Extending DNSSEC Trust Chains to Non-DNS Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
DNSSEC and DANE cannot authenticate data outside of the DNS, limiting the extension of trust chains to non-DNS services and objects.
Innovation Solution
The introduction of URIVAL DNS resource records and parameterized URIs allows for the validation of objects from non-DNS services by including cryptographic authentication information, enabling the extension of trust chains beyond DNS boundaries through resolution logic and URIVAL records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNSSEC and DANE are used to authenticate data, then authentication reliability is improved, but the scope is limited to DNS data only
Solution Approach 1:
The patent extends the DNSSEC authentication mechanism to serve multiple purposes: authenticating both traditional DNS data and external non-DNS objects (such as email messages, attachments, and calendar events). This is achieved by incorporating cryptographic authentication information from external objects into DNS resource records, allowing the same DNS infrastructure to provide security verification for diverse data types beyond its original scope.
2Measurement precision
If separate DNS records are created for each domain name, then authentication precision is improved, but record management complexity increases
Solution Approach 1:
The patent combines authentication information for multiple domain names into a single DNS resource record by incorporating the cryptographic hash of the external object into the record. This merging approach allows one DNS record to serve multiple domain names simultaneously, reducing the total number of records needed while maintaining precise authentication for each domain through the included cryptographic verification data.
Data Source
AI summary
The present invention generally relates to systems and methods for extending a chain of trust beyond the DNS. Some embodiments provide a verifier with the ability to validate a chain of trust starting with the trust anchor at the DNS root all the way to a service or object of interest outside the DNS.


