Traffic Detection Mechanism for Encrypted SNI via DNS Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing approaches face challenges in differentiating and managing encrypted traffic, particularly with TLS 1.3 and QUIC-based applications, which hinders network operator's ability to provide effective traffic management, quality of service, and optimization due to encrypted Server Name Indications (SNI), especially when nodes reside in different networks.
Innovation Solution
A mechanism is introduced where network operators and content providers collaborate to deactivate SNI encryption through service-level agreements (SLAs), allowing network operators to pre-provision DNS servers and redirect traffic to use unencrypted SNI, enabling effective traffic classification and management even when DNS traffic is encrypted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SNI encryption is used to enhance security, then security is improved, but traffic differentiation capability deteriorates
Solution Approach 1:
The patent segments the SNI handling by introducing a dedicated DNS resolver that processes DNS queries separately from regular traffic. This resolver receives DNS requests, decrypts the encrypted SNI, and returns responses without encrypted SNI, allowing network operators to maintain security for most traffic while enabling traffic differentiation for specific applications through the segmented DNS resolution path.
Solution Approach 2:
The patent introduces a DNS resolver as an intermediary component between the encrypted traffic source and the network operator's traffic management system. This intermediary decrypts the encrypted SNI in DNS queries and returns unencrypted SNI in responses, serving as a mediator that enables traffic differentiation without compromising the security of the end-to-end encrypted communication.
2Reliability
If encrypted traffic is used to protect privacy, then privacy protection is improved, but network management capability deteriorates
Solution Approach 1:
The patent segments network management functionality by introducing a dedicated DNS resolver that handles encrypted DNS queries separately. This allows the network operator to maintain privacy protection for user traffic while regaining management capability through the segmented DNS resolution process, where the operator can identify and manage specific applications without decrypting the entire communication stream.
Solution Approach 2:
The DNS resolver acts as an intermediary that enables network management of encrypted traffic. By intercepting and processing DNS queries, the resolver provides the network operator with visibility into application-level traffic patterns while maintaining the encrypted nature of the actual data communication, thus preserving privacy protection while improving network management capability.
3Ease of operation
If unencrypted SNI is used to enable traffic classification, then traffic management capability is improved, but security deteriorates
Solution Approach 1:
The patent applies local quality by providing different SNI encryption states to different network components based on their specific needs. The DNS resolver receives encrypted SNI for security, processes it locally, and returns unencrypted SNI only where needed for traffic classification by the network operator. This localized decryption at the DNS resolver level enables traffic management capability while maintaining security for the overall communication system.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A first network node operating in a first communications network can receive a first message from a second network node operating in a second communications network. The first network node can further, responsive to receiving the first message, determine that the second network node is associated with a network operator that has a service-level agreement, SLA, with a content operator associated with the first network node. The first network node can further transmit a second message to the second network node, the second message including information based on the second node being associated with the network operator that has the SLA with the content operator. The information being associated with whether a subsequent message from a communication device associated with the second network node is to be transmitted to an origin server with an unencrypted server name indication, SNI.