How DNSSEC is put together
DNSSEC adds signatures to DNS answers so that a resolver can verify they were not altered on the way. The zone publishes its public keys as DNSKEY records and signs its records with them. The parent zone (.com for example.com) publishes a DS record: a digest of the zone's key-signing key. That DS record is the link in the chain of trust from the root down to the domain, and it is set through the registrar.
Both halves are needed. Keys in the zone without a DS record at the parent are not validated by anyone. A DS record that points at a key the zone does not publish is worse: validating resolvers then refuse every answer and the domain disappears for their users.