首页    期刊浏览 2024年11月30日 星期六
登录注册

文章基本信息

  • 标题:Implementing DNSSEC soft delegation for microservices
  • 本地全文:下载
  • 作者:Andres Marin-Lopez ; Patricia Arias-Cabarcos ; Thorsten Strufe
  • 期刊名称:Electronic Communications of the EASST
  • 电子版ISSN:1863-2122
  • 出版年度:2021
  • 卷号:80
  • DOI:10.14279/tuj.eceasst.80.1165
  • 语种:English
  • 出版社:European Association of Software Science and Technology (EASST)
  • 摘要:Securing DNS in Edge- and Fog computing, or other scenarios where microservices are offloaded, requires the provision of zone signing keys to the third parties who control the computing infrastructure. This fundamentally allows the infrastructure provider to create novel signatures at their discretion and even arbitrarily extend the certificate chain.Based on our proposal on soft delegation for DNSSEC, which curtails this vulnerability, we report on our proof-of-concept: a C-implementation of chameleon hashes in OpenSSL, a server side implementation of the mechanism in the ldns server, and an offline client that validates the signed records, in this paper. We also discuss different approaches for generating DNSSEC RRSIG records, and the behavior of a resolver to verify the credentials and securely connect to an end point using TLS with SNI and DANE.
  • 关键词:DNSSEC;DANE;chameleon signatures;IoT;microservices;Fog computing
国家哲学社会科学文献中心版权所有