Algorithm for DNSSEC Trusted Key Rollover - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2005

Algorithm for DNSSEC Trusted Key Rollover

Résumé

The Domain Name System Security Extensions (DNSSEC) architecture is based on public-key cryptography. A secure DNS zone has one or more keys and signs its resource records with these keys in order to provide two security services: data integrity and authentication. These services allow to protect DNS transactions and permit the detection of attempted attacks on DNS. The DNSSEC validation process is based on the establishment of a chain of trust between zones. This chain needs a secure entry point: a DNS zone whose at least one key is trusted. In this paper we study a critical problem associated to the key rollover in DNSSEC: the trusted keys rollover problem. We propose an algorithm that allows a resolver to update its trusted keys automatically and in a secure way without any delay or any break of the DNS service.
Fichier principal
Vignette du fichier
ICOIN-2005.pdf (162.15 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01501893 , version 1 (04-04-2017)

Identifiants

Citer

Gilles Guette, Bernard Cousin, Fort David. Algorithm for DNSSEC Trusted Key Rollover. International Conference on Information Networking (ICOIN). Jeju, Korea. January 31 - February 2, 2005, Jan 2005, Jeju, South Korea. pp.679 - 688, ⟨10.1007/978-3-540-30582-8_71⟩. ⟨hal-01501893⟩
396 Consultations
197 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More