Encrypted Domain Identifier Reuse for Low-Latency Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protocols like encrypted DNS and eSNI suffer from significant computational overhead and latency due to independent operations and public key exchanges, exposing user devices to data leaks and degrading user experience.
Innovation Solution
Implementing a modified version of identifiers, such as hashed FQDNs, shared across encrypted DNS and eSNI processes, to reduce the need for public key exchanges and optimize communication latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted DNS and eSNI protocols are implemented independently with public key exchanges, then network security is improved, but computational overhead and communication latency increase significantly
Solution Approach 1:
The patent combines encrypted DNS and eSNI protocols into a unified authentication mechanism where a single cryptographic authentication establishes both DNS resolution and TLS connection. This merging eliminates the need for separate public key exchanges in each protocol, reducing computational overhead and communication latency while maintaining security.
Solution Approach 2:
The authentication mechanism serves multiple functions simultaneously: it provides DNS response authentication, enables secure TLS connection establishment, and prevents spoofing attacks. By making the authentication system universal across multiple protocol layers, the patent eliminates redundant security operations and reduces overall latency.
2Reliability
If encrypted DNS and eSNI protocols perform independent public key exchanges, then data leak prevention is improved, but device power consumption increases
Solution Approach 1:
The patent merges the cryptographic operations of encrypted DNS and eSNI into a single authentication process. By combining these operations, the device performs fewer cryptographic computations, reducing power consumption while maintaining the same level of data leak prevention through unified authentication.
Solution Approach 2:
The authentication mechanism is designed to serve multiple security functions simultaneously, including data leak prevention, spoofing protection, and secure connection establishment. This multi-functionality reduces the need for separate cryptographic operations, thereby lowering device power consumption.
3Speed
If traditional DNS resolution is used without modification, then communication speed is maintained, but domain identifier exposure to nefarious actors increases
Solution Approach 1:
The patent extracts the domain identifier from the DNS query and response messages, replacing it with a authenticated reference that does not expose the actual domain name to potential eavesdroppers. This extraction maintains communication speed while protecting domain identifier exposure through cryptographic authentication.
Solution Approach 2:
The patent introduces an authenticated reference as an intermediary between the DNS resolution process and the domain identifier. This intermediary mechanism allows fast DNS resolution while preventing direct exposure of domain names to nefarious actors through encrypted and authenticated communication channels.
Data Source
AI summary
An identifier, for example, an identifier of a domain and/or a host of the domain (e.g., a fully qualified domain name (FQDN), etc.), such as a service management device (e.g., a server, a web server, a computing device, a web host device, a webpage, etc.), may be modified (e.g., hashed, encrypted, etc.) by a network device (e.g., a server, a domain name system (DNS) server, a DNS over hypertext transfer protocol secure (HTTPS) server/gateway (DoH server), DNS over Transport Layer Security (TLS) server/gateway (DoT server), a network management device, a computing device, etc.), sent to a user device (e.g., a client device, a smart device, a mobile device, a content output device, a computing device, a web browser, a search engine, etc.), and reused by the user device to request a service (e.g., a web service, a webpage, a file, content, a content item, etc.).


