Patent · US Active

Cross-domain HTTP requests using DNS rebinding

US10536425B2 · kind B2 · utility

0Cited by
1References
54Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 25, 2016
Grant dateJan 14, 2020
Priority date
Expiry dateSep 12, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/563
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Cross-domain requests by DNS name rebinding. A domain name server at a first domain name receives an initialization request from a user agent device. The request designates a class of domain names to be resolved to an IP address belonging to a second domain name to which the user agent device seeks to issue a safe cross-domain request. That request will be directed to the first domain name, but serviced by a server belonging to the second. In a DNS cache of the user agent, the first domain name is bound to an IP address belonging to the first domain, and to an IP address belonging to the second domain name. This binding is established by providing two or more IP address resource records resolving the designation of the class of domain names, having the relevant IP addresses, and ensuring that the first domain name is pinned to the first IP address in a DNS cache of the user agent device, and that others of the IP addresses are stored in the user agent's DNS cache as alternative binding(s) to the first domain name, and then invalidating the first IP address, so that the binding falls through to an alternative one of the IP addresses.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.