DNS Privacy via Cloaked Identifier Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Domain Name System (DNS) technologies face challenges in preserving the privacy of registrants due to conflicting legal requirements and international laws restricting the storage and exposure of personal information, particularly in jurisdictions like the EU, where Thick Whois providers are required to collect and store personal data, which may not be compliant with local regulations.

Innovation Solution

A method is introduced where a registrar delegates personal information collection to privacy providers located in jurisdictions where it is legal to store such information, generating a 'cloaked identifier' that can be used to provision named resources in a DNS registry without revealing the registrant's true identity, utilizing secure/multipurpose internet mail extensions (S/MIME) A-type DNS resource records for secure registration and communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Thick Whois providers collect and store personal information from registrants, then domain name registration functionality is provided, but compliance with privacy laws and international data storage regulations deteriorates

Engineering Contradiction:
Improvedomain name registration functionalityVSAvoidcompliance with privacy laws
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a privacy provider as an intermediary between the registrar and the registrant. The privacy provider collects and stores the registrant's personal information in jurisdictions compliant with privacy laws, while the registrar only receives a cloaked identifier. This intermediary structure allows domain registration functionality to proceed while ensuring compliance with GDPR and other international data protection regulations by preventing unauthorized access to personal information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the domain registration process into two distinct parts: (1) collection and storage of personal information by the privacy provider in compliant jurisdictions, and (2) provision of cloaked identifiers to the registrar for domain registration. This segmentation separates the sensitive personal data handling from the domain registration functionality, allowing each component to operate within its legal boundaries.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If personal information is stored in registrars and registries, then domain name provisioning is enabled, but registrant privacy protection deteriorates

Engineering Contradiction:
Improvedomain name provisioningVSAvoidprivacy exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The privacy provider acts as a mediator that holds the registrant's personal information securely while providing only a cloaked identifier to the registrar and registry. This intermediary structure enables domain name provisioning to function normally while preventing direct exposure of the registrant's personal information to parties that do not need access to it.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the registrant's identity in the form of a cloaked identifier that can be used for domain registration and communication purposes. This copy allows the registrant to interact with the DNS system without revealing their true personal information, thereby protecting privacy while maintaining functionality.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If cloaked identifiers are used to protect privacy, then registrant privacy is preserved, but system complexity increases due to additional privacy providers and coordination

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

While the privacy provider intermediary adds a component to the system, it simplifies the overall architecture by centralizing personal information management in one location that complies with privacy laws. Rather than requiring multiple registrars and registries to implement their own complex privacy protection measures, the single privacy provider handles all personal data securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The privacy provider operates as a self-service system that automatically generates cloaked identifiers and manages personal information storage without requiring complex coordination between multiple parties. The registrar simply interacts with the privacy provider through standardized interfaces to obtain cloaked identifiers for domain registration.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10979384B2Systems and methods for preserving privacy of a registrant in a Domain Name System (“DNS”)
Publication Date: 2021.04.13 VERISIGN INC
  • US10979384B2 patent drawing
  • US10979384B2 patent drawing
  • US10979384B2 patent drawing

AI summary

Provided is a method of provisioning a named resource in a domain name system (“DNS”) with a registrar while preserving privacy of a registrant. The method includes obtaining, by a server of the registrar over a network, a request, from the registrant, to provision the named resource; determining, by at least one hardware processor of the server of the registrar, that the request requires additional handling by a privacy provider based on information in the request or information from the registrar; determining, by at least one hardware processor of the server of the registrar, a privacy provider from one or more privacy providers located in different geographic locations to service the request based on a location of the registrant; forwarding the request to the privacy provider; obtaining a cloaked identifier from the privacy provider; and provisioning the named resource in a database of a DNS registry using the cloaked identifier.