DNS-Based PKI for Digital Object Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital object architectures (DOA) lack a globally-trusted mechanism for establishing trust between entities, making them vulnerable to malicious attacks and compromising the security of digital object access in distributed systems.

Innovation Solution

Implementing a DNS-based public key infrastructure (PKI) that associates domain names with digital object handle identifiers, using attestations to bind public keys to domain names and handle identifiers, thereby establishing trust through a trusted PKI.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a digital object architecture (DOA) is implemented without a globally-trusted mechanism, then the system maintains simplicity and decentralization, but the system becomes vulnerable to malicious attacks and cannot establish trust between entities

Engineering Contradiction:
Improvetrust establishmentVSAvoidPKI infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a globally-trusted public key infrastructure (PKI) as an intermediary mechanism that mediates trust between entities in the DOA. The PKI uses domain name system (DNS) records to store and verify public keys, acting as a neutral mediator that enables secure authentication without requiring direct trust relationships between all entities. This resolves the contradiction by providing reliable trust establishment through a centralized intermediary while maintaining the decentralized nature of the DOA.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the DNS system serve multiple functions: its traditional role in domain name resolution plus a new role as a trusted repository for public keys and authentication data. By adding this universal functionality to the existing DNS infrastructure, the system gains reliable trust establishment capabilities without adding a completely separate complex system. The DNS now performs both naming resolution and security authentication functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If DNS-based PKI is implemented to establish trust, then authentication and verification of digital objects is secured, but the complexity of the system increases due to integration of PKI infrastructure

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the PKI infrastructure with the existing DNS system by storing public keys, attestation data, and authentication information directly in DNS records. This combination allows the system to leverage the widespread adoption and familiarity of DNS while incorporating security functions. The merger reduces overall system complexity compared to maintaining separate PKI and DNS infrastructures, as it consolidates multiple functions into a single integrated system.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If attestations are used to bind public keys to domain names and handle identifiers, then the authenticity and ownership of digital objects is verified, but the process of establishing and verifying trust relationships becomes more complex

Engineering Contradiction:
Improveownership verificationVSAvoidtrust verification process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the DNS system automatically provides verification of public keys and attestations without requiring manual intervention. When a client needs to verify a digital object's authenticity, the system automatically queries the DNS for the relevant public key and attestation data, performs verification, and proceeds with authentication. This automated self-service approach simplifies the operation despite the complexity of the underlying trust verification processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11533161B1DNS-based public key infrastructure for digital object architectures
Publication Date: 2022.12.20 VERISIGN INC
  • US11533161B1 patent drawing
  • US11533161B1 patent drawing
  • US11533161B1 patent drawing

AI summary

One embodiment of the present application sets forth a computer-implemented method for establishing trust for handles used to identify digital objects in a digital object architecture (DOA) by associating a first attester identifier with a first attester from a trusted public key infrastructure (PKI), identifying a first digital object public key for a first digital object, generating, by the first attester, a first digital object identity attestation that associates the first digital object public key with a handle identifier for the first digital object, wherein the handle identifier is external to the trusted PKI, and generating a first attester identity attestation attesting that the first attester is authentic, where the first attester identity attestation includes the first attester identifier.