Secure DNS Gateway Using Delegated Credentials and Keyless SSL
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DNS systems lack secure communication methods, particularly for home gateways, which hinders the enforcement of DNS filtering and security measures in environments using encrypted DNS protocols like DoH and DoT.
Innovation Solution
A system and method that utilize delegated credentials and keyless SSL to provide secure DNS services on home gateways, allowing for secure communication without the need for unique public certificates for each gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unique public certificates are used for each home gateway to enable secure DNS transactions, then security and privacy are improved, but device complexity and cost increase due to certificate management overhead
Solution Approach 1:
The patent introduces a certificate authority server as an intermediary that issues certificates to home gateways. This mediator handles the complex certificate management tasks, allowing individual gateways to obtain certificates without directly managing the complex issuance and revocation processes. The gateway management server acts as another intermediary layer that coordinates between the CA server and multiple gateways, simplifying the overall system architecture while maintaining security.
Solution Approach 2:
The patent extracts the certificate management functionality from individual home gateways and centralizes it in dedicated gateway management servers and certificate authority servers. By separating the certificate issuance, management, and revocation functions from the gateways themselves, the system reduces the complexity burden on each gateway while maintaining centralized control over security credentials.
2Ease of manufacture
If delegated credentials are used for secure DNS transactions, then cost and dependency on public CAs are reduced, but compatibility with endpoints that do not support delegated credentials deteriorates
Solution Approach 1:
The patent implements dynamic credential selection where the gateway determines which authentication method to use based on the endpoint's capabilities. The system dynamically switches between delegated credentials (for cost efficiency) and traditional certificates (for compatibility) depending on whether the endpoint supports the delegated credential mechanism. This dynamic adaptation allows the system to optimize for cost when possible while maintaining universal compatibility when needed.
3Reliability
If DNS filtering and security measures are enforced in encrypted DNS protocols, then security is improved, but the ability to monitor and control DNS traffic deteriorates
Solution Approach 1:
The patent establishes security associations and authentication mechanisms before DNS traffic encryption begins. By pre-establishing trusted relationships between gateways, endpoints, and DNS servers through certificate-based authentication, the system enables subsequent monitoring and filtering of encrypted DNS traffic based on these pre-established security contexts. The gateway can enforce security policies and filter DNS requests while maintaining encryption, using the preliminary authentication framework to identify and control traffic.
Data Source
AI summary
There is disclosed in an example a gateway device, including a hardware computing platform, and a secure domain name system (DNS) engine having circuitry and stored instructions to-program the circuitry, the secure DNS engine to communicatively couple to an endpoint via a local network, begin a secure DNS transaction with the endpoint, determine whether the endpoint supports delegated credentials, and after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using a delegated credential.


