IP Library Granted Patent US 10,834,066
Granted Patent B2
US 10,834,066 · App. 15/991,956 · Granted Nov 10, 2020

Secure domain name system

Inventors: Rodney Lance Joffe (Tempe, AZ); Victor Joseph Oppleman (Virginia Beach, VA); David Link King (Cave Creek, AZ); Brett Dean Watson (Scottsdale, AZ); Andrew Jackson (Sterling, VA); Sean Leach (Castle Pines, CO)
Assignee: Neustar, Inc.
H04L63/08H04L9/3247H04L61/1511H04L63/126H04L63/1408H05K999/99H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,834,066
App. No.
15/991,956
Granted
Nov 10, 2020
Kind
B2
Abstract

A method and system for authenticating answers to Domain Name System (DNS) queries originating from recursive DNS servers provided. A verification component provides a versification that a DNS query originated from the recursive DNS server. An authoritative DNS server receives the query via a network, such as the Internet, provides an answer to the query to an authentication component. The authentication component then provides an authentication such as a digital signature, which confirms that the received answer was provided by the authoritative DNS server, and then communicates the answer and the authentication to the verification component via the network. The verification component then verifies that the authentication corresponds to the receive answer and sends the answer to the recursive DNS server. When the verification component receives an answer in the absence of a corresponding authentication the verification component drops the answer.

Claims (44)

1. A system comprising:

a component in serial communication with an authoritative Domain Name System (DNS) server, wherein the component comprises one or more processors that access a corresponding memory, and are configured to:

receive an incoming communication sent by a verification component associated with a recursive DNS server, wherein the incoming communication includes:

(i) a DNS query generated by the recursive DNS server, and

(ii) a first digital signature generated by the verification component;

after validating the first digital signature, send the DNS query included in the incoming communication to the authoritative DNS server;

receive a DNS answer generated by the authoritative DNS server and destined for the recursive DNS server;

determine whether the DNS answer corresponds to the sent DNS query; and

send an outgoing communication to the recursive DNS server via the verification component, wherein the outgoing communication includes the DNS answer and a second digital signature.

2. The system of claim 1 , wherein the verification component is in serial communication with the recursive DNS server.

3. The system of claim 1 , wherein the outgoing communication to the recursive DNS server is sent after determining that the DNS answer corresponds to the sent DNS query.

4. The system of claim 1 , wherein the processors are further configured to:

after the first digital signature is validated, record that the recursive DNS server associated with the DNS query is expecting an answer from the authoritative DNS server, and wherein the determination of whether the DNS answer corresponds to the sent DNS query includes verifying whether the recursive DNS server is recorded as expecting an answer from the authoritative DNS answer.

5. The system of claim 1 , wherein the processors are further configured to generate the second digital signature.

6. The system of claim 1 , wherein the component is arranged with respect to the authoritative DNS server such that (i) all communications destined for the authoritative DNS server, and (ii) all communications originating from the authoritative DNS server are received at the component.

7. The system of claim 1 , wherein the authoritative DNS server and the component are implemented on two separate devices.

8. The system of claim 1 , further comprising a second component in serial communication with the component.

9. The system of claim 1 , wherein a second verification component is in serial communication with the verification component and the recursive DNS server.

10. The system of claim 1 , wherein at least one of the incoming communication and the outgoing communication is encrypted.

11. A method performed by a component in serial communication with an authoritative Domain Name System (DNS) server, the method comprising:

receiving an incoming communication sent by a verification component associated with a recursive DNS server, wherein the incoming communication includes:

(i) a DNS query generated by the recursive DNS server, and

(ii) a first digital signature generated by the verification component;

after validating the first digital signature, sending the DNS query included in the incoming communication to the authoritative DNS server;

receiving a DNS answer generated by the authoritative DNS server and destined for the recursive DNS server;

determining whether the DNS answer corresponds to the sent DNS query; and

sending an outgoing communication to the recursive DNS server via the verification component, wherein the outgoing communication includes the DNS answer and a second digital signature.

12. The method of claim 11 , wherein the verification component is in serial communication with the recursive DNS server.

13. The method of claim 11 , wherein the outgoing communication to the recursive DNS server is sent after determining that the DNS answer corresponds to the sent DNS query.

14. The method of claim 11 , further comprising:

after the first digital signature is validated, recording that the recursive DNS server associated with the DNS query is expecting an answer from the authoritative DNS server, and wherein the determination of whether the DNS answer corresponds to the sent DNS query includes verifying whether the recursive DNS server is recorded as expecting an answer from the authoritative DNS answer.

15. The method of claim 11 , further comprising generating the second digital signature.

16. The method of claim 11 , wherein the component is arranged with respect to the authoritative DNS server such that (i) all communications destined for the authoritative DNS server, and (ii) all communications originating from the authoritative DNS server are received at the component.

17. The method of claim 11 , wherein the authoritative DNS server and the component are implemented on two separate devices.

18. The method of claim 11 , further comprising a second component in serial communication with the component.

19. The method of claim 11 , wherein a second verification component is in serial communication with the verification component and the recursive DNS server.

20. A component in serial communication with an authoritative Domain Name System (DNS) server, comprising one or more processors that access a corresponding memory, and are configured to:

receive an incoming communication sent by a verification component associated with a recursive DNS server, wherein the incoming communication includes:

(i) a DNS query generated by the recursive DNS server, and

(ii) a first digital signature generated by the verification component;

after validating the first digital signature, send the DNS query included in the incoming communication to the authoritative DNS server;

receive a DNS answer generated by the authoritative DNS server and destined for the recursive DNS server;

determine whether the DNS answer corresponds to the sent DNS query; and

send an outgoing communication to the recursive DNS server via the verification component, wherein the outgoing communication includes the DNS answer and a second digital signature.

Assignments (9)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON JANUARY 23, 2025 AT REEL 069991 FRAME 0390 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072928/0289 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2025
From: VERCARA, LLC
To: DIGICERT, INC.
Reel/Frame 071781/0348 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0330 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2025
From: VERCARA, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 069991/0390 →
CHANGE OF NAME Recorded Mar 21, 2024
From: SECURITY SERVICES, LLC
To: VERCARA, LLC
Reel/Frame 066867/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: NEUSTAR, INC.
To: SECURITY SERVICES, LLC
Reel/Frame 057327/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2018
From: JOFFE, RODNEY LANCE; OPPLEMAN, VICTOR JOSEPH; KING, DAVID LINK; WATSON, BRETT DEAN; JACKSON, ANDREW; LEACH, SEAN
To: NEUSTAR, INC.
Reel/Frame 046991/0796 →
Continuity (4)
Continuation 15478011 · Apr 3, 2017
Continuation 14922486 · Oct 26, 2015
Continuation 12237144 · Sep 24, 2008
Related Publication 20180278598A1 · Sep 27, 2018