DNS Service Negotiation via Out-of-Band Visibility Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing DNS ecosystem limits visibility and analysis of client behavior due to unilateral decisions by intermediaries, which reduces the information available for authoritative servers, compromising security threat detection and domain name industry metrics.

Innovation Solution

Implementing an in-band communication channel for DNS services and establishing out-of-band communication channels to negotiate and exchange DNS service terms, allowing intermediaries and authoritative servers to communicate capabilities and preferences in real-time or near real-time, thereby enhancing visibility and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If intermediaries make unilateral decisions to limit information sharing, then privacy is protected, but visibility and analysis of client behavior are reduced

Engineering Contradiction:
Improvevisibility of client behaviorVSAvoidprivacy loss
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an out-of-band communication channel as an intermediary mechanism that enables authoritative servers to negotiate information sharing terms with intermediaries without directly exposing client data. This mediator channel allows metadata exchange about client behavior patterns while maintaining the privacy-protecting filtering function of intermediaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback loop where authoritative servers receive aggregated metadata from multiple intermediaries through out-of-band channels, analyze security threats and client behavior trends, and use this feedback to improve DNS service security and performance while preserving intermediary autonomy.

Inventive Principle:
Principle #23Feedback

2Loss of information

If out-of-band communication channels are established for negotiating service terms, then information exchange is enhanced, but device complexity increases

Engineering Contradiction:
Improveinformation exchange capabilityVSAvoidcommunication channel complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments communication into two distinct channels: in-band channels for DNS service operations and out-of-band channels for service term negotiations. This segmentation allows each channel to be optimized for its specific purpose, reducing the complexity burden on any single communication path.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to DNS communication by introducing out-of-band channels that operate parallel to the traditional in-band DNS query-response pathway. This dimensional addition enables metadata exchange without interfering with the core DNS resolution function.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If comprehensive client behavior data is collected at authoritative servers, then security threat detection is improved, but latency increases due to additional communication overhead

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential metadata needed for security analysis from client behavior data, rather than transmitting complete detailed logs. This extraction approach provides sufficient information for threat detection while minimizing communication overhead and latency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by having intermediaries selectively share metadata about suspicious or anomalous client behavior patterns rather than all client interactions. This partial sharing achieves security objectives while reducing the volume of data exchanged and associated latency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12531828B2Balancing visibility in the domain name system
Publication Date: 2026.01.20 VERISIGN INC
  • US12531828B2 patent drawing
  • US12531828B2 patent drawing
  • US12531828B2 patent drawing

AI summary

Systems and methods for out-of-band communications in the domain name system (DNS) are disclosed. Embodiments include a system for negotiating DNS services in the DNS. The system includes an in-band communication channel connecting a first party and a second party, and one or more out-of-band communication channels connecting the first party and the second party. The first party performs messaging for the DNS services with the second party using the in-band communication channel. Further, the first party advertises terms of the DNS service offered by the second party using the one or more out-of-band communication channels.