DNSSEC on 1 page
Data authenticity and integrity by SIGning the resource records
Public KEYs can be used to verify the SIGs
Children sign their zones with their private key. The authenticity of their KEY is established by a SIGnature over that key by the parent
In the ideal case, only one public KEY needs to be distributed off-band