QoS Policy Selection via DNS Metadata for Encrypted Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In enterprise networks with mission-critical devices and IoT devices, it is challenging to apply proper Quality of Service (QoS) treatment to traffic associated with applications using end-to-end encryption, as existing methods like deep packet inspection require high computational processing and lack clear visibility into applications.
Innovation Solution
The implementation of techniques and mechanisms for QoS policy selection and QoS flow creation based on Domain Name System (DNS) application metadata, where a user plane function receives DNS queries, interacts with a DNS server to obtain metadata, and a control plane function creates dedicated QoS flows according to selected policies, utilizing extensions like EDNS or DNS-AS mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is used to detect applications for QoS treatment, then application visibility is improved, but computational processing requirements increase significantly
Solution Approach 1:
The patent introduces DNS query metadata as an intermediary mechanism to obtain application information without directly inspecting encrypted packet contents. The DNS server acts as a mediator that provides application identifiers and QoS parameters in response to DNS queries, enabling the network to identify applications and apply appropriate QoS treatment without requiring computationally intensive deep packet inspection of encrypted traffic.
2Reliability
If end-to-end encryption is implemented for applications, then security is improved, but network visibility of applications deteriorates
Solution Approach 1:
The patent applies preliminary action by obtaining application metadata through DNS queries before the actual data transmission occurs. The DNS server provides application identifiers and QoS parameters in advance, allowing the network to establish appropriate QoS flows and policies before encrypted data traffic begins, thus maintaining visibility without compromising the end-to-end encryption of the actual application data.
Data Source
AI summary
In one illustrative example, a user plane function (UPF) configured for use in a private 5G network of an enterprise may receive, from a user device, a domain name system (DNS) query associated with an application; send, to a DNS server, one or more corresponding DNS queries based on the DNS query; receive, from the DNS server, one or more DNS query responses which include an IP address and metadata including an application identifier for the application; and send, to a control plane function, a message for reporting which includes the application identifier. In response, a dedicated Quality of Service (QoS) Flow may be created for traffic for the application according to a selected QoS policy associated with the application identifier. For obtaining the metadata, the UPF may interact with a DNS server configured with Extension mechanisms for DNS (EDNS) or a DNS as Authoritative Source (DNS-AS) mechanism.


