All update requests to a secure zone must include signatures by one or more key(s) that together can authorize that update. In order for the Domain Name System (DNS) server receiving the request to confirm this, the key or keys must be available to and authenticated by that server as a specially flagged KEY Resource Record.
The scope of authority of such keys is indicated by their KEY RR owner name, class, and signatory field flags as described below. In addition, such KEY RRs must be entity or user keys and not have the authentication use prohibited bit on. All parts of the actual update must be within the scope of at least one of the keys used for a request SIG on the update request as described in section 4.