DNS-Based PKI for Digital Object Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital object architectures (DOA) lack a globally-trusted mechanism for establishing trust between entities, making them vulnerable to malicious attacks and compromising the security of digital object access in distributed systems.
Innovation Solution
Implementing a DNS-based public key infrastructure (PKI) that associates domain names with digital object handle identifiers, using attestations to bind public keys to domain names and handle identifiers, thereby establishing trust through a trusted PKI.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a digital object architecture (DOA) is implemented without a globally-trusted mechanism, then the system maintains simplicity and decentralization, but the system becomes vulnerable to malicious attacks and cannot establish trust between entities
Solution Approach 1:
The patent introduces a globally-trusted public key infrastructure (PKI) as an intermediary mechanism that mediates trust between entities in the DOA. The PKI uses domain name system (DNS) records to store and verify public keys, acting as a neutral mediator that enables secure authentication without requiring direct trust relationships between all entities. This resolves the contradiction by providing reliable trust establishment through a centralized intermediary while maintaining the decentralized nature of the DOA.
Solution Approach 2:
The patent makes the DNS system serve multiple functions: its traditional role in domain name resolution plus a new role as a trusted repository for public keys and authentication data. By adding this universal functionality to the existing DNS infrastructure, the system gains reliable trust establishment capabilities without adding a completely separate complex system. The DNS now performs both naming resolution and security authentication functions.
2Reliability
If DNS-based PKI is implemented to establish trust, then authentication and verification of digital objects is secured, but the complexity of the system increases due to integration of PKI infrastructure
Solution Approach 1:
The patent merges the PKI infrastructure with the existing DNS system by storing public keys, attestation data, and authentication information directly in DNS records. This combination allows the system to leverage the widespread adoption and familiarity of DNS while incorporating security functions. The merger reduces overall system complexity compared to maintaining separate PKI and DNS infrastructures, as it consolidates multiple functions into a single integrated system.
3Reliability
If attestations are used to bind public keys to domain names and handle identifiers, then the authenticity and ownership of digital objects is verified, but the process of establishing and verifying trust relationships becomes more complex
Solution Approach 1:
The patent implements self-service authentication where the DNS system automatically provides verification of public keys and attestations without requiring manual intervention. When a client needs to verify a digital object's authenticity, the system automatically queries the DNS for the relevant public key and attestation data, performs verification, and proceeds with authentication. This automated self-service approach simplifies the operation despite the complexity of the underlying trust verification processes.
Data Source
AI summary
One embodiment of the present application sets forth a computer-implemented method for establishing trust for handles used to identify digital objects in a digital object architecture (DOA) by associating a first attester identifier with a first attester from a trusted public key infrastructure (PKI), identifying a first digital object public key for a first digital object, generating, by the first attester, a first digital object identity attestation that associates the first digital object public key with a handle identifier for the first digital object, wherein the handle identifier is external to the trusted PKI, and generating a first attester identity attestation attesting that the first attester is authentic, where the first attester identity attestation includes the first attester identifier.


