Content Filtering for Encrypted Domain Name Server Protocols

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content filtering methods in wireless communications networks are ineffective when data packet flows are encrypted, as they cannot detect and filter domain names encrypted using protocols like HTTPS, QUIC, or DNS over HTTPS, preventing network operators from implementing content filtering policies.

Innovation Solution

The solution involves a method where the policy control entity instructs the user equipment to add the domain name in un-encrypted form to data packets, allowing the user plane entity to extract and filter them based on content filtering policies, even when the domain name is encrypted, by using identifiers and potentially clearing the DNS cache to ensure accurate domain name detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain names are encrypted in data packet flows using protocols like HTTPS, QUIC, or DNS over HTTPS, then security and privacy are improved, but content filtering capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcontent filtering capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a policy control entity as an intermediary between the user equipment and the user plane entity. This intermediary receives policy information from a data repository and translates it into session policies that instruct the user plane entity on how to handle encrypted traffic. The policy control entity acts as a mediator that enables content filtering without requiring decryption of the actual data packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by establishing policy rules before encrypted data transmission occurs. The policy control entity receives content filtering policies from the data repository in advance and configures the user plane entity with these policies before the actual data packet flow begins. This allows the network to prepare filtering rules based on domain names or other identifiers without needing to decrypt traffic in real-time.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If content filtering is implemented on encrypted traffic, then parental control and authority compliance are improved, but network complexity increases

Engineering Contradiction:
Improvecontent filtering policy enforcementVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the content filtering functionality into distinct network entities: a data repository that stores policy information, a policy control entity that processes and translates policies, and a user plane entity that executes filtering actions. This segmentation allows each component to have a specialized function, reducing overall system complexity while enabling versatile content filtering capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The policy control entity serves as an intermediary that simplifies the complexity by handling the complex task of policy translation and interpretation. It receives high-level policy information from the data repository and converts it into specific session policies for the user plane entity, thereby shielding the rest of the network from the complexity of policy management while enabling adaptable content filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If DNS cache is cleared to ensure accurate domain name detection, then filtering accuracy is improved, but network performance deteriorates

Engineering Contradiction:
Improvefiltering accuracyVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

Instead of clearing the entire DNS cache for all users at all times (which would significantly impact performance), the system applies partial action by only clearing DNS cache for specific user equipment or specific domain names when required by content filtering policies. The policy control entity can selectively trigger DNS cache clearing based on the filtering requirements, thereby maintaining accuracy where needed while minimizing the performance impact on the overall network.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240015512A1Content Filtering Support for Protocols with Encrypted Domain Name Server
Publication Date: 2024.01.11 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240015512A1 patent drawing
  • US20240015512A1 patent drawing
  • US20240015512A1 patent drawing

AI summary

The invention relates to various methods, entities, systems and computer programs for allowing a wireless communications network to implement content filtering even when a protocol used for packet data flow through the wireless communications network requires encryption of a domain name. One method relates in particular to a method for operating a policy control entity (240) in a wireless communications network (200), in which a data packet flow is provided for exchanging data packets between a user equipment (100) and a content provider (400), the data packet flow encrypting a domain name of the content provider (400). The method comprises a step of receiving (S6, S31) a user policy profile from a data repository (250), the user policy profile comprising a content filtering policy for filtering the data packets. The method further comprises a step of transmitting (S8, S32), to a session control entity (220) of the wireless communications network (200), a session policy based on the user policy profile, the session policy instructing a user plane entity (230) of the wireless communications network (200) to filter the data packets, and a step of transmitting (S12, S33), to an access management entity (210) of the wireless communications network (200), a user policy based on the user policy profile, the user policy instructing the user equipment (100) to add the domain name in un-encrypted form to the data packets