IP Library › Granted Patent US 12,302,091
Granted Patent B2
US 12,302,091 · App. 18/023,765 · Granted May 13, 2025

Methods and nodes for deactivating server name indication, SNI, encryption in a telecommunication network

Inventors: Miguel Angel Muñoz De La Torre Alonso (Madrid, ES); Maria Luisa Mas Rosique (Tres Cantos, ES); Marcus Ihlar (Älvsjö, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/033H04L61/4511H04W12/0431
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,302,091
App. No.
18/023,765
Granted
May 13, 2025
Kind
B2
Abstract

A method for deactivating Server Name Indication, SNI, encryption in a telecommunication network, wherein said telecommunication network comprises a Domain Name System, DNS, server, said method comprising the steps of receiving, by said DNS server, from a User Equipment, UE, a DNS query comprising a Domain Name to be converted to an Internet Protocol, IP, address, determining, by said DNS server, that SNI encryption is to be deactivated for subsequent traffic associated with said Domain Name, forwarding, by said DNS server, said DNS query to an external DNS server, wherein said DNS query comprises said Domain Name and a request for deactivating SNI encryption, receiving, by said DNS server, from said external DNS server, a DNS answer, wherein said DNS answer comprises said converted IP address and wherein said DNS answer is free from encryption keys for encrypting SNI and forwarding, by said DNS server, said DNS answer comprising said converted IP address to said UE, wherein said DNS answer is free from encryption keys such that said UE is not able to encrypt said SNI in said subsequent traffic.

Claims (40)

1. A method for deactivating Server Name Indication, SNI, (SNI) encryption in a telecommunication network, wherein the telecommunication network comprises a Domain Name System (DNS) server, the method comprising the steps of:

receiving, by the DNS server, from a user equipment (UE) a DNS query comprising a Domain Name to be converted to an Internet Protocol (IP) address;

determining, by the DNS server, that SNI encryption is to be deactivated for subsequent traffic associated with the Domain Name;

forwarding, by the DNS server, the DNS query to an external DNS server, wherein the DNS query comprises the Domain Name and a request for deactivating SNI encryption;

receiving, by the DNS server, from the external DNS server, a DNS answer, wherein the DNS answer comprises the converted IP address and wherein the DNS answer is free from encryption keys for encrypting SNI; and

forwarding, by the DNS server, the DNS answer comprising the converted IP address to the UE, wherein the DNS answer is free from encryption keys such that the UE is not able to encrypt the SNI in the subsequent traffic.

2. The method of claim 1 , wherein the step of determining further comprises:

transmitting, by the DNS server, to a Policy and Charging function entity, a user consent request for querying whether the UE has provided a consent for deactivating the SNI encryption; and

receiving, by the DNS server, from the Policy and Charging function entity, a user consent response comprising an indication that the UE has provided the consent for deactivating the SNI encryption.

3. The method of claim 2 ,

wherein the received DNS query and the transmitted user consent request comprise an IP address of the UE for enabling the Policy and Charging function entity to determine whether the UE has provided the user consent.

4. The method of claim 1 , wherein the step of forwarding the DNS query comprises:

forwarding, by the DNS server, the DNS query to an external DNS server, wherein the DNS query comprises an operator identification for identifying an operator of the telecommunication network thereby enabling the external DNS server to determine whether Server Name Indication, SNI, (SNI) encryption may be deactivated for the operator.

5. The method of claim 1 , wherein the DNS answer is free from encryption keys being any of a public key corresponding to the Domain Name and an Encrypted server name indication, ESNI, key corresponding to the Domain Name.

6. A method for supporting of deactivating Server Name Indication (SNI) encryption in a telecommunication network, wherein the telecommunication network comprises a Domain Name System (DNS) server, and a Policy and Charging function entity, the method comprising the steps of:

receiving, by the Policy and Charging function entity, from the DNS server, a user consent request for querying whether the UE has provided a consent for deactivating the SNI encryption;

determining, by the Policy and Charging function entity that the UE has provided the consent for deactivating the SNI encryption; and

transmitting, by the Policy and Charging function entity, to the DNS server, a user consent response comprising an indication that the UE has provided the consent for deactivating the SNI encryption.

7. The method of claim 6 , wherein the received user consent request comprise an IP address of the UE, wherein the step of determining comprises:

determining that the UE has provided the consent based on the received IP address of the UE.

8. The method of claim 7 , wherein the method comprises the initial steps of:

transmitting, by the Policy and Charging function entity, to a Unified Data Repository, UDR, a Query Request message for retrieving policy data of the UE;

receiving, by the Policy and Charging function entity, from the Unified Data Repository, UDR, a Query Response message, wherein the Query Response message comprises the indication that the UE has provided the consent for deactivating the SNI encryption;

storing, by the Policy and Charging function entity, the received indication that the UE has provided the consent for deactivating the SNI encryption.

9. A method for supporting of deactivating Server Name Indication (SNI) encryption in a telecommunication network, by an external Domain Name System (DNS) server in an Internet Protocol (IP) communication system, wherein the external DNS server is arranged to communicate with a DNS server in a telecommunication network, wherein the method comprises the steps of:

receiving, by the external DNS server, from the DNS server in the telecommunication network, a DNS query comprising a Domain Name to be converted to an Internet Protocol (IP) address, and comprising a request for deactivating SNI encryption;

converting, by the external DNS server, the Domain Name to the IP address;

determining, by the external DNS server, that the SNI encryption may be deactivated for the Domain Name; and

transmitting, by the external DNS server, to the DNS server in the telecommunication network a DNS answer, wherein the DNS answer comprises the converted IP address and wherein the DNS answer is free from encryption keys for encrypting the SNI.

10. The method of claim 9 , wherein the received DNS query comprises an operator identification for identifying an operator of the telecommunication network, and wherein the step of determining comprises:

determining that the SNI encryption may be deactivated for the Domain Name based on the operator identification.

11. A Domain Name System (DNS) server arranged for operating in a telecommunication network and for deactivating Server Name Indication (SNI) encryption in the telecommunication network,

receive equipment arranged for receiving, from a user equipment (UE) a DNS query comprising a Domain Name to be converted to an Internet Protocol (IP) address;

process equipment arranged for determining that SNI encryption is to be deactivated for subsequent traffic associated with the Domain Name;

transmit equipment arranged for forwarding the DNS query to an external DNS server, wherein the DNS query comprises the Domain Name and a request for deactivating SNI encryption;

wherein the receive equipment is further arranged for receiving from the external DNS server, a DNS answer, wherein the DNS answer comprises the converted IP address and wherein the DNS answer is free from encryption keys for encrypting SNI;

wherein the transmit equipment is further arranged for forwarding the DNS answer comprising the converted IP address to the UE, wherein the DNS answer is free from encryption keys such that the UE is not able to encrypt the SNI in the subsequent traffic.

12. The DNS server of claim 11 , wherein:

said transmit equipment is arranged for transmitting to a Policy and Charging function entity, a user consent request for querying whether the UE has provided a consent for deactivating the SNI encryption;

said receive equipment is arranged for receiving from the Policy and Charging function entity, a user consent response comprising an indication that the UE has provided the consent for deactivating the SNI encryption.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2023
From: MUÑOZ DE LA TORRE ALONSO, MIGUEL ANGEL; MAS ROSIQUE, MARIA LUISA; IHLAR, MARCUS
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 063583/0991 →
Priority Claims (1)
EP 20382775 · Sep 1, 2020 · regional
Continuity (1)
Related Publication 20230328514A1 · Oct 12, 2023
References Cited (50)
US 9961055B1 · Johansson · 2018 [cited by examiner]
US 10425829B1 · Cui · 2019 [cited by examiner]
US 20130312054A1 · Wang · 2013 [cited by examiner]
US 20140122865A1 · Ovsiannikov · 2014 [cited by examiner]
US 20140298415A1 · Xie · 2014 [cited by examiner]
US 20160323201A1 · Choen · 2016 [cited by examiner]
US 20170223054A1 · Wing · 2017 [cited by examiner]
US 20180198823A1 · Johansson · 2018 [cited by examiner]
US 20180262348A1 · Golshan · 2018 [cited by examiner]
US 20190356693A1 · Cahana · 2019 [cited by examiner]
US 20190387021A1 · Wyatt · 2019 [cited by examiner]
US 20190394174A1 · Sillankorva · 2019 [cited by examiner]
US 20200067954A1 · Plonka · 2020 [cited by examiner]
US 20200137093A1 · Janakiraman · 2020 [cited by examiner]
US 20200137094A1 · Janakiraman · 2020 [cited by examiner]
US 20200153805A1 · Sen · 2020 [cited by examiner]
US 20200204519A1 · Isaev · 2020 [cited by examiner]
US 20200351251A1 · Bhat · 2020 [cited by examiner]
US 20210014328A1 · Singhal · 2021 [cited by examiner]
US 20210112040A1 · Niemi · 2021 [cited by examiner]
US 20210160325A1 · Lee · 2021 [cited by examiner]
US 20210204152A1 · Vasudevan · 2021 [cited by examiner]
US 20210234720A1 · Shribman · 2021 [cited by examiner]
US 20220021651A1 · Moore · 2022 [cited by examiner]
US 20220086691A1 · Ihlar · 2022 [cited by examiner]
US 20220129514A1 · Shribman · 2022 [cited by examiner]
US 20220129516A1 · Shribman · 2022 [cited by examiner]
US 20220173924A1 · Shribman · 2022 [cited by examiner]
US 20220353060A1 · Saarnivala · 2022 [cited by examiner]
US 20220360565A1 · Shribman · 2022 [cited by examiner]
US 20220368676A1 · Shribman · 2022 [cited by examiner]
US 20230093190A1 · Ramachandran · 2023 [cited by examiner]
US 20230308458A1 · Varsanyi · 2023 [cited by examiner]
US 20230327997A1 · Muñoz De La Torre Alonso · 2023 [cited by examiner]
US 20230370423A1 · Muñoz De La Torre Alonso · 2023 [cited by examiner]
Eastlake 3rd, D. “RFC 6066: Transport Layer Security (TLS) Extensions: Extension Definitions.” (2011). [cited by examiner]
Shbair, Wazen M., et al. “Efficiently bypassing SNI-based HTTPS filtering.” 2015 IFIP/IEEE International Symposium on Integrated Network Management (IM). IEEE, 2015. [cited by examiner]
Shbair, Wazen M., et al. “Improving SNI-based HTTPS security monitoring.” 2016 IEEE 36th International Conference on Distributed Computing Systems Workshops (ICDCSW). IEEE, 2016. [cited by examiner]
Keita, Khadidiatou Wane, et al. “Proposal for a new security association (SA) negotiation process in IPSec.” 2019 International Conference on Advances in Big Data, Computing and Data Communication Systems (icABCD). IEEE… [cited by examiner]
Vajaranta, Markku, Joona Kannisto, and Jarmo Harju. “IPsec and IKE as functions in SDN controlled network.” Network and System Security: 11th International Conference, NSS 2017, Helsinki, Finland, Aug. 21-23, 2017, Proc… [cited by examiner]
Bhattacharjya, Aniruddha, et al. “CoAP—application layer connection-less lightweight protocol for the Internet of Things (IoT) and CoAP-IPSEC Security with DTLS Supporting CoAP.” Digital twin technologies and smart citi… [cited by examiner]
Ranjbar, Alireza, et al. “An SDN-based approach to enhance the end-to-end security: SSL/TLS case study.” NOMS 2016-2016 IEEE/IFIP network operations and management symposium. IEEE, 2016. [cited by examiner]
Kumar, Puneet, and Behnam Dezfouli. “Implementation and analysis of QUIC for MQTT.” Computer Networks 150 (2019): 28-45. [cited by examiner]
International Search Report and Written Opinion issued in International Application No. PCT/EP2021/064811 dated Sep. 1, 2021 (11 pages). [cited by applicant]
E. Rescorla et al., “Encrypted Server Name Indication for for TLS 1.3”, tis Internet-Draft, Mar. 9, 2020 (pp. 1-27). [cited by applicant]
B. Schwartz et a., “Service binding and parameter specification via the DNS (DNS SVCB and HTTPS RRs)”, DNSOP Working Group, Internet-Draft, Jul. 13, 2020 (pp. 1-42). [cited by applicant]
E. Rescorla et al., “TLS Encrypted Client Hello”, tls, Internet-Draft, Jun. 1, 2020 (pp. 1-31). [cited by applicant]
3GPP TS 23.501 V16.5.0 (Jul. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16), Jul. 2020 (441 pages). [cited by applicant]
J. Damas et al., “Extension Mechanisms for DNS (EDNS (0) )”. Internet Engineering Task Force (IETF), Apr. 2013 (pp. 1-16). [cited by applicant]
E. Rescorla et al., “Encrypted Server Name Indication for TLS 1.3”, tls, Internet-Draft, Jul. 8, 2019 (pp. 1-30). [cited by applicant]