Packet Gateway DNS Routing by Subscriber Profile
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunications networks face challenges in efficiently managing access control and name lookup processes, particularly in packet-switched connections, which can lead to increased latency and reduced user privacy due to the need for policy server access and intermediate network node modifications.
Innovation Solution
A packet gateway system that inspects traffic on well-known ports, such as DNS requests, and forwards these requests to specific nameservers based on subscriber profiles, allowing for profile-type-specific name lookup without accessing user-specific data, thereby improving performance and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If policy server access is used for access control, then network security is improved, but latency increases and user privacy deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-categorizing subscribers into profile types (e.g., residential, business, premium) and pre-configuring specific nameservers for each profile type. When a DNS request arrives, the packet gateway immediately routes it to the appropriate nameserver based on the subscriber's profile type without needing to query the policy server, thus eliminating real-time policy server access latency while maintaining security through pre-established access rules.
Solution Approach 2:
The patent extracts the policy server access step from the DNS request handling process by implementing local profile-type-based routing at the packet gateway. This separation allows the majority of DNS requests to be handled locally without policy server involvement, reducing latency for common operations while the policy server remains available for exceptional cases or profile updates.
2Reliability
If policy server access is used for access control, then network security is improved, but user privacy deteriorates
Solution Approach 1:
The patent extracts personally identifiable information (PII) from the DNS request handling process. Instead of routing requests based on individual user identities that would require policy server access and expose user data, the system routes based on aggregate profile types. The packet gateway determines profile type from anonymized identifiers and routes requests accordingly, preventing exposure of specific user information while maintaining security through profile-based access control.
Solution Approach 2:
The patent applies local quality by implementing privacy protection at the packet gateway level rather than requiring centralized policy server processing. Each packet gateway locally stores and applies profile type mappings, enabling decentralized, privacy-preserving routing decisions. This distributed approach minimizes the collection and transmission of user-specific data while maintaining consistent security policies across the network.
3Adaptability or versatility
If intermediate network node modifications are used, then access control flexibility is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by enabling each packet gateway to independently perform profile-type-based DNS routing without requiring complex centralized control or modifications to intermediate network nodes. The packet gateway locally stores profile type configurations and makes autonomous routing decisions, simplifying the overall system architecture while maintaining flexible access control. This eliminates the need for complex policy server interactions for each DNS request and reduces the complexity of intermediate network node modifications.
4Productivity
If profile-type-specific name lookup is implemented, then productivity is improved, but device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring profile type to nameserver mappings in the packet gateway before operation. During normal DNS request handling, the packet gateway simply performs a quick lookup of the subscriber's profile type and routes to the corresponding pre-configured nameserver, achieving high-performance routing without complex real-time processing. The complexity is minimized to basic profile type identification and table lookup operations.
Solution Approach 2:
The patent applies universality by designing the packet gateway to handle both regular packet forwarding and profile-type-based DNS routing using the same infrastructure. The packet gateway leverages existing subscriber identification mechanisms and extends them to support profile-type determination, rather than implementing separate complex systems. This multi-functional approach achieves improved lookup performance without proportionally increasing device complexity.
Data Source
AI summary
In some examples, a telecommunications-network packet gateway can receive, from a terminal via a packet tunnel, a lookup request for a network address associated with a server name. The packet gateway can determine a profile identifier associated with the packet tunnel and retrieve, from a policy server, an associated profile type. The packet gateway can then select a nameserver associated with the profile type, and forward the lookup request to the nameserver. The nameserver can store a name list. Upon receiving a request, the nameserver can determine whether the server name is included in the name list and, in response, send a reply. In some examples, the packet gateway receives a request from the terminal for content, determines a profile type, selects a destination server associated with the profile type, and forwards the request to the destination server.


