Content Filtering for Encrypted Domain Name Server Protocols
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current content filtering methods in wireless communications networks are ineffective when data packet flows are encrypted, as they cannot detect and filter domain names encrypted using protocols like HTTPS, QUIC, or DNS over HTTPS, preventing network operators from implementing content filtering policies.
Innovation Solution
The solution involves a method where the policy control entity instructs the user equipment to add the domain name in un-encrypted form to data packets, allowing the user plane entity to extract and filter them based on content filtering policies, even when the domain name is encrypted, by using identifiers and potentially clearing the DNS cache to ensure accurate domain name detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If domain names are encrypted in data packet flows using protocols like HTTPS, QUIC, or DNS over HTTPS, then security and privacy are improved, but content filtering capability deteriorates
Solution Approach 1:
The patent introduces a policy control entity as an intermediary between the user equipment and the user plane entity. This intermediary receives policy information from a data repository and translates it into session policies that instruct the user plane entity on how to handle encrypted traffic. The policy control entity acts as a mediator that enables content filtering without requiring decryption of the actual data packets.
Solution Approach 2:
The system performs preliminary actions by establishing policy rules before encrypted data transmission occurs. The policy control entity receives content filtering policies from the data repository in advance and configures the user plane entity with these policies before the actual data packet flow begins. This allows the network to prepare filtering rules based on domain names or other identifiers without needing to decrypt traffic in real-time.
2Adaptability or versatility
If content filtering is implemented on encrypted traffic, then parental control and authority compliance are improved, but network complexity increases
Solution Approach 1:
The patent segments the content filtering functionality into distinct network entities: a data repository that stores policy information, a policy control entity that processes and translates policies, and a user plane entity that executes filtering actions. This segmentation allows each component to have a specialized function, reducing overall system complexity while enabling versatile content filtering capabilities.
Solution Approach 2:
The policy control entity serves as an intermediary that simplifies the complexity by handling the complex task of policy translation and interpretation. It receives high-level policy information from the data repository and converts it into specific session policies for the user plane entity, thereby shielding the rest of the network from the complexity of policy management while enabling adaptable content filtering.
3Measurement precision
If DNS cache is cleared to ensure accurate domain name detection, then filtering accuracy is improved, but network performance deteriorates
Solution Approach 1:
Instead of clearing the entire DNS cache for all users at all times (which would significantly impact performance), the system applies partial action by only clearing DNS cache for specific user equipment or specific domain names when required by content filtering policies. The policy control entity can selectively trigger DNS cache clearing based on the filtering requirements, thereby maintaining accuracy where needed while minimizing the performance impact on the overall network.
Data Source
AI summary
The invention relates to various methods, entities, systems and computer programs for allowing a wireless communications network to implement content filtering even when a protocol used for packet data flow through the wireless communications network requires encryption of a domain name. One method relates in particular to a method for operating a policy control entity (240) in a wireless communications network (200), in which a data packet flow is provided for exchanging data packets between a user equipment (100) and a content provider (400), the data packet flow encrypting a domain name of the content provider (400). The method comprises a step of receiving (S6, S31) a user policy profile from a data repository (250), the user policy profile comprising a content filtering policy for filtering the data packets. The method further comprises a step of transmitting (S8, S32), to a session control entity (220) of the wireless communications network (200), a session policy based on the user policy profile, the session policy instructing a user plane entity (230) of the wireless communications network (200) to filter the data packets, and a step of transmitting (S12, S33), to an access management entity (210) of the wireless communications network (200), a user policy based on the user policy profile, the user policy instructing the user equipment (100) to add the domain name in un-encrypted form to the data packets


