IP Library Granted Patent US 11,876,779
Granted Patent B2
US 11,876,779 · App. 17/402,271 · Granted Jan 16, 2024

Secure DNS using delegated credentials and keyless SSL

Inventors: Tirumaleswar Reddy Konda (Bangalore, IN); Shashank Jain (Bangalore, IN); Himanshu Srivastava (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/0209H04L9/3073H04L61/4511H04L63/04H04L63/0823H04L63/168H04L67/568G06F8/65
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,779
App. No.
17/402,271
Granted
Jan 16, 2024
Kind
B2
Abstract

There is disclosed in an example a gateway device, including a hardware computing platform, and a secure domain name system (DNS) engine having circuitry and stored instructions to-program the circuitry, the secure DNS engine to communicatively couple to an endpoint via a local network, begin a secure DNS transaction with the endpoint, determine whether the endpoint supports delegated credentials, and after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using a delegated credential.

Claims (38)

1. A gateway device, comprising:

a hardware computing platform; and

a secure domain name system (DNS) engine comprising circuitry and stored instructions to-program the circuitry, the secure DNS engine to:

communicatively couple to an endpoint via a local network;

begin a secure DNS transaction with the endpoint;

determine whether the endpoint supports delegated credentials;

after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using a delegated credential; and

determine that the endpoint does not support delegated credentials, and to establish a secure DNS session with the endpoint using keyless SSL.

2. The gateway device of claim 1 , wherein beginning the secure DNS transaction comprises receiving a client hello with a delegated credentials extension.

3. The gateway device of claim 1 , wherein the secure DNS engine is further to determine that the endpoint does not support delegated credentials, that the endpoint runs software that can be updated to support delegated credentials, and provide a recommendation to update the software.

4. The gateway device of claim 3 , wherein the software is an operating system or browser.

5. The gateway device of claim 1 , wherein the secure DNS engine is to provide unsecured legacy DNS services only to endpoints that do not support secure DNS.

6. The gateway device of claim 1 , wherein the secure DNS engine is to enroll with a cloud service, wherein enrolling with the cloud service comprises receiving an identity certificate.

7. The gateway device of claim 6 , wherein the secure DNS engine is further to generate a key pair to secure communication with the cloud service.

8. The gateway device of claim 1 , wherein the delegated credential is signed with a domain validated (DV) certificate of a cloud service.

9. The gateway device of claim 1 , wherein the delegated credential includes a private key, a signature verification algorithm, and an expiry.

10. The gateway device of claim 1 , wherein securing the secure DNS transaction comprises including the delegated credentials as an extension in a certificate entry of an end-entity certificate.

11. The gateway device of claim 1 , wherein the gateway device is a consumer home gateway.

12. The gateway device of claim 1 , wherein the gateway device is an enterprise home gateway.

13. One or more tangible, non-transitory computer-readable storage media having stored thereon executable instructions to:

provide a secure DNS forwarding function secured by an end-entity certificate;

receive a delegated credential from a cloud service;

begin a DNS transaction with an endpoint;

after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using the delegated credentials; and

after determining that the endpoint does not support delegated credentials, establish the secure DNS session using keyless SSL.

14. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the instructions are further to provide a caching DNS server.

15. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the instructions are further to provide a DNS forwarder.

16. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the instructions are to determine that the endpoint does not support delegated credentials, that the endpoint runs software that can be updated to support delegated credentials, and provide a recommendation to update the software.

17. A computer-implemented method, comprising:

receiving from a cloud service a delegated cryptographic credential;

identifying, on a local network, a first endpoint device that supports delegated credential encryption;

beginning a secure domain name system (DNS) transaction with the first endpoint device;

establishing a secure DNS session for the secure DNS transaction using the delegated cryptographic credential;

identifying, on the local network, a second endpoint device that does not support delegated credential encryption; and

establishing a secure DNS session with the second endpoint device using keyless SSL.

18. The method of claim 17 , further comprising providing a caching DNS server and DNS forwarder.

19. The one or more tangible, non-transitory computer-readable media of claim 13 , wherein the instructions are to receive a client hello with a delegated credentials extension.

20. The method of claim 17 , further comprising determining that the second endpoint device runs software that can be updated to support delegated credentials, and provide a recommendation to update the software.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2021
From: KONDA, TIRUMALESWAR REDDY; JAIN, SHASHANK; SRIVASTAVA, HIMANSHU
To: MCAFEE, LLC
Reel/Frame 057176/0264 →
Priority Claims (1)
IN 202141014288 · Mar 30, 2021 · national
Continuity (1)
Related Publication 20220321528A1 · Oct 6, 2022
Cited By (1)
US 12,452,081