Modified Domain Identifiers for Low-Latency Secure Content Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security protocols like encrypted DNS and eSNI suffer from significant computational overhead and latency due to independent operations and separate cryptographic identity exchanges, making them vulnerable to interception and degrading user experience.

Innovation Solution

Implementing a modified version of identifiers, such as hashed FQDNs, shared across both encrypted DNS and eSNI processes, reduces the need for public key exchanges and cryptographic hashing, allowing these protocols to operate collectively and efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted DNS and eSNI protocols operate independently with separate cryptographic identity exchanges, then network security is maintained, but computational overhead and latency increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidcomputational overhead and latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines encrypted DNS and eSNI protocols into a unified cryptographic identity exchange process. The DNS resolver and SSL/TLS server perform a single joint key exchange that establishes both DNS encryption and TLS encryption simultaneously, eliminating redundant cryptographic operations and reducing computational overhead while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal cryptographic mechanism that serves multiple functions: the same key exchange process simultaneously enables encrypted DNS resolution and encrypted TLS communication. This multi-functional approach allows a single cryptographic operation to fulfill both security requirements, reducing overall computational burden and latency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple independent cryptographic identity exchanges are performed, then security against interception is maintained, but user experience degrades due to increased latency

Engineering Contradiction:
Improvesecurity against interceptionVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the DNS encryption establishment and TLS encryption establishment into a single synchronized process. The DNS resolver and SSL/TLS server complete both cryptographic handshakes simultaneously through one unified key exchange, halving the number of separate security negotiations and significantly reducing the time users wait for secure connections.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate cryptographic operations are used for DNS and TLS, then protocol independence is maintained, but computational efficiency decreases

Engineering Contradiction:
Improveprotocol independenceVSAvoidcomputational efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements a universal cryptographic framework where a single key exchange mechanism serves both DNS encryption and TLS encryption purposes. This multi-functional design maintains the logical independence of the protocols while achieving computational efficiency through shared cryptographic operations, eliminating redundant processing without sacrificing protocol flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260113300A1Methods and systems for accessing content
Publication Date: 2026.04.23 COMCAST CABLE COMM LLC
  • US20260113300A1 patent drawing
  • US20260113300A1 patent drawing
  • US20260113300A1 patent drawing

AI summary

An identifier, for example, an identifier of a domain and/or a host of the domain (e.g., a fully qualified domain name (FQDN), etc.), such as a service management device (e.g., a server, a web server, a computing device, a web host device, a webpage, etc.), may be modified (e.g., hashed, encrypted, etc.) by a network device (e.g., a server, a domain name system (DNS) server, a DNS over hypertext transfer protocol secure (HTTPS) server/gateway (DoH server), DNS over Transport Layer Security (TLS) server/gateway (DoT server), a network management device, a computing device, etc.), sent to a user device (e.g., a client device, a smart device, a mobile device, a content output device, a computing device, a web browser, a search engine, etc.), and reused by the user device to request a service (e.g., a web service, a webpage, a file, content, a content item, etc.).