US2021258350A1PendingUtilityA1

Privacy preservation in network connections

Assignee: LOOKOUT INCPriority: Feb 19, 2020Filed: Feb 18, 2021Published: Aug 19, 2021
Est. expiryFeb 19, 2040(~13.6 yrs left)· nominal 20-yr term from priority
H04L 61/4511G06F 16/285H04L 63/0823H04L 63/20H04L 63/0272H04L 63/04H04L 63/1425H04L 61/1511G06T 7/74
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and systems provide for reducing privacy leaks in DNS request by using a private DNS service. The private DNS service provides for matching a level of privacy provided by a type of communication protocol to a level of privacy desired or required for a particular client communication. When the DNS service determines that an intended communication protocol does not supply at least the level of privacy desired for a particular communication, the private DNS service may initiate the creation of a connection with the desired level of privacy.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by a software component executing on a network-enabled client device, from an application executing on the client device initiating a first connection, a domain name system (DNS) request for the resolution of a domain name;   determining, by the software component, whether the domain name is listed in a database or is associated with a first category in the database, the database containing at least one domain name or category of domains, each domain name or category associated with a policy; and   when the determination is that the domain name is listed in the database or is associated with a category in the first database, initiating, by the software component, a resolution of the DNS according to a policy from the associated with the domain name or the category in the database, wherein:   when the policy indicates that privacy is not a consideration in the first connection, proceeding with the processing of the DNS request;   when the policy indicates that privacy is a consideration in the first connection, determining, by the software component using at least one of information associated with the DNS request or information associated with the domain name in the database, whether a first level of privacy associated with the first connection is at least equal to a second level of privacy required by the policy, and:
 when the first level of privacy is at least equal to the second level of privacy, proceeding with the processing of the DNS request, or 
 when the first level of privacy is less than the second level of privacy, causing, by the software component, the application to create a second connection to a domain associated with the domain name, the second connection providing at least the required level of privacy. 
   
     
     
         2 . The method of  claim 1 , wherein the database includes a first plurality of domain names or first category for which the policy allows the connection to have any level of privacy. 
     
     
         3 . The method of  claim 1 , wherein the database includes a first plurality of domain names or first category for which the policy requires the first connection to have a specified level of privacy. 
     
     
         4 . The method of  claim 3 , wherein the specified level of privacy specifies one of: use of a transport layer security (TLS) protocol; use of an encrypted signal name indication (ESNI) protocol; or use of a virtual private network (VPN). 
     
     
         5 . The method of  claim 1 , wherein the policy is specified by one of an enterprise associated with the client device or a user associated with the client device. 
     
     
         6 . The method of  claim 1  further comprising:
 monitoring, by the software component, traffic associated with the first connection or the second connection; 
 determining, by the software component, from the monitored traffic that a protocol associated with the required level of privacy is not being followed; and 
 causing, by the software component, a change to a third connection providing the required level of privacy. 
 
     
     
         7 . The method of  claim 1  further comprising:
 monitoring, by the software component, traffic associated with the first connection or the second connection; 
 determining, by the software component, from the monitored traffic that a protocol associated with the required level of privacy is not being followed; and 
 initiating, by the software component, an update to the database reflect that the protocol is not followed in communications to the domain. 
 
     
     
         8 . The method of  claim 1 , wherein, when processing the DNS request results in a determination that an IP address associated with the domain name is also associated with additional domain names, the method further comprises:
 substituting, by the software component, a smaller time-to-live (TTL) value for an initial TTL value associated with the IP address;   providing, by the software component, the smaller TTL value to the application along with the IP address.   
     
     
         9 . A system comprising a network-enabled client device including at least one processor and memory with instructions that when executed by the at least one processor cause the system to perform actions including:
 receiving, by a software component, from an application executing on the client device initiating a first connection, a domain name system (DNS) request for the resolution of a domain name;   determining, by the software component, whether the domain name is listed in a database or is associated with a first category in the database, the database containing at least one domain name or category of domains, each domain name or category associated with a policy; and   when the determination is that the domain name is listed in the database or is associated with a category in the first database, initiating, by the software component, a resolution of the DNS according to a policy from the associated with the domain name or the category in the database, wherein:   when the policy indicates that privacy is not a consideration in the first connection, proceeding with the processing of the DNS request;   when the policy indicates that privacy is a consideration in the first connection, determining, by the software component using at least one of information associated with the DNS request or information associated with the domain name in the database, whether a first level of privacy associated with the first connection is at least equal to a second level of privacy required by the policy, and:
 when the first level of privacy is at least equal to the second level of privacy, proceeding with the processing of the DNS request, or 
 when the first level of privacy is less than the second level of privacy, causing, by the software component, the application to create a second connection to a domain associated with the domain name, the second connection providing at least the required level of privacy. 
   
     
     
         10 . The system of  claim 9 , wherein the database includes a first plurality of domain names or first category for which the policy requires the first connection to have a specified level of privacy. 
     
     
         11 . The system of  claim 10 , wherein the specified level of privacy specifies one of: use of a transport layer security (TLS) protocol; use of an encrypted signal name indication (ESNI) protocol; or use of a virtual private network (VPN). 
     
     
         12 . The system of  claim 9  further comprising:
 monitoring, by the software component, traffic associated with the first connection or the second connection; 
 determining, by the software component, from the monitored traffic that a protocol associated with the required level of privacy is not being followed; and 
 causing, by the software component, a change to a third connection providing the required level of privacy. 
 
     
     
         13 . The system of  claim 9  further comprising:
 monitoring, by the software component, traffic associated with the first connection or the second connection; 
 determining, by the software component, from the monitored traffic that a protocol associated with the required level of privacy is not being followed; and 
 initiating, by the software component, an update to the database reflect that the protocol is not followed in communications to the domain. 
 
     
     
         14 . The system of  claim 9 , wherein, when processing the DNS request results in a determination that an IP address associated with the domain name is also associated with additional domain names, the method further comprises:
 substituting, by the software component, a smaller time-to-live (TTL) value for an initial TTL value associated with the IP address;   providing, by the software component, the smaller TTL value to the application along with the IP address.   
     
     
         15 . A non-transitory computer-readable medium comprising instructions that when executed by a processor of a network-enabled client device cause the device to perform actions including:
 receiving, by a software component, from an application executing on the client device initiating a first connection, a domain name system (DNS) request for the resolution of a domain name;   determining, by the software component, whether the domain name is listed in a database or is associated with a first category in the database, the database containing at least one domain name or category of domains, each domain name or category associated with a policy; and   when the determination is that the domain name is listed in the database or is associated with a category in the first database, initiating, by the software component, a resolution of the DNS according to a policy from the associated with the domain name or the category in the database, wherein:   when the policy indicates that privacy is not a consideration in the first connection, proceeding with the processing of the DNS request;   when the policy indicates that privacy is a consideration in the first connection, determining, by the software component using at least one of information associated with the DNS request or information associated with the domain name in the database, whether a first level of privacy associated with the first connection is at least equal to a second level of privacy required by the policy, and:
 when the first level of privacy is at least equal to the second level of privacy, proceeding with the processing of the DNS request, or 
 when the first level of privacy is less than the second level of privacy, causing, by the software component, the application to create a second connection to a domain associated with the domain name, the second connection providing at least the required level of privacy. 
   
     
     
         16 . The system of  claim 15 , wherein the database includes a first plurality of domain names or first category for which the policy requires the first connection to have a specified level of privacy. 
     
     
         17 . The system of  claim 16 , wherein the specified level of privacy specifies one of: use of a transport layer security (TLS) protocol; use of an encrypted signal name indication (ESNI) protocol; or use of a virtual private network (VPN). 
     
     
         18 . The system of  claim 15  further comprising:
 monitoring, by the software component, traffic associated with the first connection or the second connection; 
 determining, by the software component, from the monitored traffic that a protocol associated with the required level of privacy is not being followed; and 
 causing, by the software component, a change to a third connection providing the required level of privacy. 
 
     
     
         19 . The system of  claim 15  further comprising:
 monitoring, by the software component, traffic associated with the first connection or the second connection; 
 determining, by the software component, from the monitored traffic that a protocol associated with the required level of privacy is not being followed; and 
 initiating, by the software component, an update to the database reflect that the protocol is not followed in communications to the domain. 
 
     
     
         20 . The system of  claim 15 , wherein, when processing the DNS request results in a determination that an IP address associated with the domain name is also associated with additional domain names, the method further comprises:
 substituting, by the software component, a smaller time-to-live (TTL) value for an initial TTL value associated with the IP address;   providing, by the software component, the smaller TTL value to the application along with the IP address.

Join the waitlist — get patent alerts

Track US2021258350A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.