DNS Control Device for Secure Parental Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current parental control methods, particularly DNS-based systems, are insecure and inflexible, allowing technically-aware users to circumvent controls and failing to differentiate between devices within a network, leading to scalability issues and increased costs.

Innovation Solution

A method and system that assign unique user device source identifiers to control devices within a network, enabling differential control policies for each device, allowing administrators to specify control levels based on domain names and content categories, and using these identifiers to manage DNS requests and responses, thereby enhancing security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNS-based parental control is implemented, then control over digital content access is improved, but users can circumvent controls by changing DNS server settings

Engineering Contradiction:
Improveparental control effectivenessVSAvoiduser ability to circumvent controls
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary control device positioned between the user device and the DNS server. This control device intercepts DNS requests, modifies them by inserting a source identifier, and forwards them to the DNS server. The intermediary nature of this device allows the system to maintain parental control effectiveness while preventing circumvention, as the source identifier embedded in DNS requests cannot be easily removed or altered by end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by pre-configuring control policies and embedding source identifiers in DNS requests before they reach the DNS server. The control device is pre-configured with device identifiers and control policies, allowing it to proactively mark DNS requests with appropriate source identifiers. This preliminary marking ensures that parental control measures are in place before any potential circumvention attempt can occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If DNS-based parental control is implemented, then control over digital content access is improved, but all devices in the network are controlled uniformly without differentiation

Engineering Contradiction:
Improveparental control effectivenessVSAvoiddevice-specific control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by assigning different source identifiers to different user devices and configuring device-specific control policies. Each user device receives a unique source identifier that is embedded in its DNS requests, allowing the DNS server to apply different control policies to different devices. This enables the system to treat each device individually rather than uniformly, providing flexibility for administrators to create customized control profiles for different devices and users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the network control by dividing it into device-specific control units. Each user device is assigned its own source identifier, effectively segmenting the control mechanism at the device level. This segmentation allows the DNS server to process and control DNS requests from different devices independently, enabling differentiated parental control policies for each device rather than applying a single uniform policy to the entire network.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If control policies are configured for each user device, then device-specific control is improved, but system complexity and cost increase

Engineering Contradiction:
Improvedevice-specific control capabilityVSAvoidcontrol system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a control device that can handle multiple functions within a single system. The control device simultaneously performs DNS request interception, source identifier insertion, policy evaluation, and request modification for all user devices. This multi-functional approach allows the system to provide device-specific control capabilities without requiring separate control mechanisms for each device, thereby reducing overall system complexity and cost while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10440057B2Methods, apparatus and systems for processing service requests
Publication Date: 2019.10.08 BRITISH TELECOM PLC
  • US10440057B2 patent drawing
  • US10440057B2 patent drawing
  • US10440057B2 patent drawing

AI summary

Methods, apparatus and systems for processing digital content service requests from user devices in a user network are disclosed. The method, performed by a control device, comprises receiving policy indications in respect of the user devices indicating desired control policies to be implemented in respect of the user devices, and associating user device source identifiers with the user devices indicating a network location to which responses should be directed, the user device source identifier associated with a particular user device depending on the policy indication for that user device. On receiving digital content service requests containing indications of domain names associated with content providers from which digital content is desired, the control device submits server location requests to a domain name system server comprising (i) the domain name from the digital content service request and (ii) the user device source identifier for the user device in question.