IP Library Granted Patent US 10,911,420
Granted Patent B2
US 10,911,420 · App. 16/513,899 · Granted Feb 2, 2021

Manage encrypted network traffic using DNS responses

Inventors: Paul Michael Martini (San Diego, CA); Peter Anthony Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0464H04L41/00H04L61/10H04L61/103H04L61/1511H04L61/1552H04L61/2007H04L63/0428H04L67/02H04L29/12066H04L61/6009
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,911,420
App. No.
16/513,899
Granted
Feb 2, 2021
Kind
B2
Abstract

This present disclosure generally relates to managing encrypted network traffic using Domain Name System (DNS) responses. One example includes requesting an address; receiving a response from the resolution server including one or more addresses associated with the domain name; associating with the domain name a particular address selected from the received one or more addresses; receiving a request to resolve the domain name; sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name; receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name; and determining that the secure request is directed to the domain name based on the association between the particular address and the domain name.

Claims (71)

1. A computer-implemented method executed by one or more processors, the method comprising:

requesting, by a gateway of a network an address associated with a domain name from a resolution server, the domain name included in a predetermined set of domain names for which secure requests are to be identified, wherein the gateway and the network are both controlled by a controlling entity that owns the network;

receiving a response from the resolution server including one or more addresses associated with the domain name;

associating with the domain name a particular address selected from the received one or more addresses;

receiving over the network, by the gateway and from a particular client device, a request to resolve the domain name, wherein the network hosts a plurality of client devices including the particular client device, and wherein some of the client devices are controlled by the controlling entity and wherein the particular client device is not controlled by the controlling entity;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

wherein selectively decrypting the secure request comprises:

determining that the secure request should be decrypted based at least in part on one or more rules; and

decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

forwarding the secure request to an address associated with the domain name.

2. The method of claim 1 , wherein the domain name is a first domain name, the method further comprising:

requesting an address associated with a second domain name different than the first domain name from the resolution server;

receiving a second response from the resolution server including one or more addresses associated with the second domain name, wherein the one or more addresses associated with the second domain name includes the particular address; and

modifying the second response to remove the particular address.

3. The method of claim 1 , wherein:

the particular address includes an internet protocol (IP) address,

requesting the address associated with the domain name from the resolution server includes sending a Domain Name System (DNS) request;

receiving the response from the resolution server includes receiving a DNS response;

receiving the request to resolve the domain name includes receiving a DNS request; and

sending the response to the request to resolve the domain name includes sending a DNS response.

4. The method of claim 1 , wherein forwarding the secure request comprises:

re-encrypting the secure request; and

sending the secure request to the address associated with the domain name.

5. The method of claim 1 , further comprising:

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules;

modifying the decrypted information based at least in part on the one or more rules;

encrypting the decrypted information to produce a second secure request; and

forwarding the second secure request to an address associated with the domain name.

6. The method of claim 1 , further comprising:

inspecting the decrypted information;

determining that the secure request should be blocked based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

blocking the secure request.

7. The method of claim 6 , wherein blocking the secure request includes sending a redirect response to the secure request, the redirect response including an address associated with a block notification page.

8. The method of claim 1 , wherein receiving the secure request for the resource comprises:

establishing a first secure connection with a sender of the secure request;

establishing a second secure connection with an address associated with the resource after establishing the first secure connection with the sender.

9. The method of claim 1 , wherein receiving the secure request for the resource comprises:

establishing a first secure connection with an address associated with the resource;

establishing a second secure connection with a sender of the secure request after establishing the first secure connection with the address associated with the resource.

10. The method of claim 1 , wherein the domain name is a first domain name, the method further comprising:

receiving a request to resolve a second domain name different than the first domain name;

determining that the second domain name is not included in the predetermined set of domain names; and

sending a response to the request to resolve the second domain name, the response including an address corresponding to the second domain name.

11. The method of claim 1 , further comprising:

receiving a second request to resolve the domain name;

determining that the domain name is associated with the particular address; and

sending a response to the second request to resolve the domain name, the response including the particular address.

12. The method of claim 1 , wherein receiving the secure request for the resource includes receiving a request according to Hypertext Transfer Protocol Secure (HTTPS).

13. The method of claim 1 , further comprising selectively blocking the secure request based at least in part on determining that the secure request is directed to the domain name.

14. The method of claim 1 , wherein requesting the address for the domain name from the resolution server, receiving the response from the resolution server, and associating with the domain name the particular address are performed in response to receiving the request to resolve the domain name.

15. The method of claim 1 , wherein the resolution server is not controlled by the controlling entity.

16. The method of claim 1 , wherein the resolution server is a DNS server is connected to the gateway by the Internet.

17. A gateway of a network the gateway comprising a processor and memory, the processor configured to:

request an address associated with a domain name from a resolution server, the domain name included in a predetermined set of domain names for which secure requests are to be identified, wherein the gateway and the network are both controlled by a controlling entity that owns the network;

receiving a response from the resolution server including one or more addresses associated with the domain name;

associating with the domain name a particular address selected from the received one or more addresses;

receiving over the network, by the gateway and from a particular client device, a request to resolve the domain name, wherein the network hosts a plurality of client devices including the particular client device, and wherein some of the client devices are controlled by the controlling entity and wherein the particular client device is not controlled by the controlling entity;

sending a response to the request to resolve the domain name, the sent response including the particular address associated with the domain name;

receiving a secure request for a resource, the secure request directed to the particular address associated with the domain name;

determining that the secure request is directed to the domain name based on the association between the particular address and the domain name;

wherein selectively decrypting the secure request comprises:

determining that the secure request should be decrypted based at least in part on one or more rules; and

decrypting the secure request to generate decrypted information;

inspecting the decrypted information;

determining that the secure request should be forwarded based at least in part on inspecting the decrypted information and at least in part on the one or more rules; and

forwarding the secure request to an address associated with the domain name.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
FIRST AMENDMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Sep 10, 2021
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 057566/0149 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2019
From: MARTINI, PAUL MICHAEL; MARTINI, PETER ANTHONY
To: IBOSS, INC.
Reel/Frame 050670/0823 →
Continuity (5)
Continuation 15803660 · Nov 3, 2017
Continuation 15382392 · Dec 16, 2016
Continuation 14848219 · Sep 8, 2015
Continuation 14280513 · May 16, 2014
Related Publication 20190364026A1 · Nov 28, 2019
Cited By (1)
US 12,513,009