Mirror DNS System for Global DNSSEC Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DNSSEC deployment models face challenges in achieving global coverage due to limitations in online key signing and support for DNSSEC, particularly in client code and registrar infrastructure, leading to difficulties in securing content transmission and managing trust across organizational boundaries.
Innovation Solution
The implementation of a mirror DNS system that encodes DS records in NS names, allowing for secure content authentication without the need for convoluted pathways, and an automation attack detection system to prevent fraudulent activities, enabling secure content distribution and trust establishment across the globe.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNSSEC is deployed using traditional pathways, then security authentication is achieved, but deployment complexity and operational load increase severely
Solution Approach 1:
The patent introduces a mirror DNS system as an intermediary between clients and the authoritative DNS infrastructure. This mirror DNS receives authentication requests, performs DNSSEC verification, and returns results to clients. By placing this intermediary layer, the complex DNSSEC verification process is isolated from both clients and the authoritative DNS servers, simplifying deployment while maintaining security authentication.
2Loss of time
If offline key signing is used, then signature precalculation is enabled, but operational load and flexibility are severely limited
Solution Approach 1:
The patent implements dynamic key signing capability in the mirror DNS system. Instead of static offline key signing, the mirror DNS can perform key signing operations dynamically based on real-time requirements. This allows the system to adapt to changing operational needs, such as load balancing requirements and geolocation-based authentication, while still providing precalculated signatures when needed.
3Ease of manufacture
If incremental opt-in at root and TLD is implemented, then deployment is manageable, but global coverage and trust consistency are compromised
Solution Approach 1:
The mirror DNS system is designed to handle multiple DNSSEC trust models simultaneously. It can work with incrementally deployed DNSSEC at root and TLD levels while also supporting domain-level DNSSEC implementation. The system provides a universal interface that abstracts away the underlying deployment model, ensuring trust consistency for clients regardless of how DNSSEC is deployed in the infrastructure.
4Reliability
If DNSSEC verification is performed directly by clients, then authentication is achieved, but client code complexity and support requirements increase
Solution Approach 1:
The patent extracts the complex DNSSEC verification logic from client code and relocates it to the mirror DNS server. Clients only need to query the mirror DNS for authentication results, without implementing the complex DNSSEC verification algorithms themselves. This extraction reduces client code complexity to minimal requirements while maintaining strong authentication through server-side verification.
Data Source
AI summary
This invention leverages DNSSEC to makes post-password technologies work against endpoints across the globe, rather than solely within company walls. It describes a system by which DS records are encoded in NS names, which traverse well from the customer to the registry. This invention also proposes a series of steps through which DNSSEC can be explored as a useful solution to real world problems. By creating and further developing a mirror of the real DNS, which grows by combination of true DNS record information with specially synthesized authentication keys, DNSSEC scales, providing greater security and less risk of corrupting or erroneous online material. This same technology also evaluates user activity to create a database of statistics regarding automated activity, as compared to human activity. This database assists in identification and prevention, or at least mitigation, of potential future attacks on any given client by automated bot-driven activity.


