| CPC H04L 63/0876 (2013.01) [G16Y 30/10 (2020.01); H04L 61/4511 (2022.05); H04L 63/0823 (2013.01); H04L 63/083 (2013.01); H04L 63/166 (2013.01); H04L 2101/663 (2022.05)] | 20 Claims | 

| 
               1. A method of an endpoint device accessing a trusted domain name system (DNS) server, comprising: 
            provisioning to the endpoint device a client identity certificate for the endpoint device and a server certificate for the trusted DNS server; 
                connecting to an untrusted wireless access point (WAP); 
                using a DNS resolver of the untrusted WAP to resolve an address for the trusted DNS server; 
                creating a local proxy to the trusted DNS server, comprising authenticating the trusted DNS server via the client identity certificate and the server certificate; and 
                tunneling DNS traffic of the endpoint device to the trusted DNS server via the local proxy. 
               |