Multi autonomous secure domain name systems
View Patent ↗Embodiments disclosed herein allow multiple providers to answer for DNS while having DNSSEC enabled for the same zone. To do so, the system shares DNSKEY records between autonomous DNS vendors. Sharing DNSKEY records allows customers to use multiple DNS providers with DNSSEC enabled without sharing private keys amongst providers.
1 . A method comprising:
determining, by a first primary Domain Name System (DNS) server, a second primary DNS server effected a change to at least one record in the second primary DNS server based on receiving a record change communication from the second primary DNS server,
wherein the second primary DNS server generates one or more second DNSKEY records that records the change,
wherein the first primary DNS server and the second primary DNS server autonomously operate in a first group of DNS servers, and
wherein a plurality of primary DNS servers in the first group have an ability to make changes to records independently from other primary DNS servers in the first group;
effecting, by the first primary DNS server, the change to a first record in the first primary DNS server, by generating one or more first DNSKEY records that records the change; and
exchanging, by the first primary DNS server with the second primary DNS server, the one or more second DNSKEY records and the one or more first DNSKEY records to ensure a DNSKEY record request routed to any primary DNS servers autonomously operating in the first group is filled.
2 . The method of claim 1 , further comprising:
signing, by the first primary DNS server, the change with a first private key to validate the change.
3 . The method of claim 1 , further comprising:
creating a Delegation Signer record by hashing at least one first DNSKEY record signed with a public Key Signing Key.
4 . The method of claim 3 , further comprising:
sending the Delegation Signer record to a top level domain server.
5 . The method of claim 1 ,
wherein the one or more first DNSKEY records each include a first public key, wherein the one or more second DNSKEY records each include a second public key, and
wherein the first public key and the second public key each include a public Zone Signing Key and a public Key Signing Key.
6 . The method of claim 1 , wherein the one or more first DNSKEY records comprises a first DNSKEY record signed with a public Zone Signing Key and another first DNSKEY record signed with a public Key Signing Key.
7 . The method of claim 1 , wherein the first primary DNS server and the second primary DNS server are not publicly accessible.
8 . A system comprising:
one or more processors; and
one or more memories storing instructions that, when executed by the one or more processors, cause the system to perform a process comprising:
determining, by a first primary Domain Name System (DNS) server, a second primary DNS server effected a change to at least one record in the second primary DNS server based on receiving a record change communication from the second primary DNS server,
wherein the second primary DNS server generates one or more second DNSKEY records that records the change,
wherein the first primary DNS server and the second primary DNS server autonomously operate in a first group of DNS servers, and
wherein a plurality of primary DNS servers in the first group have an ability to make changes to records independently from other primary DNS servers in the first group;
effecting, by the first primary DNS server, the change to a first record in the first primary DNS server, by generating one or more first DNSKEY records that records the change; and
exchanging, by the first primary DNS server with the second primary DNS server, the one or more second DNSKEY records and the one or more first DNSKEY records to ensure a DNSKEY record request routed to any primary DNS servers autonomously operating in the first group is filled.
9 . The system according to claim 8 , wherein the process further comprises:
signing, by the first primary DNS server, the change with a first private key to validate the change.
10 . The system according to claim 8 , wherein the process further comprises:
creating a Delegation Signer record by hashing at least one first DNSKEY record signed with a public Key Signing Key.
11 . The system according to claim 10 , wherein the process further comprises:
sending the Delegation Signer record to a top level domain server.
12 . The system according to claim 8 ,
wherein the one or more first DNSKEY records each include a first public key, wherein the one or more second DNSKEY records each include a second public key, and
wherein the first public key and the second public key each include a public Zone Signing Key and a public Key Signing Key.
13 . The system according to claim 8 , wherein the one or more first DNSKEY records comprises a first DNSKEY record signed with a public Zone Signing Key and another first DNSKEY record signed with a public Key Signing Key.
14 . The system according to claim 8 , wherein the first primary DNS server and the second primary DNS server are not publicly accessible.
15 . A non-transitory computer-readable medium storing instructions that, when executed by a computing system, cause the computing system to perform operations comprising:
determining, by a first primary Domain Name System (DNS) server, a second primary DNS server effected a change to at least one record in the second primary DNS server based on receiving a record change communication from the second primary DNS server,
wherein the second primary DNS server generates one or more second DNSKEY records that records the change,
wherein the first primary DNS server and the second primary DNS server autonomously operate in a first group of DNS servers, and
wherein a plurality of primary DNS servers in the first group have an ability to make changes to records independently from other primary DNS servers in the first group;
effecting, by the first primary DNS server, the change to a first record in the first primary DNS server, by generating one or more first DNSKEY records that records the change; and
exchanging, by the first primary DNS server with the second primary DNS server, the one or more second DNSKEY records and the one or more first DNSKEY records to ensure a DNSKEY record request routed to any primary DNS servers autonomously operating in the first group is filled.
16 . The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:
signing, by the first primary DNS server, the change with a first private key to validate the change.
17 . The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:
creating a Delegation Signer record by hashing at least one first DNSKEY record signed with a public Key Signing Key.
18 . The non-transitory computer-readable medium of claim 17 , wherein the operations further comprise:
sending the Delegation Signer record to a top level domain server.
19 . The non-transitory computer-readable medium of claim 15 ,
wherein the one or more first DNSKEY records each include a first public key, wherein the one or more second DNSKEY records each include a second public key, and
wherein the first public key and the second public key each include a public Zone Signing Key and a public Key Signing Key.
20 . The non-transitory computer-readable medium of claim 15 ,
wherein the one or more first DNSKEY records comprises a first DNSKEY record signed with a public Zone Signing Key and another first DNSKEY record signed with a public Key Signing Key, and
wherein the first primary DNS server and the second primary DNS server are not publicly accessible.