Movatterモバイル変換


[0]ホーム

URL:


CA2686142A1 - Alternate dns root nameservice for dnssec purposes - Google Patents

Alternate dns root nameservice for dnssec purposes
Download PDF

Info

Publication number
CA2686142A1
CA2686142A1CA2686142ACA2686142ACA2686142A1CA 2686142 A1CA2686142 A1CA 2686142A1CA 2686142 ACA2686142 ACA 2686142ACA 2686142 ACA2686142 ACA 2686142ACA 2686142 A1CA2686142 A1CA 2686142A1
Authority
CA
Canada
Prior art keywords
root
zone
nameservice
dns
dnssec
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
CA2686142A
Other languages
French (fr)
Inventor
Thierry Moreau
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Connotech Experts Conseils Inc
Original Assignee
Connotech Experts Conseils Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Connotech Experts Conseils IncfiledCriticalConnotech Experts Conseils Inc
Priority to CA2686142ApriorityCriticalpatent/CA2686142A1/en
Publication of CA2686142A1publicationCriticalpatent/CA2686142A1/en
Abandonedlegal-statusCriticalCurrent

Links

Classifications

Landscapes

Abstract

The Internet DNS (Domain Name System) may be integrity protected with the deployment of the DNSSEC protocol extension at the root zone. The inventive methods allow a common DNSSEC-related cryptographic key configuration, also called trust anchor, to be used for a number of independent alternate root nameservice operators, each operating its own set of root nameservers. A single root signing entity feeds each nameserver operators with its own version of the signed DNS root zone. The inventive processes allow these versions to coexist on the public Internet gracefully.
It thus allows the load on root nameservers to be shared, and a DNS resolver to switch from one alternate nameservice operator to the other with minimal disturbance. The preferred embodiment is such that the exact same substantive root zone contents is delivered either by the official DNS root zone or an alternate root nameservice fed by an independent root signing entity.

Claims (2)

-12-What is claimed is:
1. A method of servicing a signed DNS root zone to a network from at least one host in a first set of hosts where a) substantially the same DNS root zone is being serviced concurrently from at least one node in a second set of hosts, b) the zone apex NS RRset serviced from hosts in said first set contains the respective domain names of hosts in said first set and is signed with a digital signature key pair, and c) the zone apex NS RRset serviced from hosts in said second set contains the respective domain names of hosts in said second set and is signed with said digital signature key pair.
2. A method of preparing a DNS root zone for DNSSEC service to a network where a) a plurality of variants is prepared with substantially the same signed DNS
root zone contents, b) each of said plurality of variants has a zone apex NS RRset containing a set of domain names non intersecting with other variants, c) each of said plurality of variants has its zone apex NS RRset signed with a common digital signature key pair, and d) each of said plurality of variants have signature inception and expiration times allowing ordinarily concurrent DNSSEC servicing of said DNS root zone.
CA2686142A2009-11-202009-11-20Alternate dns root nameservice for dnssec purposesAbandonedCA2686142A1 (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CA2686142ACA2686142A1 (en)2009-11-202009-11-20Alternate dns root nameservice for dnssec purposes

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CA2686142ACA2686142A1 (en)2009-11-202009-11-20Alternate dns root nameservice for dnssec purposes

Publications (1)

Publication NumberPublication Date
CA2686142A1true CA2686142A1 (en)2011-05-20

Family

ID=44063351

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CA2686142AAbandonedCA2686142A1 (en)2009-11-202009-11-20Alternate dns root nameservice for dnssec purposes

Country Status (1)

CountryLink
CA (1)CA2686142A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US11792079B2 (en)*2011-12-302023-10-17Verisign, Inc.DNS package in a network

Cited By (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US11792079B2 (en)*2011-12-302023-10-17Verisign, Inc.DNS package in a network

Similar Documents

PublicationPublication DateTitle
US8850553B2 (en)Service binding
WO2007064744A3 (en)Extending sso for dhcp snooping to two box redundancy
WO2011079145A3 (en)Systems and methods for mixed mode handling of ipv6 and ipv4 traffic by a virtual server
Herzberg et al.DNSSEC: Security and availability challenges
CA2586223A1 (en)Opt-in process and nameserver system for ietf dnssec
EP1326408A3 (en)Technique for enabling multiple virtual file servers on a single file server to participate in multiple address spaces with overlapping network addresses
WO2008097454A3 (en)Method and system of providing ip-based packet communications in a utility network
WO2007058981A3 (en)Method and apparatus for managing hardware address resolution
WO2007100641A3 (en)Communication using private ip addresses of local networks
WO2006031748A3 (en)System and method for connection optimization
Herzberg et al.Socket overloading for fun and cache-poisoning
TW200708009A (en)Preventing duplicate sources from clients served by a network address port translator
EP2389043A3 (en)Method and system for handover between different types of access systems
CN101119274A (en)Method for improving treatment efficiency of SSL gateway and SSL gateway
ATE530003T1 (en) SYSTEM AND METHOD FOR ACCESS NETWORK MULTIHOMING
WO2006028674A3 (en)A system and method for sharing an ip address
Herzberg et al.Antidotes for DNS poisoning by off-path adversaries
Szalachowski et al.Short paper: on deployment of DNS-based security enhancements
CA2686142A1 (en)Alternate dns root nameservice for dnssec purposes
Sridhara et al.Global distributed secure mapping of network addresses
CN101945053B (en)Method and device for transmitting message
Gilad et al.The Use of Maxlength in the RPKI
Henderson et al.Using the Host Identity Protocol with legacy applications
KR101477008B1 (en)Method, apparatus, system and computer-readable recording medium for testing load balancing device
Gayraud et al.Network Time Protocol (NTP) Server Option for DHCPv6

Legal Events

DateCodeTitleDescription
FZDEDiscontinued

Effective date:20121011


[8]ページ先頭

©2009-2025 Movatter.jp