...
首页> 外文期刊>Computer communication review >Retrofitting Post-Quantum Cryptography in Internet Protocols: A Case Study of DNSSEC
【24h】

Retrofitting Post-Quantum Cryptography in Internet Protocols: A Case Study of DNSSEC

机译:在互联网协议中改造后量子密码学:DNSSEC的案例研究

获取原文
获取原文并翻译 | 示例

摘要

Quantum computing is threatening current cryptography, especially the asymmetric algorithms used in many Internet protocols. More secure algorithms, colloquially referred to as Post-Quantum Cryptography (PQC), are under active development. These new algorithms differ significantly from current ones. They can have larger signatures or keys, and often require more computational power. This means we cannot just replace existing algorithms by PQC alternatives, but need to evaluate if they meet the requirements of the Internet protocols that rely on them. In this paper we provide a case study, analyzing the impact of PQC on the Domain Name System (DNS) and its Security Extensions (DNSSEC). In its main role, DNS translates human-readable domain names to IP addresses and DNSSEC guarantees message integrity and authenticity. DNSSEC is particularly challenging to transition to PQC, since DNSSEC and its underlying transport protocols require small signatures and keys and efficient validation. We evaluate current candidate PQC signature algorithms in the third round of the NIST competition on their suitability for use in DNSSEC.We show that three algorithms, partially, meet DNSSEC’s requirements but also show where and how we would still need to adapt DNSSEC. Thus, our research lays the foundation for making DNSSEC, and protocols with similar constraints ready for PQC.
机译:量子计算是威胁到当前的密码学,尤其是许多互联网协议中使用的非对称算法。更安全的算法,将普通称为量子密码学(PQC)进行俗称,都在主动开发。这些新的算法显着不同于当前的算法。它们可以具有更大的签名或密钥,并且通常需要更多的计算能力。这意味着我们不能只用PQC替代方案替换现有算法,但需要评估它们是否符合依赖于其的Internet协议的要求。在本文中,我们提供了一个案例研究,分析了PQC对域名系统(DNS)及其安全扩展(DNSSEC)的影响。在其主要作用中,DNS将人类可读的域名转换为IP地址,DNSSEC保证消息完整性和真实性。由于DNSSEC及其底层传输协议需要小签名和键,并且有效验证,DNSSEC尤其具有挑战性,因此尤其具有挑战性。我们在NIST竞争中评估了当前候选PQC签名算法,以便在DNSSEC中使用的适用性。我们展示了三种算法,部分地满足DNSSEC的要求,但也显示了我们仍然需要调整DNSSEC的何处以及如何以及我们如何调整DNSSEC。因此,我们的研究为制作DNSSEC的基础,以及具有PQC的类似约束的协议。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号