Traffic Detection Mechanism for Encrypted SNI via DNS Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches face challenges in differentiating and managing encrypted traffic, particularly with TLS 1.3 and QUIC-based applications, which hinders network operator's ability to provide effective traffic management, quality of service, and optimization due to encrypted Server Name Indications (SNI), especially when nodes reside in different networks.

Innovation Solution

A mechanism is introduced where network operators and content providers collaborate to deactivate SNI encryption through service-level agreements (SLAs), allowing network operators to pre-provision DNS servers and redirect traffic to use unencrypted SNI, enabling effective traffic classification and management even when DNS traffic is encrypted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SNI encryption is used to enhance security, then security is improved, but traffic differentiation capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic differentiation capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the SNI handling by introducing a dedicated DNS resolver that processes DNS queries separately from regular traffic. This resolver receives DNS requests, decrypts the encrypted SNI, and returns responses without encrypted SNI, allowing network operators to maintain security for most traffic while enabling traffic differentiation for specific applications through the segmented DNS resolution path.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a DNS resolver as an intermediary component between the encrypted traffic source and the network operator's traffic management system. This intermediary decrypts the encrypted SNI in DNS queries and returns unencrypted SNI in responses, serving as a mediator that enables traffic differentiation without compromising the security of the end-to-end encrypted communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted traffic is used to protect privacy, then privacy protection is improved, but network management capability deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoidnetwork management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments network management functionality by introducing a dedicated DNS resolver that handles encrypted DNS queries separately. This allows the network operator to maintain privacy protection for user traffic while regaining management capability through the segmented DNS resolution process, where the operator can identify and manage specific applications without decrypting the entire communication stream.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The DNS resolver acts as an intermediary that enables network management of encrypted traffic. By intercepting and processing DNS queries, the resolver provides the network operator with visibility into application-level traffic patterns while maintaining the encrypted nature of the actual data communication, thus preserving privacy protection while improving network management capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If unencrypted SNI is used to enable traffic classification, then traffic management capability is improved, but security deteriorates

Engineering Contradiction:
Improvetraffic management capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by providing different SNI encryption states to different network components based on their specific needs. The DNS resolver receives encrypted SNI for security, processes it locally, and returns unencrypted SNI only where needed for traffic classification by the network operator. This localized decryption at the DNS resolver level enables traffic management capability while maintaining security for the overall communication system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4214896B1Mechanism for traffic detection in case of encrypted traffic
Publication Date: 2025.01.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4214896B1 patent drawingFigure 1~2
  • EP4214896B1 patent drawingFigure 3
  • EP4214896B1 patent drawingFigure 4

AI summary

A first network node operating in a first communications network can receive a first message from a second network node operating in a second communications network. The first network node can further, responsive to receiving the first message, determine that the second network node is associated with a network operator that has a service-level agreement, SLA, with a content operator associated with the first network node. The first network node can further transmit a second message to the second network node, the second message including information based on the second node being associated with the network operator that has the SLA with the content operator. The information being associated with whether a subsequent message from a communication device associated with the second network node is to be transmitted to an origin server with an unencrypted server name indication, SNI.