Verisign Patents GDPR-Compliant Whois Privacy

Verisign’s Patented Innovation for Thick Whois Privacy and GDPR Compliance

In an era where digital privacy is paramount, domain registries face an increasingly complex landscape of data protection regulations. The U.S. Patent and Trademark Office has officially granted patent number 10,979,384 to Verisign (NASDAQ: VRSN), a global leader in domain name services. This groundbreaking patent, titled “Systems and methods for preserving privacy of a registrant in a Domain Name System,” offers a sophisticated solution to assist Thick Whois registries in adhering to stringent privacy laws, most notably the General Data Protection Regulation (GDPR).

Verisign patent diagram illustrating GDPR-compliant Whois privacy
A figure from Verisign’s patent that describes a way to offer GDPR-compliant Whois privacy in Thick Whois systems, addressing critical compliance challenges.

The patent application, which first garnered attention when it was published in 2017, has now materialized into a powerful tool for domain privacy. This development is particularly significant for Thick Whois models, where registries are responsible for storing comprehensive registrant data, including sensitive personal information. The Verisign patent outlines ingenious methods to navigate these regulatory complexities, ensuring data privacy while maintaining the necessary functionality of the domain name system.

Understanding Thick Whois and the Growing Privacy Challenge

The Domain Name System (DNS) is the backbone of the internet, translating human-readable domain names into IP addresses. Essential to this system is Whois, a protocol used to query databases that store registration information for domain names. There are two primary models for Whois data storage: Thin Whois and Thick Whois.

  • Thin Whois: In this model, the registry (e.g., Verisign for .com) only stores technical information like the domain’s name servers and the registrar’s identity. The actual registrant contact details (name, address, email, phone) are stored by the registrar.
  • Thick Whois: Under a Thick Whois model, the registry itself holds all the essential registration data, including the full personal details of the domain registrant. This model offers certain advantages, such as centralized data and potentially faster resolution of disputes, but it also places a much heavier burden on registries concerning data protection and privacy compliance.

The advent of comprehensive data protection regulations like the GDPR in Europe has fundamentally altered how personal data must be handled globally. GDPR dictates strict rules regarding the collection, storage, processing, and disclosure of personal data for individuals within the EU. For Thick Whois registries, which inherently store vast amounts of personal data, complying with GDPR presents significant operational and legal hurdles. Traditional Whois disclosure practices, which made registrant data publicly available, are now largely incompatible with GDPR’s principles of data minimization and privacy by design.

Verisign’s Patented Solution: A Deep Dive into Privacy Preservation

Verisign’s newly granted patent introduces an innovative framework designed to bridge the gap between the operational requirements of Thick Whois systems and the stringent demands of modern privacy laws. At its core, the solution revolves around delegating the handling of personal information to specialized privacy providers, often located in jurisdictions where legal frameworks are conducive to managing such data securely and compliantly.

The Role of Privacy Providers and Cloaked Identities

The patent describes a method that shifts the responsibility of direct personal information storage away from the primary registry, while still allowing for necessary identification and communication. The key mechanism involves the creation of a “cloaked identity”:

Provided herein is a solution to addresses the problem described above by defining a method by which personal information collection is delegated to privacy providers residing in a locality where it is legal to store the personal information. This addresses the problem of adhering to privacy laws by automating the production of a ‘cloaked identity’ that only the privacy provider knows is associated with the person. This cloaked identity can then be given to the person who’s identity is being cloaked and to various entities that need to associate some form of identity with data or a service the cloaked person is registering. The cloaked identity is not associated with the personal information of the person except within the data storage of the privacy provider, and the privacy provider will not disclose that information unless a legal mechanism applicable to the locality of the privacy provider is used. The person’s private or personal information is therefore shielded except in cases where it is legally retrieved from the privacy provider.

This approach means that when a domain is registered, the personal details of the registrant are not directly stored by the registry in an unencrypted or easily accessible format. Instead, a privacy provider acts as an intermediary, holding the actual personal data and linking it to a unique, non-identifiable “cloaked identity.” This cloaked identity is then used for public-facing Whois records and for interactions where an identity placeholder is needed. The core principle is that the privacy provider, operating under specific legal obligations, is the only entity that can connect the cloaked identity back to the real individual, and only under very specific, legally sanctioned circumstances.

This architecture provides robust protection for registrants’ privacy. Unless there is a legitimate legal process, such as a court order applicable to the jurisdiction of the privacy provider, the personal information remains shielded from public view and unauthorized access. This model significantly mitigates the risk of mass data scraping and misuse, which has been a persistent concern in the domain industry.

Enhanced Communication with Cloaked Email Addresses

Beyond simply hiding personal details, Verisign’s patent also details methods for maintaining essential communication channels in a privacy-preserving manner. One notable feature is the use of a cloaked email address:

In some examples, the cloaked identity can include a cloaked email address. If the cloaked identity is a unique cloaked email address, several other benefits are possible. The cloaked email address can be used to communicate with the person without having personal information being accessible by a party that knows the cloaked email address unless they go through a legally accepted process to get it from the privacy provider. If the cloaked email address and the public key for a person is recorded in an secure/multipurpose internet mail extensions (“S/MIME”) A-type record (also called a S/MIMEA) in a DNS server under a domain owned by the person, then proof of origin of data and email from the person can be enabled using digital signature. Proof of origin for an email is achieved if the person has used their private key to sign an email sent using the cloaked email account and a recipient uses the person’s public key received from the S/MIMEA record for the cloaked email account to verify the person’s digital signature.

This innovation ensures that stakeholders who need to contact a domain owner (e.g., for technical issues, legal notices, or abuse reports) can do so via a unique cloaked email address without directly accessing the registrant’s private contact information. The privacy provider manages the routing and verification for these communications. This balance is crucial for maintaining the operational integrity and accountability of the internet, preventing domains from becoming “black holes” where owners cannot be reached. Furthermore, the patent describes how these cloaked email addresses can be integrated with security mechanisms like S/MIME A-type records (S/MIMEA) in DNS. By recording a public key alongside the cloaked email, it becomes possible to verify the origin and authenticity of emails from the domain owner using digital signatures. This adds an extra layer of trust and security, ensuring that communications originating from the cloaked identity are genuinely from the legitimate registrant.

The Broader Context: GDPR, ICANN, and Whois Evolution

The timing of Verisign’s patent grant is highly relevant to the ongoing debates and challenges within the internet governance community. The Internet Corporation for Assigned Names and Numbers (ICANN), responsible for coordinating the global DNS, has been grappling with the implications of GDPR for Whois policy since its implementation in May 2018. The traditional public Whois model directly conflicted with GDPR’s requirements for consent, data minimization, and the “right to be forgotten.”

This conflict has led to significant delays in the planned transition of Verisign’s .com namespace from a Thin Whois to a Thick Whois system. Originally slated for 2018, this transition remains on hold as ICANN works to develop a consensus-based policy for a “next-generation” or “GDPR-compliant” Whois system. Verisign, as the registry for .com and .net, is a pivotal player in this discussion, and its patented approach provides a tangible, technically sound solution that could significantly influence future Whois policy development. Such solutions are vital not only for compliance but also for maintaining public trust in the internet’s infrastructure and ensuring a balanced approach to transparency and privacy.

Impact and Future Outlook for Domain Registries

The implications of Verisign’s patent extend far beyond just its own operations. It offers a blueprint for other Thick Whois registries and even potentially for Thin Whois systems looking to enhance privacy. Key benefits include:

  • Regulatory Compliance: Provides a robust framework for adhering to GDPR and similar data protection laws worldwide, significantly reducing legal risks for registries.
  • Enhanced Registrant Trust: By offering a verifiable and secure method for protecting personal data, it can increase registrants’ confidence in the domain registration process.
  • Operational Efficiency: Automates many aspects of privacy management, reducing manual intervention and potential for human error.
  • Balance of Interests: Skillfully balances the need for registrant privacy with the legitimate needs of law enforcement, intellectual property holders, and technical operators to access information under appropriate legal mechanisms.
  • Innovation Driver: Sets a precedent for future innovations in domain privacy and security, encouraging other industry players to develop similar or complementary solutions.

The inventor listed on the patent is Andrew Fregly, a Principal Engineer at Verisign, highlighting the internal expertise driving these critical advancements. Filed in March 2016 and granted today, this patent represents years of dedicated effort to solve one of the internet’s most pressing governance challenges.

Pioneering Domain Privacy for the Digital Age

Verisign’s patent for “Systems and methods for preserving privacy of a registrant in a Domain Name System” is more than just a legal document; it’s a significant leap forward in addressing the complex interplay between internet functionality, data protection, and global regulatory demands. By introducing a sophisticated model involving privacy providers and cloaked identities, coupled with secure communication methods, Verisign has laid down a pathway for Thick Whois registries to meet their privacy obligations without compromising the essential services that underpin the internet. As the digital landscape continues to evolve, innovations like this will be crucial in building a more secure, private, and trustworthy online environment for everyone.