DNSSEC (Domain Name System Security Extensions) is designed to provide security functions for the current DNS protocol. However, DNSSEC yet has low deployment rate in the Internet due to its heavy workload on DNS full resolvers and high administrative cost. Furthermore, DNSSEC does not cover the last one mile in name resolution: between the DNS full resolver and client. In order to provide complete DNSSEC service between authoritative zone servers and clients, a new DNSSEC validation mechanism with acceptable workload on DNS full resolver and client is required. In this paper, we propose an advanced client based DNSSEC validation mechanism and compare the DNSSEC performance between DNS full resolver and client based on evaluations in a local experimental network. By validating DNSSEC on each client, the proposed mechanism can reduce the workload of DNS full resolvers and also can provide secure name resolution for each client. According to the results of preliminary evaluations we confirmed that it is possible to reduce the workload of DNS full resolver by transferring the DNSSEC validation process to clients with acceptable extra workload. More importantly, the benefit of DNSSEC can be extended to clients with secure name resolution service.
[1]
Paul Vixie,et al.
Extension Mechanisms for DNS (EDNS0)
,
1999,
RFC.
[2]
Daniel Migault,et al.
A performance view on DNSSEC migration
,
2010,
2010 International Conference on Network and Service Management.
[3]
Daniel Migault,et al.
Overcoming DNSSEC performance issues with DHT-based architectures
,
2013,
2013 IFIP/IEEE International Symposium on Integrated Network Management (IM 2013).
[4]
Daniel J. Bernstein,et al.
Curve25519: New Diffie-Hellman Speed Records
,
2006,
Public Key Cryptography.
[5]
Paul V. Mockapetris,et al.
Domain names: Concepts and facilities
,
1983,
RFC.
[6]
Michael Graff,et al.
Extension Mechanisms for DNS (EDNS(0))
,
2013,
Request for Comments.
[7]
Scott Rose,et al.
DNS Security Introduction and Requirements
,
2005,
RFC.
[8]
Paul V. Mockapetris,et al.
Domain names - implementation and specification
,
1987,
RFC.