PDoT: Private DNS-over-TLS with TEE Support

09/25/2019
by   Yoshimichi Nakatsuka, et al.
0

Security and privacy of the Internet Domain Name System (DNS) have been longstanding concerns. Recently, there is a trend to protect DNS traffic using Transport Layer Security (TLS). However, at least two major issues remain: (1) how do clients authenticate DNS-over-TLS endpoints in a scalable and extensible manner; and (2) how can clients trust endpoints to behave as expected? In this paper, we propose a novel Private DNS-over-TLS (PDoT ) architecture. PDoT includes a DNS Recursive Resolver (RecRes) that operates within a Trusted Execution Environment (TEE). Using Remote Attestation, DNS clients can authenticate, and receive strong assurance of trustworthiness of PDoT RecRes. We provide an open-source proof-of-concept implementation of PDoT and use it to experimentally demonstrate that its latency and throughput match that of the popular Unbound DNS-over-TLS resolver.

READ FULL TEXT
research
09/04/2019

A Tale of Two Trees: One Writes, and Other Reads. Optimized Oblivious Accesses to Large-Scale Blockchains

The Bitcoin network has offered a new way of securely performing financi...
research
08/19/2021

2PPS – Publish/Subscribe with Provable Privacy

Publish/Subscribe systems like Twitter and Reddit let users communicate ...
research
10/15/2021

HTTPA: HTTPS Attestable Protocol

Hypertext Transfer Protocol Secure (HTTPS) protocol has become integral ...
research
11/18/2022

Trusted Hart for Mobile RISC-V Security

The majority of mobile devices today are based on Arm architecture that ...
research
12/20/2020

Hashcashed Reputation with Application in Designing Watchtowers

We propose a novel reputation system to stimulate well-behaviour, and co...
research
08/19/2021

F-PKI: Enabling Innovation and Trust Flexibility in the HTTPS Public-Key Infrastructure

We present F-PKI, an enhancement to the HTTPS public-key infrastructure ...
research
01/31/2021

A Trust-Based Approach for Volunteer-Based Distributed Computing in the Context of Biological Simulation

As simulating complex biological processes become more important for mod...

Please sign up or login with your details

Forgot password? Click here to reset