Skip to main navigation Skip to search Skip to main content

Negotiating dnssec algorithms over legacy proxies

  • Amir Herzberg
  • , Haya Shulman
  • Technische Universität Darmstadt

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

To ensure best security and efficiency, cryptographic protocols should allow parties to negotiate the use of the ‘best’ cryptographic algorithms supported by the different parties; this is usually referred to as cipher-suite negotiation, and considered an essential feature of such protocols, e.g., TLS and IPsec. However, such negotiation is absent from protocols designed for distribution of cryptographically-signed objects, such as DNSSEC. One reason may be the challenges of securing the choice of the ‘best’ algorithm, especially in the presence of intermediate ‘proxies’ (crucial for performance), and in particular, providing solutions, compatible with the existing legacy servers and proxies; another reason may be a lack of understanding of the security and performance damages due to lack of negotiation.

We show that most DNSSEC signed domains, support only RSA 1024-bit signatures, which are considered insecure, and are also larger than alternatives; the likely reason is lack of negotiation mechanisms. We present a DNSSEC-negotiation mechanism, allowing name-servers to send responses containing only the keys and signatures required by the requesting resolver. Our design is compatible with intermediary proxies, and even with legacy proxies, that do not support our negotiation mechanism. We show that our design enables incremental deployment and will have negligible performance impact on overhead of DNSSEC as currently deployed, and significant improved performance to DNSSEC if more domains support multiple algorithms; we also show significant security benefits from the use of our design, under realistic, rational adoption model. Ideas of our design apply to other systems requiring secure and efficient distribution of signed data, such as wireless sensor networks (WSNs).

Original languageEnglish
Title of host publicationCryptology and Network Security - 13th International Conference, CANS 2014, Proceedings
EditorsDimitris Gritzalis, Aggelos Kiayias, Ioannis Askoxylakis
PublisherSpringer Verlag
Pages111-126
Number of pages16
ISBN (Electronic)9783319122793
DOIs
StatePublished - 2014
Event13th International Conference on Cryptology and Network Security, CANS 2014 - Heraklion, Crete, Greece
Duration: 22 Oct 201424 Oct 2014

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8813
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference13th International Conference on Cryptology and Network Security, CANS 2014
Country/TerritoryGreece
CityHeraklion, Crete
Period22/10/1424/10/14

Bibliographical note

Publisher Copyright:
© Springer International Publishing Switzerland 2014.

Funding

FundersFunder number
Ministry of Science and Technology1354/11

    Fingerprint

    Dive into the research topics of 'Negotiating dnssec algorithms over legacy proxies'. Together they form a unique fingerprint.

    Cite this