IP Library Granted Patent US 9,871,794
Granted Patent B2
US 9,871,794 · App. 14/967,937 · Granted Jan 16, 2018

Domain name system and method of operating using restricted channels

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,871,794
App. No.
14/967,937
Granted
Jan 16, 2018
Kind
B2
Abstract

A server system for a domain name system (DNS) which operates to concurrently provide both public-facing and restricted channels for receiving and handling Internet Protocol (IP) address requests from a population of computers. The server system implements an alternative DNS request handling process to provide a trusted computer entity with exclusive access to the restricted channels.

Claims (27)

1. A method for operating a domain name system (DNS), the method being implemented by one or more processors and comprising:

providing a set of public-facing channels to receive and handle Internet Protocol (IP) address requests from a population of computers; and

implementing an alternative DNS request handling process by (i) establishing a set of restricted channels to receive and handle Internet Protocol (IP) address requests from a trusted computer entity, (ii) dynamically reallocating resources of the DNS to receive and handle IP address requests over the set of public-facing channels towards increasing a capacity of the DNS to receive and handle IP requests over the set of restricted channels, (iii) communicating configuration data to the trusted computer entity to enable the trusted computer entity to utilize one or more restricted channels of the restricted channel set, and (iv) receiving and handling IP address requests communicated by the trusted computer entity using the one or more restricted channels, while receiving and handling IP address requests from other computers of the population using the set of public-facing channels.

2. The method of claim 1 , wherein the configuration data identifies a network address of the one or more restricted channels.

3. The method of claim 1 , wherein the configuration data is provided as a data structure that is securely stored on the trusted computer entity.

4. The method of claim 1 , wherein the configuration data provides an encryption key for use by the trusted computer entity when communicating IP address requests using the one or more restricted channels.

5. The method of claim 1 , wherein the configuration data enables the trusted computer entity to create a persistent point-to-point connection with a server of the DNS using the one or more restricted channels.

6. The method of claim 1 , wherein the set of public channels and the set of restricted channels each include a set of network ports that are exclusively designated for the respective set of public or restricted channels.

7. The method of claim 1 , further comprising:

providing a virtual extension of a server of the DNS, the virtual extension providing access to the one or more restricted channels; and

wherein the configuration data enables the trusted computer entity to create a persistent point-to-point connection with the virtual extension.

8. The method of claim 7 , wherein the configuration data enables the trusted computer entity to execute an interface that implements the persistent point-to-point connection with the virtual extension.

9. The method of claim 1 , wherein the alternative DNS request handling process is implemented in response to detecting a denial of service (DOS) attack.

10. The method of claim 1 , wherein the trusted computer entity corresponds to an Internet Service Provider.

11. A server system for a domain name system (DNS), the server system comprising:

a memory to store a set of instructions; and

one or more processors that execute the set of instructions to:

provide a set of public-facing channels in the server system to receive and handle Internet Protocol (IP) address requests from a population of computers; and

implement an alternative DNS request handling process by (i) establishing a set of restricted channels in the server system to receive and handle Internet Protocol (IP) address requests from a trusted computer entity, (ii) dynamically reallocating resources of the server system to receive and handle the IP address requests over the set of public-facing channels towards increasing a capacity of the DNS to receive and handle IP requests over the set of restricted channels, (iii) communicating configuration data to the trusted computer entity to enable the trusted computer entity to utilize one or more restricted channels of the restricted channel set, and (iv) receiving and handling IP address requests communicated by the trusted computer entity using the one or more restricted channels, while receiving and handling IP address requests from other computers of the population using the set of public-facing channels.

12. The server system of claim 11 , wherein the configuration data identifies a network address of the one or more restricted channels.

13. The server system of claim 11 , wherein the configuration data is provided as a data structure that is securely stored on the trusted computer entity.

14. The server system of claim 11 , wherein the configuration data provides an encryption key for use by the trusted computer entity when communicating IP address requests using the one or more restricted channels.

15. The server system of claim 11 , wherein the configuration data enables the trusted computer entity to create a persistent point-to-point connection with a server of the server system using the one or more restricted channels.

16. The server system of claim 11 , wherein the set of public channels and the set of restricted channels each include a set of network ports that are exclusively designated for the respective set of public or restricted channels.

17. A non-transitory computer-readable medium to store instructions that, when executed by one or more processors of a server system for a domain name system (DNS), cause the server system to perform operations that include:

providing a set of public-facing channels in the server system to receive and handle Internet Protocol (IP) address requests from a population of computers; and

implementing an alternative DNS request handling process by (i) establishing a set of restricted channels in the server system to receive and handle Internet Protocol (IP) address requests from a trusted computer entity, (ii) dynamically reallocating resources of the server system to receive and handle IP address requests over the set of public-facing channels towards increasing a capacity of the DNS to receive and handle IP requests over the set of restricted channels, (iii) communicating configuration data to the trusted computer entity to enable the trusted computer entity to utilize one or more restricted channels of the restricted channel set, and (iv) receiving and handling IP address requests communicated by the trusted computer entity using the one or more restricted channels, while receiving and handling IP address requests from other computers of the population using the set of public-facing channels.

Assignments (13)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON JANUARY 23, 2025 AT REEL 069991 FRAME 0390 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072928/0289 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2025
From: VERCARA, LLC
To: DIGICERT, INC.
Reel/Frame 071781/0348 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0330 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0390 →
CHANGE OF NAME Recorded Mar 21, 2024
From: SECURITY SERVICES, LLC
To: VERCARA, LLC
Reel/Frame 066867/0462 →
FIRST LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: BANK OF AMERICA, N.A.
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0762 →
SECOND LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: UBS AG, STAMFORD BRANCH
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0739 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: NEUSTAR, INC.
To: SECURITY SERVICES, LLC
Reel/Frame 057327/0418 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 043633/0527 →
SECURITY INTEREST Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 043633/0440 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2016
From: JOFFE, RODNEY LANCE; KING, DAVID LINK
To: NEUSTAR, INC.
Reel/Frame 038072/0570 →