Securing DNSSEC Keys via Threshold ECDSA From Generic MPC

Securing DNSSEC Keys via Threshold ECDSA From Generic MPC
复制标题

DOI:
10.1007/978-3-030-59013-0_32
复制
发表时间:
2020-09
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Anders Dalskov;Marcel Keller;Claudio Orlandi;Kris Shrishak;Haya Shulman
Anders Dalskov;Marcel Keller;Claudio Orlandi;Kris Shrishak;Haya Shulman
中科院分区:
其他
文献类型:
--
作者:
Anders Dalskov;Marcel Keller;Claudio Orlandi;Kris Shrishak;Haya Shulman

文献摘要

被引文献

相似文献

DNSSEC的部署虽然在增加,但仍然存在许多实际问题,导致错误的安全感。虽然许多域将区域管理外包,但它们还必须将DNSSEC密钥管理外包给DNS运营商,这使得运营商成为攻击者的目标。此外,DNSSEC不提供任何形式的保护的情况下,运营商本身决定提供虚假的信息,例如,如果它得到compromised.In这项工作中,我们展示了如何使用技术从阈值ECDSA:(1)保护密钥,使域不透露他们的签名密钥的DNS运营商,(2)保护DNS运营商的操作完整性。作为高度专业化的结果,阈值ECDSA的先前工作集中在有限的一组威胁模型上,到目前为止还没有考虑过分期签名生成的技术。我们的工作采取了不同的方法,并提出了一种通用的技术,从一个适当的有限域上工作的安全多方计算协议获得一个阈值ECDSA协议。我们展示了这种技术是如何通过将其与学术界和工业界最先进的协议进行比较来实现非常高效的阈值签名协议的。对于类似的威胁模型,我们的协议在签名方面与以前的最佳协议一样快,并且在快速网络上生成密钥的速度快了一个数量级。最后,我们展示了如何将我们的应用程序集成到一个广泛使用的DNS管理软件,并通过实验证明与传统DNSSEC相比的开销。
Deployment of DNSSEC, although increasing, still suffers from many practical issues that results in a false sense of security. While many domains outsource zone management, they also have to outsource DNSSEC key management to the DNS operator, making the operator an attractive target for attackers. Moreover, DNSSEC does not provide any sort of protection in the case the operator itself decides to serve false information, for example, if it gets compromised.In this work, we show how to use techniques from threshold ECDSA: (1) to protect keys such that domains do not reveal their signing keys to a DNS operator, and (2) to protect the operational integrity of DNS operator. As a result of being highly specialized, prior work on threshold ECDSA has focused on a limited set of threat models, and none have so far considered techniques to amortize signature generation. Our work takes a different approach and presents agenerictechnique for obtaining a threshold ECDSA protocol fromanysecure multiparty computation protocol that works over an appropriate finite field. We show how this technique lends itself to very efficient threshold signing protocols by comparing it against state-of-the-art protocols from both academia and industry. For similar threat models, our protocols are as fast as the previous best protocol in terms of signing, and up to an order of magnitude faster for key generation on a fast network. Finally, we show how to integrate our application into a widely used DNS management software and demonstrate through experiments the overhead compared to traditional DNSSECs.