IP Library Granted Patent US 9,866,536
Granted Patent B2
US 9,866,536 · App. 15/173,608 · Granted Jan 9, 2018

Privacy preserving registry browsing

Inventor: Burton S. Kaliski, Jr. (Vienna, VA)
Assignee: VERISIGN, INC.
H04L63/0428G06F21/6218G06F21/6263H04L61/1511H04L61/2007H04L61/302H04L61/3025H04L63/0407H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,866,536
App. No.
15/173,608
Granted
Jan 9, 2018
Kind
B2
Abstract

A method, system, and computer-readable memory containing instructions include requesting a tokenizing authority to provide a tokenized string that represents a domain name, using the tokenized domain name string to perform a lookup against a database of registered tokenized domain name strings, determining whether the tokenized domain name string exists in the database, and returning results based on the existence of tokenized domain name strings and optionally variants thereof. The method, system, and computer-readable memory may further include returning an encryption key corresponding to an encrypted record of information related to the domain name corresponding to the tokenized domain name string.

Claims (41)

1. A method for preserving privacy of a domain name related request, comprising:

receiving, from a client computer, a request for information related to a domain name and comprising at least one tokenized string representing the domain name, wherein the tokenized string was tokenized by a first tokenizing authority computer based on a first tokenizing function, and the first tokenizing authority computer is different than the client computer;

comparing the at least one tokenized string to a store of tokenized strings, wherein the tokenized strings in the store have been tokenized by a second tokenizing authority computer based on the first tokenizing function or a tokenizing function equivalent to the first tokenizing function, and the second tokenizing authority computer is different than the client computer and a computer that holds the store of tokenized strings; and

determining whether the at least one tokenized string is contained in the store of tokenized strings to generate a result.

2. The method of claim 1 , wherein the information related to the domain name comprises a fully qualified domain name.

3. The method of claim 1 , wherein the information related to a domain name comprises a portion of the domain name.

4. The method of claim 1 , wherein the request comprises a request for encrypted information related to a domain name.

5. The method of claim 4 , wherein the at least one tokenized string is contained in the store of tokenized strings, and further comprising determining that the encrypted information is available, and returning the encrypted information.

6. The method of claim 1 , wherein the result comprises WHOIS information.

7. The method of claim 6 , further comprising returning the WHOIS information to the client computer.

8. The method of claim 1 , further comprising generating the tokenized strings in the store by transmitting a plurality of data strings to the first tokenizing authority computer, and wherein the tokenized strings in the store are derived by the first tokenizing authority computer applying the first tokenizing function to the plurality of data strings.

9. The method of claim 8 , wherein the plurality of data strings comprises a set of blinded data strings, and further comprising, prior to transmitting the plurality of data strings to the first tokenizing authority, applying a blinding function to a set of unprocessed data strings to generate the set of blinded data strings.

10. The method of claim 9 , further comprising:

receiving a plurality of blinded tokenized strings; and

applying an unblinding function to the plurality of blinded tokenized strings to generate the tokenized strings in the store.

11. The method of claim 9 , wherein the blinding function comprises a cryptographic hash function.

12. A non-transitory computer-readable storage medium including instructions that, when executed by a processor, cause the processor to perform the steps of:

generating, via a first tokenizing authority computer, a tokenized string based on a first tokenizing function and a query string representing a domain name;

transmitting, to a server computer, a request for information related to the domain name and comprising the tokenized string, wherein the first tokenizing authority computer is different than the server computer; and

receiving a result from the server computer, wherein the result is based on a comparison between the tokenized string and a store of tokenized strings, wherein the tokenized strings in the store have been tokenized by a second tokenizing authority computer based on the first tokenizing function or a tokenizing function equivalent to the first tokenizing function, and the second tokenizing authority computer is different than the server computer.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the information related to the domain name comprises a fully qualified domain name.

14. The non-transitory computer-readable storage medium of claim 12 , wherein the information related to a domain name comprises a portion of the domain name.

15. The non-transitory computer-readable storage medium of claim 12 , wherein the request comprises a request for encrypted information related to a domain name.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the tokenized string is contained in the store of tokenized strings, and further comprising determining that the encrypted information is available, and returning the encrypted information.

17. The non-transitory computer-readable storage medium of claim 12 , wherein the result comprises WHOIS information.

18. The non-transitory computer-readable storage medium of claim 12 , wherein generating the tokenized string comprises transmitting the query string to the first tokenizing authority computer, and the tokenized string is derived by the first tokenizing authority applying the first tokenizing function to the query string.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the query string comprises a blinded query string, and further comprising, prior to transmitting the query string to the first tokenizing authority, applying a blinding function to an unprocessed query string to generate the blinded query string.

20. The non-transitory computer-readable storage medium of claim 19 , further comprising:

receiving a blinded tokenized string; and

applying an unblinding function to the blinded tokenized string to generate the tokenized string.

21. The non-transitory computer-readable storage medium of claim 19 , wherein the blinding function comprises a cryptographic hash function.

22. A non-transitory computer-readable storage medium including instructions that, when executed by a processor, cause the processor to perform a method of preserving privacy of a domain name related request by performing the steps of:

receiving, from a client computer, a request for information related to a domain name and comprising at least one tokenized string representing the domain name, wherein the tokenized string was tokenized by a first tokenizing authority computer based on a first tokenizing function, and the first tokenizing authority computer is different than the client computer;

comparing the at least one tokenized string to a store of tokenized strings, wherein the tokenized strings in the store have been tokenized by a second tokenizing authority computer based on the first tokenizing function or a tokenizing function equivalent to the first tokenizing function, and the second tokenizing authority computer is different than the client computer and a computer that holds the store of tokenized strings; and

determining whether the at least one tokenized string is contained in the store of tokenized strings to generate a result.

23. The non-transitory computer-readable storage medium of claim 22 , further comprising generating the tokenized strings in the store by:

applying a blinding function to a plurality of data strings to generate a plurality of blinded data strings;

transmitting the plurality of blinded data strings to the first tokenizing authority computer;

receiving a plurality of blinded tokenized data strings; and

applying an unblinding function to the plurality of blinded tokenized data strings to generate at least a portion of the tokenized strings in the store.

24. The non-transitory computer-readable storage medium of claim 23 , further comprising transmitting the result to the client computer, wherein the result comprises WHOIS information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2016
From: KALISKI, BURTON S., JR.
To: VERISIGN, INC.
Reel/Frame 038808/0848 →
Continuity (3)
Continuation 13732815 · Jan 2, 2013
Continuation In Part 13660838 · Oct 25, 2012
Related Publication 20160285836A1 · Sep 29, 2016