DNS Privacy via Location Assertion Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Domain Name System (DNS) and Registration Data Access Protocol (RDAP) technologies face challenges in preserving the privacy of registrants, particularly due to conflicting legal requirements regarding the storage and exposure of personally identifying information (PII) across jurisdictions, especially in the EU, where the disclosure of personal data is restricted and storage outside the EU is regulated.
Innovation Solution
The implementation of a method that uses location assertions to verify the identity and location of users, allowing for the secure and compliant collection, storage, and exposure of PII, by generating verifiable location assertions on user devices, which are then used to determine the applicable legal jurisdiction for data handling and ensure compliance with privacy laws, employing cryptographic signatures and trusted on-device authentication services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If the DNS registry stores and exposes personally identifying information (PII) of registrants, then the availability of registration data is improved, but the privacy protection of registrants deteriorates
Solution Approach 1:
The patent introduces a location assertion service as an intermediary between the DNS registry and external entities. This service verifies the location of entities requesting PII using cryptographic location assertions, allowing the registry to selectively disclose information based on verified location criteria rather than disclosing all PII unconditionally, thus balancing availability with privacy protection
Solution Approach 2:
The patent applies different data handling policies based on the verified location of requesting entities. By determining the legal jurisdiction through location assertions, the system provides different levels of PII access rights according to local laws and regulations, allowing compliant data exposure in certain jurisdictions while restricting it in others
2Loss of information
If the DNS registry collects and stores PII of registrants, then the completeness of registration data is improved, but the compliance with cross-jurisdictional privacy laws deteriorates
Solution Approach 1:
The patent implements dynamic compliance checking where the registry's data handling behavior changes based on the verified location of requesting entities. The system dynamically determines which PII can be disclosed and under what conditions, allowing the registry to maintain complete data collection while adapting its disclosure policies to comply with different jurisdictional privacy laws
Solution Approach 2:
The location assertion service provides feedback to the registry about the legal jurisdiction and compliance requirements of requesting entities. This feedback mechanism enables the registry to adjust its data exposure decisions in real-time based on verified location information, ensuring compliance with applicable privacy laws while maintaining data completeness
3Measurement precision
If the system verifies location of entities requesting PII, then the accuracy of location-based access control is improved, but the complexity of the verification system deteriorates
Solution Approach 1:
The patent uses cryptographic location assertions that contain verified location information as a copy or representation of the entity's location state. These assertions serve as self-contained verification tokens that the registry can validate without complex real-time location tracking systems, achieving accurate location-based access control through verified location data copies
Solution Approach 2:
The location assertion service performs preliminary verification of location claims before the registry needs to make data access decisions. By pre-verifying location assertions and validating cryptographic proofs in advance, the system reduces the complexity of real-time verification while maintaining high accuracy in location-based access control
Data Source
AI summary
A method and a computer system is provided for executing the method for providing a registration data directory service (RDDS). The method includes obtaining, at a RDDS, a RDDS query comprising a location assertion from a RDDS client from a RDDS client; providing, by the RDDS, a request for personally identifying information (PII) for the RDDS query from a privacy provider, wherein the request comprises the location assertion; obtaining, by the RDDS, the PII for the RDDS query; and providing, by the RDDS, a response to the RDDS query to the RDDS client, wherein the response comprises PII.


