DNSSEC Proxying for Secure Domain Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional DNS systems are insecure and unable to handle DNSSEC key management, dynamic updates, and global server load balancing, leading to vulnerabilities in domain name resolution and authentication.

Innovation Solution

A traffic management device that forwards domain name requests, attaches signatures to unauthenticated responses, and provides authenticated DNSSEC responses, enabling real-time signing and secure key management, including FIPS-compliant storage and synchronization of private keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNSSEC is deployed to secure domain name resolution, then security and authentication are improved, but system complexity and key management burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management server as an intermediary between DNS servers and DNSSEC operations. This server handles key generation, storage, rotation, and distribution automatically, eliminating the need for manual key management at individual DNS servers while maintaining DNSSEC security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automated key management where the key management server performs self-service operations including automatic key generation, cryptographic signing of DNS records, key rotation, and expiration management without human intervention, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual key management is used for DNSSEC, then security control is improved, but operational efficiency and scalability deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The key management server implements self-service automation for all key management tasks including generation, distribution, rotation, and revocation of cryptographic keys. The system automatically signs DNS records and manages key lifecycles, eliminating manual operations while maintaining security controls through automated policies and procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates monitoring and feedback mechanisms that track key usage, expiration dates, and security events. The key management server automatically responds to feedback by rotating keys before expiration, alerting administrators to security events, and adjusting key management policies based on system performance and security requirements.

Inventive Principle:
Principle #23Feedback

3Reliability

If DNSSEC signatures are attached to all responses, then authentication is improved, but response time and processing overhead increase

Engineering Contradiction:
ImproveauthenticationVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key management server performs preliminary actions by pre-generating and caching cryptographic keys and signatures before they are needed. DNS records are signed in advance and signatures are cached, so when DNS queries arrive, authenticated responses can be returned quickly without real-time signing overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies DNSSEC signatures selectively rather than to all DNS responses. The key management server identifies which DNS records require authentication and applies signatures only to those records, reducing overall processing overhead while maintaining security for critical authenticated zones.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUSRE47019E1Methods for DNSSEC proxying and deployment amelioration and systems thereof
Publication Date: 2018.08.28 F5 NETWORKS INC
  • USRE47019E1 patent drawing
  • USRE47019E1 patent drawing
  • USRE47019E1 patent drawing

AI summary

A method, computer readable medium, and device for providing authenticated domain name service includes forwarding at a traffic management device a request for a domain name from a client device to one or more servers coupled to the traffic management device. The traffic management device receives a first response comprising at least a portion of the domain name from the one or more servers. The traffic management device attaches a first signature to the first response when the first response is determined by the traffic management device to be an unauthenticated response, and provides the first response with the first signature to the client device.