From the Beginning: Key Transitions in the First 15 Years of DNSSEC

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Osterweil, Eric, Tehrani, Pouyan Fotouhi, Schmidt, Thomas C., Wählisch, Matthias
Format: Preprint
Published: 2021
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909310882152448
author Osterweil, Eric
Tehrani, Pouyan Fotouhi
Schmidt, Thomas C.
Wählisch, Matthias
author_facet Osterweil, Eric
Tehrani, Pouyan Fotouhi
Schmidt, Thomas C.
Wählisch, Matthias
contents When the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magnified in favor of better security for the overall Internet. Thereby, the scale of the loosely-federated delegation in DNS became an unprecedented cryptographic key management challenge. Though fundamental for current and future operational success, our community lacks a clear notion of how to empirically evaluate the process of securely transitioning keys. In this paper, we propose two building blocks to formally characterize and assess key transitions. First, the anatomy of key transitions, i.e., measurable and well-defined properties of key changes; and second, a novel classification model based on this anatomy for describing key transition practices in abstract terms. This abstraction allows for classifying operational behavior. We apply our proposed transition anatomy and transition classes to describe the global DNSSEC deployment. Specifically, we use measurements from the first 15 years of the DNSSEC rollout to detect and understand which key transitions have been used to what degree and which rates of errors and warnings occurred. In contrast to prior work, we consider all possible transitions and not only 1:1 key rollovers. Our results show measurable gaps between prescribed key management processes and key transitions in the wild. We also find evidence that such noncompliant transitions are needed in operations.
format Preprint
id arxiv_https___arxiv_org_abs_2109_08783
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle From the Beginning: Key Transitions in the First 15 Years of DNSSEC
Osterweil, Eric
Tehrani, Pouyan Fotouhi
Schmidt, Thomas C.
Wählisch, Matthias
Cryptography and Security
Networking and Internet Architecture
C.2
When the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magnified in favor of better security for the overall Internet. Thereby, the scale of the loosely-federated delegation in DNS became an unprecedented cryptographic key management challenge. Though fundamental for current and future operational success, our community lacks a clear notion of how to empirically evaluate the process of securely transitioning keys. In this paper, we propose two building blocks to formally characterize and assess key transitions. First, the anatomy of key transitions, i.e., measurable and well-defined properties of key changes; and second, a novel classification model based on this anatomy for describing key transition practices in abstract terms. This abstraction allows for classifying operational behavior. We apply our proposed transition anatomy and transition classes to describe the global DNSSEC deployment. Specifically, we use measurements from the first 15 years of the DNSSEC rollout to detect and understand which key transitions have been used to what degree and which rates of errors and warnings occurred. In contrast to prior work, we consider all possible transitions and not only 1:1 key rollovers. Our results show measurable gaps between prescribed key management processes and key transitions in the wild. We also find evidence that such noncompliant transitions are needed in operations.
title From the Beginning: Key Transitions in the First 15 Years of DNSSEC
topic Cryptography and Security
Networking and Internet Architecture
C.2
url https://arxiv.org/abs/2109.08783