QoS Policy Selection via DNS Metadata for Encrypted Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise networks with mission-critical devices and IoT devices, it is challenging to apply proper Quality of Service (QoS) treatment to traffic associated with applications using end-to-end encryption, as existing methods like deep packet inspection require high computational processing and lack clear visibility into applications.

Innovation Solution

The implementation of techniques and mechanisms for QoS policy selection and QoS flow creation based on Domain Name System (DNS) application metadata, where a user plane function receives DNS queries, interacts with a DNS server to obtain metadata, and a control plane function creates dedicated QoS flows according to selected policies, utilizing extensions like EDNS or DNS-AS mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is used to detect applications for QoS treatment, then application visibility is improved, but computational processing requirements increase significantly

Engineering Contradiction:
Improveapplication visibilityVSAvoidcomputational processing
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent introduces DNS query metadata as an intermediary mechanism to obtain application information without directly inspecting encrypted packet contents. The DNS server acts as a mediator that provides application identifiers and QoS parameters in response to DNS queries, enabling the network to identify applications and apply appropriate QoS treatment without requiring computationally intensive deep packet inspection of encrypted traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end encryption is implemented for applications, then security is improved, but network visibility of applications deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidapplication visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by obtaining application metadata through DNS queries before the actual data transmission occurs. The DNS server provides application identifiers and QoS parameters in advance, allowing the network to establish appropriate QoS flows and policies before encrypted data traffic begins, thus maintaining visibility without compromising the end-to-end encryption of the actual application data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11570145B2Quality of service (QoS) policy selection and flow creation based on domain name system (DNS) application metadata
Publication Date: 2023.01.31 CISCO TECHNOLOGY INC
  • US11570145B2 patent drawing
  • US11570145B2 patent drawing
  • US11570145B2 patent drawing

AI summary

In one illustrative example, a user plane function (UPF) configured for use in a private 5G network of an enterprise may receive, from a user device, a domain name system (DNS) query associated with an application; send, to a DNS server, one or more corresponding DNS queries based on the DNS query; receive, from the DNS server, one or more DNS query responses which include an IP address and metadata including an application identifier for the application; and send, to a control plane function, a message for reporting which includes the application identifier. In response, a dedicated Quality of Service (QoS) Flow may be created for traffic for the application according to a selected QoS policy associated with the application identifier. For obtaining the metadata, the UPF may interact with a DNS server configured with Extension mechanisms for DNS (EDNS) or a DNS as Authoritative Source (DNS-AS) mechanism.