Journal of Networks, Vol 3, No 6 (2008), 54-61, Jun 2008
doi:10.4304/jnw.3.6.54-61
Key Revocation System for DNSSEC
Abstract
The Doma in Name System (DNS) is a distributed tree-based database largely used to translate a human readable machine name into an IP address. The DNS security extensions (DNSSEC) has been designed to protect the DNS protocol using public key cryptography and digital signatures. In this paper, we show how DNSSEC can be attacked using compromised keys and the consequences of such attacks. Then, we propose a new revocation scheme for DNSSEC based on two new resource records. There is currently no revocation system defined in the DNSSEC standard.
Keywords
DNSSEC, Revocation, Key Management, Network Security
References
Full Text: PDF


