First node, second node, third node, communications system and methods performed, thereby for verifying the second node as a server for an application
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in detecting and preventing fraudulent traffic and phishing attacks in encrypted communications networks, particularly due to the encryption of Server Name Indication (SNI) and Domain Name System (DNS) traffic, which hinders effective fraud detection and load balancing.
Innovation Solution
A method involving TLS lateral server name discovery and authentication is employed to verify the authenticity of application servers by validating and authenticating certificates, enabling fraud prevention and phishing detection through lateral connections and message exchanges among nodes in the communications system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TLS encryption is applied to secure communications, then security and privacy are improved, but fraud detection and load balancing capabilities deteriorate due to encrypted Server Name Indication and DNS traffic
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the network node performs TLS lateral connections to verify server authenticity. The node acts as a mediator that can inspect encrypted traffic characteristics and validate server certificates without decrypting the entire communication, thus maintaining security while enabling fraud detection.
Solution Approach 2:
The patent replaces traditional mechanical inspection methods with cryptographic verification mechanisms. Instead of directly inspecting encrypted traffic, the system uses certificate validation and lateral connections to verify server identity, substituting direct traffic analysis with cryptographic proof verification.
2Reliability
If Server Name Indication is encrypted to protect privacy, then user privacy is improved, but effective load balancing and fraud prevention deteriorate
Solution Approach 1:
The patent extracts critical verification information from the encrypted TLS handshake process. By capturing and validating server certificates during the lateral connection, the system extracts authenticity verification without needing to decrypt or inspect the encrypted SNI field, thus maintaining privacy while enabling load balancing.
Solution Approach 2:
The network node serves as an intermediary that performs verification functions without directly accessing encrypted SNI data. It uses the TLS protocol's built-in certificate validation mechanism to verify server identity, acting as a mediator that bridges privacy protection and load balancing requirements.
3Reliability
If DNS traffic is encrypted to prevent surveillance, then privacy and security are improved, but application identification and traffic management capabilities deteriorate
Solution Approach 1:
The patent substitutes direct DNS traffic inspection with certificate-based verification. Instead of mechanically analyzing encrypted DNS queries, the system uses TLS certificate validation to verify application server identity, enabling traffic management without decrypting DNS traffic.
Solution Approach 2:
The network node acts as an intermediary that performs application identification through certificate validation rather than direct DNS inspection. This mediator approach allows traffic management capabilities to function while maintaining encrypted DNS traffic privacy.
Data Source
AI summary
A computer-implemented method, performed by a first node (111), for verifying a second node (112) as a server for an application. The first node (111) obtains (301), from a third node (113), a first request to verify a first Internet Protocol (IP) address for a first domain for the application. The first request indicates the first domain and the first IP address. The first node (111) sends (304) a first connection request to the second node (112) using the first IP address. The first connection request comprises the first domain indicated in the first request. The first node (111) receives (305), in response to the sent first connection request, an indication from the second node (112). The indication comprises a certificate of the second node (112). The first node (111) also sends (307) a message to the third node (113) based on a result of the validation and authentication.


