Patent · US Active

Using domain name system security extensions in a mixed-mode environment

US9544278B2 · kind B2 · utility

10Cited by
2References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 7, 2015
Grant dateJan 10, 2017
Priority date
Expiry dateJan 7, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2101/30
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method relates to generating, by a processing device executing a DNS resolver, a first domain name system (DNS) query comprising a DNS request generated from an application executing on the processing device to query a first DNS server serving a first DNS zone connected to the processing device via a public network, receiving, from the first DNS server, a first resource record comprising a DNS answer to the DNS query, a second resource record comprising a digital signature generated by signing the DNS answer with a first private key of the first DNS zone, a third resource record comprising a first public key for verifying the digital signature, and one or more files for validating a chain of trust of the first public key, determining, by the processing device in view of the one or more files, that the chain of trust of the first public key misses at least one of a trust anchor or a link in the chain of trust, and generating a second DNS query comprising the DNS request to query a second DNS server residing in a private network of the processing device.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.