IP Library Granted Patent US 9,172,713
Granted Patent B2
US 9,172,713 · App. 12/237,144 · Granted Oct 27, 2015

Secure domain name system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,172,713
App. No.
12/237,144
Granted
Oct 27, 2015
Kind
B2
Abstract

A method and system for authenticating answers to Domain Name System (DNS) queries originating from recursive DNS servers are provided. A verification component provides a verification that a DNS query originated from the recursive DNS server. An authoritative DNS server receives the query via a network, such as the Internet, and provides an answer to the query to an authentication component. The authentication component then provides an authentication, such as a digital signature, which confirms that the received answer was provided by the authoritative DNS server, and then communicates the answer and the authentication to the verification component via the network. The verification component then verifies that the authentication corresponds to the received answer and sends the answer to the recursive DNS server. When the verification component receives an answer in the absence of a corresponding authentication, the verification component drops the answer.

Claims (45)

1. Apparatus for authenticating answers to Domain Name System (DNS) queries originating from recursive DNS servers, the apparatus comprising:

a verification appliance, wherein the verification appliance comprises a CPU and a memory, disposed in front of and in serial communication with a separate recursive DNS server, the verification appliance being configured to (i) receive a DNS query from the recursive DNS server and to (ii) provide a first verification that the query originated from the recursive DNS server;

a first authentication component in communication with the verification appliance via a network, the first authentication component being configured to (i) receive the DNS query and the first verification from the verification appliance, and to (ii) provide a first confirmation that the first verification corresponds to the received DNS query; and

a first authoritative DNS server in serial communication with the first authentication component, the first authoritative DNS server being configured to (i) provide an answer to the DNS query and to (ii) transmit the answer to the first authentication component,

wherein the first authentication component is further configured to (i) receive the answer to the DNS query from the first authoritative DNS server and to (ii) provide an authentication that the received answer was provided by the first authoritative DNS server, and to (iii) communicate the received answer and the authentication to the verification appliance via the network; and

wherein the verification appliance is further configured to (i) receive the answer to the DNS query and to receive the authentication, and to (ii) verify that the authentication corresponds to the received answer, wherein when the verification appliance receives the answer in the absence of a corresponding authentication, and wherein the verification appliance is configured to prevent the answer from being communicated to the recursive DNS server;

a second authentication component, the second authentication component being in communication with the verification appliance via the network, the second authentication component being configured to receive the DNS query and the first verification from the verification appliance when the first authentication component is not functioning properly, and to provide a second confirmation that the first verification corresponds to the received DNS query;

and a second authoritative DNS server,

wherein the second authoritative DNS server being in serial communication with the second authentication component, the second authoritative DNS server component being configured to provide the answer to the DNS query and to transmit the answer to the second authentication component,

wherein the second authentication component is further configured to receive the answer to the DNS query from the second authoritative DNS server and to provide an authentication that the received answer was provided by the second authoritative DNS server component, and to communicate the received answer and the authentication to the verification appliance via the network; and

wherein the verification component is further configured to receive the answer to the DNS query and to receive the authentication, and to verify that the authentication corresponds to the received answer.

2. The apparatus of claim 1 , wherein the network comprises the Internet.

3. The apparatus of claim 1 , wherein the network comprises the World Wide Web.

4. The apparatus of claim 1 , wherein the authentication comprises a digital signature.

5. The apparatus of claim 1 , further comprising a second authentication component, the second authentication component being in serial communication with both of the first authentication component and the first authoritative

DNS server, and the second authentication component being configured identically as the first authentication component to provide redundancy,

wherein the second authentication component is configured to receive the DNS query and the first verification from the verification appliance via the network and the first authentication component, and to provide a third confirmation that the first verification corresponds to the received DNS query, and to transmit the DNS query and the third confirmation to the authoritative DNS server, and

wherein the second authentication component is further configured to receive the answer from the authoritative DNS server component and to provide an authentication that the received answer was provided by the authoritative DNS server component, and to communicate the received answer and the authentication to the verification appliance via the first authentication component and the network.

6. A method of verifying an authenticity of an answer to a Domain Name System (DNS) query originating from a recursive DNS server, the method comprising the steps of:

receiving, with a verification appliance in front of and in serial communication with the recursive DNS server, the DNS query from the recursive DNS server;

the verification appliance providing a verification that the DNS query originated from the recursive DNS server;

communicating the DNS query and the verification to an authoritative DNS server via a network; and

receiving an answer to the DNS query and an authentication corresponding to the received answer,

wherein the authoritative DNS server is configured to transmit the answer to an authentication component that is configured to provide an authentication corresponding to the answer and to communicate the authentication in conjunction with the answer, said authentication component being in serial communication with the authoritative DNS server,

wherein when the answer to the DNS query is received in the absence of a corresponding authentication dropping the received answer;

wherein when the first authentication component is not functioning properly, communicating the DNS query and the verification to a second authoritative DNS server via the network; and receiving the answer to the DNS query and an authentication corresponding to the received answer, wherein the second authoritative DNS server is configured to transmit the answer to a second authentication component that is configured to provide an authentication corresponding to the answer and to communicate the authentication in conjunction with the answer.

7. The method of claim 6 , wherein the network comprises the Internet.

8. The method of claim 6 , wherein the network comprises the World Wide Web.

9. The method of claim 6 , wherein the authentication comprises a digital signature.

10. The method of claim 6 , wherein when the answer to the DNS query is received in the absence of a corresponding authentication, the method further comprises the steps of:

re-communicating the DNS query and the verification to the authoritative DNS server via the network; and

receiving a second answer to the DNS query and an authentication corresponding to the received second answer.

11. A method of authenticating an answer to a Domain Name System (DNS) query originating from a recursive DNS server, the method comprising the steps of:

receiving, with a verification appliance in front of and in serial communication with the recursive DNS server, the DNS query from the recursive DNS server;

receiving, at a first authentication component, the DNS query from the verification appliance via a network;

communicating the received DNS query to an authorized DNS server;

receiving an answer to the DNS query from the authorized DNS server;

providing an authentication corresponding to the received answer, the authentication provided by the first authentication component in serial communication with the DNS server,

wherein when an answer to the DNS query is received in the absence of a corresponding authentication dropping the received answer,

wherein when the first authentication component is not functioning properly, communicating the DNS query and the verification to a second authoritative DNS server via the network; and receiving the answer to the DNS query and an authentication corresponding to the received answer, wherein the second authoritative DNS server is configured to transmit the answer to a second authentication component that is configured to provide an authentication corresponding to the answer and to communicate the authentication in conjunction with the answer; and

communicating the received answer and the authentication to the recursive DNS server via the network.

12. The method of claim 11 , wherein the network comprises the Internet.

13. The method of claim 11 , wherein the network comprises the World Wide Web.

14. The method of claim 11 , wherein the authentication comprises a digital signature.

15. The method of claim 11 , further comprising the step of receiving, from the verification appliance, a verification that the received DNS query was actually originated by the recursive DNS server, wherein the step of receiving a verification occurs prior to the step of communicating the received DNS query to the authorized DNS server.

Assignments (17)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON JANUARY 23, 2025 AT REEL 069991 FRAME 0390 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072928/0289 →
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2025
From: VERCARA, LLC
To: DIGICERT, INC.
Reel/Frame 071781/0348 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0390 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0330 →
CHANGE OF NAME Recorded Mar 21, 2024
From: SECURITY SERVICES, LLC
To: VERCARA, LLC
Reel/Frame 066867/0462 →
SECOND LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: UBS AG, STAMFORD BRANCH
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0739 →
FIRST LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: BANK OF AMERICA, N.A.
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0762 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: NEUSTAR, INC.
To: SECURITY SERVICES, LLC
Reel/Frame 057327/0418 →
SECURITY INTEREST Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 043633/0440 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 043633/0527 →
RELEASE OF SECURITY INTEREST Recorded Aug 21, 2017
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; ULTRADNS CORPORATION; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; AGGREGATE KNOWLEDGE, INC.; MARKETSHARE ACQUISITION CORPORATION; MARKETSHARE HOLDINGS, INC.; MARKETSHARE PARTNERS, LLC
Reel/Frame 043618/0826 →
RELEASE OF SECURITY INTEREST Recorded Feb 13, 2013
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NEUSTAR, INC.; TARGUS INFORMATION CORPORATION; QUOVA, INC.; ULTRADNS CORPORATION; AMACAI INFORMATION CORPORATION; MUREX LICENSING CORPORATION
Reel/Frame 029809/0177 →
SECURITY AGREEMENT Recorded Feb 13, 2013
From: NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; ULTRADNS CORPORATION; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 029809/0260 →
SECURITY AGREEMENT Recorded Jan 10, 2012
From: NEUSTAR, INC.; TARGUS INFORMATION CORPORATION; QUOVA, INC; ULTRADNS CORPORATION; AMACAI INFORMATION CORPORATION; MUREX LICENSING CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 027512/0119 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2008
From: JOFFE, RODNEY LANCE; OPPLEMAN, VICTOR JOSEPH; KING, DAVID LINK; WATSON, BRETT DEAN; JACKSON, ANDREW; LEACH, SEAN
To: NEUSTAR, INC.
Reel/Frame 021581/0335 →