DC FieldValueLanguage
dc.contributor.authorOsterweil, Eric-
dc.contributor.authorTehrani, Pouyan Fotouhi-
dc.contributor.authorSchmidt, Thomas C.-
dc.contributor.authorWählisch, Matthias-
dc.date.accessioned2022-02-11T11:47:51Z-
dc.date.available2022-02-11T11:47:51Z-
dc.date.issued2022-
dc.identifier.citationPreprint: https://arxiv.org/abs/2109.08783. Verlagsversion: https://doi.org/10.1109/TNSM.2022.3195406.en_US
dc.identifier.issn1932-4537en_US
dc.identifier.urihttp://hdl.handle.net/20.500.12738/12389-
dc.description.abstractWhen the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, it started a first-of-its-kind trial: increasing complexity of a core Internet protocol in favor of better security for the overall Internet. The necessary cryptographic key management is made particularly challenging by DNS' loosely-federated delegation substrate and unprecedented cryptographic scale. Though fundamental for current and future operational success, our community lacks a clear notion of how to empirically evaluate the process of securely changing (or transitioning) keys. In this paper, we propose two building blocks to fundamentally understand and assess key transitions. First, the anatomy of key transitions: measurable and well-defined properties of key changes; and second a novel classification model based on this anatomy to describe key transitions practices in abstract terms. Our anatomy enables the evaluation of cryptographic keys' life cycles in general, and comparison of operational practices with prescribed key management processes, e.g., RFC key rollover guidelines. The fine-grained transition anatomy is then abstracted through our classification model to characterize transitions in abstract terms which rather describe a transition's behavior than its specific features. The applicability and utility of our proposed transition anatomy and transition classes are exemplified for the global DNSSEC deployment. Specifically, we use measurements from the first 15 years of the DNSSEC rollout to detect and measure which key rollover/transitions have been used, to what degree, and what their rates of errors and warnings have been. Our results show measurable gaps between prescribed key management processes and key transitions in the wild. We also find evidence that such noncompliant transitions are inevitable in the wild.en
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofIEEE transactions on network and service managementen_US
dc.subjectCryptographyen_US
dc.subjectDNSSECen_US
dc.subjectDomain Name Systemen_US
dc.subjectInformation securityen_US
dc.subjectInterneten_US
dc.subjectInternet measurementen_US
dc.subjectkey rolloveren_US
dc.subjectMonitoringen_US
dc.subjectPKIen_US
dc.subjectRolloveren_US
dc.subjectSea measurementsen_US
dc.subjectSecurityen_US
dc.subjectServersen_US
dc.subject.ddc004: Informatiken_US
dc.titleFrom the beginning: key transitions in the first 15 years of DNSSECen
dc.typeArticleen_US
dc.description.versionPeerRevieweden_US
tuhh.container.endpage5283en_US
tuhh.container.issue4en_US
tuhh.container.startpage5265en_US
tuhh.container.volume19en_US
tuhh.oai.showtrueen_US
tuhh.publication.instituteDepartment Informatiken_US
tuhh.publication.instituteFakultät Technik und Informatiken_US
tuhh.publisher.doi10.1109/TNSM.2022.3195406-
tuhh.publisher.urlhttps://arxiv.org/abs/2109.08783-
tuhh.type.opus(wissenschaftlicher) Artikel-
dc.rights.cchttps://creativecommons.org/licenses/by/4.0/en_US
dc.type.casraiJournal Article-
dc.type.diniarticle-
dc.type.driverarticle-
dc.type.statusinfo:eu-repo/semantics/publishedVersionen_US
dcterms.DCMITypeText-
item.creatorGNDOsterweil, Eric-
item.creatorGNDTehrani, Pouyan Fotouhi-
item.creatorGNDSchmidt, Thomas C.-
item.creatorGNDWählisch, Matthias-
item.fulltextNo Fulltext-
item.creatorOrcidOsterweil, Eric-
item.creatorOrcidTehrani, Pouyan Fotouhi-
item.creatorOrcidSchmidt, Thomas C.-
item.creatorOrcidWählisch, Matthias-
item.grantfulltextnone-
item.cerifentitytypePublications-
item.languageiso639-1en-
item.openairecristypehttp://purl.org/coar/resource_type/c_6501-
item.openairetypeArticle-
crisitem.author.deptDepartment Informatik-
crisitem.author.orcid0000-0002-0956-7885-
crisitem.author.parentorgFakultät Technik und Informatik-
Appears in Collections:Publications without full text
Show simple item record

Page view(s)

186
checked on Dec 26, 2024

Google ScholarTM

Check

HAW Katalog

Check

Add Files to Item

Note about this record


This item is licensed under a Creative Commons License Creative Commons