GDS Resource Record: Generalization of the Delegation Signer Model - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2005

GDS Resource Record: Generalization of the Delegation Signer Model

Résumé

Domain Name System Security Extensions (DNSSEC) architecture is based on public-key cryptography. A secure DNS zone has one or more keys to sign its resource records in order to provide two security services: data integrity and authentication. These services allow to protect DNS transactions and permit the detection of attacks on DNS. The DNSSEC validation process is based on the establishment of a chain of trust between secure zones. To build this chain, a resolver needs a secure entry point: a key of a DNS zone configured in the resolver as trusted. Then, the resolver must find a path from one of its secure entry point toward the DNS name to be validated. But, due to the incremental deployment of DNSSEC, some zones will remain unsecure in the DNS tree. Consequently, numerous trusted keys should be configured in re-solvers to be able to build the appropriate chains of trust. In this paper, we present a model that reduces the number of trusted keys in resolvers and ensures larger secure access to the domain name space. This model has been implemented in BIND.
Fichier principal
Vignette du fichier
icn05.pdf (93.67 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01184262 , version 1 (13-08-2015)

Identifiants

Citer

Gilles Guette, Bernard Cousin, David Fort. GDS Resource Record: Generalization of the Delegation Signer Model. 4th IEEE International Conference on Networking (ICN), Apr 2005, La Réunion, France. pp.844-851, ⟨10.1007/978-3-540-31957-3_95⟩. ⟨hal-01184262⟩
205 Consultations
95 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More