Encrypted DNS Filtering for Headless Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional DNS systems face challenges in managing domain name resolution, particularly when end-devices use encrypted communication protocols, leading to ineffective filtering and poor user experience for headless devices that cannot fallback to unencrypted protocols, resulting in blocked access to desired websites.
Innovation Solution
A network device identifies headless devices and allows them to access domain name resolution services using encrypted protocols by determining device attributes and DNS preferences, permitting access after a predefined time if they fail to switch to unencrypted protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the DNS resolver blocks DNS requests using encrypted communication protocols to enable filtering, then DNS filtering effectiveness is improved, but headless devices that cannot fallback to unencrypted protocols are unable to access desired websites
Solution Approach 1:
The patent segments the DNS request handling process into two distinct paths: one for encrypted protocols and one for unencrypted protocols. The system identifies headless devices and routes their requests through the unencrypted path while maintaining encrypted protocol support for other devices, thereby resolving the contradiction between filtering effectiveness and device compatibility
Solution Approach 2:
The patent dynamically adjusts the protocol handling strategy based on device characteristics. The DNS resolver detects whether a device is headless and adaptively switches between blocking encrypted requests and allowing them, ensuring both filtering effectiveness for regular devices and compatibility for headless devices
2Adaptability or versatility
If the DNS resolver inspects encrypted communication protocols to allow DNS requests, then user access capability is improved, but root certificate management on all end-devices becomes cumbersome
Solution Approach 1:
The patent extracts the encrypted protocol inspection capability from individual end-devices and centralizes it in the DNS resolver. This eliminates the need for root certificate installation and management on each device, while still enabling the resolver to inspect and handle encrypted DNS requests appropriately
Solution Approach 2:
The DNS resolver acts as an intermediary that handles encrypted protocol inspection centrally. Instead of requiring each end-device to have inspection capabilities, the resolver mediates all DNS requests and applies filtering logic, simplifying the overall system architecture
3Reliability
If the DNS resolver inspects encrypted communication protocols at the DNS resolver, then encrypted DNS request handling is improved, but user traffic speed is slowed down
Solution Approach 1:
The patent applies partial inspection action by identifying headless devices and exempting them from encrypted protocol inspection. Only non-headless devices undergo the full inspection process, reducing the overall inspection burden and improving traffic speed while maintaining reliable encrypted protocol handling where needed
Data Source
AI summary
A method, device, and system for managing Domain Name System (DNS) filtering is disclosed. The method may include blocking an end-device from accessing a domain for a predefined time duration using an encrypted communication protocol to access a domain name resolution service. The method may further include determining failure of the end-device to switch to an unencrypted communication protocol to access the domain name resolution service, after expiry of the predefined time duration. The method may include identifying the end-device as a headless device; and permitting the end-device to access the domain name resolution service using the encrypted communication protocol.


