Zone state revocation for DNSSEC

Proceedings of the 2007 workshop on Large scale attack defense(2007)

引用 15|浏览29
暂无评分
摘要
DNS Security Extensions (DNSSEC) are designed to add cryptographic protection to the Internet's name resolution service. However the current design lacks a key revocation mechanism. In this paper we present Zone State Revocation (ZSR), a lightweight and backward compatible enhancement to DNSSEC. ZSR enables zones to explicitly revoke keys using self-certifying certificates, and enables DNS name-servers to opportunistically inform distributed caching resolvers of key revocations via lightweight control messages. Further, ZSR allows resolvers to distinguish between legitimate key changes and potential attacks when authentication chains are broken. ZSR is designed to work well with global-scale DNS operations, where millions of caches may need to be informed of a revocation, and where time is critical.
更多
查看译文
关键词
global-scale dns operation,dns name-servers,zone state revocation,key revocation,lightweight control message,key revocation mechanism,compatible enhancement,dns security extensions,legitimate key change,authentication chain
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要