...
首页> 外文期刊>Computer communication review >Public Review for Making the Case for Elliptic Curves in DNSSEC
【24h】

Public Review for Making the Case for Elliptic Curves in DNSSEC

机译:公开审查DNSSEC中椭圆曲线的理由

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Like many of the Internet's protocols, DNS was designed without security in mind. Given its central role in translating human readable names into IP addresses, it constitutes an achilles heel in terms of Internet security. This fact has not gone unnoticed, with active development on DNS Security Extensions (DNSSEC) which adds integrity and authenticity to the DNS, by digitally signing DNS data. However, DNSSEC deployment has been lackluster. The authors argue that there are three problems at the core of the deployment impasse: DNSSEC responses are large which can result in (1) IP fragmentation and (2) open the door for DDoS based on DNSSEC. Third, key management complexities can result in domains becoming unreachable. The authors argue that the choice of RSA for DNSSEC is at the heart of these problems and they evaluate the potential benefits of leveraging elliptic curve cryptography (ECC) instead to ameliorate these issues. The reviewers appreciated the data-driven approach taken in this paper using data from a real network to evaluate the potential gains of ECC. They found the arguments for ECC were convincing with empirical evaluations of how ECC can help mitigate threats such as amplification attacks as well as key rollover management issues. The reviewers also raised open questions about the transition to ECC from RSA and how the two signature schemes could co-exist during the transition period. The potential overheads of verification for ECC signatures was also raised. The reviewers agree that the problem tackled in this paper is an important one, and the data-driven approach provides a convincing argument for ECC. The work also raises interesting questions about how a transition to ECC would occur in practice and whether there are other factors hindering deployment aside from the issues raised about RSA.
机译:像许多Internet协议一样,DNS在设计时就没有考虑安全性。鉴于其在将人类可读名称转换为IP地址方面的核心作用,它构成了Internet安全方面的一个致命弱点。随着DNS安全扩展(DNSSEC)的积极开发,通过数字签名DNS数据为DNS增加了完整性和真实性,这一事实并没有引起人们的注意。但是,DNSSEC部署一直乏善可陈。作者认为,部署僵局的核心有三个问题:DNSSEC响应很大,这可能导致(1)IP碎片和(2)为基于DNSSEC的DDoS打开大门。第三,密钥管理的复杂性可能导致域变得不可访问。作者认为,针对DNSSEC选择RSA是这些问题的核心,他们评估了利用椭圆曲线密码术(ECC)来缓解这些问题的潜在好处。审阅者赞赏本文中使用的数据驱动方法,该方法使用来自真实网络的数据来评估ECC的潜在收益。他们发现ECC的论点令人信服,对ECC如何帮助缓解诸如放大攻击和关键过渡管理问题之类的威胁进行了经验评估。审阅者还提出了有关从RSA过渡到ECC以及在过渡期间如何将两种签名方案共存的公开问题。还增加了ECC签名验证的潜在开销。审稿人同意,本文所解决的问题是重要的问题,并且数据驱动方法为ECC提供了令人信服的论点。该工作还提出了一些有趣的问题,即在实践中将如何过渡到ECC,以及除RSA问题外,是否还有其他因素阻碍部署。

著录项

  • 来源
    《Computer communication review》 |2015年第5期|13-13|共1页
  • 作者

    Phillipa Gill;

  • 作者单位

    Stony Brook University, USA;

  • 收录信息 美国《科学引文索引》(SCI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号