Secondary DNS Interface for Shared Registry Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS systems restrict service providers from performing administrative tasks without a direct client relationship with the DNS registry, limiting their ability to offer services dependent on these tasks.

Innovation Solution

Implementing a secondary DNS interface that allows DNS registrants and service providers to update domain name records and perform administrative tasks directly with the DNS registry, without requiring access through a DNS registrar, while ensuring security through identity verification and authorization tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service providers are restricted from directly accessing DNS registry functions, then security and control are maintained, but service provider versatility and operational flexibility are limited

Engineering Contradiction:
Improveservice provider versatilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where service providers obtain authorization tokens from DNS registrants, who in turn are authenticated by the DNS registry. This mediator layer (authorization token system) enables service providers to access registry functions without direct authentication, resolving the contradiction by allowing versatility while maintaining security through the intermediary authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If service providers can directly access DNS registry functions, then operational flexibility is enhanced, but security risks increase

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system requires preliminary authentication and authorization before service providers can access registry functions. DNS registrants must first authenticate with the registry and obtain authorization tokens, which are then used by service providers. This preliminary action (pre-authentication and token issuance) enables operational flexibility while maintaining security through pre-established credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorization token acts as an intermediary credential that mediates between the service provider and the DNS registry. Instead of service providers directly authenticating with the registry (which would compromise security), they use tokens issued by authenticated registrants, enabling flexible access while maintaining security through the intermediary credential system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If DNS registrants must use DNS registrars for all registry interactions, then registrar control is maintained, but service provider capability is restricted

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoidinterface complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the authentication and service access functions. DNS registrars handle initial domain registration and customer relationship management, while DNS registrants can directly authenticate with the registry and issue authorization tokens to service providers. This segmentation allows service providers to directly access registry functions for service delivery without involving registrars, improving efficiency while maintaining registrar control over customer relationships.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service capabilities where authenticated DNS registrants can directly interact with the DNS registry without registrar mediation. Registrants can issue authorization tokens to service providers and manage their own domain services, improving productivity by eliminating unnecessary registrar intermediation while maintaining security through the self-service authentication and token issuance process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250119292A1Shared registration system
Publication Date: 2025.04.10 VERISIGN INC
  • US20250119292A1 patent drawing
  • US20250119292A1 patent drawing
  • US20250119292A1 patent drawing

AI summary

Systems and methods for updating a Domain Name System (DNS) registry are disclosed. Embodiments perform operations including maintaining a domain name record of a DNS registrant recorded in a database of the DNS registry by a primary DNS interface. The operations also include receiving a request to update the domain name record of the DNS registrant via a secondary DNS interface. The operations further include modifying the domain name record of the DNS registrant in the DNS database in accordance with the request.