Invention Grant
- Patent Title: Leveraging contextual metadata communication to improve DNS security
-
Application No.: US17862019Application Date: 2022-07-11
-
Publication No.: US12255868B2Publication Date: 2025-03-18
- Inventor: Barry Qi Yuan , Robert Edgar Barton
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Lee & Hayes, P.C.
- Main IPC: H04L61/4511
- IPC: H04L61/4511 ; H04L9/32 ; H04L61/2514

Abstract:
Techniques for leveraging efficient metadata communications to improve domain name system (DNS) security are described. The DNS service uses a hash value to uniquely identify a client, and detect any change in metadata in order to keep policies up-to-date for the client. In an example method a first DNS query for a client device is intercepted. A cryptographic hash function is applied to metadata associated with the client device to generate a hash value. The hash value is added to an additional records section of the first DNS query to generate a second DNS query. The second DNS query is transmitted to a DNS service. The metadata associated with the client device is transmitted to the DNS service on an out-of-band encrypted channel. A DNS response, including the hash value, is received from the DNS service and transmitted to the client device.
Public/Granted literature
- US20240015132A1 LEVERAGING CONTEXTUAL METADATA COMMUNICATION TO IMPROVE DNS SECURITY Public/Granted day:2024-01-11
Information query