nThe parent delegates authority to sign DNS RRs to the child using
this RR
nDS is a pointer to the next key in the chain of
trust
uYou may trust data that is signed using a key
that the DS points
to
nNew RR to solve problems with key-rollovers
uMore on that later