Double-Signed Fragmented DNSSEC for Countering Quantum Threat
Syed W. Shah. Lei Pan, Din Duc Nha Nguyen, Robin Doss, Warren Armstrong, Praveen Gauravaram

TL;DR
This paper proposes a double-signature DNSSEC scheme combining classical and post-quantum signatures, using application-layer fragmentation to mitigate size issues, enhancing security against quantum threats without significantly impacting resolution efficiency.
Contribution
It introduces a double-signature DNSSEC approach with fragmentation to counter quantum threats, addressing size constraints and demonstrating practical feasibility.
Findings
Double-signatures provide enhanced security against quantum and non-quantum attacks.
Application-layer fragmentation effectively manages larger DNSSEC responses.
Implementation shows minimal impact on resolution performance.
Abstract
DNSSEC, a DNS security extension, is essential to accurately translating domain names to IP addresses. Digital signatures provide the foundation for this reliable translation; however, the evolution of 'Quantum Computers' has made traditional digital signatures vulnerable. In light of this, NIST has recently selected potential post-quantum digital signatures that can operate on conventional computers and resist attacks made with Quantum Computers. Since these post-quantum digital signatures are still in their early stages of development, replacing pre-quantum digital signature schemes in DNSSEC with post-quantum candidates is risky until the post-quantum candidates have undergone a thorough security analysis. Given this, herein, we investigate the viability of employing 'Double-Signatures' in DNSSEC, combining a post-quantum digital signature and a classic one. The rationale is that…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDiamond and Carbon-based Materials Research · Advancements in Semiconductor Devices and Circuit Design · Security and Verification in Computing
