DNS Privacy via Location Assertion Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Domain Name System (DNS) and Registration Data Access Protocol (RDAP) technologies face challenges in preserving the privacy of registrants, particularly due to conflicting legal requirements regarding the storage and exposure of personally identifying information (PII) across jurisdictions, especially in the EU, where the disclosure of personal data is restricted and storage outside the EU is regulated.

Innovation Solution

The implementation of a method that uses location assertions to verify the identity and location of users, allowing for the secure and compliant collection, storage, and exposure of PII, by generating verifiable location assertions on user devices, which are then used to determine the applicable legal jurisdiction for data handling and ensure compliance with privacy laws, employing cryptographic signatures and trusted on-device authentication services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the DNS registry stores and exposes personally identifying information (PII) of registrants, then the availability of registration data is improved, but the privacy protection of registrants deteriorates

Engineering Contradiction:
Improveavailability of registration dataVSAvoidprivacy protection of registrants
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a location assertion service as an intermediary between the DNS registry and external entities. This service verifies the location of entities requesting PII using cryptographic location assertions, allowing the registry to selectively disclose information based on verified location criteria rather than disclosing all PII unconditionally, thus balancing availability with privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different data handling policies based on the verified location of requesting entities. By determining the legal jurisdiction through location assertions, the system provides different levels of PII access rights according to local laws and regulations, allowing compliant data exposure in certain jurisdictions while restricting it in others

Inventive Principle:
Principle #3Local quality

2Loss of information

If the DNS registry collects and stores PII of registrants, then the completeness of registration data is improved, but the compliance with cross-jurisdictional privacy laws deteriorates

Engineering Contradiction:
Improvecompleteness of registration dataVSAvoidcompliance with privacy laws
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements dynamic compliance checking where the registry's data handling behavior changes based on the verified location of requesting entities. The system dynamically determines which PII can be disclosed and under what conditions, allowing the registry to maintain complete data collection while adapting its disclosure policies to comply with different jurisdictional privacy laws

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The location assertion service provides feedback to the registry about the legal jurisdiction and compliance requirements of requesting entities. This feedback mechanism enables the registry to adjust its data exposure decisions in real-time based on verified location information, ensuring compliance with applicable privacy laws while maintaining data completeness

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the system verifies location of entities requesting PII, then the accuracy of location-based access control is improved, but the complexity of the verification system deteriorates

Engineering Contradiction:
Improveaccuracy of location-based access controlVSAvoidcomplexity of verification system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses cryptographic location assertions that contain verified location information as a copy or representation of the entity's location state. These assertions serve as self-contained verification tokens that the registry can validate without complex real-time location tracking systems, achieving accurate location-based access control through verified location data copies

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The location assertion service performs preliminary verification of location claims before the registry needs to make data access decisions. By pre-verifying location assertions and validating cryptographic proofs in advance, the system reduces the complexity of real-time verification while maintaining high accuracy in location-based access control

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230327888A1Systems and methods for preserving privacy of a registrant in a domain name system ("DNS")
Publication Date: 2023.10.12 VERISIGN INC
  • US20230327888A1 patent drawing
  • US20230327888A1 patent drawing
  • US20230327888A1 patent drawing

AI summary

A method and a computer system is provided for executing the method for providing a registration data directory service (RDDS). The method includes obtaining, at a RDDS, a RDDS query comprising a location assertion from a RDDS client from a RDDS client; providing, by the RDDS, a request for personally identifying information (PII) for the RDDS query from a privacy provider, wherein the request comprises the location assertion; obtaining, by the RDDS, the PII for the RDDS query; and providing, by the RDDS, a response to the RDDS query to the RDDS client, wherein the response comprises PII.