DNS-Based Security Seal Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security seal systems on the Internet lack efficiency and scalability in providing real-time verification of web site security, leading to a need for improved methods to enhance user trust and site security visibility.

Innovation Solution

A method and system utilizing DNS queries to verify web site trust services, such as SSL certificates, by parsing DNS queries, accessing DNS zone files, and transmitting identifiers to display security seals next to search results, leveraging existing DNS infrastructure for rapid and scalable verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security seal systems are used to verify web site security, then user trust is provided, but efficiency and scalability are insufficient for real-time verification

Engineering Contradiction:
Improveuser trustVSAvoidverification efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies universality by making the DNS infrastructure perform multiple functions: its original domain name resolution function plus the new function of security verification. The DNS system is enhanced to return both domain resolution information and security seal information through the same query mechanism, eliminating the need for separate verification systems and improving both efficiency and reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses an intermediary approach by introducing a seal verification server that mediates between the DNS system and clients. This server receives DNS queries, checks them against a database of secure domains, and returns appropriate seal information. The intermediary handles the complexity of verification while keeping the DNS system simple and efficient

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security verification methods are implemented, then security information can be provided, but maintenance costs are high and scalability is limited

Engineering Contradiction:
Improvesecurity verificationVSAvoidmaintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the DNS system to automatically verify domain security status without requiring manual intervention. The seal verification server automatically queries the database, compares domain names, and returns seal information. This automated approach reduces maintenance complexity while maintaining high reliability of security verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-populating a database with secure domain names and their associated seal information before verification is needed. When a DNS query arrives, the system simply checks against this pre-prepared database rather than performing complex real-time analysis, reducing both maintenance complexity and improving verification speed

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security seals are displayed on web pages, then user trust is enhanced, but the system lacks rapid response capability

Engineering Contradiction:
Improveuser trustVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the domain name resolution process with the security verification process into a single DNS query operation. Instead of first resolving the domain name and then separately verifying security, both operations are combined into one query that returns both the resolved address and the security seal information simultaneously, eliminating time loss while maintaining user trust

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8407802B2Method and system for providing security seals on web pages
Publication Date: 2013.03.26 DIGICERT INC
  • US8407802B2 patent drawing
  • US8407802B2 patent drawing
  • US8407802B2 patent drawing

AI summary

A method of providing web site verification information to a user includes receiving a DNS query including a host name and a seal verification site name, parsing the DNS query, and extracting the host name from the DNS query. The method also includes accessing a DNS zone file including a list of Trust Services customers and determining if the host name is associated with a Trust Services customer in the list of Trust Services customers. The method further includes transmitting a positive identifier to the requester if the host name is associated with a Trust Services customer and transmitting a negative identifier to the requester if the host name is not associated with a Trust Services customer. In a specific embodiment, the Trust Services include issuance of digital certificates.