Transparent Attested DNS for Confidential Computing Services

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Delignat-Lavaud, Antoine, Fournet, Cédric, Vaswani, Kapil, Costa, Manuel, Clebsch, Sylvan, Wintersteiger, Christoph M.
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912282082017280
author Delignat-Lavaud, Antoine
Fournet, Cédric
Vaswani, Kapil
Costa, Manuel
Clebsch, Sylvan
Wintersteiger, Christoph M.
author_facet Delignat-Lavaud, Antoine
Fournet, Cédric
Vaswani, Kapil
Costa, Manuel
Clebsch, Sylvan
Wintersteiger, Christoph M.
contents Confidential services running in hardware-protected Trusted Execution Environments (TEEs) can provide higher security assurance, but this requires custom clients and protocols to distribute, update, and verify their attestation evidence. Compared with classic Internet security, built upon universal abstractions such as domain names, origins, and certificates, this puts a significant burden on service users and providers. In particular, Web browsers and other legacy clients do not get the same security guaranties as custom clients. We present a new approach for users to establish trust in confidential services. We propose attested DNS (aDNS): a name service that securely binds the attested implementation of confidential services to their domain names. ADNS enforces policies for all names in its zone of authority: any TEE that runs a service must present hardware attestation that complies with the domain-specific policy before registering keys and obtaining certificates for any name in this domain. ADNS provides protocols for zone delegation, TEE registration, and certificate issuance. ADNS builds on standards such as DNSSEC, DANE, ACME and Certificate Transparency. ADNS provides DNS transparency by keeping all records, policies, and attestations in a public append-only log, thereby enabling auditing and preventing targeted attacks. We implement aDNS as a confidential service using a fault-tolerant network of TEEs. We evaluate it using sample confidential services that illustrate various TEE platforms. On the client side, we provide a generic browser extension that queries and verifies attestation records before opening TLS connections, with negligible performance overhead, and we show that, with aDNS, even legacy Web clients benefit from confidential computing as long as some enlightened clients verify attestations to deter or blame malicious actors.
format Preprint
id arxiv_https___arxiv_org_abs_2503_14611
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Transparent Attested DNS for Confidential Computing Services
Delignat-Lavaud, Antoine
Fournet, Cédric
Vaswani, Kapil
Costa, Manuel
Clebsch, Sylvan
Wintersteiger, Christoph M.
Cryptography and Security
Networking and Internet Architecture
68M25
Confidential services running in hardware-protected Trusted Execution Environments (TEEs) can provide higher security assurance, but this requires custom clients and protocols to distribute, update, and verify their attestation evidence. Compared with classic Internet security, built upon universal abstractions such as domain names, origins, and certificates, this puts a significant burden on service users and providers. In particular, Web browsers and other legacy clients do not get the same security guaranties as custom clients. We present a new approach for users to establish trust in confidential services. We propose attested DNS (aDNS): a name service that securely binds the attested implementation of confidential services to their domain names. ADNS enforces policies for all names in its zone of authority: any TEE that runs a service must present hardware attestation that complies with the domain-specific policy before registering keys and obtaining certificates for any name in this domain. ADNS provides protocols for zone delegation, TEE registration, and certificate issuance. ADNS builds on standards such as DNSSEC, DANE, ACME and Certificate Transparency. ADNS provides DNS transparency by keeping all records, policies, and attestations in a public append-only log, thereby enabling auditing and preventing targeted attacks. We implement aDNS as a confidential service using a fault-tolerant network of TEEs. We evaluate it using sample confidential services that illustrate various TEE platforms. On the client side, we provide a generic browser extension that queries and verifies attestation records before opening TLS connections, with negligible performance overhead, and we show that, with aDNS, even legacy Web clients benefit from confidential computing as long as some enlightened clients verify attestations to deter or blame malicious actors.
title Transparent Attested DNS for Confidential Computing Services
topic Cryptography and Security
Networking and Internet Architecture
68M25
url https://arxiv.org/abs/2503.14611