RFC 2137:Secure Domain Name System Dynamic Update
RFC-Ref

Entity


Click on the red underlined text to get to the source

... SIGs appear at the end of a request and authenticate the request with the key of the submitting entity. ...


... KEY RRs that can authorize dynamic updates, i.e., entity or user KEY RRs with the signatory field non-zero ...
... authenticated by dynamic keys which expire, updates are transient in nature. Key rollover for an entity that can authorize dynamic updates is more cumbersome since the authority ...


... class, and signatory field flags as described below. In addition, such KEY RRs must be entity or user keys and not have the authentication use prohibited bit ...



Google
Web
RFC-Ref