Modified Domain Identifiers for Low-Latency Secure Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protocols like encrypted DNS and eSNI suffer from significant computational overhead and latency due to independent operations and separate cryptographic identity exchanges, making them vulnerable to interception and degrading user experience.
Innovation Solution
Implementing a modified version of identifiers, such as hashed FQDNs, shared across both encrypted DNS and eSNI processes, reduces the need for public key exchanges and cryptographic hashing, allowing these protocols to operate collectively and efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted DNS and eSNI protocols operate independently with separate cryptographic identity exchanges, then network security is maintained, but computational overhead and latency increase significantly
Solution Approach 1:
The patent combines encrypted DNS and eSNI protocols into a unified cryptographic identity exchange process. The DNS resolver and SSL/TLS server perform a single joint key exchange that establishes both DNS encryption and TLS encryption simultaneously, eliminating redundant cryptographic operations and reducing computational overhead while maintaining security.
Solution Approach 2:
The patent creates a universal cryptographic mechanism that serves multiple functions: the same key exchange process simultaneously enables encrypted DNS resolution and encrypted TLS communication. This multi-functional approach allows a single cryptographic operation to fulfill both security requirements, reducing overall computational burden and latency.
2Reliability
If multiple independent cryptographic identity exchanges are performed, then security against interception is maintained, but user experience degrades due to increased latency
Solution Approach 1:
The patent merges the DNS encryption establishment and TLS encryption establishment into a single synchronized process. The DNS resolver and SSL/TLS server complete both cryptographic handshakes simultaneously through one unified key exchange, halving the number of separate security negotiations and significantly reducing the time users wait for secure connections.
3Adaptability or versatility
If separate cryptographic operations are used for DNS and TLS, then protocol independence is maintained, but computational efficiency decreases
Solution Approach 1:
The patent implements a universal cryptographic framework where a single key exchange mechanism serves both DNS encryption and TLS encryption purposes. This multi-functional design maintains the logical independence of the protocols while achieving computational efficiency through shared cryptographic operations, eliminating redundant processing without sacrificing protocol flexibility.
Data Source
AI summary
An identifier, for example, an identifier of a domain and/or a host of the domain (e.g., a fully qualified domain name (FQDN), etc.), such as a service management device (e.g., a server, a web server, a computing device, a web host device, a webpage, etc.), may be modified (e.g., hashed, encrypted, etc.) by a network device (e.g., a server, a domain name system (DNS) server, a DNS over hypertext transfer protocol secure (HTTPS) server/gateway (DoH server), DNS over Transport Layer Security (TLS) server/gateway (DoT server), a network management device, a computing device, etc.), sent to a user device (e.g., a client device, a smart device, a mobile device, a content output device, a computing device, a web browser, a search engine, etc.), and reused by the user device to request a service (e.g., a web service, a webpage, a file, content, a content item, etc.).


