首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Deploying Cryptography in Internet-Scale Systems: A Case Study on DNSSEC
【24h】

Deploying Cryptography in Internet-Scale Systems: A Case Study on DNSSEC

机译:在Internet规模的系统中部署密码术:以DNSSEC为例

获取原文
获取原文并翻译 | 示例

摘要

The DNS Security Extensions (DNSSEC) are among the first attempts to deploy cryptographic protections in an Internet-scale operational system. DNSSEC applies well-established public key cryptography to ensure data integrity and origin authenticity in the DNS system. While the cryptographic design of DNSSEC is sound and seemingly simple, its development has taken the IETF over a decade and several protocol revisions, and even today its deployment is still in the early stage of rolling out. In this paper, we provide the first systematic examination of the design, deployment, and operational challenges encountered by DNSSEC over the years. Our study reveals a fundamental gap between cryptographic designs and operational Internet systems. To be deployed in the global Internet, a cryptographic protocol must possess several critical properties including scalability, flexibility, incremental deployability, and ability to function in face of imperfect operations. We believe that the insights gained from this study can offer valuable inputs to future cryptographic designs for other Internet-scale systems.
机译:DNS安全扩展(DNSSEC)是在Internet规模的操作系统中首次部署加密保护的尝试之一。 DNSSEC应用完善的公钥加密技术,以确保DNS系统中的数据完整性和源真实性。尽管DNSSEC的密码设计合理且看似简单,但IETF的发展已经花费了IETF十多年的时间,并且对协议进行了多次修订,甚至到今天,它的部署仍处于推出初期。在本文中,我们对DNSSEC多年来遇到的设计,部署和运营挑战进行了首次系统检查。我们的研究揭示了密码设计和可操作的Internet系统之间的根本差距。要部署在全球Internet中,加密协议必须具有几个关键属性,包括可伸缩性,灵活性,增量可部署性以及面对不完善操作的功能。我们相信,从这项研究中获得的见识可以为其他Internet规模系统的未来密码设计提供有价值的输入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号