The domain owner generates a pair of cryptographic keys when DNSSEC is used. The private key is used to sign DNS data, creating DNSKEY records. It generates a unique digital signature for each record.