Extending DNSSEC Trust Chains to Non-DNS Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
DNSSEC and DANE are limited to authenticating objects within the DNS, failing to validate and authenticate data from non-DNS services and objects delivered by them.
Innovation Solution
The introduction of URIVAL DNS resource records and parameterized URIs allows for the extension of trust chains to authenticate objects outside the DNS, using cryptographic information such as public keys, digital certificates, and hashes to validate data from non-DNS services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNSSEC and DANE are used to authenticate data, then authentication reliability within DNS is improved, but the ability to authenticate objects outside DNS deteriorates (cannot authenticate non-DNS services)
Solution Approach 1:
The patent extends the DNSSEC authentication mechanism to serve multiple purposes: both traditional DNS data authentication and non-DNS service authentication. By allowing DNS resource records to contain cryptographic authentication information for external services (via URI schemes like 'arbitrary:' or 'data:'), the system achieves multi-functionality where DNS infrastructure authenticates both internal and external objects
Solution Approach 2:
The patent introduces DNS resource records as an intermediary mechanism that bridges DNS and non-DNS authentication. The DNS record acts as a mediator by storing cryptographic information (public keys, certificates, hashes) that enables verification of external services, effectively using DNS infrastructure as a trust anchor for non-DNS objects
2Adaptability or versatility
If trust chains are extended to non-DNS services, then authentication versatility is improved, but system complexity increases (requiring new DNS record types and resolution logic)
Solution Approach 1:
The patent segments the authentication information into distinct DNS resource record types (e.g., URI records containing authentication data, separate validation records). This segmentation allows the complex authentication mechanism to be broken down into manageable, standardized components that can be processed independently by DNS resolvers and clients
Solution Approach 2:
The patent leverages existing DNSSEC infrastructure and cryptographic verification mechanisms, copying proven authentication techniques from DNS to non-DNS contexts. By reusing established cryptographic algorithms, signature verification processes, and trust chain validation logic, the system extends authentication capability without reinventing the underlying complexity
Data Source
AI summary
The present invention generally relates to systems and methods for extending a chain of trust beyond the DNS. Some embodiments provide a verifier with the ability to validate a chain of trust starting with the trust anchor at the DNS root all the way to a service or object of interest outside the DNS.


