• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Cipher-suite negotiation for DNSSEC: Hop-by-hop or end-to-end?
 
  • Details
  • Full
Options
2015
Journal Article
Title

Cipher-suite negotiation for DNSSEC: Hop-by-hop or end-to-end?

Abstract
To ensure the best security and efficiency, cryptographic protocols such as Transport Layer Security and IPsec should let parties negotiate the use of the "best" cryptographic algorithms; this is referred to as cipher-suite negotiation. However, cipher-suite negotiation is lacking in DNS Security Extensions (DNSSEC), introducing several problems. To address these issues, the authors propose two designs: hop-by-hop and end-to-end cipher-suite negotiation. They compare these two approaches with respect to efficiency, ease of deployment, changes each would require of the existing infrastructure, and compatibility with the legacy DNS infrastructure and caches.
Author(s)
Herzberg, Amir
Shulman, Haya  
Journal
IEEE Internet Computing  
DOI
10.1109/MIC.2015.3
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024