发表机构
Virginia Tech(弗吉尼亚理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
Enc53提出一种DNSSEC锚定的无状态票据协议,将DNS加密分为配置和稳定两阶段,实现高效的后量子权威DNS加密,显著降低字节和延迟开销。
AI 中文摘要
DNSSEC对RRset进行认证,但不提供端点认证或通道安全。DNS-over-TLS(DoT)和DNS-over-QUIC(DoQ)可以满足此类需求,但它们是针对存根到解析器这一跳设计的,在该跳中,稳定的长连接可以摊销昂贵的初始设置成本。递归到权威路径的高扇入和每个解析器非均匀的查询频率反转了上述动态。后量子原语进一步加剧了这种不匹配:ML-DSA WebPKI证书链跨越TCP的初始窗口,冷PQ DoQ可能产生高达同一查询在UDP上总字节数约140倍的流量。对TLD和2LD名称服务器的调查进一步限制了连接生命周期,近一半被调查的服务器甚至对非空闲连接施加限制。我们提出Enc53——一种无状态会话票据协议,可实现高效的认证权威DNS加密。Enc53将DNS加密分为两个阶段:第一阶段在初始查询时进行短暂的、DNSSEC锚定的、TLS认证的配置;第二阶段进入稳定状态,使用1-RTT AEAD加密的UDP DNS查询。Enc53在服务器端是无状态的:递归解析器持有流量密钥和会话票据,权威名称服务器仅持有对称的STEK。我们在Knot DNS中实现了Enc53。配置后,稳定状态的Enc53交换成本约为570字节——大约是普通UDP查询的3倍——并且与未加密的UDP基线相比,延迟在1毫秒以内。恢复的PQ-ADoT支付7.7倍的字节和3倍的延迟;恢复的PQ-ADoQ支付10倍的字节,但延迟相同。当针对根服务器查询轨迹进行评估时,Enc53在计算效率上比ADoT/ADoQ高2倍,在内存效率上比ADoT高3倍,比ADoQ高12倍。最后,当与FN-DSA-512 PQ-DNSSEC联合部署时,Enc53-DNSSEC联合UDP数据报保持在1232字节缓冲区限制以下。
英文摘要
DNSSEC authenticates RRsets, but does not provide endpoint authentication or channel security. DNS-over-TLS (DoT) and DNS-over-QUIC (DoQ) can facilitate such needs, but were designed for the stub-to-resolver hop, where stable long-lived connections amortize the expensive initial setup. The recursive-to-authoritative path's high fan-in and nonuniform per-resolver query frequency invert said dynamics. Post- quantum primitives further sharpen this mismatch: an ML-DSA WebPKI certificate chain crosses TCP's initial window, a cold PQ DoQ may incur up to about 140 times the total bytes of the same query over UDP. A survey of TLD and 2LD nameservers further bounds connection lifetimes, with almost half surveyed imposing limits on even non-idle connections. We present Enc53 -- a stateless session ticket protocol enabling efficient authenticated authoritative DNS encryption. Enc53 splits DNS encryption into 2 phases: a short-lived, DNSSEC-anchored, TLS- authenticated provisioning on the initial query in the 1st, and a steady state of 1-RTT AEAD-encrypted UDP DNS queries in the 2nd. Enc53 is server-side stateless: recursive resolvers hold the traffic secret and session ticket, authoritative nameservers hold only a symmetric STEK. We implemented Enc53 in Knot DNS. After provisioning, a steady state Enc53 exchange costs about 570 B -- roughly 3 times a plain UDP query -- and lands within 1 ms of the unencrypted UDP baseline. Resumed PQ-ADoT pays 7.7 times the bytes and 3 times the latency; resumed PQ-ADoQ pays 10 times the bytes for the same latency. When evaluated against a root server query trace, Enc53 achieves 2-fold compute efficiency over ADoT/ADoQ, 3-fold memory efficiency over ADoT, and 12-fold memory efficiency over ADoQ. Finally, when deployed in conjunction with FN-DSA-512 PQ-DNSSEC, the joint Enc53-DNSSEC UDP datagram remains below the 1232B buffer limit.
Comments18 pages, 11 figures, 5 tables