Skip to main content

2018 | OriginalPaper | Buchkapitel

Domain Name System Without Root Servers

verfasst von : Matthäus Wander, Christopher Boelmann, Torben Weis

Erschienen in: Risks and Security of Internet and Systems

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

We present a variation to the infrastructure of the Domain Name System (DNS) that works without DNS root servers. This allows to switch from a centralized trust model (root) to a decentralized trust model (top-level domains). By dropping DNS root in our approach, users have one entity less that they must trust. Besides trust issues, not relying on DNS root means that DNS root servers are no longer a central point of failure. Our approach is minimally invasive, builds on established DNS architecture and protocols and supports the DNS Security Extensions (DNSSEC). Furthermore, we designed our approach as an opt-in technology. Thus, each top-level domain operator can decide whether to support rootless DNS or not.
The challenge of a rootless DNS is to keep track of changing IP addresses of top-level domain servers and to handle key rollovers, which are part of normal DNSSEC operation. Top-level domains opting in to rootless DNS must follow constraints regarding the frequency of changes of IP addresses and DNSSEC keys. We conducted a four-year measurement to show that 82% respectively 72% of top-level domains fulfill these constraints already.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
7.
Zurück zum Zitat Lentz, M., Levin, D., Castonguay, J., Spring, N., Bhattacharjee, B.: D-mystifying the D-root address change. In: Proceedings of the 2013 Conference on Internet Measurement Conference, IMC 2013, pp. 57–62. ACM, New York (2013) Lentz, M., Levin, D., Castonguay, J., Spring, N., Bhattacharjee, B.: D-mystifying the D-root address change. In: Proceedings of the 2013 Conference on Internet Measurement Conference, IMC 2013, pp. 57–62. ACM, New York (2013)
9.
Zurück zum Zitat Mueller, M.L.: Competing DNS roots: creative destruction or just plain destruction. J. Netw. Ind. 3, 313 (2002)CrossRef Mueller, M.L.: Competing DNS roots: creative destruction or just plain destruction. J. Netw. Ind. 3, 313 (2002)CrossRef
11.
Zurück zum Zitat Ramasubramanian, V., Sirer, E.G.: The design and implementation of a next generation name service for the internet. In: ACM SIGCOMM Computer Communication Review, vol. 34, no. 4, pp. 331–342. ACM (2004) Ramasubramanian, V., Sirer, E.G.: The design and implementation of a next generation name service for the internet. In: ACM SIGCOMM Computer Communication Review, vol. 34, no. 4, pp. 331–342. ACM (2004)
12.
14.
Zurück zum Zitat Theimer, M., Jones, M.: Overlook: scalable name service on an overlay network. In: Proceedings of the 22nd International Conference on Distributed Computing Systems, pp. 52–61 (2002) Theimer, M., Jones, M.: Overlook: scalable name service on an overlay network. In: Proceedings of the 22nd International Conference on Distributed Computing Systems, pp. 52–61 (2002)
15.
16.
Zurück zum Zitat Massey, D., Lewis, E., Gudmundsson, O., Mundy, R., Mankin, A.: Public key validation for the DNS security extensions. In: Proceedings of the DARPA Information Survivability Conference & amp; Exposition II, DISCEX 2001, vol. 1, pp. 227–238. IEEE (2001) Massey, D., Lewis, E., Gudmundsson, O., Mundy, R., Mankin, A.: Public key validation for the DNS security extensions. In: Proceedings of the DARPA Information Survivability Conference & amp; Exposition II, DISCEX 2001, vol. 1, pp. 227–238. IEEE (2001)
17.
Zurück zum Zitat Malone, D.: The root of the matter: hints or slaves. In: Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement, IMC 2004, pp. 15–20. ACM, New York (2004) Malone, D.: The root of the matter: hints or slaves. In: Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement, IMC 2004, pp. 15–20. ACM, New York (2004)
18.
Zurück zum Zitat Kuerbis, B., Mueller, M.: Securing the root: a proposal for distributing signing authority. Paper IGP07-002 (2007) Kuerbis, B., Mueller, M.: Securing the root: a proposal for distributing signing authority. Paper IGP07-002 (2007)
Metadaten
Titel
Domain Name System Without Root Servers
verfasst von
Matthäus Wander
Christopher Boelmann
Torben Weis
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-76687-4_14