IP Library Granted Patent US 12,647,263
Granted Patent B1
US 12,647,263 · App. 18/416,847 · Granted Jun 2, 2026

Multi autonomous secure domain name systems

Inventor: Jason Paul Larrew (Helotes, TX)
Assignee: United Services Automobile Association (USAA)
H04L9/088H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,263
App. No.
18/416,847
Granted
Jun 2, 2026
Kind
B1
Abstract

Embodiments disclosed herein allow multiple providers to answer for DNS while having DNSSEC enabled for the same zone. To do so, the system shares DNSKEY records between autonomous DNS vendors. Sharing DNSKEY records allows customers to use multiple DNS providers with DNSSEC enabled without sharing private keys amongst providers.

Claims (57)

1 . A method comprising:

determining, by a first primary Domain Name System (DNS) server, a second primary DNS server effected a change to at least one record in the second primary DNS server based on receiving a record change communication from the second primary DNS server,

wherein the second primary DNS server generates one or more second DNSKEY records that records the change,

wherein the first primary DNS server and the second primary DNS server autonomously operate in a first group of DNS servers, and

wherein a plurality of primary DNS servers in the first group have an ability to make changes to records independently from other primary DNS servers in the first group;

effecting, by the first primary DNS server, the change to a first record in the first primary DNS server, by generating one or more first DNSKEY records that records the change; and

exchanging, by the first primary DNS server with the second primary DNS server, the one or more second DNSKEY records and the one or more first DNSKEY records to ensure a DNSKEY record request routed to any primary DNS servers autonomously operating in the first group is filled.

2 . The method of claim 1 , further comprising:

signing, by the first primary DNS server, the change with a first private key to validate the change.

3 . The method of claim 1 , further comprising:

creating a Delegation Signer record by hashing at least one first DNSKEY record signed with a public Key Signing Key.

4 . The method of claim 3 , further comprising:

sending the Delegation Signer record to a top level domain server.

5 . The method of claim 1 ,

wherein the one or more first DNSKEY records each include a first public key, wherein the one or more second DNSKEY records each include a second public key, and

wherein the first public key and the second public key each include a public Zone Signing Key and a public Key Signing Key.

6 . The method of claim 1 , wherein the one or more first DNSKEY records comprises a first DNSKEY record signed with a public Zone Signing Key and another first DNSKEY record signed with a public Key Signing Key.

7 . The method of claim 1 , wherein the first primary DNS server and the second primary DNS server are not publicly accessible.

8 . A system comprising:

one or more processors; and

one or more memories storing instructions that, when executed by the one or more processors, cause the system to perform a process comprising:

determining, by a first primary Domain Name System (DNS) server, a second primary DNS server effected a change to at least one record in the second primary DNS server based on receiving a record change communication from the second primary DNS server,

wherein the second primary DNS server generates one or more second DNSKEY records that records the change,

wherein the first primary DNS server and the second primary DNS server autonomously operate in a first group of DNS servers, and

wherein a plurality of primary DNS servers in the first group have an ability to make changes to records independently from other primary DNS servers in the first group;

effecting, by the first primary DNS server, the change to a first record in the first primary DNS server, by generating one or more first DNSKEY records that records the change; and

exchanging, by the first primary DNS server with the second primary DNS server, the one or more second DNSKEY records and the one or more first DNSKEY records to ensure a DNSKEY record request routed to any primary DNS servers autonomously operating in the first group is filled.

9 . The system according to claim 8 , wherein the process further comprises:

signing, by the first primary DNS server, the change with a first private key to validate the change.

10 . The system according to claim 8 , wherein the process further comprises:

creating a Delegation Signer record by hashing at least one first DNSKEY record signed with a public Key Signing Key.

11 . The system according to claim 10 , wherein the process further comprises:

sending the Delegation Signer record to a top level domain server.

12 . The system according to claim 8 ,

wherein the one or more first DNSKEY records each include a first public key, wherein the one or more second DNSKEY records each include a second public key, and

wherein the first public key and the second public key each include a public Zone Signing Key and a public Key Signing Key.

13 . The system according to claim 8 , wherein the one or more first DNSKEY records comprises a first DNSKEY record signed with a public Zone Signing Key and another first DNSKEY record signed with a public Key Signing Key.

14 . The system according to claim 8 , wherein the first primary DNS server and the second primary DNS server are not publicly accessible.

15 . A non-transitory computer-readable medium storing instructions that, when executed by a computing system, cause the computing system to perform operations comprising:

determining, by a first primary Domain Name System (DNS) server, a second primary DNS server effected a change to at least one record in the second primary DNS server based on receiving a record change communication from the second primary DNS server,

wherein the second primary DNS server generates one or more second DNSKEY records that records the change,

wherein the first primary DNS server and the second primary DNS server autonomously operate in a first group of DNS servers, and

wherein a plurality of primary DNS servers in the first group have an ability to make changes to records independently from other primary DNS servers in the first group;

effecting, by the first primary DNS server, the change to a first record in the first primary DNS server, by generating one or more first DNSKEY records that records the change; and

exchanging, by the first primary DNS server with the second primary DNS server, the one or more second DNSKEY records and the one or more first DNSKEY records to ensure a DNSKEY record request routed to any primary DNS servers autonomously operating in the first group is filled.

16 . The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

signing, by the first primary DNS server, the change with a first private key to validate the change.

17 . The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

creating a Delegation Signer record by hashing at least one first DNSKEY record signed with a public Key Signing Key.

18 . The non-transitory computer-readable medium of claim 17 , wherein the operations further comprise:

sending the Delegation Signer record to a top level domain server.

19 . The non-transitory computer-readable medium of claim 15 ,

wherein the one or more first DNSKEY records each include a first public key, wherein the one or more second DNSKEY records each include a second public key, and

wherein the first public key and the second public key each include a public Zone Signing Key and a public Key Signing Key.

20 . The non-transitory computer-readable medium of claim 15 ,

wherein the one or more first DNSKEY records comprises a first DNSKEY record signed with a public Zone Signing Key and another first DNSKEY record signed with a public Key Signing Key, and

wherein the first primary DNS server and the second primary DNS server are not publicly accessible.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2024
From: LARREW, JASON PAUL
To: UIPCO, LLC
Reel/Frame 066432/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2024
From: UIPCO, LLC
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 066432/0973 →
Continuity (3)
Continuation 17841584 · Jun 15, 2022
Continuation 16547811 · Aug 22, 2019
Provisional Application 62725105 · Aug 30, 2018
References Cited (11)
US 10135882B1 · Salour · 2018 [cited by examiner]
US 11394540B1 · Larrew · 2022 [cited by applicant]
US 20100070569A1 · Turakhia · 2010 [cited by applicant]
US 20120017090A1 · Gould · 2012 [cited by examiner]
US 20120117621A1 · Kondamuru · 2012 [cited by examiner]
US 20120278626A1 · Smith et al. · 2012 [cited by applicant]
US 20120284505A1 · Smith et al. · 2012 [cited by applicant]
US 20150058999A1 · McPherson · 2015 [cited by examiner]
US 20160330174A1 · Sullivan et al. · 2016 [cited by applicant]
US 20170012943A1 · Kaliski et al. · 2017 [cited by applicant]
US 20170324724A1 · Smith · 2017 [cited by examiner]