Extending DNSSEC Trust Chains to Non-DNS Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

DNSSEC and DANE cannot authenticate data outside of the DNS, limiting the extension of trust chains to non-DNS services and objects.

Innovation Solution

The introduction of URIVAL DNS resource records and parameterized URIs allows for the validation of objects from non-DNS services by including cryptographic authentication information, enabling the extension of trust chains beyond DNS boundaries through resolution logic and URIVAL records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNSSEC and DANE are used to authenticate data, then authentication reliability is improved, but the scope is limited to DNS data only

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the DNSSEC authentication mechanism to serve multiple purposes: authenticating both traditional DNS data and external non-DNS objects (such as email messages, attachments, and calendar events). This is achieved by incorporating cryptographic authentication information from external objects into DNS resource records, allowing the same DNS infrastructure to provide security verification for diverse data types beyond its original scope.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If separate DNS records are created for each domain name, then authentication precision is improved, but record management complexity increases

Engineering Contradiction:
Improveauthentication precisionVSAvoidrecord management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines authentication information for multiple domain names into a single DNS resource record by incorporating the cryptographic hash of the external object into the record. This merging approach allows one DNS record to serve multiple domain names simultaneously, reducing the total number of records needed while maintaining precise authentication for each domain through the included cryptographic verification data.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9705851B2Extending DNSSEC trust chains to objects outside the DNS
Publication Date: 2017.07.11 VERISIGN INC
  • US9705851B2 patent drawing
  • US9705851B2 patent drawing
  • US9705851B2 patent drawing

AI summary

The present invention generally relates to systems and methods for extending a chain of trust beyond the DNS. Some embodiments provide a verifier with the ability to validate a chain of trust starting with the trust anchor at the DNS root all the way to a service or object of interest outside the DNS.