DNS Service Negotiation via Out-of-Band Visibility Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing DNS ecosystem limits visibility and analysis of client behavior due to unilateral decisions by intermediaries, which reduces the information available for authoritative servers, compromising security threat detection and domain name industry metrics.
Innovation Solution
Implementing an in-band communication channel for DNS services and establishing out-of-band communication channels to negotiate and exchange DNS service terms, allowing intermediaries and authoritative servers to communicate capabilities and preferences in real-time or near real-time, thereby enhancing visibility and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If intermediaries make unilateral decisions to limit information sharing, then privacy is protected, but visibility and analysis of client behavior are reduced
Solution Approach 1:
The patent introduces an out-of-band communication channel as an intermediary mechanism that enables authoritative servers to negotiate information sharing terms with intermediaries without directly exposing client data. This mediator channel allows metadata exchange about client behavior patterns while maintaining the privacy-protecting filtering function of intermediaries.
Solution Approach 2:
The patent implements a feedback loop where authoritative servers receive aggregated metadata from multiple intermediaries through out-of-band channels, analyze security threats and client behavior trends, and use this feedback to improve DNS service security and performance while preserving intermediary autonomy.
2Loss of information
If out-of-band communication channels are established for negotiating service terms, then information exchange is enhanced, but device complexity increases
Solution Approach 1:
The patent segments communication into two distinct channels: in-band channels for DNS service operations and out-of-band channels for service term negotiations. This segmentation allows each channel to be optimized for its specific purpose, reducing the complexity burden on any single communication path.
Solution Approach 2:
The patent adds a new dimension to DNS communication by introducing out-of-band channels that operate parallel to the traditional in-band DNS query-response pathway. This dimensional addition enables metadata exchange without interfering with the core DNS resolution function.
3Reliability
If comprehensive client behavior data is collected at authoritative servers, then security threat detection is improved, but latency increases due to additional communication overhead
Solution Approach 1:
The patent extracts only the essential metadata needed for security analysis from client behavior data, rather than transmitting complete detailed logs. This extraction approach provides sufficient information for threat detection while minimizing communication overhead and latency.
Solution Approach 2:
The patent implements partial action by having intermediaries selectively share metadata about suspicious or anomalous client behavior patterns rather than all client interactions. This partial sharing achieves security objectives while reducing the volume of data exchanged and associated latency.
Data Source
AI summary
Systems and methods for out-of-band communications in the domain name system (DNS) are disclosed. Embodiments include a system for negotiating DNS services in the DNS. The system includes an in-band communication channel connecting a first party and a second party, and one or more out-of-band communication channels connecting the first party and the second party. The first party performs messaging for the DNS services with the second party using the in-band communication channel. Further, the first party advertises terms of the DNS service offered by the second party using the one or more out-of-band communication channels.


