IP Library › Granted Patent US 12,652,266
Granted Patent B1
US 12,652,266 · App. 17/827,576 · Granted Jun 9, 2026

Methods and systems for data retrieval

Inventors: Andrew Fregly (Reston, VA); Joseph Harvey (Clifton, VA); Burton S. Kaliski, Jr. (McLean, VA)
Assignee: VeriSign, Inc.
H04L61/4511H04L61/58H04L63/0485H04L69/164
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,266
App. No.
17/827,576
Granted
Jun 9, 2026
Kind
B1
Abstract

A method for use by a Domain Name System (DNS) resolver includes: obtaining a first identifier that the DNS resolver associates with cache data, the cache data comprising at least a portion of one or more DNS resource records; receiving or obtaining a second identifier that an DNS nameserver associates with current data; determining whether the first identifier corresponds to the second identifier; and performing an action to maintain or update the cache data based on whether the first identifier corresponds to the second identifier.

Claims (59)

1 . A computer-implemented method for use by a Domain Name System (DNS) nameserver, the computer-implemented method comprising:

obtaining a first identifier that the DNS nameserver associates with current data, the current data comprising at least a portion of one or more DNS resource records;

receiving or obtaining a second identifier that a DNS recursive resolver associates with cache data;

determining whether the first identifier corresponds to the second identifier; and

sending, from the DNS nameserver to the DNS recursive resolver, an indication to maintain the cache data in response to determining that the first identifier corresponds to the second identifier.

2 . The computer-implemented method of claim 1 , wherein the indication indicates to increase a time-to-live associated with the cache data.

3 . The computer-implemented method of claim 1 , wherein, when the first identifier does not correspond to the second identifier:

sending, to the DNS recursive resolver, an indication to update the cache data; and

sending, to the DNS recursive resolver, at least a portion of the current data or a reference to at least a portion of the current data.

4 . The computer-implemented method of claim 1 , determining the first identifier does not correspond to the second identifier:

sending, to the DNS recursive resolver, an indication to update the cache data; and

sending, to the DNS recursive resolver, at least a portion of the current data, wherein the at least a portion of the current data is sent via a connectionless protocol.

5 . The computer-implemented method of claim 4 , wherein the connectionless protocol is User Datagram Protocol (UDP).

6 . The computer-implemented method of claim 1 , wherein determining whether the first identifier corresponds to the second identifier is in response to a timer expiry.

7 . The computer-implemented method of claim 1 , wherein determining whether the first identifier corresponds to the second identifier is in response to a request from the DNS recursive resolver.

8 . The computer-implemented method of claim 1 , wherein determining that the first identifier corresponds to the second identifier indicates that the current data corresponds to the cache data.

9 . The computer-implemented method of claim 1 , wherein the at least a portion of the one or more DNS resource records comprises information used for DNS Security Extensions (DNSSEC) validation.

10 . The computer-implemented method of claim 9 , wherein the information used for DNSSEC validation comprises a key or a signature.

11 . The computer-implemented method of claim 1 , wherein obtaining the first identifier comprises retrieving the first identifier from memory of the DNS nameserver.

12 . The computer-implemented method of claim 1 , wherein obtaining the first identifier comprises dynamically calculating the first identifier by the DNS nameserver.

13 . The computer-implemented method of claim 1 , wherein the first identifier is derived from the current data and the second identifier is derived from the cache data.

14 . The computer-implemented method of claim 1 , wherein the first identifier comprises a hash of the current data and the second identifier comprises a hash of the cache data.

15 . The computer-implemented method of claim 1 , wherein the first identifier comprises a subset of a hash of the current data and the second identifier comprises a subset of a hash of the cache data.

16 . The computer-implemented method of claim 1 , wherein the first identifier comprises a subset of the current data and the second identifier comprises a subset of the cache data.

17 . The computer-implemented method of claim 1 , wherein the first identifier and the second identifier are each managed by the DNS nameserver, wherein the first identifier is bound to the current data and the second identifier is bound to the cache data.

18 . The computer-implemented method of claim 17 , wherein the DNS nameserver is configured to validate that the first identifier is for the current data, and the DNS nameserver is configured to validate that the second identifier is for the cache data.

19 . The computer-implemented method of claim 1 , wherein the first identifier is a first verifiable instance identifier (VIID) and the second identifier is a second VIID.

20 . The computer-implemented method of claim 19 , wherein

the first VIID and the second VIID are verifiably associated with data instances.

21 . The computer-implemented method of claim 19 , wherein the first VIID and the second VIID are labeled as label VIIDs, wherein the label VIID is a unique identifier assigned to a data instance by an authoritative source.

22 . The computer-implemented method of claim 19 , wherein the first VIID and the second VIID are not cryptographically derived.

23 . The computer-implemented method of claim 1 , the computer-implemented method further comprising:

receiving a request for at least a portion of the current data from the DNS recursive resolver; and

facilitating out-of-band transfer of the at least a portion of the current data to the DNS recursive resolver.

24 . The computer-implemented method of claim 23 , wherein facilitating the out-of-band transfer of the at least a portion of the current data is based at least in part on determining that a size of the at least a portion of the current data exceeds a threshold.

25 . The computer-implemented method of claim 23 , wherein facilitating the out-of-band transfer of the at least a portion of the current data comprises indicating, to the DNS recursive resolver, a reference to an out-of-band source from which to retrieve at least a portion of the current data.

26 . The computer-implemented method of claim 1 , wherein the first identifier comprises a reference to an out-of-band data source from which to receive at least a portion of the current data.

27 . The computer-implemented method of claim 1 , the computer-implemented method further comprising:

receiving a granular request for data from a DNS recursive resolver, the granular request requesting a portion of the current data comprising less than a full resource record (RR) set; and

sending, to the DNS recursive resolver, the portion of the current data or a reference to an out-of-band source from which to retrieve the portion of the current data.

28 . The computer-implemented method of claim 27 , wherein the granular request indicates one or more requested RRs selected from the full RR set.

29 . The computer-implemented method of claim 27 , wherein the granular request indicates one or more requested elements of one or more RRs selected from the full RR set.

30 . The computer-implemented method of claim 1 , wherein the second identifier is received from the DNS recursive resolver.

31 . The computer-implemented method of claim 1 , wherein the current data comprises authoritative data instances, and the cached data comprises cached data instances.

32 . An apparatus for use by a Domain Name System (DNS) nameserver, the apparatus comprising one or more processors and one or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the apparatus to perform operations comprising:

obtaining a first identifier that the DNS nameserver associates with current data, the current data comprising at least a portion of one or more DNS resource records;

receiving or obtaining a second identifier that a DNS recursive resolver associates with cache data;

determining whether the first identifier corresponds to the second identifier; and

sending, from the DNS nameserver to the DNS recursive resolver, an indication to maintain the cache data in response to determining that the first identifier corresponds to the second identifier.

33 . A system for use by a Domain Name System (DNS) nameserver, the system comprising one or more processors and one or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

obtaining a first identifier that the DNS nameserver associates with current data, the current data comprising at least a portion of one or more DNS resource records;

receiving or obtaining a second identifier that a DNS recursive resolver associates with cache data;

determining whether the first identifier corresponds to the second identifier; and

sending, from the DNS nameserver to the DNS recursive resolver, an indication to maintain the cache data in response to determining that the first identifier corresponds to the second identifier.

34 . One or more non-transitory computer-readable media for use by a Domain Name System (DNS) nameserver, the one or more non-transitory computer-readable media storing instructions that, when executed by one or more processors, cause the performance of operations comprising:

obtaining a first identifier that the DNS nameserver associates with current data, the current data comprising at least a portion of one or more DNS resource records;

receiving or obtaining a second identifier that a DNS recursive resolver associates with cache data;

determining whether the first identifier corresponds to the second identifier; and

sending, from the DNS nameserver to the DNS recursive resolver, an indication to maintain the cache data in response to determining that the first identifier corresponds to the second identifier.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THIRD INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 060272 FRAME: 0574. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jul 8, 2022
From: FREGLY, ANDREW; HARVEY, JOSEPH; KALISKI, BURTON S., JR
To: VERISIGN, INC.
Reel/Frame 060615/0700 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2022
From: FREGLY, ANDREW; HARVEY, JOSEPH; KALISKI, BURTON S, JR.
To: VERISIGN, INC.
Reel/Frame 060272/0574 →
Continuity (1)
Provisional Application 63194835 · May 28, 2021
References Cited (44)
US 8356106B2 · Sood · 2013 [cited by examiner]
US 9026676B1 · Chen · 2015 [cited by examiner]
US 9300560B2 · Leighton · 2016 [cited by examiner]
US 9342698B2 · McPherson · 2016 [cited by examiner]
US 9467461B2 · Balderas · 2016 [cited by examiner]
US 9544266B2 · Tuliani · 2017 [cited by examiner]
US 9887956B2 · Akcin · 2018 [cited by examiner]
US 9906488B2 · Kagan · 2018 [cited by examiner]
US 10044629B1 · Raftery · 2018 [cited by examiner]
US 10158620B2 · Smith · 2018 [cited by examiner]
US 10230526B2 · Manning · 2019 [cited by examiner]
US 10911520B2 · Plamondon · 2021 [cited by examiner]
US 11025482B2 · Huque · 2021 [cited by examiner]
US 11082394B2 · Maslak · 2021 [cited by examiner]
US 11323414B2 · Vavrusa · 2022 [cited by examiner]
US 11329946B2 · Dupont · 2022 [cited by examiner]
US 11546319B2 · Galvin · 2023 [cited by examiner]
US 11665133B2 · Fieau · 2023 [cited by examiner]
US 20160028847A1 · Bradshaw · 2016 [cited by examiner]
US 20180375716A1 · Huque · 2018 [cited by examiner]
US 20190253411A1 · Joyner · 2019 [cited by examiner]
US 20210266342A1 · Maslak · 2021 [cited by examiner]
CN 112689030A · 2021 [cited by examiner]
“Post-Quantum Cryptography PQC,” (2021), 4 pages, https://csrc.nist.gov/projects/post-quantum-cryptography. [cited by applicant]
Kazunori Fujiwara et al., “Fragmentation Avoidance in DNS draft-ieft-dnsop-avoid-fragmentation-01,” (2020), 7 pages, https://tools.ietf.org/id/draft-ietf-dnsop-avoid-fragmentation-01.html#rfc.section.4. [cited by applicant]
Joao Damas et al., “Extension Mechanisms for DNS (EDNS(0)),” (2013), 16 pages, https://datatracker.ietf.org/doc/html/rfc6891. [cited by applicant]
Shumon Huque et al., “Algorithm Negotiation in DNSSEC draft-huque-dnssec-alg-nego-03,” (2018), 9 pages, https://tools.ietf.org/pdf/draft-huque-dnssec-alg-nego-03.pdf. [cited by applicant]
Amir Herzberg et al., “Less is More Cipher-Suite Negotiation for DNSSEC,” (2014), 20 pages, https://www.acsac.org/2014/program-final/oc_multifile/3/195.pdf. [cited by applicant]
Steve Crocker et al., “Signaling Cryptographic Algorithm Understanding in DNS Security Extensions (DNSSEC),” (2013), 9 pages, https://datatracker.ietf.org/doc/html/rfc6975. [cited by applicant]
Paul Wouters et al., “The edns-tcp-keepalive EDNS0 Option,” (2016), 11 pages, https://datatracker.ietf.org/doc/html/rfc7828. [cited by applicant]
“IPFS powers the Distributed Web,” (2021), https://ipfs.io/. [cited by applicant]
Andrew Banks et al., “MQTT Message Queuing Telemetry Transport (MQTT),” (2021), 7 pages, https://en.wikipedia.org/wiki/MQTT. [cited by applicant]
“Public-key cryptography,” (2021), 10 pages, https://en.wikipedia.org/wiki/Public-key_cryptography. [cited by applicant]
“DNSSEC,” (2021), 3 pages, https://www.internetsociety.org/deploy360/dnssec/. [cited by applicant]
Roy Arends et al., “DNS Security Introduction and Requirements,” (2005), 21 pages, https://datatracker.ietf.org/doc/html/rfc4033. [cited by applicant]
Roy Arends et al., “Resource Records for the DNS Security Extensions,” (2005), 29 pages, https://tools.ietf.org/pdf/rfc4034.pdf. [cited by applicant]
Roy Arends et al., “Protocol Modifications for the DNS Security Extensions,” (2005), 53 pages, https://datatracker.ietf.org/doc/html/rfc4035. [cited by applicant]
Olaf M. Kolkman et al., “DNSSEC Operational Practices, Version 2,” (2012), 71 pages, https://datatracker.ietf.org/doc/html/rfc6781. [cited by applicant]
Paul Wouters et al., “Algorithm Implementation Requirements and Usage Guidance for DNSSEC,” (2019), 11 pages, https://datatracker.ietf.org/doc/html/rfc8624. [cited by applicant]
Juan Benet et al., “DNSLink—linking content and services with DNS,” (2021), 7 pages, https://dnslink.io/. [cited by applicant]
“IPFS DNSLink Concepts,” (2021), 3 pages, https://docs.ipfs.io/concepts/dnslink/. [cited by applicant]
Luke Conway, “Blockchain Explained,” (2020), https://www.investopedia.com/terms/b/blockchain.asp. [cited by applicant]
Donald E. Eastlake, 3rd., “Indirect KEY RRs in the Domain Name System (DNS),” (1999), 9 pages, https://datatracker.ietf.org/doc/html/draft-ietf-dnsind-indirect-key-00. [cited by applicant]
Roy Arends et al., “Resource Records for the DNS Security Extensions (see Table in A.1), ” (2005), 29 pages, https://datatracker.ietf.org/doc/html/rfc4034#appendix-A.1. [cited by applicant]