DNS-Based Policy Interception for Encrypted Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for enforcing policy-driven interception of encrypted network traffic in enterprises are cumbersome, requiring VPN clients on remote devices and are intrusive, and lack effective mechanisms to ensure compliance with policies, especially with the rise of opaque DNS services like DoH and DoT.

Innovation Solution

An enterprise traffic interception service (TIS) that combines a domain name service (DNS) and single sign-on (SSO) to selectively intercept TLS traffic using a DNS server, identity provider, and TLS inspecting proxy, allowing for policy-driven redirection of client devices to either direct or proxied access paths based on user identity and service policies, without the need for VPN clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN clients are installed on client devices to enforce policy-driven interception, then policy enforcement capability is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a DNS server as an intermediary component that enforces policy decisions without requiring VPN clients on client devices. The DNS server mediates between clients and services by resolving domain names to IP addresses, thereby controlling traffic paths indirectly through the DNS resolution process rather than through direct client-side VPN software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of VPN client installations with a DNS-based policy enforcement mechanism. Instead of using traditional VPN software that requires installation and configuration on each client device, the system uses DNS resolution to achieve the same policy enforcement goal, thereby simplifying deployment and operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If VPN clients are installed on client devices to enforce policy-driven interception, then policy enforcement capability is improved, but device complexity deteriorates

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The DNS server acts as an intermediary that centralizes policy enforcement logic, eliminating the need for complex VPN client software on each client device. The complexity is shifted from distributed client devices to a centralized DNS infrastructure, thereby reducing device complexity while maintaining policy enforcement capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent substitutes the complex mechanical system of VPN client installations with a simpler DNS-based approach. The DNS protocol, which is already widely deployed and understood, provides a straightforward mechanism for policy enforcement without introducing additional software complexity on client devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If all traffic is attracted to enterprise-controlled network for VPN enforcement, then policy coverage is improved, but adaptability deteriorates

Engineering Contradiction:
Improvepolicy coverageVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by applying different DNS resolution behaviors to different client-service pairs based on policy. Instead of forcing all traffic through a centralized VPN, the system locally controls DNS resolution for specific services, allowing direct access for some clients while routing others through inspection proxies, thereby achieving both coverage and adaptability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts traffic routing decisions based on real-time policy requirements. The DNS server can change resolution outcomes based on client identity, service type, and current policy settings, enabling flexible adaptation to different security and performance needs without requiring static VPN configurations.

Inventive Principle:
Principle #15Dynamics

4Ease of operation

If selective interception is implemented without VPN clients, then ease of operation is improved, but measurement precision of traffic compliance deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidcompliance verification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the DNS server receives policy information and returns appropriate IP addresses based on client identity and service requirements. This feedback loop enables the system to verify compliance by observing whether clients follow the DNS resolution instructions, providing a simple yet effective compliance verification method.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The DNS server serves as an intermediary that both directs traffic and can verify compliance. By controlling the DNS resolution process, the system can observe whether clients are accessing services through the intended paths and can provide feedback or corrective measures if policies are violated, thereby maintaining measurement precision without complex monitoring software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4289112B1Selective policy-driven interception of encrypted network traffic utilizing a domain name service and a single-sign on service
Publication Date: 2025.03.26 CISCO TECHNOLOGY INC
  • EP4289112B1 patent drawingFigure 1A
  • EP4289112B1 patent drawingFigure 1B
  • EP4289112B1 patent drawingFigure 2A

AI summary

Techniques for utilizing an enterprise traffic interception service (TIS) to enforce policies that mandate how clients access software as a service (SaaS) offered by service providers and selectively intercept enterprise network traffic utilizing a domain name service (DNS) and a single sign-on (SSO) service on a per-client per-service basis. The TIS may include a DNS server, an identity provider service, a TLS inspecting proxy, and/or a policy server. The DNS server may handle requests to resolve an address of a service, and identify a policy, stored in the policy server, to redirect the client based on the identity of the client and the service. The identity provider service may later query the policy server during client authorization for the service to verify that the client request is in line with the policy and allow or deny access to the service.