In Zeroconf networks, digital signatures for RRs can be created by using the public key pair related to a group of devices. However, it is not necessary to include KEY RR in responses because this public key would have already been shared in a particular secure zone. Meanwhile, the disadvantage of using DNSSEC is that it is not really designed to support confidentiality and access control and consequently it cannot authenticate the sender of a DNS request or to prevent passive discovery of device information.