Loading [MathJax]/extensions/MathZoom.js
Secure distributed DNS | IEEE Conference Publication | IEEE Xplore

Secure distributed DNS


Abstract:

A correctly working domain name system (DNS) is essential for the Internet. Due to its significance and because of deficiencies in its current design, the DNS is vulnerab...Show More

Abstract:

A correctly working domain name system (DNS) is essential for the Internet. Due to its significance and because of deficiencies in its current design, the DNS is vulnerable to a wide range of attacks. This paper presents the design and implementation of a secure distributed name service on the level of a DNS zone. Our service is able to provide fault tolerance and security even in the presence of a fraction of corrupted name servers, avoiding any single point of failure. It further solves the problem of storing zone secrets online without leaking them to a corrupted server, while still supporting secure dynamic updates. Our service uses state-machine replication and threshold cryptography. We present results from experiments performed using a prototype implementation on the Internet in realistic setups. The results show that our design achieves the required assurances while servicing the most frequent requests in reasonable time.
Date of Conference: 28 June 2004 - 01 July 2004
Date Added to IEEE Xplore: 26 July 2004
Print ISBN:0-7695-2052-9
Conference Location: Florence, Italy

1. Introduction

The Domain Name System (DNS) is one of the most critical parts of the Internet infrastructure and maps symbolic domain names to IP addresses. a name server that fails may deliver incorrect name-to-address mappings to its clients and can cause services to become unreachable or, even worse, to be masqueraded by fraudulent replacements operated by an attacker.

Contact IEEE to Subscribe

References

References is not available for this document.