IP Library Patent Application 12312510
Patent Application
App. No. 12/312,510

DNSSEC BASE ROLLOUT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/312,510
Abstract

The invention relates to a method for accessing via a first device a predetermined piece of information duplicated in several server devices, each server device implementing a sub-assembly of safety mechanisms from a predetermined set of safety mechanisms in order to provide a predetermined safety level for accessing the predetermined piece of information, wherein said method comprises the following steps: a) transmission ( 40 ) by the first device of at least one access request adapted for receiving the list of safety mechanisms implemented by the server devices; b) transmission ( 46 ) by the first device to at least one of said server devices of an access request to the predetermined piece of information, said request using the safety mechanisms implemented by the and at least one of said server devices.

Claims (19)

1 . A method of access by a first device ( 1 ) to a predetermined information item duplicated in several server devices ( 3 , 4 , 5 ), each server device implementing a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a predefined level of security of access to the predetermined information item, said method comprising the steps of:

a) sending ( 40 , 50 ) by the first device of at least one access request adapted for receiving the list of security mechanisms implemented by the server devices,

b) sending ( 46 , 56 ) by the first device to at least one of said server devices of a request for access to the predetermined information item, said request using the security mechanisms implemented by the at least one of said server devices.

2 . The method as claimed in claim 1 , characterized in that it comprises, after step a) of sending at least one request, a step a1) of selection ( 44 , 54 ) by the first device of a server device having implemented a predetermined subset of security mechanisms.

3 . The method as claimed in claim 2 , characterized in that a central server device comprising a list referencing the server devices and the subset of security mechanisms implemented by each server device, step a) consists in sending ( 50 ) an access request directed towards the central server device.

4 . The method as claimed in claim 3 , characterized in that the list referencing the server devices furthermore comprising at least one reference to a server device not comprising the predetermined information item, in response to the access request of step a), the central server device dispatches ( 52 ) to the first device a sub-list of said list, said sub-list comprising only references to the server devices comprising the predetermined information item.

5 . The method as claimed in claim 4 , characterized in that the server devices being DNS servers at least one of which implements all or part of the security mechanisms of the DNSSEC standard and the central server device being a DNS server of higher level in the DNS hierarchy, the base of whose DNS servers comprises at least one field describing the security mechanisms of the DNSSEC standard that are implemented by each DNS server, step a) consists in sending a DNS request of type A so as to determine the IP address corresponding to a DNS address at the DNS server of higher level and the response of the DNS server of higher level to this request consists of a DNS response of type NS with which are concatenated the fields describing the security mechanisms of the DNSSEC standard that are implemented for each DNS server whose address is transmitted in the response of type NS.

6 . The method as claimed in claim 1 , characterized in that the server devices being DNS servers at least one of which implements all or part of the security mechanisms of the DNSSEC standard, step a) consists of a DNS request for acquiring the characteristics of a server device which is addressed to said server device, to which said server device responds by transmitting to the first device a field describing the security mechanisms of the DNSSEC standard that are implemented by said server device.

7 . A device for access to a predetermined information item duplicated in several server devices ( 3 , 4 , 5 ), each server device implementing a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a predefined level of security of access to the predetermined information item, characterized in that it comprises:

a) means ( 12 ) for sending at least one access request, which request is adapted for receiving the list of security mechanisms implemented by the server devices,

b) means ( 14 ) for sending to at least one of said server devices a request for access to the predetermined information item, said request using the security mechanisms implemented by the at least one of said server devices.

8 . A server device implementing a subset of security mechanisms of a predetermined set of security mechanisms so as to provide a predefined level of security of access to a predetermined information item, characterized in that it comprises:

a) means ( 26 ) for receiving at least one access request by a first device, which request is adapted for receiving the list of security mechanisms implemented by said server device,

b) means ( 28 ) for dispatching in response to the access request the list of security mechanisms implemented,

c) means ( 30 ) for receiving a request for access to the predetermined information item sent by the first device, said request using the security mechanisms implemented by said server device.

9 . A system for access to a predetermined information item, comprising:

an access device as claimed in claim 7 ,

several server devices as claimed in claim 8 .

10 . A computer program comprising program code instructions for executing the steps of the method as claimed in any one of claims 1 to 6 when said program is executed on a computer.

Assignments (2)
CHANGE OF NAME Recorded Apr 16, 2014
From: FRANCE TELECOM
To: ORANGE
Reel/Frame 032698/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2010
From: MIGAULT, DANIEL; COMBES, JEAN-MICHEL
To: FRANCE TELECOM
Reel/Frame 024065/0028 →