DNS-Based Policy Interception for Encrypted Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for enforcing policy-driven interception of encrypted network traffic in enterprises are cumbersome, requiring VPN clients on remote devices and are intrusive, and lack effective mechanisms to ensure compliance with policies, especially with the rise of opaque DNS services like DoH and DoT.
Innovation Solution
An enterprise traffic interception service (TIS) that combines a domain name service (DNS) and single sign-on (SSO) to selectively intercept TLS traffic using a DNS server, identity provider, and TLS inspecting proxy, allowing for policy-driven redirection of client devices to either direct or proxied access paths based on user identity and service policies, without the need for VPN clients.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN clients are installed on client devices to enforce policy-driven interception, then policy enforcement capability is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent introduces a DNS server as an intermediary component that enforces policy decisions without requiring VPN clients on client devices. The DNS server mediates between clients and services by resolving domain names to IP addresses, thereby controlling traffic paths indirectly through the DNS resolution process rather than through direct client-side VPN software.
Solution Approach 2:
The patent replaces the mechanical system of VPN client installations with a DNS-based policy enforcement mechanism. Instead of using traditional VPN software that requires installation and configuration on each client device, the system uses DNS resolution to achieve the same policy enforcement goal, thereby simplifying deployment and operation.
2Reliability
If VPN clients are installed on client devices to enforce policy-driven interception, then policy enforcement capability is improved, but device complexity deteriorates
Solution Approach 1:
The DNS server acts as an intermediary that centralizes policy enforcement logic, eliminating the need for complex VPN client software on each client device. The complexity is shifted from distributed client devices to a centralized DNS infrastructure, thereby reducing device complexity while maintaining policy enforcement capability.
Solution Approach 2:
The patent substitutes the complex mechanical system of VPN client installations with a simpler DNS-based approach. The DNS protocol, which is already widely deployed and understood, provides a straightforward mechanism for policy enforcement without introducing additional software complexity on client devices.
3Reliability
If all traffic is attracted to enterprise-controlled network for VPN enforcement, then policy coverage is improved, but adaptability deteriorates
Solution Approach 1:
The patent implements local quality by applying different DNS resolution behaviors to different client-service pairs based on policy. Instead of forcing all traffic through a centralized VPN, the system locally controls DNS resolution for specific services, allowing direct access for some clients while routing others through inspection proxies, thereby achieving both coverage and adaptability.
Solution Approach 2:
The system dynamically adjusts traffic routing decisions based on real-time policy requirements. The DNS server can change resolution outcomes based on client identity, service type, and current policy settings, enabling flexible adaptation to different security and performance needs without requiring static VPN configurations.
4Ease of operation
If selective interception is implemented without VPN clients, then ease of operation is improved, but measurement precision of traffic compliance deteriorates
Solution Approach 1:
The patent implements feedback mechanisms where the DNS server receives policy information and returns appropriate IP addresses based on client identity and service requirements. This feedback loop enables the system to verify compliance by observing whether clients follow the DNS resolution instructions, providing a simple yet effective compliance verification method.
Solution Approach 2:
The DNS server serves as an intermediary that both directs traffic and can verify compliance. By controlling the DNS resolution process, the system can observe whether clients are accessing services through the intended paths and can provide feedback or corrective measures if policies are violated, thereby maintaining measurement precision without complex monitoring software.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
Techniques for utilizing an enterprise traffic interception service (TIS) to enforce policies that mandate how clients access software as a service (SaaS) offered by service providers and selectively intercept enterprise network traffic utilizing a domain name service (DNS) and a single sign-on (SSO) service on a per-client per-service basis. The TIS may include a DNS server, an identity provider service, a TLS inspecting proxy, and/or a policy server. The DNS server may handle requests to resolve an address of a service, and identify a policy, stored in the policy server, to redirect the client based on the identity of the client and the service. The identity provider service may later query the policy server during client authorization for the service to verify that the client request is in line with the policy and allow or deny access to the service.