Cloud DNSSEC Signing Platform for Multi-User Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNSSEC implementations require users to manage hardware-based key management and signing appliances, which are complex, costly, and limited to single-user setups, failing to provide scalable and user-friendly solutions for multiple users and zones.

Innovation Solution

A cloud-based DNSSEC Signing Cloud system that allows remote users to manage and sign DNS zones without requiring on-site hardware, using a scalable and highly available platform for key management and zone signing, enabling multiple users to manage their zones with reduced complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based key management and signing appliances are used, then security and integrity of DNS data is maintained, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity and integrityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management and zone signing functions from local hardware appliances and relocates them to a centralized cloud-based system. This allows users to maintain security and integrity through remote DNSSEC signing while eliminating the complexity of on-site hardware management. The cloud system handles cryptographic operations remotely, extracting the complex functionality from individual user devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based signing cloud as an intermediary between DNS zone masters and resolvers. This intermediary system performs the complex cryptographic signing operations remotely, mediating between the need for strong security and the desire to simplify local device complexity. The signing cloud acts as a mediator that provides secure signing without requiring complex local infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based key management appliances are deployed, then DNSSEC security is ensured, but scalability to multiple users is limited

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal cloud-based signing cloud that serves multiple users and zones through a single scalable platform. Instead of requiring separate hardware appliances for each user, the system provides multi-functional service where one cloud infrastructure can securely sign zones for numerous different users simultaneously, achieving both security and scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transitions from a horizontal scaling approach (adding more separate hardware appliances to serve more users) to a vertical scaling approach (using a single cloud platform that can dynamically allocate resources to multiple users). This dimensional change allows the system to serve multiple users without proportionally increasing physical infrastructure complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If on-site hardware appliances are used, then zone signing functionality is provided, but ease of operation is reduced

Engineering Contradiction:
Improvezone signing functionalityVSAvoidease of operation
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements a self-service model where users can easily manage their zone signing through remote access to the cloud-based system. Users interact with simplified web interfaces or APIs to configure and manage their zones, while the complex cryptographic operations are automatically handled by the cloud system in the background, significantly improving ease of operation while maintaining full functionality.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8645701B2System and method for zone signing and key management in a DNS system
Publication Date: 2014.02.04 VERISIGN INC
  • US8645701B2 patent drawing
  • US8645701B2 patent drawing
  • US8645701B2 patent drawing

AI summary

Methods and systems for signing a DNS zone file and managing zone file signing are provided. An indication of a first DNS zone to be signed is received from one of several remote users, where each such remote user has control over a separate DNS zone. Unsigned zone data is retrieved for the first DNS zone to be signed and is cryptographically signed. The signed zone data is provided to a signed zone master for propagation to one or more DNS servers.