Delegation Chain for Secure Domain Name Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication architectures face challenges in securely delegating a data server identifier from a source domain to a terminal, as they often require sharing private keys between domains, which is insecure, and lack control over the reliability of data access before or after connection, especially in complex network setups with multiple domains involved in content delivery.

Innovation Solution

A method that involves a delegation chain, where a terminal receives an information message with the data server identifier and a series of redirections from a second domain to the first domain, allowing the terminal to verify the authenticity and authorization of the data server, eliminating the need for private key sharing and enabling secure content delivery across multiple domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private keys are shared between domains to enable secure content delivery, then security is improved, but security risks worsen due to the confidentiality problems associated with private key transmission

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security verification process into multiple independent domains forming a delegation chain. Instead of sharing private keys between all domains, each domain in the chain maintains its own security credentials and independently verifies the next domain, eliminating the need for widespread private key distribution while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate domains as mediators in the delegation chain. These intermediaries facilitate secure content delivery by verifying the authenticity of subsequent domains without requiring direct private key sharing between all parties. The terminal uses these intermediaries to indirectly verify the source domain's authorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple domains are involved in content delivery, then adaptability is improved, but control over reliability worsens due to lack of a priori control of the source domain

Engineering Contradiction:
Improveflexibility in content deliveryVSAvoidcontrol over source domain
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary verification actions by requiring the terminal to validate the entire delegation chain before connecting to the data server. The terminal checks the authenticity and authorization of each domain in the chain a priori, ensuring control over the source domain's legitimacy before any content delivery occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism where the terminal verifies each domain's authorization credentials in the delegation chain. This feedback loop ensures that only properly authorized domains can deliver content, maintaining reliability while allowing multiple domains to participate in the delivery process.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If private key sharing is implemented between domains, then ease of operation is improved, but device complexity worsens due to the need for secure key management infrastructure

Engineering Contradiction:
Improvesimplicity of content deliveryVSAvoidkey management infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the private key sharing requirement from the system by replacing it with a public key infrastructure-based delegation chain. Each domain publishes its public key or certificate, and the terminal verifies authenticity using these public credentials, completely eliminating the need for private key distribution and complex key management infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

4Productivity

If domain delegation is implemented without verification, then productivity is improved, but reliability worsens due to inability to check content origin

Engineering Contradiction:
Improvespeed of content deliveryVSAvoidverification of content origin
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a streamlined verification process that checks only the essential elements of the delegation chain (authenticity and authorization of each domain) rather than performing exhaustive verification of all possible attributes. This partial verification approach maintains fast content delivery while ensuring sufficient reliability to verify content origin.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11575644B2Method for acquiring a delegation chain relating to resolving a domain name identifier in a communication network
Publication Date: 2023.02.07 ORANGE SA
  • US11575644B2 patent drawing
  • US11575644B2 patent drawing
  • US11575644B2 patent drawing

AI summary

A method and a device for acquiring an identifier of a data server able to deliver content to a terminal. The method is executed by the terminal, which transmits, to a resolution server of a communication architecture, a message requesting to obtain an identifier of the data server in the second domain. This request message triggers reception, from the resolution server, of an information message includes the identifier of the data server in a first domain. This message furthermore includes a delegation chain, which includes a sequence of redirections from the second domain to the first domain.