Intermediary Device for DNSSEC Zone Mode Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Domain Name System (DNS) security solutions, such as DNSSEC, face challenges in effectively managing and providing security features across multiple modes of operation in a DNS namespace, particularly in ensuring the integrity and authenticity of data transmitted between clients and servers.

Innovation Solution

An intermediary device is introduced to manage and provide DNSSEC security features to specific modes of operation within a DNS namespace, acting as a intermediary between clients and servers to establish and maintain secure communication channels, utilizing appliances like Citrix NetScaler, F5 Networks' BigIP, and Juniper Networks' DX acceleration devices to accelerate, optimize, and load-balance communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNSSEC security features are implemented across multiple modes of operation, then security and reliability are improved, but device complexity and management difficulty increase

Engineering Contradiction:
ImproveDNS security and data integrityVSAvoidDNSSEC management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary device positioned between DNS clients and servers that centralizes DNSSEC security management. This intermediary handles security operations for multiple modes of operation, reducing the complexity burden on individual DNS servers while maintaining enhanced security across the entire DNS namespace.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DNSSEC is implemented to protect against forged data, then data authenticity is improved, but processing overhead and performance degradation occur

Engineering Contradiction:
ImproveData authenticityVSAvoidDNS query performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The intermediary device performs DNSSEC validation and security operations in advance, before DNS responses are returned to clients. By pre-processing security checks and caching validated results, the system maintains data authenticity while reducing the performance impact on real-time DNS queries.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If DNSSEC security features are provided to multiple modes of operation, then security coverage is improved, but management difficulty increases

Engineering Contradiction:
ImproveSecurity coverage across modesVSAvoidDNSSEC management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The intermediary device is designed to provide universal DNSSEC security management across multiple DNS operation modes (standard DNS, DNS over HTTPS, DNS over TLS, etc.). A single multi-functional platform handles security operations for all modes, eliminating the need for separate management systems and simplifying operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2636210B1Systems and methods for managing domain name system security (dnssec)
Publication Date: 2020.07.15 CITRIX SYSTEMS INC
  • EP2636210B1 patent drawingFigure 1A
  • EP2636210B1 patent drawingFigure 1B
  • EP2636210B1 patent drawingFigure 1C

AI summary

The present invention is directed towards systems and methods for providing multiple modes of a zone for DNSSEC by an intermediary device. The method includes providing, by a device intermediary to a plurality of clients and a plurality of servers, a plurality of modes of a zone for Domain Name Service. The device receives a selection of a first mode of the zone of the plurality of modes of the zone. The device receives information identifying to enable DNS Security for the selected first mode. The device establishes the zone for DNS in accordance with the selected first mode and with DNS Security enabled.