DocumentCode :
3264742
Title :
Limiting replay vulnerabilities in DNSSEC
Author :
Yan, He ; Osterweil, Eric ; Hajdu, Jon ; Acres, Jonas ; Massey, Dan
Author_Institution :
Colorado State Univ., Fort Collins, CO
fYear :
2008
fDate :
19-19 Oct. 2008
Firstpage :
3
Lastpage :
8
Abstract :
The DNS security extensions (DNSSEC) added public key cryptography to the DNS, but problems remain in selecting signature lifetimes. A zonepsilas master server distributes signatures to secondary servers. The signatures lifetimes should be long so that a secondary server can still operate if the master fails. However, DNSSEC lacks revocation. Signed data can be replayed until the signature expires and thus zones should select a short signature lifetime. Operators must choose between reduced robustness or long replay vulnerability windows. This paper introduces a revised DNSSEC signature that allows secondary servers to operate even if the master has failed while simultaneously limiting replay windows to twice the TTL. Each secondary server constructs a hash chain and relays the hash chain anchor to the master server. The signature produced by the master server ensures the authenticity of the hash anchor and the DNS data. A secondary server includes both the signature and a hash chain value used by resolvers to limit signature replay. Our implementation shows the added costs are minimal compared to DNSSEC and ensures robustness against long-term master server failures. At the same time, we limit replay to twice the record TTL value.
Keywords :
Internet; digital signatures; network servers; public key cryptography; DNS security extensions; DNSSEC signature; hash anchor authenticity; hash chain; master server; public key cryptography; replay vulnerability; secondary servers; short signature lifetime; signature lifetimes; vulnerability windows; Costs; Data security; Helium; Internet; Master-slave; Packaging; Public key; Public key cryptography; Relays; Robustness;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Network Protocols, 2008. NPSec 2008. 4th Workshop on
Conference_Location :
Orlando, FL
Print_ISBN :
978-1-4244-2651-5
Electronic_ISBN :
978-1-4244-2652-2
Type :
conf
DOI :
10.1109/NPSEC.2008.4664873
Filename :
4664873
Link To Document :
بازگشت