IP Library › Granted Patent US 9,769,193
Granted Patent B2
US 9,769,193 · App. 14/742,945 · Granted Sep 19, 2017

Advanced security for domain names

Inventor: Mehmet Akcin (Bothell, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/1433H04L61/1511H04L61/2007H04L61/302H04L63/083H04L63/1483H04L67/02H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,769,193
App. No.
14/742,945
Granted
Sep 19, 2017
Kind
B2
Abstract

Various techniques for improving security of domain name records are disclosed herein. In one embodiment, a method includes receiving a request to modify a domain name record containing a first domain name server to containing a second domain name server. In response to the received request, the first and second domain name servers are individually queries for corresponding first and second security records. The method can also include receiving the first and second security records from the first and second domain name servers, respectively and determining whether to allow the domain name record to be modified based on a comparison of the first and second security records.

Claims (89)

1. A computing device, comprising:

a processor; and

a memory containing instructions executable by the processor to cause the computing device to:

receive a request to modify a domain name record, the domain name record containing a first domain name server as an authoritative domain name server of a domain, wherein the request seeks to replace the first domain name server with a second domain name server in the domain name record as the authoritative domain name server of the domain;

in response to receiving the request to modify the domain name record, individually query the first and second domain name servers for corresponding first and second security records contained on the first and second domain name servers, respectively, the first and second security records individually containing security data configured by an owner of the domain;

receive at least one of the first or second security record from the first or second domain name server, respectively; and

upon receiving the at least one of the first or second security record, determine whether to allow the requested modification to the domain name record based on a comparison of the first and second security records.

2. The computing device of claim 1 wherein:

the computing device is a domain name server associated with a domain name space; and

the domain name record is associated with a subdomain of the domain name space.

3. The computing device of claim 1 wherein:

the computing device contains a first security query record associated with the first domain name server and a second security query record associated with the second domain name server;

the memory contains additional instructions executable by the processor to cause the computing device to:

construct first and second security queries based on the first and second security query records, the first and second security query records individually containing a network location at which the first or second security record is stored; and

transmit the constructed first and second security queries to the first and second domain name servers, respectively.

4. The computing device of claim 1 wherein:

the computing device contains a first set of security query records associated with the first domain name server and a second set of security query records associated with the second domain name server;

the memory contains additional instructions executable by the processor to cause the computing device to:

randomly select a first security query record from the first set of security query records;

randomly select a second security query record from the second set of security query records;

construct first and second security queries based on the selected first and second security query records, the first and second security query records individually containing a network location at which the first or second security record is stored; and

transmit the constructed first and second security queries to the first and second domain name servers, respectively.

5. The computing device of claim 1 wherein the first and second security records individually contain a text string, a value of which is periodically or continually modified.

6. The computing device of claim 1 wherein:

the first and second security records include first and second text strings, respectively; and

the memory contains additional instructions executable by the processor to cause the computing device to:

determine whether the first text string matches the second text string; and

in response to determining that the first text string matches the second text string, indicate that the requested modification of the domain name record is allowed.

7. The computing device of claim 1 wherein:

the first and second security records include first and second text strings, respectively; and

the memory contains additional instructions executable by the processor to cause the computing device to:

determine whether the first text string matches the second text string; and

in response to determining that the first text string does not at least substantially match the second text string, indicate that the requested modification of the domain name record is not allowed.

8. A method for protecting domain name security, comprising:

receiving a request to modify a domain name record containing a first domain name server to containing a second domain name server;

in response to the received request, individually querying the first and second domain name servers for corresponding first and second security records;

receiving the first and second security records from the first and second domain name servers, respectively; and

determining whether to allow the domain name record to be modified based on a comparison of the first and second security records.

9. The method of claim 8 wherein:

receiving the request to modify includes receiving the request to modify at a domain name server associated with a domain name space; and

the domain name record is contained at the domain name server associated with a domain name space; and

the domain name record is associated with a subdomain of the domain name space.

10. The method of claim 8 wherein:

receiving the request to modify includes receiving the request to modify at a domain name server containing a first security query record associated with the first domain name server and a second security query record associated with the second domain name server;

individually querying the first and second domain name servers includes:

constructing first and second security queries based on the first and second security query records stored at the domain name server, the first and second security query records individually containing a network location at which the first or second security record is stored; and

transmitting the constructed first and second security queries to the first and second domain name servers, respectively.

11. The method of claim 8 wherein:

receiving the request to modify includes receiving the request to modify at a domain name server containing a first set of security query records associated with the first domain name server and a second set of security query records associated with the second domain name server;

individually querying the first and second domain name servers includes:

randomly selecting a first security query record from the first set of security query records;

randomly selecting a second security query record from the second set of security query records;

constructing first and second security queries based on the selected first and second security query records, the first and second security query records individually containing a network location at which the first or second security record is stored; and

transmitting the constructed first and second security queries to the first and second domain name servers, respectively.

12. The method of claim 8 wherein receiving the first and second security records includes receiving first and second security records individually containing a text string, a value of which is periodically or continually modified.

13. The method of claim 8 wherein:

the first and second security records include first and second text strings, respectively; and

determining whether to allow the domain name record to be modified includes:

determining whether the first text string matches the second text string; and

in response to determining that the first text string matches the second text string, allowing the domain name record to be modified in response to the received request.

14. The method of claim 8 wherein:

the first and second security records include first and second text strings, respectively; and

determining whether to allow the domain name record to be modified includes:

determining whether the first text string matches the second text string; and

in response to determining that the first text string does not match the second text string, rejecting the request to modify the domain name record.

15. A method for protecting domain name security, comprising:

receiving a request to replace a first domain name server with a second domain name server as an authoritative server associated with a domain name; and

in response to the received request,

transmitting first and second security queries to the first and second domain name servers, respectively;

receiving first and second security records in response to the first and second security queries from the first and second domain name servers, respectively; and

maintaining the first domain name server as the authoritative server associated with the domain name unless the first and second security records at least substantially match each other.

16. The method of claim 15 , further comprising:

performing a bit-wise or character-wise comparison of the first and second security records; and

determining whether the first and second security records at least substantially match each other based on the bit-wise or character-wise comparison.

17. The method of claim 15 , further comprising:

performing a bit-wise or character-wise comparison of the first and second security records;

determining whether the first and second security records at least substantially match each other based on the bit-wise or character-wise comparison; and

in response to determining that the first and second security records at least substantially match each other, allowing the first domain name server to be replaced by the second domain name server as the authoritative server associated with the domain name.

18. The method of claim 15 , further comprising:

performing a bit-wise or character-wise comparison of the first and second security records;

determining whether the first and second security records at least substantially match each other based on the bit-wise or character-wise comparison; and

in response to determining that the first and second security records do not at least substantially match each other, maintaining the first domain name server as the authoritative server associated with the domain name.

19. The method of claim 15 , further comprising:

determining a first IP address associated with the first domain name server and a second IP address associated with the second domain name server based on first and second security query records associated with the first and second domain name servers, respectively; and

wherein transmitting the first and second security queries includes transmitting first and second security queries to the first and second IP addresses, respectively.

20. The method of claim 15 , further comprising:

determining whether a first IP address is associated with the first domain name server and a second IP address is associated with the second domain name server based on first and second security query records associated with the first and second domain name servers, respectively;

in response to determining that the first or second IP address is not associated with the first or second domain name server, recursively resolving the first or second domain name server to determine the first or second IP address; and

wherein transmitting the first and second security queries includes transmitting first and second security queries to the first and second IP addresses, respectively.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2015
From: AKCIN, MEHMET
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 035860/0537 →
Continuity (1)
Related Publication 20160373479A1 · Dec 22, 2016