IP Library › Granted Patent US 12,659,289
Granted Patent B2
US 12,659,289 · App. 17/177,838 · Granted Jun 16, 2026

GTLD domain name registries RDAP architecture

Inventors: Patrick Kane (Ashburn, VA); Marc Anderson (Herndon, VA); Scott Hollenbeck (Fairfax Station, VA); Swapneel Sheth (Fairfax, VA); Joseph Waldron (Herndon, VA); James Gould (Leesburg, VA)
Assignee: VeriSign, Inc.
H04L61/30G06F16/95G06F16/951H04L9/14H04L9/30H04L9/3247H04L61/302H04L63/06H04L61/4511H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,289
App. No.
17/177,838
Filed
Feb 17, 2021
Granted
Jun 16, 2026
Kind
B2
Examiner
KING, JOHN B
Art Unit
2498
USPC
713/176
Abstract

Provided is a method for providing a response to a user query for domain-related information of a domain. The method can include obtaining, at a client over a network, the user query for the domain-related information, and identifying one or more thick services based on thin data for the domain. The method can also include providing, by the client, the user query to the identified one or more thick services and obtaining a first answer to the user query from the one or more thick services. Furthermore, the method can include providing a second answer to a user based on the first answer.

Claims (53)

1 . A method for obtaining registration data by a first registration data service, the method comprising:

obtaining, by the first registration data service, a first query for registration data, wherein the first query is from a client, wherein a thin data is accessible by the first registration data service;

obtaining, by the first registration data service, an access token, wherein the access token is provided to the client by an authorization service;

selecting, by the first registration data service, a second registration data service from a plurality of registration data services based on the thin data;

sending, to the second registration data service, the access token and a second query for registration data, wherein the second query is based on the first query, wherein the second registration data service is configured to trust the access token based on a first relationship between the second registration data service and the authorization service; and

receiving, by the first registration data service, a response to the second query for registration data from the second registration data service.

2 . The method of claim 1 , wherein the first relationship between the second registration data service and the authorization service comprises a first trust relationship.

3 . The method of claim 2 , wherein the first trust relationship comprises an identity of the authorization service being verifiable by the second registration data service.

4 . The method of claim 3 , wherein the identity of the authorization service is verifiable using a public key of the authorization service and the access token, wherein the access token comprises a cryptographic signature of the authorization service.

5 . The method of claim 1 , further comprising: providing to the client, by the first registration data service, the response to the second query for registration data.

6 . The method of claim 1 , wherein the first registration data service is configured to trust the access token based on a second relationship between the first registration data service and the authorization service.

7 . The method of claim 1 , wherein the access token comprises a differentiated level of access.

8 . The method of claim 1 , wherein the access token is obtained at the client based on a request by the first registration data service or the second registration data service.

9 . A system for obtaining registration data by a first registration data service, the system comprising:

one or more processors; and

a memory system comprising one or more computer-readable media, wherein the one or more computer-readable media contain instructions that cause the one or more processors to perform one or more operations, comprising:

obtaining, by the first registration data service, a first query for registration data, wherein the first query is from a client, wherein a thin data is accessible by the first registration data service;

obtaining, by the first registration data service, an access token, wherein the access token is provided to the client by an authorization service;

selecting, by the first registration data service, a second registration data service from a plurality of registration data services based on the thin data;

sending, to the second registration data service, the access token and a second query for registration data, wherein the second query is based on the first query, wherein the second registration data service is configured to trust the access token based on a first relationship between the second registration data service and the authorization service; and

receiving, by the first registration data service, a response to the second query for registration data from the second registration data service.

10 . The system of claim 9 , wherein the first relationship between the second registration data service and the authorization service comprises a first trust relationship.

11 . The system of claim 10 , wherein the first trust relationship comprises an identity of the authorization service being verifiable by the second registration data service.

12 . The system of claim 11 , wherein the identity of the authorization service is verifiable using a public key of the authorization service and the access token, wherein the access token comprises a cryptographic signature of the authorization service.

13 . The system of claim 9 , wherein the one or more processors are further operable to perform operations comprising providing, to the client, by the first registration data service, the response to the second query for registration data.

14 . The system of claim 9 , wherein the first registration data service is configured to trust the access token based on a second relationship between the first registration data service and the authorization service.

15 . The system of claim 9 , wherein the access token comprises a differentiated level of access.

16 . The system of claim 9 , wherein the access token is obtained at the client based on a request provided by the first registration data service or the second registration data service.

17 . A method for obtaining registration data by a first registration data service, the method comprising:

obtaining, by the first registration data service, a first query for registration data, wherein the first query is from a client, wherein a thin data is accessible by the first registration data service;

selecting, by the first registration data service, a second registration data service from a plurality of registration data services based on the thin data;

sending, to the second registration data service, a second query for registration data, wherein the second query is based on the first query, wherein the second registration data service has a first relationship with an authorization service, wherein the second registration data service is configured to respond to the second query based on the first relationship with the authorization service; and

receiving, by the first registration data service, a response to the second query for registration data from the second registration data service.

18 . The method of claim 17 , wherein the first relationship comprises an identity of the authorization service being verifiable by the second registration data service.

19 . The method of claim 18 , wherein the identity of the authorization service is verifiable using a public key of the authorization service and an access token, wherein the access token comprises a cryptographic signature of the authorization service.

20 . The method of claim 1 , further comprising:

selecting, by the first registration data service, a third registration data service from the plurality of registration data services based on the thin data, the third registration data service being different from the second registration data service;

sending, to the third registration data service, the access token and a third query for registration data, wherein the third query is based on the first query, wherein the third registration data service is configured to trust the access token based on a third relationship between the third registration data service and the authorization service; and

receiving, by the first registration data service, a response to the third query for registration data from the third registration data service.

21 . The method of claim 20 , further comprising:

aggregating, by the first registration data service, the response to the second query for registration data from the second registration data service and the response to the third query for registration data from the third registration data service.

22 . The method of claim 1 , wherein the first registration data service comprises a registry.

23 . The method of claim 1 , wherein the first registration data service is unable to respond to the first query based on the thin data accessible by the first registration data service.

24 . The method of claim 1 , wherein the thin data accessible by the first registration data service identifies the second registration data service.

25 . The method of claim 1 , wherein the thin data accessible by the first registration data service identifies the plurality of registration data services.

26 . The method of claim 1 , further comprising:

selecting, by the first registration data service, a third registration data service from the plurality of registration data services based on the thin data;

sending, to the third registration data service, a third query for registration data;

receiving, by the first registration data service, a response to the third query for registration data from the third registration data service, wherein the third query is based on the first query; and

providing to the client, by the first registration data service, an aggregated response to the first query for registration data based on the response received from the second registration data service and the response received from the third registration data service.

27 . The method of claim 1 , wherein the first query is the same as the second query.

28 . The system of claim 9 , wherein the first query is the same as the second query.

29 . The method of claim 17 , wherein the first query is the same as the second query.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2021
From: KANE, PATRICK; ANDERSON, MARC; HOLLENBECK, SCOTT; SHETH, SWAPNEEL; WALDRON, JOSEPH; GOULD, JAMES
To: VERISIGN, INC.
Reel/Frame 055298/0731 →
Continuity (3)
Continuation 16704572 · Dec 5, 2019
Continuation 15269698 · Sep 19, 2016
Related Publication 20210176208A1 · Jun 10, 2021
References Cited (96)
US 8195652B1 · Parsons · 2012 [cited by examiner]
US 8849849B2 · Kothapalli · 2014 [cited by examiner]
US 9165134B2 · Lorenzo et al. · 2015 [cited by applicant]
US 9365188B1 · Penilla et al. · 2016 [cited by applicant]
US 10009337B1 · Fischer et al. · 2018 [cited by applicant]
US 10523632B2 · Kane et al. · 2019 [cited by applicant]
US 10659424B2 · Jheeta · 2020 [cited by examiner]
US 11689495B2 · Stahura · 2023 [cited by examiner]
US 20020091703A1 · Bayles · 2002 [cited by applicant]
US 20020103806A1 · Yamanoue · 2002 [cited by examiner]
US 20020136410A1 · Hanna · 2002 [cited by applicant]
US 20030023878A1 · Rosenberg · 2003 [cited by examiner]
US 20030093556A1 · Yeung et al. · 2003 [cited by applicant]
US 20030140119A1 · Acharya et al. · 2003 [cited by applicant]
US 20030187841A1 · Zhang · 2003 [cited by examiner]
US 20030229900A1 · Reisman · 2003 [cited by applicant]
US 20040006597A1 · Hughes · 2004 [cited by applicant]
US 20040162983A1 · Gotoh et al. · 2004 [cited by applicant]
US 20040199493A1 · Ruiz · 2004 [cited by examiner]
US 20040199520A1 · Ruiz · 2004 [cited by examiner]
US 20040199608A1 · Rechterman · 2004 [cited by examiner]
US 20040199620A1 · Ruiz et al. · 2004 [cited by applicant]
US 20050037750A1 · Goering · 2005 [cited by examiner]
US 20050102354A1 · Hollenbeck et al. · 2005 [cited by applicant]
US 20050125451A1 · Mooney · 2005 [cited by examiner]
US 20060007894A1 · Igarashi · 2006 [cited by examiner]
US 20060095404A1 · Adelman · 2006 [cited by examiner]
US 20060095459A1 · Adelman · 2006 [cited by examiner]
US 20070040021A1 · Nakayma · 2007 [cited by applicant]
US 20070208869A1 · Adelman et al. · 2007 [cited by applicant]
US 20070208940A1 · Adelman · 2007 [cited by examiner]
US 20080034211A1 · Shull et al. · 2008 [cited by applicant]
US 20110078437A1 · Reddy · 2011 [cited by applicant]
US 20120304004A1 · Gould · 2012 [cited by examiner]
US 20130061046A1 · Joy et al. · 2013 [cited by applicant]
US 20130085932A1 · Waldron et al. · 2013 [cited by applicant]
US 20130159499A1 · Besehanic · 2013 [cited by examiner]
US 20130311478A1 · Frett · 2013 [cited by examiner]
US 20140006642A1 · Kothapalli et al. · 2014 [cited by applicant]
US 20140188651A1 · Krueger · 2014 [cited by applicant]
US 20140245012A1 · Arya et al. · 2014 [cited by applicant]
US 20150033332A1 · Merza · 2015 [cited by applicant]
US 20150334049A1 · Miura · 2015 [cited by applicant]
US 20160179822A1 · Gupta et al. · 2016 [cited by applicant]
US 20170118172A1 · Blinn · 2017 [cited by examiner]
US 20170141926A1 · Xu et al. · 2017 [cited by applicant]
US 20170279762A1 · Fregly · 2017 [cited by examiner]
US 20180052836A1 · Nicholls · 2018 [cited by applicant]
US 20180083781A1 · Kaliski, Jr. et al. · 2018 [cited by applicant]
US 20180083919A1 · Kane et al. · 2018 [cited by applicant]
US 20190052650A1 · Hu · 2019 [cited by examiner]
US 20220182345A1 · Birch · 2022 [cited by examiner]
CN 114978740A · 2022 [cited by examiner]
JP 2004288118A · 2004 [cited by examiner]
WO WO02056132A2 · 2002 [cited by examiner]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-weirds-rdap-openid-00, IETF, May 14, 2015, pp. 1-10. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-weirds-rdap-openid-01, IETF, Jun. 16, 2015, pp. 1-10. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-weirds-rdap-openid-02, IETF, Jun. 18, 2015, pp. 1-10. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using Open ID Connect”, draft-hollenbeck-weirds-rdap-openid-03, IETF, Nov. 19, 2015, pp. 1-11. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-weirds-rdap-openid-04, IETF, Dec. 17, 2015, pp. 1-14. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-weirds-rdap-openid-05, IETF, Jan. 7, 2016, pp. 1-15. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-regext-rdap-openid-01, IETF, Sep. 26, 2016, pp. 1-22. [cited by applicant]
Hollenbeck, S., “Federated Authentication for the Registration Data Access Protocol (RDAP) Using OpenID Connect”, draft-hollenbeck-regext-rdap-openid-02, IETF, Dec. 2, 2016, pp. 1-23. [cited by applicant]
Non-Final Office Action issued in corresponding U.S. Appl. No. 15/269,698, filed Mar. 22, 2018, (11 pages). [cited by applicant]
Non-Final Office Action issued in corresponding U.S. Appl. No. 15/269,698, filed Nov. 2, 2018, (17 pages). [cited by applicant]
Final Office Action issued in corresponding U.S. Appl. No. 15/269,698, filed Apr. 17, 2019, (16 pages). [cited by applicant]
Notice of Allowance issued in corresponding U.S. Appl. No. 15/269,698, filed Aug. 15, 2019, (10 pages). [cited by applicant]
Corrected Notice of Allowability issued in corresponding U.S. Appl. No. 15/269,698, filed Oct. 17, 2019, (8 pages). [cited by applicant]
Notice of Allowance issued in corresponding U.S. Appl. No. 16/704,572, filed Oct. 6, 2020, (23 pages). [cited by applicant]
Corrected Notice of Allowability issued in corresponding U.S. Appl. No. 16/704,572, filed Jan. 25, 2021, (8 pages). [cited by applicant]
Extended European Search Report issued in corresponding European Patent Application No. 18159568.7 on Aug. 1, 2018, pp. 1-11. [cited by applicant]
Anonymous, “Whois—Wikipedia”, (2015) XP055367775; retrieved from the Internet: https://en.wikipedia.org/w/index.phptitle=WHOIS oldid-689698417, pp. 1-14. [cited by applicant]
Extended European Search Report dated Feb. 13, 2018, European Application No. 17191912.9, pp. 1-9. [cited by applicant]
Anonymous, “RDAP Operational Profile for gTLD Registries and Registrars”, Version 1.0, IETF, Dec. 3, 2015, pp. 1-26. [cited by applicant]
S. Hollenbeck, “Federated Authentication for the Registration Data Access Protocol (RDAP) Using Open ID Connect”, IETF, Apr. 26, 2016, pp. 1-22. [cited by applicant]
A. Newton et al., “JSON Responses for the Registration Data Access Protocol (RDAP)”, IETF, Mar. 2015, pp. 1-78. [cited by applicant]
M. Blanchet et al., “Finding the Authoritative Registration Data (RDAP) Service”, IETF, Mar. 2015, pp. 1-18. [cited by applicant]
S. Hollenbeck et al., Security Services for the Registration Data Access Protocol (RDAP), IETF, Mar. 2015, pp. 1-14. [cited by applicant]
A. Newton et al., “Registration Data Access Protocol (RDAP) Query Format”, IETF, Mar. 2015, pp. 1-20. [cited by applicant]
A. Newton et al., “HTTP Usage in the Registration Data Access Protocol (RDAP)”, IETF, Mar. 2015, pp. 1-16. [cited by applicant]
Hess et al., “Advanced Client/Server Authentication in TLS”, Computer Science Department, Brigham Yong Univerisy, https://www.researchgate.net, Apr. 2002, pp. 1-12. [cited by applicant]
US Office Action cited in corresponding U.S. Appl. No. 15/452,997, filed Aug. 21, 2019, pp. 1-14. [cited by applicant]
Newton et al., “Registration Data Access Protocol Query Format”, Network Working Group, Internet Draft, Dec. 23, 2014, pp. 1-20. [cited by applicant]
European Office Action issued in corresponding European Patent Application No. 17 191 912.9 on Feb. 3, 2020, 4 pages. [cited by applicant]
European Intention to Grant issued in corresponding European Patent Application No. 18 159 568.7 on Mar. 24, 2020, 7 pages. [cited by applicant]
Extended European Search Report issued in corresponding European Patent Application No. 20195144.9 on Nov. 23, 2020, (11 pages). [cited by applicant]
Williamson et al., “Referral Whois (RWhois) Protocol V1.5,” IEFT, Jun. 1997, pp. 1-70. [cited by applicant]
Newton A, Ellacott B, Kong No. “Http usage in the registration data access protocol (rdap).” Mar. 2015. ISSN: 2010-1721, Internet Egineering Task Force (IETF) pp. 1-16 (Year: 2015). [cited by applicant]
D. Hardt, “The OAuth 2.0 Authorization Framework,” RFC 6749, Oct. 2012, 89 pages. [cited by applicant]
W. Denniss et al., “OAuth 2.0 for Native Apps,” RFC 8252, Oct. 2017, 25 pages. [cited by applicant]
W. Denniss et al., “OAuth 2.0 for Native Apps draft-ietf-oauth-native-apps-08,” dated Mar. 2, 2017, 15 pages. [cited by applicant]
W. Denniss et al., “OAuth 2.0 for Native Apps draft-ietf-oauth-native-apps-03,” dated Jul. 20, 2016, 14 pages. [cited by applicant]
N. Sakimura et al., “OpenID Connect Core 1.0 incorporating errata set 2,” https://openid.net/specs/openid-connect-core-1_0.html, 89 pages. [cited by applicant]
Openid-connect-core-1_0.xml, dated Dec. 16, 2023, 3 pages. [cited by applicant]
OpenID Connect Works—OpenID Foundation, 6 pages. [cited by applicant]
U.S. Notice of Allowance issued in corresponding U.S. Appl. No. 16/704,572, filed Oct. 6, 2020, pp. 1-23. [cited by applicant]