From the Beginning: Key Transitions in the First 15 Years of DNSSEC

dc.contributor.authorOsterweil, Eric
dc.contributor.authorTehrani, Pouyan Fotouhi
dc.contributor.authorSchmidt, Thomas C.
dc.contributor.authorWahlisch, Matthias
dc.date.accessioned2023-09-19T15:27:36Z
dc.date.available2023-09-19T15:27:36Z
dc.date.issued2022
dc.description.abstractWhen the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magni- fied in favor of better security for the overall Internet. Thereby, the scale of the loosely-federated delegation in DNS became an unprecedented cryptographic key management challenge. Though fundamental for current and future operational success, our community lacks a clear notion of how to empirically eval- uate the process of securely transitioning keys. In this paper, we propose two building blocks to formally characterize and assess key transitions. First, the anatomy of key transitions, i.e., mea- surable and well-defined properties of key changes; and second, a novel classification model based on this anatomy for describing key transition practices in abstract terms. This abstraction allows for classifying operational behavior. We apply our proposed transition anatomy and transition classes to describe the global DNSSEC deployment. Specifically, we use measurements from the first 15 years of the DNSSEC rollout to detect and under- stand which key transitions have been used to what degree and which rates of errors and warnings occurred. In contrast to prior work, we consider all possible transitions and not only 1:1 key rollovers. Our results show measurable gaps between prescribed key management processes and key transitions in the wild. We also find evidence that such noncompliant transitions are needed in operations.en
dc.identifier.citationOsterweil, E., Tehrani, P. F., Schmidt, T. C., & Wahlisch, M. (2022). From the Beginning: Key Transitions in the First 15 Years of DNSSEC. IEEE Transactions on Network and Service Management, 19(4), 5265–5283. https://doi.org/10.1109/TNSM.2022.3195406
dc.identifier.doihttps://doi.org/10.1109/tnsm.2022.3195406
dc.identifier.issn1932-4537
dc.identifier.issn2373-7379
dc.identifier.urihttps://www.weizenbaum-library.de/handle/id/316
dc.language.isoeng
dc.rightsopen access
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.titleFrom the Beginning: Key Transitions in the First 15 Years of DNSSEC
dc.typeArticle
dc.type.statuspublishedVersion
dcmi.typeText
dcterms.bibliographicCitation.booktitleIEEE Transactions on Network and Service Management
dcterms.bibliographicCitation.doi10.1109/TNSM.2022.3195406
dcterms.bibliographicCitation.issue4
dcterms.bibliographicCitation.journaltitleIEEE Transactions on Network and Service Management
dcterms.bibliographicCitation.pageend5283
dcterms.bibliographicCitation.pagestart5265
dcterms.bibliographicCitation.urlhttps://ieeexplore.ieee.org/document/9845707/
dcterms.bibliographicCitation.volume19
local.researchgroupDigitalisierung und vernetzte Sicherheit
local.researchtopicDigitale Infrastrukturen in der Demokratie
Dateien
Originalbündel
Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
Tehrani_From-the-beginning.pdf
Größe:
4.31 MB
Format:
Adobe Portable Document Format
Beschreibung: