Extending DNSSEC Trust Chains to Non-DNS Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

DNSSEC and DANE are limited to authenticating objects within the DNS, failing to validate and authenticate data from non-DNS services and objects delivered by them.

Innovation Solution

The introduction of URIVAL DNS resource records and parameterized URIs allows for the extension of trust chains to authenticate objects outside the DNS, using cryptographic information such as public keys, digital certificates, and hashes to validate data from non-DNS services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNSSEC and DANE are used to authenticate data, then authentication reliability within DNS is improved, but the ability to authenticate objects outside DNS deteriorates (cannot authenticate non-DNS services)

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the DNSSEC authentication mechanism to serve multiple purposes: both traditional DNS data authentication and non-DNS service authentication. By allowing DNS resource records to contain cryptographic authentication information for external services (via URI schemes like 'arbitrary:' or 'data:'), the system achieves multi-functionality where DNS infrastructure authenticates both internal and external objects

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces DNS resource records as an intermediary mechanism that bridges DNS and non-DNS authentication. The DNS record acts as a mediator by storing cryptographic information (public keys, certificates, hashes) that enables verification of external services, effectively using DNS infrastructure as a trust anchor for non-DNS objects

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If trust chains are extended to non-DNS services, then authentication versatility is improved, but system complexity increases (requiring new DNS record types and resolution logic)

Engineering Contradiction:
Improveauthentication scopeVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication information into distinct DNS resource record types (e.g., URI records containing authentication data, separate validation records). This segmentation allows the complex authentication mechanism to be broken down into manageable, standardized components that can be processed independently by DNS resolvers and clients

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent leverages existing DNSSEC infrastructure and cryptographic verification mechanisms, copying proven authentication techniques from DNS to non-DNS contexts. By reusing established cryptographic algorithms, signature verification processes, and trust chain validation logic, the system extends authentication capability without reinventing the underlying complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10009181B2Extending DNSSEC trust chains to objects outside the DNS
Publication Date: 2018.06.26 VERISIGN INC
  • US10009181B2 patent drawing
  • US10009181B2 patent drawing
  • US10009181B2 patent drawing

AI summary

The present invention generally relates to systems and methods for extending a chain of trust beyond the DNS. Some embodiments provide a verifier with the ability to validate a chain of trust starting with the trust anchor at the DNS root all the way to a service or object of interest outside the DNS.