16-11-2017 дата публикации
Номер: US20170329850A1
Принадлежит:
A secure DNS query may be made by establishing a secure connection with a specific DNS server to determine an address for a hostname. A client device may have a database that may contain a record of a secure DNS server for one or more hostnames. When a DNS request contains one of the specified hostnames, an authenticated session may be created with the designated secure DNS server and a network address for the hostname is returned using the session. The authenticated session may authenticate a client device to the server as well as authenticate the server to the client. In some embodiments, the secure DNS server may accept connections from authenticated clients and may disregard connection requests from non authenticated clients. 1. A method , comprising:receiving a first request for a first network address for a first node having a first name;determining, based on information from a local database, an identifier associated with a secure DNS server that is to be employed in resolving the first name;establishing a secure session with the secure DNS server using the identifier;querying the secure DNS server for a network address associated with the first name; andreceiving the first network address in response to the query.2. The method of claim 1 , wherein the identifier associated with the secure DNS server is a second network address.3. The method of claim 1 , further comprising:receiving a second request for a second network address for a second node having a second name;looking up the second name in the local database;not finding the second name in the local database; andquerying another DNS server for the second network address.4. The method of claim 1 , further comprising:receiving a second request for a second network address for a second node having a second name;determining that the local database associates the second name with a second network address for another secure DNS server;attempting to establish a secure session with the other secure DNS server at ...
Подробнее