Domain Name Transfer Risk Mitigation via TREA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing domain name transfer systems lack sufficient security measures to prevent unauthorized domain name transfers and theft, as they rely on simple password authentication and email transmission of authorization codes, which are vulnerable to hacking and man-in-the-middle attacks.

Innovation Solution

Implementing a Transfer Risk Evaluation Algorithm (TREA) and Transfer Workflow System that assesses the characteristics of domain name transfers to identify high-risk activities, routing suspicious requests through a manual review process and using additional verification methods such as SMS codes and phone contact to authenticate registrants, thereby increasing security and preventing unauthorized transfers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple password authentication and email transmission are used for domain name transfers, then the ease of operation is improved, but the security and reliability deteriorate due to vulnerability to hacking and man-in-the-middle attacks

Engineering Contradiction:
Improveease of domain name transferVSAvoidsecurity of domain name transfer
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary verification system that acts as a mediator between the transfer request and the execution. This system includes automated risk assessment algorithms and manual review processes that verify the authenticity of transfer requests without requiring complex user actions, thus maintaining ease of operation while significantly improving security and reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary verification actions before domain name transfer is executed. This includes pre-assessment of transfer risk, verification of registrant identity, and validation of authorization codes before the actual transfer occurs. These preliminary checks prevent unauthorized transfers while keeping the process simple for legitimate users

Inventive Principle:
Principle #10Preliminary action

2Reliability

If enhanced scrutiny and manual review processes are implemented for domain name transfers, then the security and reliability are improved, but the productivity and time required for transfers deteriorate

Engineering Contradiction:
Improvesecurity of domain name transferVSAvoidspeed of domain name transfer
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the domain name transfer process into distinct phases: automated risk assessment, conditional manual review, and execution. By dividing the process, routine transfers with low risk can proceed quickly through automated channels, while only suspicious transfers require manual review, thus maintaining high productivity for legitimate transfers while ensuring security for high-risk cases

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial verification actions based on risk assessment. For low-risk transfers, minimal verification is performed allowing quick completion. For high-risk transfers, more extensive manual review is conducted. This selective approach ensures security where needed while maintaining efficiency for the majority of legitimate transfers

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11087374B2Domain name transfer risk mitigation
Publication Date: 2021.08.10 GO DADDY OPERATING CO LLC
  • US11087374B2 patent drawing
  • US11087374B2 patent drawing
  • US11087374B2 patent drawing

AI summary

Systems and methods of the present invention provide for one or more server computers communicatively coupled to a network and configured to: receive a request for a modification to domain name management; analyze metadata and registrant accounts associated with the request; determine whether related domain name activities indicate high or low risk of malicious behavior; if high risk, the request may be queued for manual review; on manual review, if the request is deemed high risk, an attempt to contact the registrant may be made; if unsuccessful, or if the registrant verifies an invalid request, the request may be cancelled. if the behavior or request is low risk, and/or if the registrant confirms the request is valid, the request may be approved and fulfilled.