IP Library › Granted Patent US 9,531,603
Granted Patent B2
US 9,531,603 · App. 14/209,783 · Granted Dec 27, 2016

Reconciling internet DNS zone file changes with origin change requests

Inventors: Ramesh Balasubramanian (Bangalore, IN); Brian Coppola (Arlington, VA); Punit Rathore (Ashburn, VA); Surabhi Sudha (Sterling, VA)
Assignee: VERISIGN, INC.
H04L43/04H04L61/1511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,531,603
App. No.
14/209,783
Granted
Dec 27, 2016
Kind
B2
Abstract

Techniques for monitoring zone file changes are presented. The techniques may include obtaining at least one zone change request and parsing the at least one zone change request to obtain at least one change request unit. The techniques may include obtaining a last published zone file, obtaining a new zone file, and comparing the last published zone file to the new zone file to obtain at least one difference object. The techniques may include matching the at least one difference object to the at least one change request unit to identify at least one unmatched difference object. The techniques may include providing a human readable report comprising an indication of the at least one unmatched difference object.

Claims (44)

1. A method for monitoring Domain Name System (DNS) zone file changes, the method comprising:

obtaining at least one zone change request;

parsing the at least one zone change request to obtain at least one change request unit, wherein each change request unit constitutes a single executable instruction;

obtaining a last published zone file;

obtaining an unpublished new zone file;

comparing the last published zone file to the new zone file to obtain at least one difference object, wherein the at least one difference object identifies a DNS record type, a DNS record, and a difference type;

matching the at least one difference object to the at least one change request unit to identify at least one unmatched difference object;

providing a human readable report comprising an indication of the at least one unmatched difference object.

2. The method of claim 1 , wherein each change request unit is a smallest possible unit that can be executed on a domain or a host.

3. The method of claim 1 , wherein each change request unit is of the form of one of: DomainCreateHostAdd, DomainCreateDSAdd, DomainDelete, DomainUpdateHostAdd, DomainUpdateHostRemove, DomainUpdateDSAdd, DomainUpdateDSRemove, DomainUpdateDSChange, HostUpdatelPAdd, HostUpdatelPRemove, and HostUpdateHostNameChange.

4. The method of claim 1 , wherein each difference object comprises a DNSJAVA object.

5. The method of claim 4 , wherein each difference object comprises an org.xbill.DNS.record object.

6. The method of claim 1 , wherein each difference object is of the form of one of: AddNameServer, DeleteNameServer, AddA/AAAA, DeleteA/AAAA, AddDelegationSigner, and DeleteDelegationSigner.

7. The method of claim 1 , wherein the matching comprises, for each difference object, searching for a corresponding change request unit.

8. The method of claim 1 , further comprising filtering the at least one difference object to remove DNSSEC records.

9. The method of claim 1 , further comprising:

altering the new zone file to account for the at least one unmatched difference object, whereby a corrected new zone file is produced; and

providing the corrected new zone file for publishing.

10. The method of claim 1 , wherein:

the at least one zone change request comprises at least one root zone change request;

the last published zone file comprises a last published root zone file; and

the new zone file comprises a new root zone file.

11. A system for monitoring zone file changes, the system comprising:

at least one processor configured to obtain at least one zone change request;

at least one processor configured to parse the at least one zone change request to obtain at least one change request unit, wherein each change request unit constitutes a single executable instruction;

at least one processor configured to obtain a last published zone file;

at least one processor configured to obtain an unpublished new zone file;

at least one processor configured to compare the last published zone file to the new zone file to obtain at least one difference object, wherein the at least one difference object identifies a domain name system (DNS) record type, a DNS record, and a difference type;

at least one processor configured to match the at least one difference object to the at least one change request unit to identify at least one unmatched difference object;

at least one processor configured to generate a human readable report comprising an indication of the at least one unmatched difference object.

12. The system of claim 11 , wherein each change request unit is a smallest possible unit that can be executed on a domain or a host.

13. The system of claim 11 , wherein each change request unit is of the form of one of: DomainCreateHostAdd, DomainCreateDSAdd, DomainDelete, DomainUpdateHostAdd, DomainUpdateHostRemove, DomainUpdateDSAdd, DomainUpdateDSRemove, DomainUpdateDSChange, HostUpdatelPAdd, HostUpdatelPRemove, and HostUpdateHostNameChange.

14. The system of claim 11 , wherein each difference object comprises a DNSJAVA object.

15. The system of claim 11 , wherein each difference object comprises an org.xbill.DNS.record object.

16. The system of claim 11 , wherein each difference object is of the form of one of: AddNameServer, DeleteNameServer, AddA/AAAA, DeleteA/AAAA, AddDelegationSigner, and DeleteDelegationSigner.

17. The system of claim 11 , wherein the at least one processor configured to match is further configured to, for each difference object, search for a corresponding change request unit.

18. The system of claim 11 , further comprising at least one processor configured to filter the at least one difference object to remove DNSSEC records.

19. The system of claim 11 , further comprising:

at least one processor configured to alter the new zone file to account for the at least one unmatched item, whereby a corrected new zone file is produced; and

at least one processor configured to provide the corrected new zone file for publishing.

20. The system of claim 11 , wherein:

the at least one zone change request comprises at least one root zone change request;

the last published zone file comprises a last published root zone file; and

the new zone file comprises a new root zone file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2014
From: BALASUBRAMANIAN, RAMESH; COPPOLA, BRIAN; RATHORE, PUNIT; SUDHA, SURABHI
To: VERISIGN, INC.
Reel/Frame 032433/0910 →
Continuity (2)
Provisional Application 61784693 · Mar 14, 2013
Related Publication 20140280916A1 · Sep 18, 2014