IP Library › Granted Patent US 12,445,433
Granted Patent B1
US 12,445,433 · App. 18/631,620 · Granted Oct 14, 2025

Shared authentication via DNS request routing

Inventors: Seven Starosta (Brooklyn, NY); Jeffrey M. Tejnecky (Chesterfield, VA); Brandon Krouse (Frisco, TX)
Assignee: Capital One Services, LLC
H04L63/083H04L63/0435H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,433
App. No.
18/631,620
Filed
Apr 10, 2024
Granted
Oct 14, 2025
Kind
B1
Art Unit
2434
USPC
726/4
Abstract

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DOS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.

Claims (103)

1. A computing device configured to manage authentication for a Domain Name System (DNS) using shared authentication credentials of a first authentication framework, the computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the computing device to:

receive, via an Application Programming Interface (API), a first DNS request comprising:

first authentication credentials for a first user; and

a first requested change to a first DNS Canonical Name (CNAME) record;

query a first authentication database corresponding to the first authentication framework to determine whether the first authentication credentials are associated with one or more existing authentication tokens;

based on determining that the first authentication credentials are not associated with the one or more existing authentication tokens, determine, by querying a second authentication database corresponding to a second authentication framework different from the first authentication framework, whether the first authentication credentials are valid by comparing the first authentication credentials to a blocklist;

based on a determination that the first authentication credentials are valid, generate a modified DNS request comprising:

the first requested change to the first DNS CNAME record; and

the shared authentication credentials of the first authentication framework; and

transmit the modified DNS request to a DNS server.

2. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, via the API, a second DNS request comprising:

second authentication credentials for a second user; and

a second requested change to a second DNS CNAME record;

query the first authentication database corresponding to the first authentication framework to determine whether the second authentication credentials are associated with the one or more existing authentication tokens;

based on a determination that the second authentication credentials are associated with a first authentication token of the one or more existing authentication tokens:

determine, based on the first authentication token, a secret key;

generate a second modified DNS request comprising:

the second requested change to the second DNS CNAME record;

the first authentication token; and

the secret key; and

transmit the second modified DNS request to the DNS server.

3. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, via the API, a second DNS request comprising:

second authentication credentials for a second user; and

a second requested change to a second DNS CNAME record;

query the first authentication database corresponding to the first authentication framework to determine whether the second authentication credentials are associated with the one or more existing authentication tokens; and

based on determining that the second authentication credentials are not associated with the one or more existing authentication tokens, and based on determining that the second authentication credentials are valid, cause output of a notification that the second DNS request is denied.

4. The computing device of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, from the DNS server, a response to the modified DNS request;

modify the response to the modified DNS request by removing, from the response, one or more indications of the shared authentication credentials; and

send the modified response to a user device.

5. The computing device of claim 1 , wherein the first requested change to the first DNS CNAME record comprises a request to create a CNAME record.

6. The computing device of claim 1 , wherein the one or more existing authentication tokens are generated in accordance with the first authentication framework upon successful authentication of one or more users.

7. A method configured to manage authentication for a Domain Name System (DNS) using shared authentication credentials of a first authentication framework, the method comprising:

receiving, via an Application Programming Interface (API), a first DNS request comprising:

first authentication credentials for a first user; and

a first requested change to a first DNS Canonical Name (CNAME) record;

querying a first authentication database corresponding to the first authentication framework to determine whether the first authentication credentials are associated with one or more existing authentication tokens;

based on determining that the first authentication credentials are not associated with the one or more existing authentication tokens, determining, by querying a second authentication database corresponding to a second authentication framework different from the first authentication framework, whether the first authentication credentials are valid by comparing the first authentication credentials to a blocklist;

based on a determination that the first authentication credentials are valid, generating a modified DNS request comprising:

the first requested change to the first DNS CNAME record; and

the shared authentication credentials of the first authentication framework; and

transmitting the modified DNS request to a DNS server.

8. The method of claim 7 , further comprising:

receiving, via the API, a second DNS request comprising:

second authentication credentials for a second user; and

a second requested change to a second DNS CNAME record;

querying the first authentication database corresponding to the first authentication framework to determine whether the second authentication credentials are associated with the one or more existing authentication tokens;

based on a determination that the second authentication credentials are associated with a first authentication token of the one or more existing authentication tokens:

determining, based on the first authentication token, a secret key;

generating a second modified DNS request comprising:

the second requested change to the second DNS CNAME record;

the first authentication token; and

the secret key; and

transmitting the second modified DNS request to the DNS server.

9. The method of claim 7 , further comprising:

receiving, via the API, a second DNS request comprising:

second authentication credentials for a second user; and

a second requested change to a second DNS CNAME record;

querying the first authentication database corresponding to the first authentication framework to determine whether the second authentication credentials are associated with the one or more existing authentication tokens; and

based on determining that the second authentication credentials are not associated with the one or more existing authentication tokens, and based on determining that the second authentication credentials are valid, causing output of a notification that the second DNS request is denied.

10. The method of claim 7 , further comprising:

receiving, from the DNS server, a response to the modified DNS request;

modifying the response to the modified DNS request by removing, from the response, one or more indications of the shared authentication credentials; and

sending the modified response to a user device.

11. The method of claim 7 , wherein the first requested change to the first DNS CNAME record comprises a request to create a CNAME record.

12. The method of claim 7 , wherein the one or more existing authentication tokens are generated in accordance with the first authentication framework upon successful authentication of one or more users.

13. One or more non-transitory computer-readable media storing instructions configured to manage authentication for a Domain Name System (DNS) using shared authentication credentials of a first authentication framework, wherein the instructions, when executed by one or more processors, cause a computing device to:

receive, via an Application Programming Interface (API), a first DNS request comprising:

first authentication credentials for a first user; and

a first requested change to a first DNS Canonical Name (CNAME) record;

query a first authentication database corresponding to the first authentication framework to determine whether the first authentication credentials are associated with one or more existing authentication tokens;

based on determining that the first authentication credentials are not associated with the one or more existing authentication tokens, determine, by querying a second authentication database corresponding to a second authentication framework different from the first authentication framework, whether the first authentication credentials are valid by comparing the first authentication credentials to a blocklist;

based on a determination that the first authentication credentials are valid, generate a modified DNS request comprising:

the first requested change to the first DNS CNAME record; and

the shared authentication credentials of the first authentication framework; and

transmit the modified DNS request to a DNS server.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, via the API, a second DNS request comprising:

second authentication credentials for a second user; and

a second requested change to a second DNS CNAME record;

query the first authentication database corresponding to the first authentication framework to determine whether the second authentication credentials are associated with the one or more existing authentication tokens;

based on a determination that the second authentication credentials are associated with a first authentication token of the one or more existing authentication tokens:

determine, based on the first authentication token, a secret key;

generate a second modified DNS request comprising:

the second requested change to the second DNS CNAME record;

the first authentication token; and

the secret key; and

transmit the second modified DNS request to the DNS server.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, via the API, a second DNS request comprising:

second authentication credentials for a second user; and

a second requested change to a second DNS CNAME record;

query the first authentication database corresponding to the first authentication framework to determine whether the second authentication credentials are associated with the one or more existing authentication tokens; and

based on determining that the second authentication credentials are not associated with the one or more existing authentication tokens, and based on determining that the second authentication credentials are valid, cause output of a notification that the second DNS request is denied.

16. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, cause the computing device to:

receive, from the DNS server, a response to the modified DNS request;

modify the response to the modified DNS request by removing, from the response, one or more indications of the shared authentication credentials; and

send the modified response to a user device.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the first requested change to the first DNS CNAME record comprises a request to create a CNAME record.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2024
From: STAROSTA, SEVEN; TEJNECKY, JEFFREY M.; KROUSE, BRANDON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 067148/0601 →
References Cited (27)
US 8473635B1 · Lohner et al. · 2013 [cited by applicant]
US 9705959B1 · Strand et al. · 2017 [cited by applicant]
US 20040083306A1 · Gloe · 2004 [cited by applicant]
US 20050203875A1 · Mohammed et al. · 2005 [cited by applicant]
US 20070073660A1 · Quinlan · 2007 [cited by applicant]
US 20100174785A1 · Cai et al. · 2010 [cited by applicant]
US 20160262021A1 · Lee · 2016 [cited by examiner]
US 20160381048A1 · Zhao et al. · 2016 [cited by applicant]
US 20170041321A1 · Tan et al. · 2017 [cited by applicant]
US 20170302699A1 · Adams et al. · 2017 [cited by applicant]
US 20180213052A1 · MacCarthaigh et al. · 2018 [cited by applicant]
US 20190130100A1 · Dymshits et al. · 2019 [cited by applicant]
US 20190207927A1 · Lakhani · 2019 [cited by examiner]
US 20190245875A1 · Chen et al. · 2019 [cited by applicant]
US 20200007548A1 · Sanghavi et al. · 2020 [cited by applicant]
US 20200220946A1 · Chan et al. · 2020 [cited by applicant]
US 20210203671A1 · Baldwin et al. · 2021 [cited by applicant]
US 20220321596A1 · Weizman · 2022 [cited by examiner]
US 20230362207A1 · St. Pierre et al. · 2023 [cited by applicant]
US 20240176829A1 · Vilcinskas et al. · 2024 [cited by applicant]
US 20250088531A1 · St. Pierre et al. · 2025 [cited by applicant]
What is Airflow™?, <<https://airflow.apache.org/docs/apache-airflow/stable/>>, publication date unknown but, prior to May 29, 2022, 5 pages. [cited by applicant]
DAGs, Apache Airflow, date of publication unknown but, <<https://airflow.apache.org/docs/apache-airflow/stable/concepts/dags.html>>, prior to Mar. 24, 2024, 27 pages. [cited by applicant]
Xu, Tony, “Step by Step: build a data pipeline with Airflow,” Towards Data Science, Aug. 15, 2020, <<https://towardsdatascience.com/step-by-step-build-a-data-pipeline-with-airflow-4f96854f7466>>, 35 pages. [cited by applicant]
Apache Airflow, “How to Work with Databases—ETL Pipeline,” better data science, date of publication unknown but, prior to Feb. 17, 2022, <<https://betterdatascience.com/apache-airflow-postgres-database/>>, 31 pages. [cited by applicant]
Access the Airflow database, <<https://docs.astronomer.io/software/access-airflow-database>>, date of publication unknown but, prior to May 7, 2020, 10 pages. [cited by applicant]
Understanding the Airflow metadata database, <<https://www.astronomer.io/guides/airflow-database>>, date of publication unknown but, prior to Apr. 18, 2022, 8 pages. [cited by applicant]
Cited By (2)
US 12,568,138 US 12,579,229