Top Banner
23

Vanishing Point - Resilient DNSSEC Key Repository

Jun 27, 2015

Download

Technology

Nuno Loureiro

Security analysis of DNS: provides an overview of DNSSEC architecture and limitations, and highlights some of its problems: lack of resilience, multiple-root scenario, lack of isolation, legacy and Trust Anchor Management. DNSSEC Lookaside Validation (DLV) addresses most of these problems but not only it fails in providing resilience but also it devotes the root of trust of a zone into a unique trusted entity.
We propose Vanishing Point for solving the highlighted problems of DNSSEC. Vanishing Point is a resilient DNSSEC Key Repository Service that allows lookaside validation without relying solely on a PKI infrastructure.

Paper: http://dev.sig9.net/files/ResearchProject.pdf
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Vanishing Point - Resilient DNSSEC Key Repository
Page 2: Vanishing Point - Resilient DNSSEC Key Repository
Page 3: Vanishing Point - Resilient DNSSEC Key Repository
Page 4: Vanishing Point - Resilient DNSSEC Key Repository
Page 5: Vanishing Point - Resilient DNSSEC Key Repository
Page 6: Vanishing Point - Resilient DNSSEC Key Repository
Page 7: Vanishing Point - Resilient DNSSEC Key Repository
Page 8: Vanishing Point - Resilient DNSSEC Key Repository
Page 9: Vanishing Point - Resilient DNSSEC Key Repository
Page 10: Vanishing Point - Resilient DNSSEC Key Repository
Page 11: Vanishing Point - Resilient DNSSEC Key Repository
Page 12: Vanishing Point - Resilient DNSSEC Key Repository
Page 13: Vanishing Point - Resilient DNSSEC Key Repository
Page 14: Vanishing Point - Resilient DNSSEC Key Repository
Page 15: Vanishing Point - Resilient DNSSEC Key Repository
Page 16: Vanishing Point - Resilient DNSSEC Key Repository

DNSSEC-aware

Cache Resolver

{ message }

Page 17: Vanishing Point - Resilient DNSSEC Key Repository

DNSSEC-aware

Cache Resolver

{ message } another.net

K3

{ message } example.net

K2

Page 18: Vanishing Point - Resilient DNSSEC Key Repository
Page 19: Vanishing Point - Resilient DNSSEC Key Repository
Page 20: Vanishing Point - Resilient DNSSEC Key Repository
Page 21: Vanishing Point - Resilient DNSSEC Key Repository
Page 22: Vanishing Point - Resilient DNSSEC Key Repository
Page 23: Vanishing Point - Resilient DNSSEC Key Repository