Domain Name Resolution Proxy Server for Bandwidth Security Trade-off

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for a user's terminal to access sites outside a private network while maintaining security and bandwidth efficiency are inadequate, as they either consume excessive bandwidth or compromise security by losing control over data flows.

Innovation Solution

A domain name resolution proxy server processes requests from a terminal via a communication tunnel, determining user authorization and filtering access to ensure security while allowing direct access to external sites, thereby maintaining control over data flows and optimizing bandwidth usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal transmits all data streams via the secure communication tunnel with the private network, then security control and firewall filtering are maintained, but bandwidth consumption increases and user experience degrades

Engineering Contradiction:
Improvesecurity controlVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments data streams into two categories: those requiring security filtering (sent through the tunnel) and those that can be sent directly (local breakout). The proxy server identifies and separates traffic types, allowing secure streams to use the tunnel while non-sensitive streams use direct paths, thus resolving the bandwidth-security contradiction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy server acts as an intermediary between the terminal and external entities. It receives requests through the secure tunnel, determines whether local breakout is appropriate, and manages the separation of traffic paths. This intermediary enables intelligent routing decisions that balance security requirements with bandwidth efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the terminal sends data streams directly to external entities without using the communication tunnel, then user experience improves with faster access, but security control and visibility over data flows are lost

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The proxy server performs preliminary actions by receiving and processing requests through the secure tunnel before allowing direct access. It authenticates users, determines authorization levels, and makes pre-decisions about which traffic can use local breakout. This preliminary security check through the tunnel ensures control is maintained while enabling fast direct access for approved traffic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the proxy server continuously monitors traffic patterns and user behavior. Based on this feedback, it dynamically adjusts which streams use the tunnel versus local breakout, maintaining security control while optimizing access speed. The proxy server learns from observed traffic to make intelligent routing decisions.

Inventive Principle:
Principle #23Feedback

3Reliability

If a firewall filters all data streams through the private network, then security is guaranteed, but the path becomes longer and bandwidth is consumed

Engineering Contradiction:
Improvesecurity guaranteeVSAvoiddata flow path length
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The patent applies local quality by providing different security processing to different data streams based on their specific characteristics. Instead of uniformly routing all traffic through the tunnel, the proxy server analyzes each stream's security requirements and applies appropriate handling - some streams get full tunnel routing with firewall filtering, while others receive direct local breakout access, optimizing path length for each case.

Inventive Principle:
Principle #3Local quality

4Reliability

If the proxy server processes all requests through the tunnel, then centralized security control is maintained, but bandwidth is consumed and user experience degrades

Engineering Contradiction:
Improvecentralized security controlVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The proxy server segments request processing into two paths: requests requiring centralized security review are processed through the tunnel, while requests deemed safe for local breakout are handled directly. This segmentation maintains centralized control for necessary cases while eliminating unnecessary tunnel traffic, resolving the contradiction between security control and bandwidth consumption.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3503508B1Method for processing requests and proxy server
Publication Date: 2022.01.26 ORANGE SA
  • EP3503508B1 patent drawingFigure 1
  • EP3503508B1 patent drawingFigure 2~3

AI summary

The invention relates to a method for processing requests, implemented by a domain name resolution proxy server of a first communication network accessible by a user's terminal via a communication tunnel established on a second communication network, this processing method comprising, upon receipt (E10) of a domain name resolution request from the terminal issued via the communication tunnel: - a step of obtaining (E20) a user identifier from at least one piece of information contained in a field of the request; - a step of determining (E30), using said user identifier, whether or not this user is authorized to access said domain name; - if the user is authorized to access the domain name, a step of sending (E60) to the terminal via the communication tunnel an IP address corresponding to the domain name accessible by the terminal via said second communication network;- otherwise, a rejection step (E40) of the terminal request.;