Making the Case for Elliptic Curves in DNSSEC

被引:13
作者
Gill, Phillipa [1 ]
机构
[1] SUNY Stony Brook, Stony Brook, NY 11794 USA
基金
欧盟第七框架计划;
关键词
DNS; DNSSEC; fragmentation; DDoS; amplification attack; elliptic curve cryptography; ECDSA; EdDSA;
D O I
10.1145/2831347.2831350
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Domain Name System Security Extensions (DNSSEC) add authenticity and integrity to the DNS, improving its security. Unfortunately, DNSSEC is not without problems. DNSSEC adds digital signatures to the DNS, significantly increasing the size of DNS responses. This means DNSSEC is more susceptible to packet fragmentation and makes DNSSEC an attractive vector to abuse in amplification-based denial-of-service attacks. Additionally, key management policies are often complex. This makes DNSSEC fragile and leads to operational failures. In this paper, we argue that the choice for RSA as default cryptosystem in DNSSEC is a major factor in these three problems. Alternative cryptosystems, based on elliptic curve cryptography (EC-DSA and EdDSA), exist but are rarely used in DNSSEC. We show that these are highly attractive for use in DNSSEC, although they also have disadvantages. To address these, we have initiated research that aims to investigate the viability of deploying ECC at a large scale in DNSSEC.
引用
收藏
页码:13 / 19
页数:7
相关论文
共 14 条
[1]  
Ager Bernhard, 2007, P IEEE CISS 2006, P1484
[2]  
Barker E., 2015, NIST SP
[3]  
Barker Elaine., 2012, NIST
[4]  
Bernstein DJ, 2008, LECT NOTES COMPUT SC, V5023, P389
[5]   High-speed high-security signatures [J].
Bernstein, Daniel J. ;
Duif, Niels ;
Lange, Tanja ;
Schwabe, Peter ;
Yang, Bo-Yin .
JOURNAL OF CRYPTOGRAPHIC ENGINEERING, 2012, 2 (02) :77-89
[6]  
Hankerson D.., 2004, Guide to Elliptic Curve Cryptography
[7]   Cipher-Suite Negotiation for DNSSEC: Hop-by-Hop or End-to-End? [J].
Herzberg, Amir ;
Shulman, Haya .
IEEE INTERNET COMPUTING, 2015, 19 (01) :80-84
[8]  
Josefsson S., 2015, EDDSA ED255 IN PRESS
[9]  
NIST, 2009, FIPS PUB
[10]  
Smart N., 2012, TECHNICAL REPORT