DNS Record Updates via Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS systems face challenges in allowing third-party DNS service providers to programmatically initiate changes to DNS resource records without relying on manual human intervention, leading to errors and inefficiencies.

Innovation Solution

Implement a method and system that enable third-party DNS service providers to authenticate using digital certificates or access tokens, allowing them to electronically update DNS resource records through a registrar or registry, ensuring secure and authorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual human intervention is used to initiate changes to DNS resource records, then authorization and control can be maintained, but errors and inefficiencies increase due to manual processes

Engineering Contradiction:
Improveerror-free updatesVSAvoidmanual intervention requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The DNS service provider is empowered to autonomously initiate and execute DNS record changes without requiring manual human intervention. The system uses automated authentication mechanisms where the provider presents credentials (such as DS records or TXT records) that the registrar verifies programmatically, enabling the provider to self-service DNS update operations while maintaining security and authorization controls

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes (human operators physically initiating changes) with automated electronic systems. The authentication and authorization process is substituted from manual verification to automated cryptographic verification using digital certificates, DS records, or TXT records, eliminating human error while maintaining secure control

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If third-party DNS service providers are allowed to programmatically update DNS records, then efficiency increases, but security risks arise from unauthorized changes

Engineering Contradiction:
Improveupdate efficiencyVSAvoidauthorization security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The registrar acts as an intermediary between the DNS service provider and the DNS registry. The registrar receives update requests from the provider, verifies authorization using cryptographic credentials (DS records, TXT records, or digital certificates), and only forwards authenticated requests to the registry. This intermediary mechanism enables efficient automated updates while maintaining security through programmatic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the authorization parameter from manual trust relationships to cryptographic proof parameters. Instead of relying on human operators to verify identities, the system uses cryptographic parameters (public keys, digital signatures, certificate validity) that can be automatically verified by machines, enabling both efficiency and security

Inventive Principle:
Principle #35Parameter changes

3Reliability

If automated authentication using digital certificates is implemented, then security and authorization are strengthened, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that can handle multiple authentication methods (DS records, TXT records, digital certificates) through a common architectural pattern. The registrar uses the same basic verification flow regardless of which authentication method is employed, reducing the perceived complexity by providing a unified interface for diverse authentication mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250211453A1Integrated DNS service provider services using certificate-based authentication
Publication Date: 2025.06.26 VERISIGN INC
  • US20250211453A1 patent drawing
  • US20250211453A1 patent drawing
  • US20250211453A1 patent drawing

AI summary

Techniques for allowing third-party DNS service providers to programmatically initiate changes to DNS resource records using an interface provided by a registrar or registry are disclosed. Further, techniques for validating change requests received at such an interface are disclosed. The disclosed techniques reduce errors and increase convenience.