SOCKS Proxy for Secure DNS Resolution in Vehicles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing internet-based communication within motor vehicles against DNS-spoofing attacks are complex, expensive, and inconvenient, failing to provide adequate data security and user comfort.

Innovation Solution

A method and system utilizing a SOCKS server as a proxy within a connection unit to manage user requests for internet connections, selecting a DNS server based on a network interface and utilizing an allocation table for secure and efficient communication, with optional encryption and eSIM card-based mobile communication for flexible access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex encryption methods are used to secure communication against DNS-spoofing attacks, then data security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a proxy server as an intermediary component between the user terminal and the DNS server. This proxy server receives DNS requests from user terminals, resolves the domain names itself, and forwards the resolved IP addresses to the terminals. By using this intermediary, the system achieves secure communication without requiring complex encryption mechanisms, as the proxy server acts as a trusted mediator that prevents DNS-spoofing attacks through its centralized resolution process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex encryption methods are used to secure communication, then data security is improved, but implementation cost increases

Engineering Contradiction:
Improvedata securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The proxy server serves as a cost-effective intermediary that provides security functions without requiring expensive encryption hardware or complex cryptographic protocols. The system uses standard DNS resolution mechanisms within the proxy server to achieve protection against DNS-spoofing attacks, avoiding the need for costly encryption implementations while maintaining data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If complex encryption methods are used to secure communication, then data security is improved, but user comfort decreases due to time consumption

Engineering Contradiction:
Improvedata securityVSAvoiduser comfort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The proxy server acts as a transparent intermediary that handles DNS resolution in the background without requiring user intervention. Users simply access websites through their terminals, and the proxy server automatically resolves domain names and manages secure communication. This approach provides data security while maintaining user comfort, as the security mechanisms operate transparently without adding noticeable delays or complexity for the end user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3965394B1Method for controlling an internet-based communication
Publication Date: 2024.12.18 VOLKSWAGEN AG
  • EP3965394B1 patent drawingFigure 1
  • EP3965394B1 patent drawingFigure 2
  • EP3965394B1 patent drawingFigure 3

AI summary

A method for regulating internet-based communication within a motor vehicle (26), comprising receiving a user request (40) by means of a connection unit from a user (4) and/or user terminal (4), the user request requesting a connection between the user (4) and/or user terminal (4) and a backend server (12, 14), , processing the user request (44) for selecting a specific network interface (24a, 24b, 24c, 24d) for connecting the user (4) and/or user terminal (4) to the backend server (12, 14) within the connection unit (6), and selecting (46) a specific DNS server (22a, 22b, 22c) based on the selected network interface (24a, 24b, 24c, 24d) for resolving the Uniform Resource Locator (URL) of the backend server (12, 14) to create a connection between the user (4) and/or user terminal (4) and the backend server (12, 14).