Skip to content
U1.ca NAMES
U1 Names / Canada

Independent Canadian
Namespace Architecture

A structured digital-asset and infrastructure-naming framework for separated DNS service classes, carrier operating models, sovereign cloud environments, and the Namespace0 primitive foundation.

Conceptual architecture. This is a namespace and infrastructure reference model, not a deployed production DNS, resolver, registry, anycast, cloud, or telecommunications service. No affiliation with or endorsement from CIRA is implied or claimed.
Master architecture

Two control planes with explicit service boundaries.

The model separates public authoritative DNS identity from a protected service class while keeping resolver identity, authority, serving nodes, operations, and provisioning as distinct functions.

Master architecture — Sovereign Seven and Assurance Enclave.
Control Plane 1

Sovereign Seven

A proposed public authoritative service class using dns0.ca as the administrative and service apex, ns1.ca–ns7.ca as serving identities, ix1.ca–ix7.ca as unicast operations and telemetry identities, r1.ca as a separate recursive identity, and ns9.ca as the hidden-primary identity.

Open dns0.ca endpoint →
Control Plane 1 — provisional Sovereign Seven visual.
Control Plane 2 — provisional Assurance Enclave visual.
Control Plane 2

Assurance Enclave

A proposed protected service class using dns9.ca as the administrative and service apex, dns3.ca–dns8.ca as authoritative identities, ixp3.ca–ixp8.ca as protected operations and telemetry identities, and r9.ca as a separate recursive identity. Its provisioning primary remains unnamed and is not shown.

Open dns9.ca endpoint →
Primary use case

Carrier-grade authoritative DNS operating model.

The architecture maps most naturally to operators that already manage BGP, anycast, peering, DDoS mitigation, telemetry, DNSSEC operations, secure administration, and national service delivery.

Carrier operating model — provisional use-case visual.
Enabled environments

Separated policy and service classes.

A second plane can support differentiated trust boundaries, signing policy, IAM, change control, telemetry, service eligibility, and operational governance. It is not merely additional capacity.

Cloud and service environments — provisional conceptual visual.
Primitive foundation

Namespace0 layered architecture.

A seven-layer internal taxonomy spanning network infrastructure, DNS and delivery, compute, data, identity, operations, and AI.

Namespace0 — layered primitive foundation.