DNSSEC Proxying for Secure Domain Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional DNS systems are insecure and unable to handle DNSSEC key management, dynamic updates, and global server load balancing, leading to vulnerabilities in domain name resolution and authentication.
Innovation Solution
A traffic management device that forwards domain name requests, attaches signatures to unauthenticated responses, and provides authenticated DNSSEC responses, enabling real-time signing and secure key management, including FIPS-compliant storage and synchronization of private keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNSSEC is deployed to secure domain name resolution, then security and authentication are improved, but system complexity and key management burden increase
Solution Approach 1:
The patent introduces a key management server as an intermediary between DNS servers and DNSSEC operations. This server handles key generation, storage, rotation, and distribution automatically, eliminating the need for manual key management at individual DNS servers while maintaining DNSSEC security requirements.
Solution Approach 2:
The system enables automated key management where the key management server performs self-service operations including automatic key generation, cryptographic signing of DNS records, key rotation, and expiration management without human intervention, reducing operational complexity.
2Reliability
If manual key management is used for DNSSEC, then security control is improved, but operational efficiency and scalability deteriorate
Solution Approach 1:
The key management server implements self-service automation for all key management tasks including generation, distribution, rotation, and revocation of cryptographic keys. The system automatically signs DNS records and manages key lifecycles, eliminating manual operations while maintaining security controls through automated policies and procedures.
Solution Approach 2:
The system incorporates monitoring and feedback mechanisms that track key usage, expiration dates, and security events. The key management server automatically responds to feedback by rotating keys before expiration, alerting administrators to security events, and adjusting key management policies based on system performance and security requirements.
3Reliability
If DNSSEC signatures are attached to all responses, then authentication is improved, but response time and processing overhead increase
Solution Approach 1:
The key management server performs preliminary actions by pre-generating and caching cryptographic keys and signatures before they are needed. DNS records are signed in advance and signatures are cached, so when DNS queries arrive, authenticated responses can be returned quickly without real-time signing overhead.
Solution Approach 2:
The system applies DNSSEC signatures selectively rather than to all DNS responses. The key management server identifies which DNS records require authentication and applies signatures only to those records, reducing overall processing overhead while maintaining security for critical authenticated zones.
Data Source
AI summary
A method, computer readable medium, and device for providing authenticated domain name service includes forwarding at a traffic management device a request for a domain name from a client device to one or more servers coupled to the traffic management device. The traffic management device receives a first response comprising at least a portion of the domain name from the one or more servers. The traffic management device attaches a first signature to the first response when the first response is determined by the traffic management device to be an unauthenticated response, and provides the first response with the first signature to the client device.


