• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Negotiating PQC for DNSSEC
 
  • Details
  • Full
Options
2021
Conference Paper
Title

Negotiating PQC for DNSSEC

Abstract
Domain Name System Security Extensions (DNSSEC) provides authentication and integrity to Domain Name System (DNS) through the use of digital signatures based on public-key cryptography. Quantum computers threaten public key cryptography and DNSSEC is unprepared. As the process to change algorithms in DNSSEC involves a lot of overhead, requires significant investment and takes many years, we advocate for deployment of long term cryptography for DNSSEC. In this work we explore the challenges and obstacles towards deployment of post-quantum signatures and explain that smooth adoption towards quantum-safe ciphers can be achieved with cipher-suite negotiation for DNSSEC.Cipher-suite negotiation, which DNSSEC currently does not support, ensures that the best cryptographic algorithms supported by the server and the resolver are used. Servers usually do not deprecate old algorithms because they are unaware whether resolvers support new algorithms. The signals in cipher-suite negotiation inform the servers and the resolvers of algorithm support that creates a feedback loop that could accelerate adoption of post-quantum signatures and the deprecation of old algorithms while preventing packet fragmentation. As a consequence, cipher-suite negotiation can contribute towards a greater adoption of DNSSEC.
Author(s)
Shrishak, Kris
Shulman, Haya  
Mainwork
51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Supplemental Volume, DSN-S 2021. Proceedings  
Conference
International Conference on Dependable Systems and Networks (DSN) 2021  
DOI
10.1109/DSN-S52858.2021.00015
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024