then forwards encrypted responses to clients. This intermediary role enables both encryption and caching to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted DNS is used, then privacy is improved, but satellite radio resources are used inefficiently

Engineering Contradiction:
ImproveprivacyVSAvoidsatellite radio resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by preloading and caching DNS records at the CPE before they are needed. When DNS queries arrive at the CPE, cached records can be served locally without transmitting over the satellite link, thus saving valuable radio resources while maintaining privacy through encrypted DNS transmission.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encrypted DNS is used, then security is improved, but security measures like filtering and content blocking can no longer function

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity measures functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing different security measures at different locations in the network. At the CPE level, encrypted DNS provides privacy protection. At the gateway level, unencrypted DNS queries can still be filtered and monitored for security policies. This layered approach maintains both encryption benefits and security measure functionality.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11843635B2Provisioning encrypted domain name service and secure value-added service with certificates at a customer premise equipment in a broadband satellite system
Publication Date: 2023.12.12 HUGHES NETWORK SYST
  • US11843635B2 patent drawing
  • US11843635B2 patent drawing
  • US11843635B2 patent drawing

AI summary

A satellite communication system which supports encrypted DNS at the customer premise equipment terminal to provide the benefits of local DNS caching. Some implementations use Certificate Authority (CA)-signed Transport Layer Security (TLS) certificates. Implementations may provide encrypted DNS service at the CPE, where the system installs CA-signed TLS certificate at the customer premise equipment (CPE) terminal. The same certificate can be used at multiple terminals using a wild-card certificate distributed by the satellite to provide value added services at a CPE as secure web services to off-the-shelf web clients and applications.