ODoQ: Oblivious DNS-over-QUIC

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Kulkarni, Aditya, Das, Tamal, Balachandran, Vivek
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914187099242496
author Kulkarni, Aditya
Das, Tamal
Balachandran, Vivek
author_facet Kulkarni, Aditya
Das, Tamal
Balachandran, Vivek
contents The Domain Name System (DNS), which converts domain names to their respective IP addresses, has advanced enhancements aimed at safeguarding DNS data and users' identity from attackers. The recent privacy-focused advancements have enabled the IETF to standardize several protocols. Nevertheless, these protocols tend to focus on either strengthening user privacy (like Oblivious DNS and Oblivious DNS-over-HTTPS) or reducing resolution latency (as demonstrated by DNS-over-QUIC). Achieving both within a single protocol remains a key challenge, which we address in this paper. Our proposed protocol -- 'Oblivious DNS-over-QUIC' (ODoQ) -- leverages the benefits of the QUIC protocol and incorporates an intermediary proxy server to protect the client's identity from exposure to the recursive resolver.
format Preprint
id arxiv_https___arxiv_org_abs_2509_11123
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle ODoQ: Oblivious DNS-over-QUIC
Kulkarni, Aditya
Das, Tamal
Balachandran, Vivek
Cryptography and Security
The Domain Name System (DNS), which converts domain names to their respective IP addresses, has advanced enhancements aimed at safeguarding DNS data and users' identity from attackers. The recent privacy-focused advancements have enabled the IETF to standardize several protocols. Nevertheless, these protocols tend to focus on either strengthening user privacy (like Oblivious DNS and Oblivious DNS-over-HTTPS) or reducing resolution latency (as demonstrated by DNS-over-QUIC). Achieving both within a single protocol remains a key challenge, which we address in this paper. Our proposed protocol -- 'Oblivious DNS-over-QUIC' (ODoQ) -- leverages the benefits of the QUIC protocol and incorporates an intermediary proxy server to protect the client's identity from exposure to the recursive resolver.
title ODoQ: Oblivious DNS-over-QUIC
topic Cryptography and Security
url https://arxiv.org/abs/2509.11123