Token-Based DNS Record Update Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS systems face challenges in allowing third-party DNS service providers to programmatically initiate changes to DNS resource records, as they rely on manual processes through registrants, leading to errors and lack of direct communication with registrars or registries.

Innovation Solution

Implementing a method that allows DNS service providers to authenticate using digital certificates or access tokens to directly interact with registrars or registries, enabling them to programmatically update DNS resource records, such as NS, DS, MX, and DNSSEC records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes through registrants are used to initiate changes to DNS resource records, then third-party DNS service providers can make changes, but errors increase and reliability decreases

Engineering Contradiction:
ImprovereliabilityVSAvoidautomation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism (access tokens or digital certificates) that mediates between third-party DNS service providers and registrars/registries. This intermediary system enables automated changes while maintaining security, resolving the contradiction by allowing automation without directly exposing registrar/registry systems to untrusted automated access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual processes through registrants are used to initiate changes to DNS resource records, then changes can be made, but time consumption increases and efficiency decreases

Engineering Contradiction:
ImproveefficiencyVSAvoidautomation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent enables third-party DNS service providers to autonomously initiate and complete DNS record changes through automated authentication with registrars or registries. The system allows these providers to self-service DNS management tasks without requiring registrant intervention, thereby improving productivity while implementing automation.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If direct communication channels between DNS service providers and registrars/registries are established, then automation is enabled, but system complexity increases

Engineering Contradiction:
ImproveautomationVSAvoidcomplexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework using access tokens or digital certificates that can be used across different registrars and registries. This multi-functional authentication mechanism enables automated communication between DNS service providers and various registrars/registries without requiring provider-specific implementations, thereby managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If automated authentication using access tokens or digital certificates is implemented, then security is improved, but authentication process complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication actions where DNS service providers obtain access tokens or digital certificates before initiating DNS record changes. This preliminary authentication step establishes security credentials in advance, allowing subsequent automated operations to proceed securely without repeating complex authentication sequences, thereby managing complexity through pre-established trust relationships.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20180063141A1Integrated DNS service provider services using token-based authentication
Publication Date: 2018.03.01 VERISIGN INC
  • US20180063141A1 patent drawing
  • US20180063141A1 patent drawing
  • US20180063141A1 patent drawing

AI summary

Techniques for allowing third-party DNS service providers to programmatically initiate changes to DNS resource records using an interface provided by a registrar or registry are disclosed. Further, techniques for validating change requests received at such an interface are disclosed. The disclosed techniques reduce errors and increase convenience.