搜索结果: 1-7 共查到“DNSSEC”相关记录7条 . 查询时间(0.328 秒)
一种基于区块链的DNSSEC公钥验证机制
域名安全扩展 公钥基础设施 区块链 密码学累加器
2024/1/17
针对中心化域名安全扩展(Domain name system security extensions,DNSSEC)架构所导致的信任链复杂性和单边控制模式,提出了一种去中心化的DNSSEC公钥验证机制.该机制结合区块链结构、密码学累加器和共识算法设计,创新性地实现使用区块链技术的密钥绑定、轮转和验证操作,无需中心化权威节点即可使用可信公钥验证域名记录.进一步分析和实验表明,所提出的机制在保证密钥管...
Securing DNSSEC Keys via Threshold ECDSA From Generic MPC
Multiparty computation Threshold ECDSA Honest majority
2019/8/6
A surge in DNS cache poisoning attacks in the recent years generated an incentive to push the deployment of DNSSEC forward. ICANN accredited registrars are required to support DNSSEC signing for their...
Can NSEC5 be practical for DNSSEC deployments?
Internet protocols verifiable random functions zone enumeration
2017/2/20
NSEC5 is a new proposal for providing authenticated denial of existence for DNSSEC, i.e., for securely responding to DNS queries for names that do not exist in a zone. NSEC5 simultaneously guarantees ...
NSEC5 from Elliptic Curves: Provably Preventing DNSSEC Zone Enumeration with Shorter Responses
verifiable random functions DNSSEC zone enumeration secure Internet protocols
2016/2/23
While DNSSEC securely provides authenticity and integrity to the domain name system (DNS), it also creates a new security vulnerability called zone enumeration that allows an adversary that asks a sma...
We use cryptographic techniques to study zone enumeration in DNSSEC. DNSSEC is designed to prevent attackers from tampering with domain name system (DNS) messages. The cryptographic machinery used in ...
Towards Adoption of DNSSEC: Availability and Security Challenges
DNS security DNS cache poisoning
2014/3/13
DNSSEC deployment is long overdue; however, it seems to be finally taking off. Recent cache poisoning attacks motivate protecting DNS, with strong cryptography, rather than with challenge-response ‘de...
Domain Name System Security Extensions (DNSSEC) and
Hashed Authenticated Denial of Existence (NSEC3) are
slated for adoption by important parts of the DNS hierarchy,
including the root zone, as a s...