Searching for just a few words should be enough to get started. If you need to make more complex queries, use the tips below to guide you.
Article type: Research Article
Authors: Guette, Gilles
Affiliations: IRISA/Université de Rennes 1, Campus de Beaulieu, 35042 Rennes Cedex, France. E-mail: gilles.guette@irisa.fr
Abstract: The Domain Name System (DNS) is a distributed tree-based database largely used to translate a human readable machine name into an IP address. The DNS security extensions (DNSSEC) has been designed to protect the DNS protocol using public key cryptography and digital signatures. Every secure DNS zone owns at least a key pair (public/private) to provide two security services: data integrity and authentication. To trust some DNS data, a DNS client has to verify the signature of this data with the right zone key. This verification is based on the establishment of a chain of trust. To build this chain of trust, a DNSSEC client needs a secure entry point: a zone key configured as trusted in the client. In this paper, we study the management problem of this kind of key also call the trusted key rollover problem. We propose a new resource record (RR) to automate this rollover and avoid the inconsistency problem between the resolver key set and the name server key set. Without our new record and solution, this problem needs an administrator action to be solved.
Keywords: DNSSEC, network security, key management, key rollover
DOI: 10.3233/JCS-2009-0343
Journal: Journal of Computer Security, vol. 17, no. 6, pp. 839-854, 2009
IOS Press, Inc.
6751 Tepper Drive
Clifton, VA 20124
USA
Tel: +1 703 830 6300
Fax: +1 703 830 2300
sales@iospress.com
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
IOS Press
Nieuwe Hemweg 6B
1013 BG Amsterdam
The Netherlands
Tel: +31 20 688 3355
Fax: +31 20 687 0091
info@iospress.nl
For editorial issues, permissions, book requests, submissions and proceedings, contact the Amsterdam office info@iospress.nl
Inspirees International (China Office)
Ciyunsi Beili 207(CapitaLand), Bld 1, 7-901
100025, Beijing
China
Free service line: 400 661 8717
Fax: +86 10 8446 7947
china@iospress.cn
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
如果您在出版方面需要帮助或有任何建, 件至: editorial@iospress.nl