IP Library Granted Patent US 12,438,913
Granted Patent B2
US 12,438,913 · App. 18/498,711 · Granted Oct 7, 2025

Provisioning encrypted domain name service and secure value-added service with certificates at a customer premise equipment in a broadband satellite system

Inventor: Chi-Jiun Su (Rockville, MD)
Assignee: Hughes Network Systems, LLC
H04L63/166H04L9/3268H04L63/0485G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,913
App. No.
18/498,711
Granted
Oct 7, 2025
Kind
B2
Abstract

A satellite communication system which supports encrypted DNS at the customer premise equipment terminal to provide the benefits of local DNS caching. Some implementations use Certificate Authority (CA)-signed Transport Layer Security (TLS) certificates. Implementations may provide encrypted DNS service at the CPE, where the system installs CA-signed TLS certificate at the customer premise equipment (CPE) terminal. The same certificate can be used at multiple terminals using a wild-card certificate distributed by the satellite to provide value added services at a CPE as secure web services to off-the-shelf web clients and applications.

Claims (37)

1. A customer premise equipment (CPE) terminal comprising:

a processor with a memory, where the memory stores instructions that when executed cause the processor to:

provide internet services to a client device at a customer premise through a satellite connected to a satellite gateway by:

receiving a signed certificate from a certificate server connected to the satellite gateway,

assigning a private internet protocol (IP) address to the client device in a local area network,

and

providing encrypted domain name server (DNS) services to the client device using the signed certificate and the private IP address.

2. The CPE terminal of claim 1 , wherein the instructions further cause the processor to communicate with an application, browser and a DNS resolver in the client device.

3. The CPE terminal of claim 1 , wherein the instructions further cause the processor to provide additional web services protected by Transport Layer Security (TLS) security using the signed certificate.

4. The CPE terminal of claim 1 , wherein the instructions further cause the processor to provide local split-DNS for encrypted fully qualified domain names.

5. The CPE terminal of claim 1 , wherein the encrypted DNS services are provided to the client device located at the customer premise without requiring the client device to communicate over an internet.

6. The CPE terminal of claim 1 , wherein the signed certificate is a transport layer security (TLS) certificate received from a certificate authority (CA).

7. The CPE terminal of claim 1 , wherein the instructions further cause the processor to use split-horizon DNS for providing the encrypted DNS services.

8. The CPE terminal of claim 1 , wherein the signed certificate is a single certificate used for a plurality of CPEs.

9. The CPE terminal of claim 8 , wherein the single certificate is a wild-card certificate that provisions secure and encrypted services with multiple CPEs within a CPE group.

10. A customer premise equipment (CPE) terminal comprising:

a processor with a memory, where the memory stores instructions that when executed cause the processor to:

provide internet services to a plurality of client devices at a customer premise through a satellite connected to a satellite gateway by:

receiving a Certificate Authority (CA) signed wildcard Transport Layer Security (TLS) certificate from a certificate server connected to the satellite gateway,

assigning a private internet protocol (IP) address to the plurality of client devices in a local area network, and

providing encrypted domain name server (DNS) services to the plurality of client devices using the CA signed wildcard TLS certificate and the private IP address.

11. The CPE terminal of claim 10 , wherein the instructions further cause the processor to provide additional web services protected by TLS security using the signed wildcard certificate.

12. The CPE terminal of claim 10 , wherein the instructions further cause the processor to provide local split-DNS for encrypted fully qualified domain names.

13. The CPE terminal of claim 10 , wherein the encrypted DNS services are provided to a client device of the plurality of client devices located at the customer premise without requiring the client device to communicate over an internet.

14. A customer premise equipment (CPE) terminal comprising:

a processor with a memory, where the memory stores instructions that when executed cause the processor to:

provide internet services to a client device and provisioning workflow at the CPE through a satellite connected to a satellite gateway by:

receiving a signed certificate from a certificate server connected to the satellite gateway and installing the signed certificate at a secure place in the CPE, wherein the signed certificate is a wild-card certificate that provisions secure and encrypted services with multiple CPEs within a CPE group,

assigning a private internet protocol (IP) address to the client device in a local area network,

and

providing encrypted domain name server (DNS) services to the client device using the signed certificate and the private IP address.

15. The CPE terminal of claim 14 , wherein the instructions further cause the processor to communicate with an application, browser and a DNS resolver in the client device.

16. The CPE terminal of claim 14 , wherein the instructions further cause the processor to provide additional web services protected by Transport Layer Security (TLS) security using the signed certificate.

17. The CPE terminal of claim 14 , wherein the instructions further cause the processor to provide local split-DNS for encrypted fully qualified domain names.

18. The CPE terminal of claim 14 , wherein the encrypted DNS services are provided to the client device located at a customer premise without requiring the client device to communicate over an internet.

19. The CPE terminal of claim 14 , wherein the signed certificate is a transport layer security (TLS) certificate received from a certificate authority (CA).

20. The CPE terminal of claim 14 , wherein the instructions further cause the processor to use split-horizon DNS for providing the encrypted DNS services.

Assignments (2)
SECURITY INTEREST Recorded Jan 14, 2025
From: HUGHES NETWORK SYSTEMS, LLC
To: U.S. BANK NATIONAL ASSOCIATION
Reel/Frame 069862/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: SU, CHI-JIUN
To: HUGHES NETWORK SYSTEMS, LLC
Reel/Frame 065406/0960 →
Continuity (3)
Continuation 17552785 · Dec 16, 2021
Provisional Application 63255046 · Oct 13, 2021
Related Publication 20240064173A1 · Feb 22, 2024
References Cited (4)
US 20170093802A1 · Norum · 2017 [cited by examiner]
US 20210250349A1 · Konda · 2021 [cited by examiner]
US 20210266185A1 · Konda · 2021 [cited by examiner]
US 20220239696A1 · Konda · 2022 [cited by examiner]