IP Library › Granted Patent US 12,137,026
Granted Patent B1
US 12,137,026 · App. 17/537,296 · Granted Nov 5, 2024

Identifying trusted configuration information to perform service discovery

Inventors: Andrew Cathrow (Ashburn, VA); Andrew Fregly (Herndon, VA); Stephen D. James (South Riding, VA)
Assignee: VeriSign, Inc.
H04L41/0806H04L61/4511H04L61/4541H04L63/08H04L63/123H04L63/166H04L67/51H04L63/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,137,026
App. No.
17/537,296
Granted
Nov 5, 2024
Kind
B1
Abstract

In one embodiment, a delegation engine automatically provisions a device connected to a network to securely identify and interact with external services. As a device boots in a deployment environment, the delegation engine generates a search domain name based on a manufacturer-supplied domain name and a domain name associated with the deployment environment. The delegation engine then searches a Domain Name System (DNS) to retrieve a delegation record stored at the search domain name. After verifying a manufacturer signature associated with the delegation record, the delegation engine configures the device based on service discovery information included in the delegation record. Because the delegation engine automates the provisioning process, the time required to provision devices is acceptable irrespective of the number of the devices. Further, because the delegation engine verifies the delegation record, the delegation engine does not expose the device to security risks during the provisioning process.

Claims (39)

1. A computer-implemented method, the method comprising:

searching, by a device, a domain name system (DNS) for a record associated with a domain name, wherein the record comprises a transport layer security authentication (TLSA) record;

obtaining, by the device, the record from the DNS, wherein the record is associated with a signature generated using a private key, and wherein the record enables retrieval of a public key that corresponds to the private key;

authenticating, by the device, the signature associated with the record, wherein the authenticating is based on the public key; and

configuring the device based on information included in the record,

wherein the information included in the record comprises a trusted domain name that facilitates discovery of one or more services identified by an Internet of Things (IoT) device.

2. The computer-implemented method of claim 1 , wherein searching the DNS for the record comprises:

generating a DNS record query that includes the domain name; and

transmitting the DNS record query to a DNS server.

3. The computer-implemented method of claim 2 , wherein:

the delegation record is associated with a DNS Security Extensions (DNSSEC) signature that is generated based on DNSSEC; and

the DNS server is configured to verify the DNSSEC signature.

4. The computer-implemented method of claim 1 , further comprising:

transmitting a Dynamic Host Configuration Protocol (DHCP) request to a DHCP server; and

receiving, from the DHCP server, a response that includes the domain name.

5. The computer-implemented method of claim 1 , wherein a portion of the domain name is associated with a manufacturer of the device.

6. One or more non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to perform steps comprising:

searching, by a device, a Domain Name System (DNS) for a record associated with a domain name, wherein the record comprises a transport layer security authentication (TLSA) record;

obtaining, by the device, the record from the DNS, wherein the record is associated with a signature generated using a private key, and wherein the record enables retrieval of a public key that corresponds to the private key;

authenticating, by the device, the signature associated with the record, wherein the authenticating is based on the public key; and

configuring the device based on information included in the record,

wherein the information included in the record comprises a trusted domain name that facilitates discovery of one or more services identified by an Internet of Things (IoT) device.

7. The one or more non-transitory computer-readable storage media of claim 6 , wherein searching the DNS for the record comprises:

generating a DNS record query that includes the domain name; and

transmitting the DNS record query to a DNS server.

8. The one or more non-transitory computer-readable storage media of claim 6 , further comprising:

transmitting a Dynamic Host Configuration Protocol (DHCP) request to a DHCP server; and

receiving, from the DHCP server, a response that includes the domain name.

9. The one or more non-transitory computer-readable storage media of claim 6 , wherein the record comprises a text record (TXT).

10. A system comprising:

a memory storing an engine associated with a device; and

a processor that is coupled to the memory and, when executing the engine, is configured to cause the engine to:

search a Domain Name System (DNS) for a record associated with a domain name, wherein the record comprises a transport layer security authentication (TLSA) record;

obtain the record from the DNS, wherein the record is associated with a signature generated using a private key, and wherein the record enables retrieval of a public key that corresponds to the private key;

authenticate the signature associated with the record, wherein the authenticating is based on the public key; and

configure the device based on information included in the record,

wherein the information included in the record comprises a trusted domain name that facilitates discovery of one or more services identified by an Internet of Things (IoT) device.

11. The system of claim 10 , wherein the record comprises a text record (TXT).

12. The system of claim 10 , wherein the device comprises a computing device, a smart phone, a wearable technology device, an appliance, or a sensor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2021
From: CATHROW, ANDREW; FREGLY, ANDREW; JAMES, STEPHEN D.
To: VERISIGN, INC.
Reel/Frame 058232/0535 →
Continuity (2)
Continuation 15148990 · May 6, 2016
Provisional Application 62159779 · May 11, 2015