Delegation Chain for Secure Domain Name Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication architectures face challenges in securely delegating a data server identifier from a source domain to a terminal, as they often require sharing private keys between domains, which is insecure, and lack control over the reliability of data access before or after connection, especially in complex network setups with multiple domains involved in content delivery.
Innovation Solution
A method that involves a delegation chain, where a terminal receives an information message with the data server identifier and a series of redirections from a second domain to the first domain, allowing the terminal to verify the authenticity and authorization of the data server, eliminating the need for private key sharing and enabling secure content delivery across multiple domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private keys are shared between domains to enable secure content delivery, then security is improved, but security risks worsen due to the confidentiality problems associated with private key transmission
Solution Approach 1:
The patent segments the security verification process into multiple independent domains forming a delegation chain. Instead of sharing private keys between all domains, each domain in the chain maintains its own security credentials and independently verifies the next domain, eliminating the need for widespread private key distribution while maintaining security.
Solution Approach 2:
The patent introduces intermediate domains as mediators in the delegation chain. These intermediaries facilitate secure content delivery by verifying the authenticity of subsequent domains without requiring direct private key sharing between all parties. The terminal uses these intermediaries to indirectly verify the source domain's authorization.
2Adaptability or versatility
If multiple domains are involved in content delivery, then adaptability is improved, but control over reliability worsens due to lack of a priori control of the source domain
Solution Approach 1:
The patent implements preliminary verification actions by requiring the terminal to validate the entire delegation chain before connecting to the data server. The terminal checks the authenticity and authorization of each domain in the chain a priori, ensuring control over the source domain's legitimacy before any content delivery occurs.
Solution Approach 2:
The patent establishes a feedback mechanism where the terminal verifies each domain's authorization credentials in the delegation chain. This feedback loop ensures that only properly authorized domains can deliver content, maintaining reliability while allowing multiple domains to participate in the delivery process.
3Ease of operation
If private key sharing is implemented between domains, then ease of operation is improved, but device complexity worsens due to the need for secure key management infrastructure
Solution Approach 1:
The patent extracts the private key sharing requirement from the system by replacing it with a public key infrastructure-based delegation chain. Each domain publishes its public key or certificate, and the terminal verifies authenticity using these public credentials, completely eliminating the need for private key distribution and complex key management infrastructure.
4Productivity
If domain delegation is implemented without verification, then productivity is improved, but reliability worsens due to inability to check content origin
Solution Approach 1:
The patent implements a streamlined verification process that checks only the essential elements of the delegation chain (authenticity and authorization of each domain) rather than performing exhaustive verification of all possible attributes. This partial verification approach maintains fast content delivery while ensuring sufficient reliability to verify content origin.
Data Source
AI summary
A method and a device for acquiring an identifier of a data server able to deliver content to a terminal. The method is executed by the terminal, which transmits, to a resolution server of a communication architecture, a message requesting to obtain an identifier of the data server in the second domain. This request message triggers reception, from the resolution server, of an information message includes the identifier of the data server in a first domain. This message furthermore includes a delegation chain, which includes a sequence of redirections from the second domain to the first domain.


