Patents
Literature
Hiro is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Hiro

30 results about "DNS zone" patented technology

A DNS zone is any distinct, contiguous portion of the domain name space in the Domain Name System (DNS) for which administrative responsibility has been delegated to a single manager. The domain name space of the Internet is organized into a hierarchical layout of subdomains below the DNS root domain. The individual domains of this tree may serve as delegation points for administrative authority and management. However, usually it is furthermore desirable to implement fine-grained boundaries of delegation, so that multiple sub-levels of a domain may be managed independently. Therefore, the domain name space is partitioned into areas (zones) for this purpose. A zone starts at a domain and extends downward in the tree to the leaf nodes or to the top-level of subdomains where other zones start.

Opt-in process and nameserver system for IETF DNSSEC

InactiveUS20080260160A1Facilitating DNSSEC deploymentDecreases comprehensivenessSpecial service provision for substationPublic key for secure communicationComputer networkName server
The process of signing and then publishing a DNS zone according to the IETF DNSSEC protocols is improved by the present invention, in order to facilitate the DNSSEC deployment until most of the DNS zones are signed. The prior art situation is that a second-level domain, e.g. example.com, often faces an unwanted status of “DNSSEC island of security,” and a challenging task of “trust anchor key” out-of-band distribution. The invention somehow fixes such broken DNSSEC chains of trust, e.g. it fills the gap between a DNSSEC island of security and its signed grandparent or ancestor. The invention is deemed useful for the introduction of DNS root nameservice substitution for DNSSEC support purposes, and allows opt-in while NSEC3 opt-out is awaiting deployment in large TLDs.
Owner:CONNOTECH EXPERTS CONSEIL

Method for administering a top-level domain

A method for administering a top-level domain by analyzing domain name registrations for requests for suspicious or malicious domain names. A request to register a domain name is received. The requested domain name's information may be stored in a registry database. The requested domain name may also be conditionally stored in the domain name system (DNS) zone. The requested domain name is compared to a list of botnet domain names stored in a watch list database. If the requested domain name corresponds to one of the botnet domain names, the requested domain name is prevented from being added to the DNS zone or is removed from the DNS zone, if it has already been stored there. The information regarding the requested domain name is stored in the registry database, even if the domain name does not ultimately stay in the DNS zone.
Owner:VERISIGN

DNS zone file multi-node transmission method and system

The invention relates to a DNS zone file multi-node transmission method and system. A DNS zone file segmentation module and a slave server management module are added to a master server. The method includes the steps: (1) a plurality of authority servers including the master server and a plurality of slave servers are deployed in a DNS system, the master server periodically produces DNS zone files and sends the DNS zone files to the slave servers; (2) after the DNS zone files are segmented on the master server, file subblocks are numbered, and a slave server list is generated according to register information on the master server; (3) the master server sends a zone file update command to the slave servers in the slave server list and meanwhile sends the slave server list to the slave servers; (4) the slave servers pick neighbor nodes after receiving the update command and load the multi-node file subblocks after the neighbor nodes are selected to complete transmission of the DNS zone files.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER

DNS zone data verification method and device

The invention discloses a DNS zone data verification method and device, and the method comprises the steps: obtaining a latest updated transaction digital fingerprint corresponding to a latest serialnumber from a latest updated transaction of an incremental data file as a first verification digital fingerprint after an auxiliary DNS server completes incremental updating each time; wherein the kthupdated transaction digital fingerprint is generated and stored in advance by using a digital fingerprint coding algorithm based on resource record query hash values of the first to kth updated transactions in the local area file and the incremental data file; acquiring the digital fingerprint corresponding to the latest serial number from the zone file of the main DNS server as a first standarddigital fingerprint; and if the first verification digital fingerprint is inconsistent with the first standard digital fingerprint, determining that the DNS region data of the auxiliary DNS server isabnormal. Therefore, the digital fingerprint technology is applied to DNS region data verification, a DNS region data consistency verification method is established, and potential safety hazards of DNS region data inconsistency are discovered in time.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER

Method for Automatically Configuring a Router, Method for Automatic Address Configuration, Router, Computer Program and Computer-Readable Medium

A method for automatic address configuration, router, computer program, computer-readable medium and method for automatically configuring a router that has an upstream interface, connected or connectable to a higher-level subnetwork and / or a higher-level router, and a downstream interface, connected or connectable to a lower-level subnetwork, wherein whether the router receives, on the upstream interface, messages providing notification of at least one domain as part of a DNS search list option, is monitored and, if the message is not received over a prescribed period, a DNS island mode is automatically activated in which the DNS zone of a local DNS server of the router is configured using a predefined island domain, and a transmission module of the router is prompted to send a message via the downstream interface, which message includes the preconfigured island domain as part of a DNS search list option, preferably an address of the downstream interface.
Owner:SIEMENS AG

A method and device for verifying dns area data

The present application discloses a method and device for verifying DNS zone data. The method includes: obtaining the latest update corresponding to the latest serial number from the latest update transaction of the incremental data file after the secondary DNS server completes the incremental update each time. The digital fingerprint of the transaction is the first verification digital fingerprint; the digital fingerprint of the kth updated transaction is pre-generated based on the resource record query hash value of the 1st to k updated transactions in the local area file and the incremental data file using the digital fingerprint encoding algorithm And stored; Obtain the digital fingerprint corresponding to the latest serial number from the zone file of the primary DNS server as the first standard digital fingerprint; if the first verification digital fingerprint is inconsistent with the first standard digital fingerprint, determine the DNS zone data of the secondary DNS server abnormal. It can be seen that the digital fingerprint technology is applied to the data verification of the DNS area, and the data consistency verification method of the DNS area is established to timely discover the security risks of the inconsistency of the DNS area data.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER

Method, server and domain name system for realizing purpose of creating synchronization in DNS region

The present invention provides a method, primary Domain Name System(DNS) server, secondary DNS server and domain name system for realizing synchronization of the DNS zone creation, wherein the method includes: the primary DNS server creates a DNS zone and sets the dependence relationship between each DNS server in the DNS zone, and each DNS server includes a primary DNS server and at least two levels of secondary DNS servers(11); according to the dependence relationship, the primary DNS server sends to the secondary DNS servers level by level a notification message including the information of the higher-level server of the secondary DNS servers, until each secondary DNS server has recorded the information of the higher-level server which each secondary DNS server belongs to, and has obtained the zone file from each higher-level server according to the notification message(12). The defect of the prior art that when the DNS server creates a new DNS zone, the DNS administer needs to execute manual update on the zone file corresponding to the newly created DNS zone and the higher-level server information of the secondary DNS server in the secondary DNS server is changed, and thus when the DNS server creates a new DNS zone, an automatic update is realized.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER

A method and device for delivering full volume of multi-version DNS zone files

ActiveCN110099117BImprove zone transfer performanceReduce consumptionTransmissionEngineeringTerm memory
This application discloses a method and device for delivering full-volume multi-version DNS zone files. The method includes: if a new version of DNS zone files is obtained during the process of full-volume delivery, and a new full-volume delivery request is received, the old version of DNS files is determined to be transferred to the new version. The resource record involved in the update operation of the version DNS zone file is the target resource record; based on the target resource record, the update operation corresponding to the target resource record, and the data transmission block set corresponding to the old version DNS zone file, the multiplexed data transmission block and the new The data transfer block forms a data transfer block set corresponding to the new version of the DNS zone file; according to the new full-volume delivery request, the full-volume delivery of the data transfer block set corresponding to the new version of the DNS zone file. Based on the resource records involved in the update operation in the new version of the DNS zone file, the data transmission blocks in the data transmission block set corresponding to the old version of the DNS zone file are reused to the maximum extent to reduce the resource consumption of CPU and memory.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products